Skip to content

Entra ID Inventory Modules ​

Overview ​

AzureScout's live Entra query catalog contains 26 entries: 24 collected datasets and two disabled coverage records whose results no released collector consumes. It extracts tenant-wide identity and access-management data via Microsoft Graph, then retains every query outcome in the raw evidence ledger.

Run Entra-only extraction with:

powershell
Invoke-AzureScout -Scope EntraOnly

How Entra Extraction Works ​

The Start-AZSCEntraExtraction function calls Invoke-AZSCGraphRequest for each Entra module, which:

  1. Authenticates via the Graph token obtained during login
  2. Queries the relevant Microsoft Graph endpoint
  3. Handles pagination (following @odata.nextLink)
  4. Normalizes each result into a consistent resource shape:
json
{
  "id": "...",
  "name": "Display Name",
  "TYPE": "microsoft.graph/users",
  "tenantId": "00000000-...",
  "properties": { }
}

Module Catalog ​

Get-ScoutEntraQueryCatalog (src/collect/Get-ScoutEntraQueryCatalog.ps1) is the single source of truth for these 26 catalog entries — Start-AZSCEntraExtraction runs every enabled entry, and the -PermissionAudit impact table is built by joining the same list against the collector manifests, so the two can no longer drift the way a hand-maintained second copy could.

ModuleGraph EndpointPermissionDescription
Users/usersUser.Read.AllAll user accounts (members and guests)
Groups/groupsGroup.Read.AllSecurity groups, Microsoft 365 groups, distribution lists
Applications/applicationsApplication.Read.AllApplication registrations (app IDs, credentials, API permissions)
Service Principals/servicePrincipalsApplication.Read.AllEnterprise applications and service principals
Managed Identities/servicePrincipals (filtered to servicePrincipalType eq 'ManagedIdentity')Application.Read.AllManaged identities (system and user-assigned), as seen from the Entra service-principal object
Directory Roles/directoryRolesRoleManagement.Read.DirectoryActivated directory roles and their members
PIM Assignments/roleManagement/directory/roleAssignmentsRoleManagement.Read.DirectoryPrivileged Identity Management (PIM) role assignments
Conditional Access Policies/identity/conditionalAccess/policiesPolicy.Read.AllConditional Access policies
Authentication Method Registration Details/reports/authenticationMethods/userRegistrationDetailsReports.Read.AllPer-user MFA registration, capability, and registered methods
Sign-ins (last 30 days)/auditLogs/signInsAuditLog.Read.AllCA report-only impact, legacy authentication, and last-sign-in correlations
Directory Role Assignment Schedules/roleManagement/directory/roleAssignmentSchedulesRoleAssignmentSchedule.Read.DirectoryActive/permanent PIM schedules
Directory Role Eligibility Schedules/roleManagement/directory/roleEligibilitySchedulesRoleEligibilitySchedule.Read.DirectoryEligible PIM schedules
Access Review Definitions/identityGovernance/accessReviews/definitionsAccessReview.Read.AllAccess-review definitions and instances
Organization/organizationDirectory.Read.AllEntra Connect sync state and last sync time
Named Locations/identity/conditionalAccess/namedLocationsPolicy.Read.AllTrusted locations for conditional access
Administrative Units/directory/administrativeUnitsAdministrativeUnit.Read.AllAdministrative units for delegated management
Domains/domainsDomain.Read.AllVerified and unverified domains
Subscribed SKUs/subscribedSkusOrganization.Read.AllLicense SKUs and service plan assignments
Cross-Tenant Access/policies/crossTenantAccessPolicy/partnersPolicy.Read.AllB2B cross-tenant access settings
External Identities/policies/crossTenantAccessPolicy/defaultPolicy.Read.AllDefault inbound/outbound B2B trust posture
Security Policies/policies/authorizationPolicyPolicy.Read.AllTenant authorization policy
Risky Users/identityProtection/riskyUsersIdentityRiskyUser.Read.AllUsers flagged by Identity Protection (requires Entra ID P2)
Verified ID Authentication Method/policies/authenticationMethodsPolicy/authenticationMethodConfigurations/VerifiableCredentialsPolicy.Read.AuthenticationMethodTenant Verified ID authentication-method state and target groups
Verified ID Profiles/identity/verifiedId/profilesVerifiedId-Profile.Read.AllConfigured Verified ID profiles
Identity Providers ⚠️/identity/identityProvidersIdentityProvider.Read.AllConfigured external/social identity providers
Security Defaults ⚠️/policies/identitySecurityDefaultsEnforcementPolicyPolicy.Read.AllTenant-wide security defaults enforcement state

