Product | Lepide Auditor |
Category | SharePoint Online |
Affected Area | Lepide Auditor – SharePoint Online Component |
Version | 26.1 |
1. Overview
This article explains how to configure SharePoint Online auditing in Lepide Auditor by creating an Azure App Registration in the Entra Admin Portal. This setup allows Lepide to collect and report on all SharePoint Online activity including file access, modifications, deletions, permission changes, and site-level changes.
2. What Lepide Can Audit in SharePoint Online
Once configured, Lepide audits the following SharePoint Online activities:
Files created, modified, deleted, downloaded, or uploaded
Document library changes
Permission changes on sites, folders, or files
Site-level modifications and settings changes
User access and activity across all SharePoint sites in the organization
3. Prerequisites
Access to Azure Entra Admin Portal (Global Admin or App Registration permissions required)
SharePoint Online active in the Microsoft 365 tenant
4. Configuration Steps
Step 1: Open Entra Admin Portal
Log in to the Entra Admin Portal (entra.microsoft.com) using a Global Admin account or an account with App Registration permissions.
Step 2: Create a New App Registration
Navigate to: App Registrations > New Registration
Enter a descriptive name for the app (e.g., 'Lepide SharePoint Audit')
Leave the Redirect URI blank
Click Register
Step 3: Assign API Permissions
After the app is created, go to: API Permissions > Add a Permission Add the following permissions as required by Lepide:
After adding the permissions, click Grant Admin Consent to apply them across the entire tenant.
Step 4: Generate a Client Secret
Navigate to: Certificates & Secrets > Client Secrets > New Client Secret
Enter a description (e.g., 'Lepide SharePoint Secret')
Set an appropriate expiry period (e.g., 12 or 24 months)
Click Add
Copy and securely save the Client Secret Value immediately after creation — it will NOT be shown again once you navigate away from the page.
Note: The Client Secret has an expiry date. Set a calendar reminder before it expires to regenerate and update it in Lepide, otherwise auditing will stop.
Step 5: Note the App Credentials
From the app's Overview page, note and securely save the following three values — all are required for the Lepide configuration:
Application (Client) ID
Directory (Tenant) ID
Client Secret Value (from Step 4)
Save these credentials in a secure location on the Lepide server for future reference.
Step 6: Configure SharePoint Online in Lepide
Open the Lepide Auditor console and navigate to the SharePoint Online component configuration:
Select SharePoint Online as the component type
Enter the Client ID, Tenant ID, and Client Secret from the app registration
Set the audit scope to All Objects (recommended for initial setup — exclusions can be added later)
Enter the SQL Server name and create a new dedicated database (e.g., LepideSPOnline)
Click Save / Finish to apply the configuration
Step 7: Verify Connection and Data Ingestion
After saving, Lepide will attempt to connect to SharePoint Online via the app registration. Check the Lepide console status panel to confirm:
Successful connection to SharePoint Online
Successful data insertion
Note: The first data pull typically may take upto 15 minutes. After the initial sync, Lepide collects logs on a 5-minute interval.
Step 8: Generate a Report to Verify
Navigate to the following path in the Lepide console to verify data is flowing:
User Entity Behavior > SharePoint Online > All Modifications
Click Generate Report. SharePoint activity should appear showing the user, operation type (e.g., file downloaded, modified), file path, and timestamp.
Tip: If no data appears immediately, wait 15 minutes after configuration and try generating the report again. If data still does not appear, verify the API permissions have Admin Consent granted in Azure Entra.
5. Resolution
Creating an App Registration in Azure Entra with the correct API permissions and entering the credentials into Lepide's SharePoint Online configuration allows Lepide to successfully collect and report on all SharePoint Online activity. Reports are available within 15 minutes of completing the configuration.
6. Best Practices & Prevention
Document the App Registration credentials (Client ID, Tenant ID, Client Secret, expiry date) and store them securely on the Lepide server.
Set a calendar reminder before the Client Secret expires to regenerate and update it in Lepide — failure to do so will cause auditing to stop silently.
After any tenant-level changes in Azure (e.g., admin consent revoked, policy changes), re-verify that the app registration permissions are still intact.
Create a dedicated SQL database for SharePoint Online data to keep it separate from AD and file server audit data.
Monitor the SharePoint database size regularly, especially if using SQL Express (10GB limit).