Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

All integrations
ME
IDENTITY·Beta

Microsoft Entra

Enterprise application inventory and consent grant tracking via Microsoft Graph.

WHAT IT DOES

What ScopeMantle can do with Microsoft Entra.

  • Inventory enterprise applications and service principals across the tenant
  • Pull every user, admin, and application consent grant with the full requested permission set
  • Resolve user identities, group memberships, and directory roles via Microsoft Graph
  • Stream Entra audit logs and sign-in activity into the ScopeMantle normalized event schema
  • Surface conditional access policies that affect third-party app authentication

LEAST PRIVILEGE

What we read, and what we don't.

We read
  • Application.Read.AllEnumerate enterprise applications and service principals
  • DelegatedPermissionGrant.Read.AllInventory user-consented OAuth grants
  • AppRoleAssignment.Read.AllMap application role assignments to users and groups
  • Directory.Read.AllRead users, groups, and directory roles
  • AuditLog.Read.AllStream Entra audit and sign-in events
We never
  • Modify user accounts, group memberships, or directory roles
  • Grant or revoke application permissions, write actions require a separate, opt-in scope set
  • Read mail, calendar, files, or any Microsoft 365 user data
  • Issue tokens or sign in as users via OBO (on-behalf-of) flows

SETUP

Connect in a few steps.

  1. 01

    Register ScopeMantle as a Microsoft Entra application

    In the Entra admin center, register a new app, generate a client secret or upload a certificate, and grant admin consent for the read-only Microsoft Graph permissions listed above.

  2. 02

    Provide the credentials to ScopeMantle

    Paste the tenant ID, client ID, and credential into ScopeMantle's connect flow. The Beta connector supports certificate authentication and is recommended for production tenants.

  3. 03

    Verify the first sync

    Initial discovery typically completes in 30–90 minutes depending on tenant size. Validate the application count against your Entra admin center before enabling governance policies.

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.