Entra ID App Registration

Register Proventeq365 in Microsoft Entra ID, assign the Cloud Application Administrator role, and grant the Microsoft Graph and SharePoint API permissions for your deployment mode.

What this does: Registers Proventeq365 as an application in your Microsoft Entra ID tenant and grants it the permissions it needs to access Microsoft 365 services.

Note: You can either follow the steps below or use the Entra App Creation Script in the Appendix. The specific API permissions depend on your chosen deployment mode (Read-only or Read-write). Proventeq will confirm the exact permissions list before you complete this step.

Create the App Registration

Steps — Azure Portal

  1. Sign in to the Azure Portal (https://portal.azure.com) and go to Microsoft Entra ID.
  2. Select App registrations > + New registration.
  3. Enter a meaningful name (e.g. Proventeq365), leave the default account type, and click Register.
  4. Note the Application (client) ID and Directory (tenant) ID — you will need to share these with Proventeq.

Steps — Azure CLI (alternative)

bash
az ad app create \
  --display-name "<APP_NAME>" \
  --sign-in-audience AzureADMyOrg

Assign the Cloud Application Administrator Role

Steps — Azure Portal

  1. In Microsoft Entra ID, go to Roles and administrators.
  2. Search for and select Cloud Application Administrator.
  3. Click + Add assignment.
  4. On the Members tab, click Select member(s) and add the deployment user account created in Create a Deployment Identity.
  5. On the Settings tab, set the assignment type to Active, then confirm.

Alternative — app registration ownership

If a tenant-wide directory role is not acceptable under your policy, an alternative is to make the deployment identity an owner of this app registration. That grants exactly the rights needed to configure the Application ID URI, the scope and the client secret, and nothing else. Agree the approach with your Proventeq contact.

bash
az ad app owner add \
  --id <APP_OBJECT_ID> \
  --owner-object-id <USER_OBJECT_ID>

Set the Application ID URI

What this does: Defines the identifier that Proventeq365 uses to validate API access tokens. This is a required deployment input.

Who performs this and the two steps that follow. Where you have granted Proventeq the access described in Assign the Cloud Application Administrator Role — either the Cloud Application Administrator role or ownership of this app registration — Proventeq completes these three steps. Follow them yourself only if that access has not been granted, and then share the resulting values with your Proventeq contact as listed in Share Details with Proventeq.

Steps — Azure Portal

  1. In the app registration, go to Expose an API.
  2. Next to Application ID URI, click Set.
  3. Accept the default api://<application-client-id>, or use a verified custom domain form if you prefer, then click Save.
  4. Record the value — it must be shared with Proventeq exactly as configured.

Add the access_as_user Scope

What this does: Defines the delegated scope that the Proventeq365 user interface requests to call its API. This is a required deployment input.

Steps — Azure Portal

  1. In the app registration, go to Expose an API and click + Add a scope.
  2. Set Scope name to access_as_user.
  3. Set Who can consent to Admins and users.
  4. Provide display names and descriptions for both admin and user consent, then click Add scope.

Important: the exact scope string matters. Whatever scope name you create must be shared with Proventeq verbatim — it is used unmodified in the deployment configuration and in the user interface.

Create a Client Secret

What this does: Provides the credential the deployment uses to authenticate as the application. This is a required deployment input.

Steps — Azure Portal

  1. In the app registration, go to Certificates & secrets, then Client secrets.
  2. Click + New client secret, add a description and an expiry period, then click Add.
  3. Copy the Value immediately — it cannot be retrieved after you leave the page.
  4. Share it with Proventeq through your approved secure channel. Never send it by email.

Steps — Azure CLI (alternative)

bash
az ad app credential reset \
  --id <APP_OBJECT_ID> \
  --display-name "Proventeq365 deployment" \
  --years 1 \
  --append

Certificate. In addition to the client secret, Proventeq will upload a public-key certificate to this app registration. It is required for application-only access to SharePoint Online. The private key never leaves Proventeq's key store. This is noted here because certificate upload is normally a change-control item.

Grant API Permissions

  1. In the app registration, go to Manage > API permissions.
  2. Add the required Microsoft Graph and service permissions for your chosen deployment mode:
    • Read-only mode: Apply the permissions shown in the Read-only permissions screenshot provided by Proventeq.
    • Read-write mode: Apply the permissions shown in the Read-write permissions screenshot provided by Proventeq (this includes additional permissions compared to Read-only).
  3. Once all permissions are added, click Grant Admin Consent for [your organization] and confirm.

