A Microsoft Entra ID and Microsoft 365 cloud action lets you discover user identities, groups, and license assignments across your Microsoft 365 tenant. This provides insight into identity and access management details for better asset governance.
Prerequisites
- You have completed the steps in Prepare Microsoft Cloud for Cloud Discovery
- Your Tenant ID, Application ID, and Key Vault URI are available.
Create a Microsoft 365 / Entra ID cloud action
- In your Lansweeper Site, go to Discovery > Actions.
- Select Create action.
- Select Cloud as the action type.
- In the pop-up, select Identity access - Microsoft 365 / Entra ID as the cloud source.
- Select Create.
- Enter a name and description for the action.
- Select Set up new connection, and enter your Tenant ID, Application ID, and Key Vault URI.
- Select Validate connection to confirm access to Microsoft 365 / Entra ID.
- Select Create trigger.
- Select Instant to run at a scheduled time on select days. Enter the name, time, and days you prefer.
- Select Create.
- Finally, select Save and finish.
What to expect after the action runs
After the trigger runs for the first time, Lansweeper discovers the user identities, groups, and license assignments in your Microsoft 365 tenant and adds this identity and access data to your inventory. Use it to see how users, groups, and licenses relate to the rest of your environment.
Discovery runs on the schedule you set in the trigger, so the data refreshes with each successful run.
Troubleshoot the Microsoft 365 / Entra ID cloud action
If the action doesn't return the results you expect, check the following:
- Connection validation fails. Confirm your Tenant ID, Application ID, and Key Vault URI are correct, and that federated credentials and the key vault are configured as described in Prepare Microsoft Cloud for Cloud Discovery.
- No data is discovered. In your app registration, confirm the
Organization.Read.AllandDirectory.Read.Allapplication permissions are added and that admin consent is granted. - Key vault access errors. Confirm the key vault contains the
LansweeperSiteIDsecret and that inbound access allows the Lansweeper IP ranges for your region.