Chat now with support
Chat with Support

Enterprise Reporter 3.5.1 - Installation and Deployment Guide

Product Overview Installation Considerations for Enterprise Reporter Installing and Configuring Enterprise Reporter Managing Your Enterprise Reporter Deployment Troubleshooting Issues with Enterprise Reporter Appendix: Database Content Wizard Appendix: Encryption Key Manager Appendix: Log Viewer

Permissions for Enterprise Reporter tenant applications

Enterprise Reporter requires Azure applications for the collection of Azure and Microsoft 365 objects and attributes. These applications must be registered in the Azure portal and consent must be granted for delegated permissions. To manage tenant applications used by Enterprise Reporter, you use the Configuration | Application Tenant Management option.

For the Azure Active Directory discovery, the Exchange Online discovery, and the collection of nested group members for the OneDrive, Exchange Online, and Azure Resource discovery, an application with a name that begins with “Quest Enterprise Reporter Azure Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Enterprise Reporter Azure discovery application, the following permissions are required:

 

Microsoft Graph

User.ReadBasic.All

Read all users' basic profiles

Delegated

Microsoft Graph

Directory.AccessAsUser.All

Access directory as the signed in user

Delegated

Microsoft Graph

Directory.Read.All

Read directory data

Delegated

Microsoft Graph

Group.Read.All

Read all groups

 

Microsoft Graph

IdentityRiskyUser.Read.All

Read identity risky user information

Delegated

Microsoft Graph

SecurityEvents.Read.All

Read your organization's security events

Delegated

Microsoft Graph

User.Read.All

Read all users' full profiles

Delegated

Microsoft Graph

Reports.Read.All

Read all usage reports

Delegated

Microsoft Graph

UserAuthenticationMethod.Read.All

Read all users' authentication methods

Delegated

If you want to collect details about Microsoft 365 user activity, such as which licenses are assigned to a user and dates when a user last used a licensed service, the following delegated permission is required:

Also, you must clear the Microsoft default setting that anonymizes the user-level data. To include user activity data in the Enterprise Reporter reports, do the following steps:

2
Navigate to Settings | Org Settings | Services.
3
Select Reports.
4
Clear the Display concealed user, group, and site names in all reports check box.

For more information, see https://learn.microsoft.com/en-US/microsoft-365/troubleshoot/miscellaneous/reports-show-anonymous-user-name

For the OneDrive discovery, an application with a name that begins with “Quest Enterprise Reporter OneDrive Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Quest Enterprise Reporter OneDrive Discovery application, the following permissions are required:

 

Microsoft Graph

Directory.Read.All

Read directory data

Delegated

Microsoft Graph

Files.Read.All

Read all files that user can access

Delegated

Microsoft Graph

Sites.FullControl.All

Have full control of all site collections

Delegated

Microsoft Graph

Directory.AccessAsUser.All

Access directory as the signed in user

Delegated

Office 365 SharePoint Online

MyFiles.Read

Read user files

Delegated

For the Azure Resource discovery, an application with a name that begins with “Quest Enterprise Reporter Azure Resource Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Enterprise Reporter Azure Resource discovery application, the following permissions are required:

 

Microsoft Graph

User.ReadBasic.All

Read all users' basic profiles

Delegated

Microsoft Graph

Directory.AccessAsUser.All

Access directory as the signed in user

Delegated

Windows Azure Service Management API

user_impersonation

Access Azure Service Management as organization users

Delegated

For the Microsoft Teams discovery, an application with a name that begins with “Quest Enterprise Reporter Microsoft Teams Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Quest Enterprise Reporter Microsoft Teams Discovery application, the following permissions are required:

 

Microsoft Graph

Directory.Read.All

Read directory data

Delegated

Microsoft Graph

User.ReadBasic.All

Read all users' basic profiles

Delegated

Microsoft Graph

Files.Read

Read user files

Delegated

Microsoft Graph

Sites.FullControl.All

Have full control of all site collections

Delegated

Microsoft Graph

Directory.AccessAsUser.All

Access directory as the signed in user

Delegated

Microsoft Graph

Group.Read.All

Read all groups

Delegated

Office 365 SharePoint Online

MyFiles.Read

Read user files

Delegated

For the SharePoint Online discovery, an application with a name that begins with “Quest Enterprise Reporter SharePoint Online Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Quest Enterprise Reporter SharePoint Online Discovery application, the following permissions are required:

 

Microsoft Graph

Directory.Read.All

Read directory data

Delegated

Microsoft Graph

Sites.FullControl.All

Have full control of all site collections

Delegated

IDG Managing Your Deployment.4.25.html

Troubleshooting Issues with Enterprise Reporter

Troubleshooting Installation Issues

Although the installation should proceed smoothly if proper credentials are used, there are some environmental and security issues to consider.

See also:

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating