Microsoft Graph (Entra + Intune + O365)
Purpose
Ingests users, groups, service principals, role assignments, managed devices, detected apps, compliance policies, and Office 365 licensing (subscribed SKUs, service plans, and per-user license assignments) from Microsoft Graph. Combine with the azure module for a complete view of identity, application, and device access across your Microsoft estate.
Recommended: connect through admin consent
The simplest setup registers no application at all. A tenant administrator grants admin consent to SubImage's multi-tenant Entra application once, and this module needs no credential fields.
Connect Microsoft from Settings > Integrations, then run a sync here. See the Microsoft integration guide for the permissions it requests and the reason for each.
The rest of this page covers registering your own application instead, which is the path to use when your organization does not permit consenting to a vendor multi-tenant application.
Secret fields below accept either an AWS Secrets Manager ARN or a value pasted directly into SubImage's managed vault. See Secrets for details.
Fields
Leave these empty when Microsoft is connected through admin consent. When set, they take precedence over the integration.
These credentials drive upstream Cartography's canonical --microsoft-* args for Microsoft (Entra ID + Intune + O365) ingestion. The legacy --entra-* args remain accepted as deprecated aliases; the SubImage field names below stay entra_*.
| Field | Secret? | Description |
|---|---|---|
entra_tenant_id |
No | Directory / Tenant ID |
entra_client_id |
No | Application (client) ID of a registered app |
entra_client_secret |
Yes | Client secret for the registered app |
One-time delegated sync
Use delegated authentication only when you can't grant application consent and need a best-effort snapshot of the Entra data visible to a signed-in user. This mode doesn't grant the user additional permissions, and it isn't a replacement for application authentication.
Delegated authentication has these limitations:
- It attempts Entra datasets only. It skips Intune and Office 365.
- Microsoft Graph can omit fields or related objects without returning an authorization error. A successful run doesn't prove that the user could read every object.
- When Graph returns
403 Forbiddenfor a dataset, Cartography preserves any records already loaded, continues with the next dataset, and SubImage marks the run as Degraded. A denial for one group member or owner can instead omit that relationship and let the dataset continue. - Cleanup is disabled. A run doesn't delete Entra data that the user can't see.
- The access token expires quickly. Use this mode for an attended, one-time run, and keep the module's schedule set to Manual.
To run a delegated sync:
If you need to identify the tenant ID for the Azure CLI command, inspect the currently selected account context. This command is read-only and does not display an access token or secret:
az account show \ --query '{tenantId:tenantId,tenantName:tenantDisplayName,subscriptionId:id,subscriptionName:name}' \ --output jsonUse the
tenantIdGUID, not the tenant display name, in the commands below. The subscription fields are informational; delegated authentication can also work in a tenant with no subscriptions.On a trusted workstation, sign in to the target tenant with the user whose visibility you want to test:
az login --tenant '<TENANT_ID>' --allow-no-subscriptionsIf a browser can't open, add
--use-device-code. Your tenant's Conditional Access policy might not allow device-code authentication.Get a Microsoft Graph access token:
az account get-access-token \ --tenant '<TENANT_ID>' \ --resource-type ms-graph \ --query accessToken \ --output tsvTreat the token like a password. Don't put it in shell history, logs, tickets, or chat messages.
In the microsoft module, set the schedule to Manual, enter the tenant ID, enable delegated authentication, and paste the token into the delegated access-token field. Leave the client ID and client secret empty.
Save the module, then select Run sync.
After the run finishes, disable delegated authentication, clear the delegated access token, and save the module again. The token is short-lived, but clearing it also removes the stored credential reference. Disable delegated mode before clearing the field because delegated authentication requires a token. Clear this field before switching back to application authentication.
SubImage stores the pasted token in the configured secret provider. It doesn't return the token to the browser after you save it. Replace the token before each later run because an expired token causes the sync to stop.
Bring your own application
- Register a new App registration in Azure Portal → Entra ID.
- Under API permissions, add the following Application permissions and grant admin consent:
AdministrativeUnit.Read.AllApplication.Read.AllDeviceManagementApps.Read.AllDeviceManagementConfiguration.Read.AllDeviceManagementManagedDevices.Read.AllDirectory.Read.AllGroup.Read.AllGroupMember.Read.AllRoleManagement.Read.DirectoryUser.Read.All
- Generate a Client Secret under Certificates & secrets.
- In SubImage, fill in the fields above (use the client secret or its AWS Secret ARN for
entra_client_secret) and save the module.
Authenticates via the OAuth 2.0 client credentials flow.