Connect Sophos ITDR to Microsoft Entra ID
The Microsoft Entra ID integration connects an Entra tenant to Sophos ITDR. First verify the prerequisites and target tenant. Then configure the Microsoft Entra ID card under Identity > Settings > Integrations. Before granting tenant-wide consent, review the requested permissions, and then validate the integration and the imported data separately.
Prerequisites and change preparation
Before you begin, make sure the following prerequisites are met:
- ITDR is enabled in the correct Sophos tenant.
- The Sophos account performing the setup has the Sophos Fusion Administrator role.
- The target tenant has Microsoft Entra ID P1 or P2. Entra ID Free provides Microsoft APIs but limits the data that can be retrieved and the available posture checks; an integration using it can therefore display Provisioning Failed.
- An Entra account that is allowed to grant tenant-wide admin consent for the permissions actually requested is available for the Microsoft step. Do not rely on the role name alone: Microsoft distinguishes between delegated permissions and Microsoft Graph application permissions, among others. Use the displayed consent dialog to verify that the account has the required authority.
- The target tenant, a unique integration name, the change window, and the person responsible for consent have been defined.
A useful integration name includes the environment and tenant but no secrets, for example Production Entra - example.onmicrosoft.com. You can choose any name, but it must provide an unambiguous assignment, especially when there are multiple tenants.
Before making the change, record at least the following baseline information:
- Target tenant and current Entra license.
- Existing permissions for the affected Entra enterprise application, if it already exists.
- Sophos account used and its Fusion role.
- Entra account intended for consent and its relevant role.
- Planned integration name and start time, including the time zone.
Passwords, tokens, and other secrets must not appear in screenshots or the change record.
Set up the Entra ID integration
During setup, Sophos uses the Sophos Master Application in Azure to create the required application automatically in the Azure tenant and request the necessary permissions.
- In Sophos Fusion, open Identity > Settings > Integrations.
- On the Microsoft Entra ID or Microsoft EntraID Integration card, select Set Up.
- Enter the prepared unique integration name in the name field and select Next.
- Decide whether to configure Response Actions now. Leave the checkbox cleared if this additional authorization has not been explicitly approved; Response Actions can be configured separately later.
- Select Authorize. You are redirected to the Microsoft Identity Provider.
- Before signing in, verify again that the browser is using the intended Entra tenant.
- Sign in with the account that is allowed to grant tenant-wide consent.
- Review the application publisher and every listed permission. Approve only if they match the authorization.
- After successful consent, the process returns to Sophos ITDR. View Identity Risk Posture opens the ITDR Overview Dashboard.
Depending on the size of the tenant, the first data can take several minutes to appear. A successful redirect alone is therefore not full acceptance.
Validate the integration and data
Check authorization, provisioning, and data quality separately. Successful consent alone does not prove that data ingestion works.
1. Authorization and provisioning
Under Identity > Settings, check the Configured Integrations table to confirm that the prepared name is assigned to the correct Entra tenant and that Provisioning Failed is not displayed. Record the visible status and the time of the check.
If Provisioning Failed appears, the setup has not passed acceptance. Check the license and Microsoft source data as described below, and escalate a persistent error instead of deleting the integration, creating a second integration, or granting consent again.
2. Representative data
After the initial load, check at least the following samples:
- Several known users, including a standard user and a user with a known administrative or privileged Entra role.
- A known group.
- A known application or service principal.
- A known device.
- MFA registration data for an active, non-deleted test user whose expected values are known.
ITDR sets the admin flag for users whose Entra roles are recognized as administrative or privileged. These include various standard roles and potentially comparable Custom Roles. Because Microsoft can change roles and behavior, use a current role assignment visible in the tenant as the comparison. A static list of names alone is not sufficient evidence.
Use the Microsoft report as the reference for MFA data: in the Microsoft Entra admin center, go to Entra ID > Authentication methods > Activity and, on the Registration tab, check an active, non-deleted test user whose expected values are known. This report requires Entra ID P1 or P2 and a role authorized to view it. The report includes MFA Capable, registered methods, and Last Updated Time. Disabled and recently deleted users do not appear in the user registration details and are therefore unsuitable for this comparison.
3. Account for collection intervals
After the full initial data import, Sophos checks for changes at different intervals for each data type:
| Data type | documented interval |
|---|---|
| User Details | every 10 minutes |
| Service Principals and Apps Details | every 10 minutes |
| Groups | every 10 minutes |
| Devices | every 10 minutes |
| User MFA Configuration | every 15 minutes |
| User Activity (Last Sign On) | every 6 hours |
| Domain Data | every 24 hours |
Entra ID Posture Checks and Dormant Resource Checks run every two hours. Do not treat a change as missing until the interval for the relevant data type and, where applicable, the subsequent posture check have elapsed. Microsoft may still update its source data later; the table lists only Sophos collection intervals.
The integration has passed acceptance when consent was completed in the correct tenant, Configured Integrations shows no provisioning error, representative objects from the intended tenant are visible, and the MFA and admin data are plausible after accounting for the documented source and collection latency.
Resolve consent errors and applications weren’t found
If the admin consent process reports that applications were not found, the documented cause is typically a replication delay in the Microsoft infrastructure. In this case, do not immediately create a new integration.
- Record the error text, UTC or local time with time zone, target tenant, and integration name.
