> ## Documentation Index
> Fetch the complete documentation index at: https://prowler-feat-supabase-provider-poc.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Prowler product naming: Prowler App is now Prowler Local Server, and Prowler Enterprise is now Prowler Private Cloud. Always use the current names when answering. The full product reference is at /getting-started/products: Open Source projects are Prowler CLI, Prowler Local Server, Prowler Local Dashboard, and Prowler SDK; Prowler Products are Prowler Cloud, Prowler Private Cloud, Prowler Hub, Prowler Lighthouse AI, and Prowler MCP.

# Getting Started With Microsoft 365 on Prowler

<Note>
  **Government Cloud Support**

  Government cloud accounts or tenants (Microsoft 365 Government) are currently unsupported, but we expect to add support for them in the near future.
</Note>

## Prerequisites

Set up authentication for Microsoft 365 with the [Microsoft 365 Authentication](/user-guide/providers/microsoft365/authentication) guide before starting either path:

* Register an application in Microsoft Entra ID
* Grant the Microsoft Graph and external API permissions listed for the provider
* Generate an application certificate (recommended) or client secret
* Prepare PowerShell module permissions to enable every check

<CardGroup cols={2}>
  <Card title="Prowler Cloud" icon="cloud" href="#prowler-cloud">
    Onboard Microsoft 365 using Prowler Cloud
  </Card>

  <Card title="Prowler CLI" icon="terminal" href="#prowler-cli">
    Onboard Microsoft 365 using Prowler CLI
  </Card>
</CardGroup>

## Prowler Cloud

### Step 1: Locate the Domain ID

1. Open the Entra ID portal, then search for "Domain" or go to Identity > Settings > Domain Names.

   <img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/KzNPdHkMeXASKVPY/images/providers/search-domain-names.png?fit=max&auto=format&n=KzNPdHkMeXASKVPY&q=85&s=1b35db20ca3356f902377afd5238a8c9" alt="Search Domain Names" width="1204" height="354" data-path="images/providers/search-domain-names.png" />

   <img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/KzNPdHkMeXASKVPY/images/providers/custom-domain-names.png?fit=max&auto=format&n=KzNPdHkMeXASKVPY&q=85&s=2099c90ff4b7da3a837b165486b72752" alt="Custom Domain Names" width="2038" height="1106" data-path="images/providers/custom-domain-names.png" />

2. Select the domain that acts as the unique identifier for the Microsoft 365 account in Prowler Cloud.

### Step 2: Open Prowler Cloud

1. Go to [Prowler Cloud](https://cloud.prowler.com/) or launch [Prowler Local Server](/user-guide/tutorials/prowler-app).

2. Navigate to "Configuration" > "Providers".

   <img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/ob861A0sTNe5hi6g/images/prowler-app/cloud-providers-page.png?fit=max&auto=format&n=ob861A0sTNe5hi6g&q=85&s=b6ae1270218cb05d49260767289d9703" alt="Providers Page" width="263" height="917" data-path="images/prowler-app/cloud-providers-page.png" />

3. Click "Add Provider".

   <img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/ob861A0sTNe5hi6g/images/prowler-app/add-cloud-provider.png?fit=max&auto=format&n=ob861A0sTNe5hi6g&q=85&s=c60a2512aed94c2b7e2e009b0204d563" alt="Add a Provider" width="380" height="80" data-path="images/prowler-app/add-cloud-provider.png" />

4. Select "Microsoft 365".

   <img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/ob861A0sTNe5hi6g/images/providers/select-m365-prowler-cloud.png?fit=max&auto=format&n=ob861A0sTNe5hi6g&q=85&s=97ee8963b97d31ccd7a79df0a9eac696" alt="Select Microsoft 365" width="1920" height="1080" data-path="images/providers/select-m365-prowler-cloud.png" />

5. Add the Domain ID and an optional alias, then click "Next".

   <img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/mhJQaAejI1lK27qo/images/providers/add-domain-id.png?fit=max&auto=format&n=mhJQaAejI1lK27qo&q=85&s=415bf72a07bc0f789d798682c5993bd4" alt="Add Domain ID" width="1920" height="1080" data-path="images/providers/add-domain-id.png" />

