Before configuring Entra ID for Lepide Trust, check the following:
To see what the Prerequisites and Requirements are for Entra ID, click here:
https://www.lepide.com/knowledgebase/?page_id=3887366295&slug=prerequisites-and-requirements-entra-id-azure-adHave you added an Entra ID component? If not click here:
https://www.lepide.com/knowledgebase/?page_id=3887333453&slug=adding-a-component-entra-id-azure-ad
For information on configuring Entra ID with least privileges, click here:
https://www.lepide.com/knowledgebase/?page_id=3837722625&slug=least-privilege-configuration-for-auditing
1. Configure the Entra ID (Azure AD) Component
1.1 Register an App and Generate the Client ID and Secret Key for Entra ID (Azure AD) Current Permissions Analysis (CPA)
For information on this please use the following link and follow the steps described:
Create or Update Client IDs and Secrets
NOTE: Copy the Client ID and Secret value for adding a Microsoft 365 component for Entra ID
Click on the API permission tab for the given Client ID and select Add a Permission
1.2 Permissions for Current Permissions Analysis (CPA)
Exchange.ManageAsApp | Application |
NOTE: Every permission change required must be granted admin consent
Now add the components with Client ID and Secret Key Analysis for Azure
2. Add a Data Set for Azure Active Directory
NOTE: The data set for Azure Active Directory is added in the main console and the steps to do this are explained below. The output reports are only available in the Web Console.
From the Settings Screen
Select the Current Permission Scan Settings option:
Create a new Data Set Profile by clicking the (+) icon and give the Data Set a name
Click Next
Select Azure AD and add the Credentials:
Click Validate Credentials and the Credentials will validate:
Once the Credentials are Successfully verified, the Scan options dialog is displayed:
Here, you can select from the following options:
Scan Now: Check this box to start the Permission scan immediately
Schedule Scan: Check this box and click Change Schedule to specify a time to run the scan
Scan on Remote Agent: Check this box to run the Scan on a Remote Agent. This is explained further in the following section.
Running a Permission Scan using a Remote Agent
A permission scan can be configured to run using a remote agent. This can be done while setting up a new profile or when modifying a profile and is explained as follows:
From the Add a Data Set Wizard, in the Scan Options dialog box, there is a check box for Scan on Remote Agent:
Check this box to run the permission scan on a remote agent
Once the Scan on Remote Agent box is checked, the Agent Location/IP option becomes available to enter the IP/Agent Location
There is also a icon next to the Agent Location/Ip option
Click on the icon and an Add Agent dialog box will be displayed with four fields: IP Address, Agent Path, Username, Password:
Enter the Agent details and click OK when finished