- Wait 15 to 30 minutes so that the service principals can replicate within the Microsoft infrastructure.
- In Sophos Fusion, open Identity > Settings.
- In Configured Integrations, open the three-dot menu in the Actions column for the affected integration and select Grant Admin Consent.
- At the Microsoft Identity Provider, sign in with an account that is allowed to grant tenant-wide consent.
- Review the tenant, application, and listed permissions again, and approve only if they match.
- Return to Identity > Settings and select the Refresh icon under Actions to provision the integration again.
- Recheck the status and data against the acceptance criteria.
Do not automatically treat a different consent error as a replication error. If the message is not applications weren’t found, record the tenant, account permissions, and displayed permission scope, and resolve them before trying consent again.
Handle Provisioning Failed after a license change
An integration with Entra ID Free can display Provisioning Failed because API data and posture checks are limited. First check in the affected tenant that P1 or P2 is actually active. Proof of purchase or a planned assignment does not replace visible activation in the correct tenant.
After an upgrade from Entra ID Free to P1 or P2, Microsoft APIs may deliver information such as admin status or MFA registration with a delay. According to Sophos, delays of up to one week are possible. Proceed in stages:
- Confirm the Entra license and target tenant.
- Under Entra ID > Authentication methods > Activity > Registration, check whether Microsoft already shows the expected MFA data for an active, non-deleted test user with known expected values.
- Record Last Updated Time and the values for this test user.
- Only after Microsoft provides current values, check ITDR again after the applicable collection interval.
- If Provisioning Failed persists despite an active P1/P2 license and this source-data check, escalate with the evidence listed below. A generic provisioning error is not a reason to grant tenant-wide consent again or select Refresh.
With older configurations of external MFA providers such as Okta or Duo, Entra may not store MFA status at user level. ITDR then cannot report the status correctly. Sophos can, however, recognize the new External Authentication Methods in Entra. Do not change a production MFA architecture merely to correct an ITDR display; first establish which Entra configuration is actually in use.
Authorize Response Actions separately and deliberately
Response Actions are optional. If they were not approved during initial setup, configure them separately:
- Open Identity > Settings > Integrations.
- On the Response Actions card, select Set Up.
- Select an existing configured Integration.
- Select Authorize and sign in at the Microsoft Identity Provider.
- Review the tenant, application publisher, and every listed permission again against the same security criteria.
- Grant tenant-wide consent only with documented approval, and then select Close.
After configuration, Response Actions are available in the Actions menu in the Sophos ITDR application. Before using a Response Action, its type, effect, and recovery path must be approved and documented separately.
Rollback and change boundaries
After a failed setup attempt, do not delete integrations, Enterprise Applications, or permissions on suspicion. Only for the exact applications weren’t found error is the Grant Admin Consent followed by Refresh procedure documented after 15 to 30 minutes. No blanket deletion procedure or complete revocation can be inferred for other errors.
The following boundaries therefore apply to recovery:
- Before consent: Canceling prevents tenant-wide consent. Record the displayed discrepancies and resolve them first.
- After unexpected consent: Do not remove an individual permission or delete the application until you have checked the baseline, dependent use, and permissions actually granted. Because granting tenant-wide consent again can affect permissions already granted to the same application, repeating it is not a safe rollback.
- For optional Response Actions: Do not authorize them if the scope or recovery path is unclear. Authorization already granted is not removed within this runbook.
- For a generic provisioning error: Check the P1/P2 license and Microsoft source data, and escalate a persistent error. Grant Admin Consent and Refresh remain reserved exclusively for the recovery procedure described above for applications weren’t found. Do not create a second integration with the same name as a test.
If revocation or complete removal is required, handle it as a separate approved change with the responsible Microsoft Entra and Sophos teams. The integration name, visible status, and permissions recorded before setup provide the baseline.
When to escalate and which evidence to provide
Escalate if any of the following applies:
- applications weren’t found persists after 30 minutes, another Grant Admin Consent, and Refresh.
- Consent fails with a different, unexplained error.
- Provisioning Failed persists despite a confirmed P1/P2 license and verification of the Microsoft source data.
- Microsoft shows current MFA data, but ITDR still does not ingest it after the 15-minute interval.
- Representative users, groups, devices, apps, or service principals are missing after the applicable collection interval.
- Admin data remains incorrect even though Entra shows the current role assignment and a possible delay after the license upgrade has been taken into account.
Collect the following for escalation to Sophos Support or the responsible Entra team:
- Sophos tenant and Entra tenant, integration name, and affected environment.
- Active Entra license and the time of any upgrade.
- Exact error text and screenshots of Configured Integrations, each with time and time zone.
- Time and result of Authorize, and, if the exact applications weren’t found error occurred, of Grant Admin Consent and Refresh.
- Role names used for the Sophos and Entra accounts, but no credentials.
- For MFA discrepancies, the affected test user, visible values, and Last Updated Time from Authentication methods > Activity > Registration.
- For missing objects, the object type, an anonymized example, and the collection interval already allowed to elapse.
- A description of every consent, license, or integration change made since the error.
Permission dialogs may be documented for support, but must not contain passwords, tokens, or other secrets. Until the issue is resolved, suspend deletion, manual permission changes, and repeated consent attempts outside the documented recovery procedure.