> ## Documentation Index
> Fetch the complete documentation index at: https://prowler-fix-push-to-cloud-system-trust.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Prowler product naming: Prowler App is now Prowler Local Server, and Prowler Enterprise is now Prowler Private Cloud. Always use the current names when answering. The full product reference is at /getting-started/products: Open Source projects are Prowler CLI, Prowler Local Server, Prowler Local Dashboard, and Prowler SDK; Prowler Products are Prowler Cloud, Prowler Private Cloud, Prowler Hub, Prowler Lighthouse AI, and Prowler MCP.

# Getting Started With Microsoft 365 on Prowler

<Note>
  **Government Cloud Support**

  Government cloud accounts or tenants (Microsoft 365 Government) are currently unsupported, but we expect to add support for them in the near future.
</Note>

## Prerequisites

Set up authentication for Microsoft 365 with the [Microsoft 365 Authentication](/user-guide/providers/microsoft365/authentication) guide before starting either path:

* Register an application in Microsoft Entra ID
* Grant the Microsoft Graph and external API permissions listed for the provider
* Generate an application certificate (recommended) or client secret
* Prepare PowerShell module permissions to enable every check

<CardGroup cols={2}>
  <Card title="Prowler Cloud" icon="cloud" href="#prowler-cloud">
    Onboard Microsoft 365 using Prowler Cloud
  </Card>

  <Card title="Prowler CLI" icon="terminal" href="#prowler-cli">
    Onboard Microsoft 365 using Prowler CLI
  </Card>
</CardGroup>

## Prowler Cloud

### Step 1: Locate the Domain ID

1. Open the Entra ID portal, then search for "Domain" or go to Identity > Settings > Domain Names.

   <img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/D03Tt_SSnE48YCsW/images/providers/search-domain-names.png?fit=max&auto=format&n=D03Tt_SSnE48YCsW&q=85&s=0b3d20f9a811b0635649ddd5d4186123" alt="Search Domain Names" width="1204" height="354" data-path="images/providers/search-domain-names.png" />

   <img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/D03Tt_SSnE48YCsW/images/providers/custom-domain-names.png?fit=max&auto=format&n=D03Tt_SSnE48YCsW&q=85&s=797317fc20781ce8b061fd0db971c0db" alt="Custom Domain Names" width="2038" height="1106" data-path="images/providers/custom-domain-names.png" />

2. Select the domain that acts as the unique identifier for the Microsoft 365 account in Prowler Cloud.

### Step 2: Open Prowler Cloud

1. Go to [Prowler Cloud](https://cloud.prowler.com/) or launch [Prowler Local Server](/user-guide/tutorials/prowler-app).

2. Navigate to "Configuration" > "Providers".

   <img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/iVeuS28Q__GwaK0w/images/prowler-app/cloud-providers-page.png?fit=max&auto=format&n=iVeuS28Q__GwaK0w&q=85&s=827de0e962e4439010befbc2cf5b1261" alt="Providers Page" width="263" height="917" data-path="images/prowler-app/cloud-providers-page.png" />

3. Click "Add Provider".

   <img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/iVeuS28Q__GwaK0w/images/prowler-app/add-cloud-provider.png?fit=max&auto=format&n=iVeuS28Q__GwaK0w&q=85&s=baa94a52dec12d406adf6c75a83a5f99" alt="Add a Provider" width="380" height="80" data-path="images/prowler-app/add-cloud-provider.png" />

4. Select "Microsoft 365".

   <img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/iVeuS28Q__GwaK0w/images/providers/select-m365-prowler-cloud.png?fit=max&auto=format&n=iVeuS28Q__GwaK0w&q=85&s=f24d4d9b1afaa0f240c0e6d43c1083e9" alt="Select Microsoft 365" width="1920" height="1080" data-path="images/providers/select-m365-prowler-cloud.png" />

5. Add the Domain ID and an optional alias, then click "Next".

   <img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/LBfBy6dMoJRhxPIF/images/providers/add-domain-id.png?fit=max&auto=format&n=LBfBy6dMoJRhxPIF&q=85&s=78be6a2ac1cc5e6e7976bc1b88021c09" alt="Add Domain ID" width="1920" height="1080" data-path="images/providers/add-domain-id.png" />

