Connect a Microsoft Entra ID instance to SSPM to detect posture risks.
| Where Can I Use This? | What Do I Need? |
|
|
- SaaS Security Posture Management license
Or any of the following licenses that include the Data Security license:
|
For SSPM to detect posture risks in your Microsoft Entra ID instance, you must
onboard your Microsoft Entra ID instance to SSPM. Through the onboarding process,
SSPM connects to the Microsoft Graph API and, through the API, scans your Microsoft
Entra ID instance at regular intervals.
SSPM gets access to your Microsoft Entra ID instance through a service principal,
which represents a Microsoft Entra application that you create. You will configure
this application's permissions to enable SSPM to access only the API scopes that
SSPM requires to complete its scans. When you register this application, Microsoft
Entra creates the associated service principle that SSPM will use to connect to the
API.
The supported Microsoft account plans for SSPM scans are the following plans:
To access your Microsoft Entra ID instance, SSPM requires the following information,
which you will specify during the onboarding process.
| Item | Description |
| Tenant ID | A globally unique identifier (GUID) for your Microsoft Entra
tenant. |
| Client ID | SSPM will access the Microsoft Graph API through a Microsoft
Entra service principal that represents an application that you
create. Microsoft Entra generates the client ID to uniquely identify
the application and its associated service principal. |
| Client Secret | SSPM will access the Microsoft Graph API through a Microsoft
Entra service principal that represents an application that you
create. Microsoft Entra generates the client secret, which SSPM uses
to authenticate to the service principal. |
To onboard your Microsoft Entra ID instance, you complete the following actions: