Configuration Steps for Entra ID (Azure AD) - Lepide Trust

1. Configure the Entra ID (Azure AD) Component

1.1 Register an App and Generate the Client ID and Secret Key for Entra ID (Azure AD) Current Permissions Analysis (CPA)

NOTE: Copy the Client ID and Secret value for adding a Microsoft 365 component for Entra ID

  • Click on the API permission tab for the given Client ID and select Add a Permission

1.2 Permissions for Current Permissions Analysis (CPA)

Exchange.ManageAsApp

Application

NOTE: Every permission change required must be granted admin consent

Now add the components with Client ID and Secret Key Analysis for Azure

2. Add a Data Set for Azure Active Directory

NOTE: The data set for Azure Active Directory is added in the main console and the steps to do this are explained below. The output reports are only available in the Web Console.

  • From the Settings Screen

  • Select the Current Permission Scan Settings option:

A screenshot of a computer

Description automatically generated
Current Permission Scan Settings

  • Create a new Data Set Profile by clicking the (+) icon and give the Data Set a name

A screenshot of a computer screen

Description automatically generated
Add a Data Set Name

  • Click Next

  • Select Azure AD and add the Credentials:

A screenshot of a computer

Description automatically generated
Add Component and Server Information

  • Click Validate Credentials and the Credentials will validate:

A screenshot of a computer

Description automatically generated
Validate Credentials
  • Once the Credentials are Successfully verified, the Scan options dialog is displayed:

A screenshot of a computer screen

AI-generated content may be incorrect.
Scan Options
  • Here, you can select from the following options:

    • Scan Now: Check this box to start the Permission scan immediately

    • Schedule Scan: Check this box and click Change Schedule to specify a time to run the scan

    • Scan on Remote Agent: Check this box to run the Scan on a Remote Agent. This is explained further in the following section.

Running a Permission Scan using a Remote Agent

A permission scan can be configured to run using a remote agent. This can be done while setting up a new profile or when modifying a profile and is explained as follows:

  • From the Add a Data Set Wizard, in the Scan Options dialog box, there is a check box for Scan on Remote Agent:

A screenshot of a computer screen

AI-generated content may be incorrect.
Permission Scanning Options

  • Check this box to run the permission scan on a remote agent

  • Once the Scan on Remote Agent box is checked, the Agent Location/IP option becomes available to enter the IP/Agent Location

  • There is also a

    Add Agent
    icon next to the Agent Location/Ip option

  • Click on the

    icon and an Add Agent dialog box will be displayed with four fields: IP Address, Agent Path, Username, Password:

A screenshot of a computer

Description automatically generated
  • Enter the Agent details and click OK when finished