Who can grant admin consent. This step requires Privileged Role Administrator or Global Administrator. The Cloud Application Administrator role assigned in Assign the Cloud Application Administrator Role is not sufficient to consent to Microsoft Graph application permissions, so admin consent cannot be performed by Proventeq on your behalf and must be carried out by an administrator in your tenant.

Read-only mode permissions

Microsoft Graph (13 permissions)

API / PermissionTypeDescriptionAdmin Consent
AuditLog.Read.AllApplicationRequired to read sign-in activity for users and service principals. Without it the whole request fails, not just that field.Yes
Directory.Read.AllApplicationRequired to read directory roles and members, service principals, app role assignments and OAuth2 permission grants.Yes
Group.Read.AllApplicationRead all groupsYes
Mail.ReadApplicationRead mail in all mailboxesYes
offline_accessDelegatedRequired for token refresh in the Proventeq365 interface.No
openidDelegatedRequired for user sign-in to the Proventeq365 interface.No
Organization.Read.AllApplicationRequired for the tenant storage entitlement figure (subscribedSkus). Without it storage entitlement is silently reported as zero rather than failing.Yes
profileDelegatedRequired for user sign-in to the Proventeq365 interface.No
Reports.Read.AllApplicationRequired for tenant usage and site engagement reporting.Yes
SensitivityLabels.Read.AllApplicationRequired to read sensitivity labels.Yes
Sites.FullControl.AllApplicationMicrosoft Graph — separate from the SharePoint permission of the same name. Required — do not omit. Beyond reading site permissions, this grant is required for the tenant-wide site enumeration that all SharePoint discovery starts from, and for site engagement reporting. Without it SharePoint discovery returns nothing. Despite the name, these are read operations; Microsoft Graph exposes no lesser permission for them.Yes
Sites.Read.AllApplicationRead items in all site collectionsYes
User.Read.AllApplicationRead all users' full profilesYes

SharePoint (2 permissions)

API / PermissionTypeDescriptionAdmin Consent
Sites.Read.AllApplicationRead items in all site collectionsYes
User.Read.AllApplicationRead user profilesYes

Read-write mode permissions

Microsoft Graph (25 permissions)

API / PermissionTypeDescriptionAdmin Consent
AuditLog.Read.AllApplicationRead all audit log dataYes
Directory.ReadWrite.AllApplicationRead and write directory dataYes
Group.Read.AllApplicationRead all groupsYes
Group.ReadWrite.AllApplicationRead and write all groupsYes
InformationProtectionPolicy.Read.AllApplicationRead all published labels and label policiesYes
Mail.ReadApplicationRead mail in all mailboxesYes
Mail.ReadBasic.AllApplicationRead basic mail in all mailboxesYes
offline_accessDelegatedMaintain access to data you have given it access toNo
openidDelegatedSign users inNo
Organization.Read.AllApplicationRequired for the tenant storage entitlement figure (subscribedSkus).Yes
profileDelegatedView users' basic profileNo
RecordsManagement.Read.AllApplicationRead Records Management configuration, labelsYes
RecordsManagement.ReadWrite.AllApplicationRead and write Records Management configurationYes
Reports.Read.AllApplicationRead all usage reports — required for tenant usage and site engagement reportingYes
SensitivityLabels.Read.AllApplicationGet labels tenant scopeYes
Sites.Archive.AllApplicationArchive/reactivate Site Collections without a signatureYes
Sites.FullControl.AllApplicationRequired for the tenant-wide site enumeration that all SharePoint discovery starts from, for reading site permissions, and for site engagement reporting.Yes
Sites.Manage.AllApplicationCreate, edit, and delete items and lists in all sitesYes
Sites.Read.AllApplicationRead items in all site collectionsYes
Sites.ReadWrite.AllApplicationRead and write items in all site collectionsYes
Team.ReadBasic.AllApplicationGet a list of all teamsYes
User.ReadDelegatedSign in and read user profileNo
User.Read.AllApplicationRead all users' full profilesYes
User.ReadBasic.AllApplicationRead all users' basic profilesYes
User.ReadWrite.AllApplicationRead and write all users' full profilesYes

SharePoint (2 permissions)

API / PermissionTypeDescriptionAdmin Consent
Sites.FullControl.AllApplicationHave full control of all site collectionsYes
User.ReadWrite.AllApplicationRead and write user profilesYes