⚠️ Collected, normalized, and read by nothing

Identity Providers and Security Defaults remain in the catalog as disabled coverage records, but Scout does not issue those two requests. The raw query-outcome ledger states that no released collector consumes them. AuditLog.Read.All, by contrast, now has multiple released consumers and is required for the last-30-day correlation datasets.

Required Microsoft Graph Permissions ​

"I'm a Global Administrator but the Entra modules still fail with 403 — why?"

Global Administrator is an Entra directory role, not a Microsoft Graph API scope. Entra extraction uses the Graph token issued for the same Az context account and tenant that ARM collection uses (Get-AzAccessToken). That token only carries the delegated Graph scopes issued to the authentication client — your directory role does not widen those OAuth scopes. So an endpoint whose scope has not been consented returns 403 Forbidden regardless of your role.

To read every module above, the signed-in identity needs these delegated Microsoft Graph permissions carried by the selected identity's token (or application permissions on your own service principal) — see the Permission column in the Module Catalog above for which permission unlocks which module:

PermissionUnlocks
User.Read.AllUsers
Group.Read.AllGroups
Application.Read.AllApplications, Service Principals, Managed Identities
RoleManagement.Read.DirectoryDirectory Roles, PIM Assignments
Policy.Read.AllConditional Access Policies, Named Locations, Security Policies, Cross-Tenant Access, Security Defaults ⚠️
Reports.Read.AllAuthentication Method Registration Details
AuditLog.Read.AllSign-ins (last 30 days)
RoleAssignmentSchedule.Read.DirectoryDirectory Role Assignment Schedules
RoleEligibilitySchedule.Read.DirectoryDirectory Role Eligibility Schedules
AccessReview.Read.AllAccess Review Definitions
Directory.Read.AllOrganization / hybrid sync state
AdministrativeUnit.Read.AllAdministrative Units
Domain.Read.AllDomains
Organization.Read.AllSubscribed SKUs
IdentityRiskyUser.Read.AllRisky Users (Identity Protection — also requires Entra ID P2)
IdentityProvider.Read.All ⚠️Identity Providers
Policy.Read.AuthenticationMethodVerified ID Authentication Method
VerifiedId-Profile.Read.AllVerified ID Profiles

⚠️ marks the two permissions behind the unconsumed queries — granting them satisfies the pre-flight but adds nothing to any report; see the warning above.

A broad Directory.Read.All grant also satisfies User.Read.All, Group.Read.All and Application.Read.All in practice, since it is a superset scope, but the table above is the minimum each query actually needs.

Grant/consent once (tenant admin), e.g.:

powershell
# Re-establish the Az context for the exact account and tenant being scanned:
Connect-AzAccount -Tenant '<tenant-id>'
# For scopes the delegated token cannot carry, use AzureScout's service-principal parameters
# with the required Microsoft Graph application permissions admin-consented in Entra ID.

Endpoints requiring a licensing tier you don't have (e.g. Risky Users without Entra ID P2) will still 403 — that is expected and is handled by Graceful Degradation below rather than aborting the run.

Data Normalization ​

All collected Entra datasets produce output in the same normalized shape:

FieldSource
idGraph object id
namedisplayName (or most relevant name field)
TYPESynthetic type string (e.g., microsoft.graph/users)
tenantIdTenant ID from the current session
propertiesFull Graph object properties

This normalization allows ARM and Entra resources to be processed by the same reporting pipeline.

Graceful Degradation ​

If a single Entra query fails (e.g., insufficient permissions for Conditional Access policies), the module:

  • Logs a warning
  • Continues with the remaining enabled queries
  • Returns partial results rather than failing entirely

If all queries fail, the function returns an empty EntraResources collection.

Released under the MIT License.