> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning Microsoft 365

> Capturing the Microsoft tenant through an Entra ID app registration – choose the app, verify access, watch the expiry dates.

The *Microsoft 365* module addresses no addresses in your network but your
Microsoft tenant. Instead of targets and passwords it therefore requires exactly
one entry: the **Entra ID app registration** through which access happens.

<Note>
  A cloud scan runs over a gateway as well: the *Basics* step requires a gateway
  and a job name for every module.
</Note>

The wizard shows four steps for this module:

*Basics* › *Entra ID App* › *Schedule* › *Summary*

All but *Entra ID App* are the same for every module – see
[Creating a Scan Job](/docs/en/scan/create-inventory).

## Preparing the app registration

Access hangs on an app registration in your Microsoft tenant. You manage it under
*Scan › Credentials* as an entry of the type *Entra ID App* – either you bring an
existing app or Docusnap365 registers a new one after you sign in.

<Steps>
  <Step title="Create the entry">
    *Scan › Credentials*, *Credentials* button, as *Type* *Entra ID App*. Either
    an existing app with application ID and client secret or certificate, or a
    new app – it is then created in your tenant after you sign in in the pop-up.
  </Step>

  <Step title="Verify access">
    Select the entry and use *Verify* in the selection bar. It shows whether
    the app is available, whether the *Global Reader Role* is assigned, until when
    certificate and client secret apply and which permissions are granted.
  </Step>

  <Step title="Add what is missing">
    If something is not right, correct it in the tenant and verify again. Through
    *Update Entra ID App Registration* Docusnap365 renews the certificate and
    secret of the app.
  </Step>
</Steps>

<Note>
  Signing in to Microsoft runs in a pop-up. If the browser blocks it, Docusnap365
  reports that the sign-in window was blocked and that pop-ups have to be allowed
  for this page. If you close the window yourself, that counts as a cancellation –
  then **no** message appears.
</Note>

<Tip>
  Run *Verify* **before** you create the job. The wizard only checks whether an app
  is chosen – whether it may actually read in the tenant is told to you only by the
  verification.
</Tip>

## Creating the job

In the *Entra ID App* step you choose the prepared entry in a searchable picker;
the second line per entry names the tenant. If the entry is missing, you create
it through the creation row directly here – there are no one-time credentials
here, an Entra ID app always lies in the *Vault*. Without a selection the step
stops.

After that only *Schedule* and *Summary* follow. This module enters no targets –
the scope follows from what the app is allowed to see in the tenant.

## Watching the expiry dates

Client secrets and certificates expire, and access with them. The dashboard tile
*Credentials Expiring* in the *Action Required* section counts the entries that
have expired or expire within the next five days and jumps to *Scan ›
Credentials*. It names only the number, no names.

Which entry is affected you see in the *Scan › Credentials* list in the
*Expiration Date* column – sort by it to bring the urgent ones to the top.

<Tip>
  Renew access through *Verify › Update Entra ID App Registration* as soon as an
  expiration date draws near. The operation verifies again automatically afterwards,
  so that the new validity dates stand in the dialog immediately. The job itself
  stays unchanged.
</Tip>

<Note>
  Saving an entry can be cancelled; the entry may then not have been created. Check
  the list in that case before you try again.
</Note>

## Deleting an entry

When deleting a single row in *Scan › Credentials*, Docusnap365 asks whether the
app registration is to be removed **in Azure as well**. That requires signing in
to Microsoft and deletes the registration in the tenant; without that checkbox
only the entry disappears from the *Vault*.

The bulk deletion through the checkboxes offers this choice as well, as soon as
the selection contains at least one *Entra ID App*. The checkbox then applies to
all Entra ID apps in the selection together; each one requires its own sign-in to
Microsoft, so the pop-ups appear one after another. All other entries in the
selection are removed from the *Vault* only in any case.

<Warning>
  Without that checkbox the app registration stays in your Microsoft tenant and has
  to be removed there by hand. Deleting the vault entry alone does not revoke the
  app's access.
</Warning>

Entries that lie locally on a gateway cannot be checked here at all – in this
list they are read-only.

## Related module

[**Microsoft Intune**](/docs/en/scan/microsoft-intune) uses the same step and the same
app selection. Once the entry for Microsoft 365 is prepared, an Intune job can be
created with the same app.

## Related

After the first execution the job detail shows under *Last Scan Details* what was
captured – see [Managing Jobs](/docs/en/scan/manage-jobs).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.