Posture setup

Posture credentials setup

Prepare Azure or Microsoft 365 posture credentials and map each input field required by the Posture connector form.

Updated May 5, 2026 | 9 min

Auth mode and baseline

  • Posture connectors currently support client-secret authentication only.
  • Required in all providers: client_id, tenant_guid, client_secret.
  • Connector creation queues an initial posture scan immediately.
  • Credentials are stored through the posture credential protection service.

Field mapping for the ITDR form

ITDR fieldCustomer sourceRequired for
Client IDMicrosoft Entra app registration -> Application (client) IDAzure and Microsoft 365 posture
Tenant GUIDMicrosoft Entra ID -> Overview -> Tenant IDAzure and Microsoft 365 posture
Client secretApp registration -> Certificates & secrets -> secret valueAzure and Microsoft 365 posture
Subscription IDsAzure portal -> Subscriptions -> Subscription IDAzure posture only
Tenant domainPrimary verified Microsoft tenant domainRecommended for Microsoft 365 posture
NotesPermissions granted, owner, rotation date, onboarding contextRecommended for customer handoff

Microsoft 365 posture connector

Connector provider: Microsoft 365 posture.

Required fields: Client ID, Tenant GUID, Client secret.

Recommended fields: primary tenant domain and notes explaining granted permissions.

Setup flow in ITDR

  1. Open Posture in ITDR and use Add connector.
  2. Choose provider (Azure posture or Microsoft 365 posture).
  3. Enter required credential fields and save.
  4. Wait for connector_setup run to start, then review findings and run summary.
  5. Use posture remediation and risk-acceptance workflows after first findings import.
Detailed permission matrices for posture providers depend on which posture checks are enabled. Use the provider documentation linked in the in-app setup page for the latest required grant sets.

Validation checklist

  • Connector status should move from pending_setup to active after successful run.
  • Runs tab should show new run records with trigger `connector_setup` or `manual`.
  • Findings should populate by severity and provider.
  • Export (JSON/CSV) and run artifacts should download successfully for completed runs.

Setup worksheet

Have the customer prepare these values before opening the posture connector form.

Provider: Azure posture or Microsoft 365 posture
Client ID: <application client id>
Tenant GUID: <directory tenant id>
Client secret: <secret value, share only through approved secret channel>
Subscription IDs: <comma-separated subscription ids, Azure posture only>
Tenant domain: <example.onmicrosoft.com or primary verified domain>
Secret expires: <date>
Permissions/roles granted: <reader/security reader/global reader/etc. based on customer policy>