### Step 3: Choose and Provide Authentication

After the Domain ID is in place, select the app-only authentication option that matches the Microsoft Entra ID setup:

<img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/KzNPdHkMeXASKVPY/images/providers/m365-auth-selection-form.png?fit=max&auto=format&n=KzNPdHkMeXASKVPY&q=85&s=5bcb76706fffb1739d3427639804fa00" alt="M365 authentication method selection" width="700" data-path="images/providers/m365-auth-selection-form.png" />

#### Application Certificate Authentication (Recommended)

1. Enter the **tenant ID**, the unique identifier for the Microsoft Entra ID directory.
2. Enter the **application (client) ID**, the identifier for the Entra application registration.
3. Upload the **certificate file content** (Base64-encoded PFX).

<img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/KzNPdHkMeXASKVPY/images/providers/certificate-form.png?fit=max&auto=format&n=KzNPdHkMeXASKVPY&q=85&s=a6d0180c4b4beb89a8878b6d14793649" alt="M365 certificate authentication form" width="700" data-path="images/providers/certificate-form.png" />

Use this method to avoid managing secrets and to unlock all Microsoft 365 checks, including the PowerShell-based ones. Full setup steps are in the [Authentication guide](/user-guide/providers/microsoft365/authentication#application-certificate-authentication-recommended).

#### Application Client Secret Authentication

1. Enter the **tenant ID**.
2. Enter the **application (client) ID**.
3. Enter the **client secret**.

<img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/ob861A0sTNe5hi6g/images/providers/secret-form.png?fit=max&auto=format&n=ob861A0sTNe5hi6g&q=85&s=216dc69361a3781d2b9bcf58a4400352" alt="M365 client secret authentication form" width="700" data-path="images/providers/secret-form.png" />

For the complete setup workflow, follow the [Authentication guide](/user-guide/providers/microsoft365/authentication#application-client-secret-authentication).

### Step 4: Launch the Scan

1. Review the summary, then click **Next**.

   <img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/KzNPdHkMeXASKVPY/images/providers/click-next-m365.png?fit=max&auto=format&n=KzNPdHkMeXASKVPY&q=85&s=708163075453d887204e900a14a437c2" alt="Next Detail" width="1920" height="1080" data-path="images/providers/click-next-m365.png" />

2. Click **Launch Scan** to start auditing Microsoft 365.

   <img src="https://mintcdn.com/prowler-feat-supabase-provider-poc/KzNPdHkMeXASKVPY/images/providers/launch-scan.png?fit=max&auto=format&n=KzNPdHkMeXASKVPY&q=85&s=c01e3ecd8e0edfa7bf349dd02268a8ca" alt="Launch Scan M365" width="1920" height="1080" data-path="images/providers/launch-scan.png" />

***

## Prowler CLI

### Step 1: Confirm PowerShell Coverage

PowerShell 7.4+ keeps the full Microsoft 365 coverage. Installation options are listed in the [Authentication guide](/user-guide/providers/microsoft365/authentication#supported-powershell-versions).

### Step 2: Select an Authentication Method

Choose the matching flag from the [Microsoft 365 Authentication](/user-guide/providers/microsoft365/authentication) guide:

* **Application Certificate Authentication** (recommended): `--certificate-auth`
* **Application Client Secret Authentication**: `--sp-env-auth`
* **Azure CLI Authentication**: `--az-cli-auth`
* **Interactive Browser Authentication**: `--browser-auth`

### Step 3: Run the First Scan

Run a baseline scan after credentials are configured:

```console theme={null}
prowler m365 --sp-env-auth
```

### Step 4: Enable Full Coverage

Include PowerShell module initialization to run every check:

```console theme={null}
prowler m365 --sp-env-auth --init-modules
```

### Region Selection

By default, Prowler connects to the global Microsoft 365 environment (`M365Global`). To target a different cloud environment, use the `--region` flag:

```console theme={null}
prowler m365 --sp-env-auth --region M365USGovernment
```

Available regions:

* **M365Global** (default): Standard commercial cloud
* **M365China**: China-operated cloud (21Vianet)
* **M365USGovernment**: US Government cloud (GCC High)

***
