How to Configure SharePoint Online Auditing in Lepide

Product

Lepide Auditor

Category

SharePoint Online

Affected Area

Lepide Auditor – SharePoint Online Component

Version

26.1

1. Overview

This article explains how to configure SharePoint Online auditing in Lepide Auditor by creating an Azure App Registration in the Entra Admin Portal. This setup allows Lepide to collect and report on all SharePoint Online activity including file access, modifications, deletions, permission changes, and site-level changes.

2. What Lepide Can Audit in SharePoint Online

Once configured, Lepide audits the following SharePoint Online activities:

  • Files created, modified, deleted, downloaded, or uploaded

  • Document library changes

  • Permission changes on sites, folders, or files

  • Site-level modifications and settings changes

  • User access and activity across all SharePoint sites in the organization

3. Prerequisites

  • Access to Azure Entra Admin Portal (Global Admin or App Registration permissions required)

  • SharePoint Online active in the Microsoft 365 tenant

4. Configuration Steps

Step 1: Open Entra Admin Portal

Log in to the Entra Admin Portal (entra.microsoft.com) using a Global Admin account or an account with App Registration permissions.

Step 2: Create a New App Registration

Navigate to: App Registrations > New Registration

  • Enter a descriptive name for the app (e.g., 'Lepide SharePoint Audit')

  • Leave the Redirect URI blank

  • Click Register

Step 3: Assign API Permissions

After the app is created, go to: API Permissions > Add a Permission Add the following permissions as required by Lepide:

After adding the permissions, click Grant Admin Consent to apply them across the entire tenant.

Step 4: Generate a Client Secret

Navigate to: Certificates & Secrets > Client Secrets > New Client Secret

  • Enter a description (e.g., 'Lepide SharePoint Secret')

  • Set an appropriate expiry period (e.g., 12 or 24 months)

  • Click Add

Copy and securely save the Client Secret Value immediately after creation — it will NOT be shown again once you navigate away from the page.

Note: The Client Secret has an expiry date. Set a calendar reminder before it expires to regenerate and update it in Lepide, otherwise auditing will stop.

Step 5: Note the App Credentials

From the app's Overview page, note and securely save the following three values — all are required for the Lepide configuration:

  • Application (Client) ID

  • Directory (Tenant) ID

  • Client Secret Value (from Step 4)

Save these credentials in a secure location on the Lepide server for future reference.

Step 6: Configure SharePoint Online in Lepide

Open the Lepide Auditor console and navigate to the SharePoint Online component configuration:

  • Select SharePoint Online as the component type

  • Enter the Client ID, Tenant ID, and Client Secret from the app registration

  • Set the audit scope to All Objects (recommended for initial setup — exclusions can be added later)

  • Enter the SQL Server name and create a new dedicated database (e.g., LepideSPOnline)

  • Click Save / Finish to apply the configuration

Step 7: Verify Connection and Data Ingestion

After saving, Lepide will attempt to connect to SharePoint Online via the app registration. Check the Lepide console status panel to confirm:

  • Successful connection to SharePoint Online

  • Successful data insertion

Note: The first data pull typically may take upto 15 minutes. After the initial sync, Lepide collects logs on a 5-minute interval.

Step 8: Generate a Report to Verify

image-20261007-134257.png

Navigate to the following path in the Lepide console to verify data is flowing:

User Entity Behavior > SharePoint Online > All Modifications

Click Generate Report. SharePoint activity should appear showing the user, operation type (e.g., file downloaded, modified), file path, and timestamp.

image-20261007-134448.png

Tip: If no data appears immediately, wait 15 minutes after configuration and try generating the report again. If data still does not appear, verify the API permissions have Admin Consent granted in Azure Entra.

5. Resolution

Creating an App Registration in Azure Entra with the correct API permissions and entering the credentials into Lepide's SharePoint Online configuration allows Lepide to successfully collect and report on all SharePoint Online activity. Reports are available within 15 minutes of completing the configuration.

6. Best Practices & Prevention

  • Document the App Registration credentials (Client ID, Tenant ID, Client Secret, expiry date) and store them securely on the Lepide server.

  • Set a calendar reminder before the Client Secret expires to regenerate and update it in Lepide — failure to do so will cause auditing to stop silently.

  • After any tenant-level changes in Azure (e.g., admin consent revoked, policy changes), re-verify that the app registration permissions are still intact.

  • Create a dedicated SQL database for SharePoint Online data to keep it separate from AD and file server audit data.

  • Monitor the SharePoint database size regularly, especially if using SQL Express (10GB limit).