Microsoft Entra ID

View as Markdown

Community Platform

runZero integrates with Microsoft Entra ID (formerly Azure AD) to sync and enrich your asset inventory and to show you Entra ID users and groups. With your Entra ID data in runZero, assets that aren’t part of your domain are easier to find.

The runZero product still refers to Entra ID as Azure AD.

Getting started

To set up the Entra ID integration:

  1. Configure Entra ID to allow API access through runZero.

  2. Add the Entra ID credential in runZero.

  3. Choose whether to run the integration as a scan probe or connector task.

  4. Activate the Entra ID integration to sync your data with runZero.

Requirements

You need access to the Microsoft Azure portal.

Step 1: Register an Azure application for Entra ID API access

runZero can authenticate to the Entra ID API with either a username and password or a client secret. Either way, start by registering an application for Entra ID API access.

  1. Sign in to the Microsoft Azure portal.

  2. Go to App registrations and click + New registration.

    • Provide a name.
    • Select the supported account types.
    • Optionally add a redirect URI.
  3. Click Register.

  4. Once the application is created, go back to the main Azure portal page and select App registrations. You should find the application you just registered (selecting the Owned applications tab may help). Click the app’s name.

  5. On the app registration overview, note the following information:

    • Application (client) ID
    • Directory (tenant) ID
  6. Click the application’s display name to open its management pages.

  7. Select Manage > Authentication on the left. Set Allow public client flows to Yes and save the configuration.

  8. Go to API permissions and click + Add a permission.

  9. Select Microsoft Graph from the list of Microsoft APIs.

  10. Select the permissions type for the credential you plan to use:

    • Username & password: select Delegated permissions
    • Client secret: select Application permissions
  11. Search for and select these required permissions:

    • Device.Read.All
    • Group.Read.All
    • User.Read.All
  12. Click Add permissions to save the permissions to the application.

  13. Click Grant admin consent to grant the application consent for those permissions.

  14. If you’re using a client secret, also do the following:

    • Go to Azure Active Directory > App registrations and select the application you created.
    • Go to Certificates & secrets and click New client secret.
      • Enter a description.
      • Select the expiration.
    • Click Add to create the client secret, then save the client secret value.

Step 2: Add the Entra ID credential to runZero

Step 2a: Add an Azure Username & Password credential to runZero

  1. Go to the Credentials page in runZero and click Add Credential.

  2. Provide a name for the credential, like Azure Username & Password.

  3. Choose Azure Username & Password from the list of credential types.

  4. Provide the following information:

    • Azure application (client) ID: The unique ID for the registered application. To find it in the Azure portal, go to App registrations and select the application.
    • Azure directory (tenant) ID: The unique ID for the tenant. To find it in the Azure portal, go to App registrations and select the application.
    • Azure username: The username for your Azure cloud account. It can’t be a federated user account.
    • Azure password: The password for your Azure cloud account.
  5. To let other organizations use this credential, select the Make this a global credential option. Otherwise, you can configure access per organization.

  6. Save the credential.

Step 2b: Add an Azure Client Secret credential to runZero

You can use this credential type to sync all resources in a single directory (across multiple subscriptions).

  1. Go to the Credentials page in runZero and click Add Credential.

  2. Provide a name for the credential, like Azure Client Secret.

  3. Choose Azure Client Secret from the list of credential types.

  4. Provide the following information:

    • Azure application (client) ID: The unique ID for the registered application. To find it in the Azure portal, go to App registrations and select the application.
    • Azure client secret: To generate a client secret, go to App registrations, select your application, go to Certificates & secrets, and click + New client secret.
    • Azure directory (tenant) ID: The unique ID for the tenant. To find it in the Azure portal, go to App registrations and select the application.
    • Select the Access all subscriptions in this directory (tenant) option to sync all resources in your directory. Otherwise, specify the Azure subscription ID, the unique ID for the subscription you want to sync. To find it in the Azure portal, go to Subscriptions and select the subscription.
  5. To let other organizations use this credential, select the Make this a global credential option. Otherwise, you can configure access per organization.

  6. Save the credential.

Step 3: Choose how to configure the Entra ID integration

You can run the Entra ID integration as either a scan probe or a connector task. A scan probe gathers integration data during a scan task. A connector task runs on its own, from the cloud or from one of your Explorers, and performs only the integration sync.

Step 4: Set up and activate the Entra ID integration to sync data

With your Entra ID credential saved, set up a connector task or a scan probe to sync your data.

Step 4a: Configure the Entra ID integration as a connector task

A connection needs a schedule and a site. The schedule sets when the sync runs, and the site is where runZero creates any new Entra ID-only assets.

  1. Activate a connection to Entra ID. You can reach every third-party connection from the integrations page, your inventory, or the tasks page.

  2. Choose the credential you added earlier. If it isn’t listed, make sure it has access to the organization you’re currently in.