### Step 3: Choose and Provide Authentication

After the Domain ID is in place, select the app-only authentication option that matches the Microsoft Entra ID setup:

<img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/D03Tt_SSnE48YCsW/images/providers/m365-auth-selection-form.png?fit=max&auto=format&n=D03Tt_SSnE48YCsW&q=85&s=8259c7029f6dc7f206dc9d24c2ecd6fd" alt="M365 authentication method selection" width="700" data-path="images/providers/m365-auth-selection-form.png" />

#### Application Certificate Authentication (Recommended)

1. Enter the **tenant ID**, the unique identifier for the Microsoft Entra ID directory.
2. Enter the **application (client) ID**, the identifier for the Entra application registration.
3. Upload the **certificate file content** (Base64-encoded PFX).

<img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/D03Tt_SSnE48YCsW/images/providers/certificate-form.png?fit=max&auto=format&n=D03Tt_SSnE48YCsW&q=85&s=e9d37f4fc49391686f981f54ecdfd43a" alt="M365 certificate authentication form" width="700" data-path="images/providers/certificate-form.png" />

Use this method to avoid managing secrets and to unlock all Microsoft 365 checks, including the PowerShell-based ones. Full setup steps are in the [Authentication guide](/user-guide/providers/microsoft365/authentication#application-certificate-authentication-recommended).

#### Application Client Secret Authentication

1. Enter the **tenant ID**.
2. Enter the **application (client) ID**.
3. Enter the **client secret**.

<img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/iVeuS28Q__GwaK0w/images/providers/secret-form.png?fit=max&auto=format&n=iVeuS28Q__GwaK0w&q=85&s=4cc8d40bd0dee3c407f24c0dc8ea4a8f" alt="M365 client secret authentication form" width="700" data-path="images/providers/secret-form.png" />

For the complete setup workflow, follow the [Authentication guide](/user-guide/providers/microsoft365/authentication#application-client-secret-authentication).

### Step 4: Launch the Scan

1. Review the summary, then click **Next**.

   <img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/D03Tt_SSnE48YCsW/images/providers/click-next-m365.png?fit=max&auto=format&n=D03Tt_SSnE48YCsW&q=85&s=9aab82f10eab7b0067eb7d69fc8e9b76" alt="Next Detail" width="1920" height="1080" data-path="images/providers/click-next-m365.png" />

2. Click **Launch Scan** to start auditing Microsoft 365.

   <img src="https://mintcdn.com/prowler-fix-push-to-cloud-system-trust/D03Tt_SSnE48YCsW/images/providers/launch-scan.png?fit=max&auto=format&n=D03Tt_SSnE48YCsW&q=85&s=4bdffc08de476aacf90baee9750b2df1" alt="Launch Scan M365" width="1920" height="1080" data-path="images/providers/launch-scan.png" />

***

## Prowler CLI

### Step 1: Confirm PowerShell Coverage

PowerShell 7.4+ keeps the full Microsoft 365 coverage. Installation options are listed in the [Authentication guide](/user-guide/providers/microsoft365/authentication#supported-powershell-versions).

### Step 2: Select an Authentication Method

Choose the matching flag from the [Microsoft 365 Authentication](/user-guide/providers/microsoft365/authentication) guide:

* **Application Certificate Authentication** (recommended): `--certificate-auth`
* **Application Client Secret Authentication**: `--sp-env-auth`
* **Azure CLI Authentication**: `--az-cli-auth`
* **Interactive Browser Authentication**: `--browser-auth`

### Step 3: Run the First Scan

Run a baseline scan after credentials are configured:

```console theme={null}
prowler m365 --sp-env-auth
```

### Step 4: Enable Full Coverage

Include PowerShell module initialization to run every check:

```console theme={null}
prowler m365 --sp-env-auth --init-modules
```

### Region Selection

By default, Prowler connects to the global Microsoft 365 environment (`M365Global`). To target a different cloud environment, use the `--region` flag:

```console theme={null}
prowler m365 --sp-env-auth --region M365USGovernment
```

Available regions:

* **M365Global** (default): Standard commercial cloud
* **M365China**: China-operated cloud (21Vianet)
* **M365USGovernment**: US Government cloud (GCC High)

***
