Skip to main content
The Microsoft 365 module addresses no addresses in your network but your Microsoft tenant. Instead of targets and passwords it therefore requires exactly one entry: the Entra ID app registration through which access happens.
A cloud scan runs over a gateway as well: the Basics step requires a gateway and a job name for every module.
The wizard shows four steps for this module: Basics › Entra ID App › Schedule › Summary All but Entra ID App are the same for every module – see Creating a Scan Job.

Preparing the app registration

Access hangs on an app registration in your Microsoft tenant. You manage it under Scan › Credentials as an entry of the type Entra ID App – either you bring an existing app or Docusnap365 registers a new one after you sign in.
1

Create the entry

Scan › Credentials, Credentials button, as Type Entra ID App. Either an existing app with application ID and client secret or certificate, or a new app – it is then created in your tenant after you sign in in the pop-up.
2

Verify access

Select the entry and use Verify in the selection bar. It shows whether the app is available, whether the Global Reader Role is assigned, until when certificate and client secret apply and which permissions are granted.
3

Add what is missing

If something is not right, correct it in the tenant and verify again. Through Update Entra ID App Registration Docusnap365 renews the certificate and secret of the app.
Signing in to Microsoft runs in a pop-up. If the browser blocks it, Docusnap365 reports that the sign-in window was blocked and that pop-ups have to be allowed for this page. If you close the window yourself, that counts as a cancellation – then no message appears.
Run Verify before you create the job. The wizard only checks whether an app is chosen – whether it may actually read in the tenant is told to you only by the verification.

Creating the job

In the Entra ID App step you choose the prepared entry in a searchable picker; the second line per entry names the tenant. If the entry is missing, you create it through the creation row directly here – there are no one-time credentials here, an Entra ID app always lies in the Vault. Without a selection the step stops. After that only Schedule and Summary follow. This module enters no targets – the scope follows from what the app is allowed to see in the tenant.

Watching the expiry dates

Client secrets and certificates expire, and access with them. The dashboard tile Credentials Expiring in the Action Required section counts the entries that have expired or expire within the next five days and jumps to Scan › Credentials. It names only the number, no names. Which entry is affected you see in the Scan › Credentials list in the Expiration Date column – sort by it to bring the urgent ones to the top.
Renew access through Verify › Update Entra ID App Registration as soon as an expiration date draws near. The operation verifies again automatically afterwards, so that the new validity dates stand in the dialog immediately. The job itself stays unchanged.
Saving an entry can be cancelled; the entry may then not have been created. Check the list in that case before you try again.

Deleting an entry

When deleting a single row in Scan › Credentials, Docusnap365 asks whether the app registration is to be removed in Azure as well. That requires signing in to Microsoft and deletes the registration in the tenant; without that checkbox only the entry disappears from the Vault. The bulk deletion through the checkboxes offers this choice as well, as soon as the selection contains at least one Entra ID App. The checkbox then applies to all Entra ID apps in the selection together; each one requires its own sign-in to Microsoft, so the pop-ups appear one after another. All other entries in the selection are removed from the Vault only in any case.
Without that checkbox the app registration stays in your Microsoft tenant and has to be removed there by hand. Deleting the vault entry alone does not revoke the app’s access.
Entries that lie locally on a gateway cannot be checked here at all – in this list they are read-only. Microsoft Intune uses the same step and the same app selection. Once the entry for Microsoft 365 is prepared, an Intune job can be created with the same app. After the first execution the job detail shows under Last Scan Details what was captured – see Managing Jobs.