Reference
Policies for Entra ID
See the Entra ID inventory reference for the objects these templates work on.
| Policy | Description | Severity | Category | Checks |
|---|---|---|---|---|
| Applications with client secrets that are about to expire | Shows Entra ID applications where client secrets expire in the next 30 days | High | Operation | Application registration |
| Applications with expired certificates | Shows Entra ID applications with expired certificates | High | Operation | Application registration |
| Enterprise Applications Using Exchange Web Services (EWS) ⭐ | This policy detects app registrations in Microsoft Entra ID with the EWS.AccessAsUser.All delegated API permission, which will be deprecated by Microsoft in October 2026. Review each flagged app registration and work with the application owner to migrate from Exchange Web Services (EWS) to Microsoft Graph API before October 2026. Use the EWS Deprecation Hub (https://aka.ms/ews1page50) to understand the timeline and the EWS Audit Tools (https://aka.ms/ewsTools) to identify all EWS dependencies across your tenant. For migration guidance, refer to the Microsoft Graph API documentation (https://learn.microsoft.com/en-us/graph/overview) | High | Security | Enterprise Application |
| Enterprise applications that use SharePoint Online permissions | Shows Enterprise applications that use SharePoint Online permissions | Information | Security | Enterprise Application |
| Applications with expired client secrets | Shows Entra ID applications with expired client secrets | High | Operation | Application registration |
| Application registrations without owners | Shows Application registrations without any owners | Medium | Operation | Application registration |
| Enterprise applications with Full Control or Write permissions | Shows Enterprise applications with permissions that contain the words FullControl or Write | Medium | Security | Enterprise Application |
| Enterprise Applications without owners | Shows Enterprise Applications without owners (excluding first-party Microsoft apps) | Medium | Operation | Enterprise Application |
| Risky Sign-Ins | Shows Sign-Ins with risk state "At Risk" | High | Security | Risky Entra ID Sign-In |
| Enterprise applications (SharePoint Add-Ins) with certificates or client secrets | Shows Enterprise applications with certificates or client secrets. In most cases these applications are SharePoint Add-Ins | Medium | Operation | Enterprise Application |
| Applications with certificates that are about to expire | Shows Entra ID applications where certificates expire in the next 30 days | High | Operation | Application registration |
| Enterprise applications that use Microsoft Graph permissions | Shows Entra ID apps that use Microsoft Graph permissions | Information | Security | Enterprise Application |
| Devices with disabled user accounts | Shows devices with disabled owners or user accounts | Medium | Operation | Device |
| Enterprise applications (SharePoint Add-Ins) with expired certificates or client secrets | Shows Enterprise applications with expired certificates or client secrets. In most cases these applications are SharePoint Add-Ins | Medium | Operation | Enterprise Application |