Connect your Entra tenant to let CredAware collect credential data automatically — no script needed. Uses a read-only Application.Read.All app role. Nothing is ever written to your tenant.
How it works / what you need to approve
Permission requested: Application.Read.All (Application type, not Delegated)
What it reads: App registration metadata, service principal metadata, credential key IDs, start/expiry dates, certificate thumbprints
What it never reads: Secret values, private keys, certificate private keys, access tokens, passwords
Who must approve: A Global Administrator (or Privileged Role Administrator) of your Entra tenant
Add -AutoUpload -UploadEndpoint -UploadToken to your PowerShell command.
Each scan will automatically upload to this portal and trigger alerts.
Full PowerShell command:
| Uploaded | Generated | Expired | Critical | Warning | Total |
|---|