  3. Optionally provide a filter in the Microsoft Graph API filter syntax. runZero imports only the devices that match it.

  4. Enter a name for the task, like Entra ID sync.

  5. Schedule the sync to run once or on a recurring schedule. The schedule starts on the date and time you set.

  6. Under Task configuration, choose the site to add your assets to.

  7. To leave out assets that runZero has not scanned, switch the Exclude unknown assets toggle to Yes. By default, the integration includes them.

  8. To import assets that the Entra ID account has marked as inactive, switch the Include inactive assets toggle to Yes. By default, the integration leaves out assets marked as inactive.

  9. Activate the connection. The sync runs on the schedule you defined, and the Scheduled tasks page shows when the next sync will occur.

Step 4b: Configure the Entra ID integration as a scan probe

  1. Create a new scan task or select a future or recurring scan task from your Tasks page.

  2. Add or update the scan parameters to fit any additional requirements.

  3. On the Probes and SNMP tab, choose any additional probes to include, set the Azure AD toggle to Yes, and change any default options as needed.

  4. On the Credentials tab, set the Azure AD toggle to Yes for the credential you want to use.

  5. Click Initialize scan to save the scan task. It runs immediately or at the scheduled time.

Step 5: View Entra ID assets

After a successful sync, go to your inventory to view your Entra ID assets. They show an Active Directory icon in the Source column.

To filter for Entra ID assets, try these queries:

Click into an asset to see the attributes Entra ID returned. To write your own queries, start with the search query syntax.

Community Platform

The Entra ID integration also imports details about users and groups. Go to Inventory > Users or Inventory > Groups to see them.

Filtering Entra ID assets

You can apply an optional filter to Entra ID integration tasks. runZero filters assets with the Microsoft Graph $filter query parameter. Each expression follows the syntax <property> [operator] <value>, and you can combine expressions with and or or for more complex filtering.

Properties

You can filter on any property that runZero imports from Entra ID. Some examples:

Entra ID Property runZero Attribute Description Example
displayName @azuread.dev.displayName The hostname of the device EXPLORER-01
operatingSystem @azuread.dev.operatingSystem The operating system of the device Windows
operatingSystemVersion @azuread.dev.operatingSystemVersion The version of the operating system 10.0.x
manufacturer @azuread.dev.manufacturer The manufacturer of the device Dell Inc.
model @azuread.dev.model The model of the device Precision 3560
isManaged @azuread.dev.isManaged Boolean value specifying whether device is managed true, false
managementType @azuread.dev.managementType Description of how the device is managed MDM, MicrosoftSense
deviceOwnership @azuread.dev.deviceOwnership Description of who owns the device Company, Personal

Operators

Common operators for an Entra ID filter:

  • Equal to (eq)
  • Not equal to (ne)
  • Has (has)
  • Less than (lt)
  • Greater than (gt)
  • Less than or equal to (le)
  • Greater than or equal to (ge)

Common functions, which follow the syntax function(<property>, <value>):

  • Starts with (startswith)
  • Ends with (endswith)

Example filters

Search Filter Description
not(startsWith(operatingSystem, 'Android')) Import all assets except those with an Android operating system
not(operatingSystem eq 'iOS') and not(operatingSystem eq 'iPad') Import all assets except those with an iOS or iPad operating system
startswith(displayName, 'PROD') Import all devices with a hostname that starts with PROD
not(startswith(displayName, 'DEV')) Import all devices except those with a hostname that starts with DEV
deviceOwnership eq 'Company' or isManaged eq true Import all devices that are owned by company or that are configured as managed devices

For more on the filter syntax and additional examples, see Microsoft’s Graph API documentation.

Troubleshooting

If the integration isn’t working, start with these checks.

Why is the Azure Active Directory integration unable to connect?

  1. Check whether the Entra ID integration is returning any data.

    • Query the inventory rather than the task details to review all the data available from this integration.
    • In some cases, an integration’s configuration limits how much data reaches the runZero console.
  2. Some integrations require specific actions that are easy to overlook. If you miss a step during setup, the integration may not work correctly. Review this page and follow the steps exactly.

  3. If the Entra ID integration can’t connect, check the task log for errors. Common errors include:

    • 500: server error, unable to connect to the endpoint
    • 404: hitting an unknown endpoint on the server
    • 403: not authorized, likely a credential issue

How do I solve the following Entra ID errors?

  • (invalid_client) AADSTS7000218: The request body must contain the following parameter: 'client_assertion' or 'client_secret'

    1. Enable Allow Public Client Flows in Entra ID. On the application details page, go to Authentication > Advanced Settings and toggle the Allow Public Client Flows setting to Yes.

    2. Also confirm that you granted application permissions correctly when registering the Azure application for Entra ID API access. On the API permissions settings page, check that each API/Permission has its type set to application and that the permission granted is Grant Admin Consent for Default Directory.

  • failed to get Entra ID groups: invalid response: 403 (403 Forbidden)

    Check that you entered every credential value correctly and followed every step on this page. A credential problem is the likely cause.

Updated