- Documentation
- Getting started
Register the app and grant Microsoft Graph consent
Create the Entra app registration Certaria uses to read your tenant's compliance signals, and grant admin consent. About 15 minutes, once.
Who this is for: the person in your organisation who holds the Global Administrator role (or Privileged Role Administrator) in Microsoft Entra ID. Granting admin consent requires that role.
Where: the Microsoft Entra admin centre, then the Certaria app to record the result.
How long it takes: about 15 minutes, once.
Why this step exists: Certaria reads a small, fixed set of signals from your Microsoft 365 tenant (for example your Secure Score, device compliance, and Conditional Access policy names) and maps them to ISO 27001 Annex A controls as evidence. It also writes the documents it produces for you, such as your Statement of Applicability PDF, into your own ISMS site.
What you will end up with
Section titled “What you will end up with”- A single app registration in your Entra ID, named for Certaria.
- Ten Microsoft Graph application permissions granted on that app, with your admin consent recorded. Eight of them read. Two of them let Certaria write the documents it generates into your ISMS site.
- One client secret, which you paste into Certaria once. The secret is stored in your own environment. Talastron never sees it.
Before you start, it helps to have the Certaria onboarding page open in one browser tab and the Microsoft Entra admin center open in another.
Step 1: Register the application
Section titled “Step 1: Register the application”- Sign in to the Microsoft Entra admin center at
https://entra.microsoft.comwith your Global Administrator account. - In the left navigation, select Microsoft Entra ID, expand Identity, expand Applications, then select App registrations.
- Select New registration.
- In Name, enter something clear, for example
Certaria ISMS Evidence Reader. - Under Supported account types, select Accounts in this organizational directory only (single tenant). Certaria never reaches beyond your own tenant.
- Leave Redirect URI empty for now.
- Select Register.
- On the app’s Overview page, copy the Application (client) ID and the Directory (tenant) ID. You will paste these into Certaria during onboarding.
Step 2: Add the ten Graph permissions
Section titled “Step 2: Add the ten Graph permissions”- On the app, under Manage, select API permissions.
- If a default User.Read delegated permission is listed, you can leave it or remove it. It is not one of the ten Certaria uses.
- Select Add a permission, then Microsoft Graph, then Application permissions. Application permissions let Certaria read the signals on a schedule without a person needing to be signed in, which is what the recurring readiness scan requires.
- Search for and tick each of the following ten permissions, then select Add permissions:
The eight that read.
| Permission | What Certaria reads with it |
|---|---|
SecurityEvents.Read.All | Your Secure Score and security alerts (read only) |
DeviceManagementManagedDevices.Read.All | Intune device inventory and compliance state |
SensitivityLabels.Read.All | The names and counts of your published sensitivity labels |
AuditLog.Read.All | Confirmation that audit telemetry is flowing (a presence check) |
User.Read.All | User and group directory reads for access-review evidence |
RoleManagement.Read.Directory | Who holds privileged roles, to evidence privileged-access control |
Policy.Read.All | Your Conditional Access policy definitions (names and conditions) |
Directory.Read.All | The list of third-party apps granted access to your tenant |
None of those eight lets Certaria create, change or delete anything in your tenant.
The two that write.
| Permission | What Certaria does with it |
|---|---|
Files.ReadWrite.All | Generates your documents. Certaria writes a temporary file into your ISMS document library, asks Microsoft to convert it to PDF, saves the PDF, and deletes the temporary file. This is how your Statement of Applicability and compliance summary PDFs are produced. |
Sites.ReadWrite.All | Finds and writes to the document libraries on your ISMS site |
Worth understanding before you consent. Microsoft names these two permissions broadly, and they are broad. On the consent screen they read “Read and write files in all site collections” and “Read and write items in all site collections”, and by permission that is what they allow. Microsoft does offer a per-site alternative (Sites.Selected), which needs a separate grant by a Global Administrator after your ISMS site exists; Certaria does not currently use it. What Certaria actually does with them is narrow: it writes the documents it generates into your ISMS site, and nothing else. Every write Certaria performs is a file it produced for you.
The app holding these permissions is one you created, in your tenant, with a secret only you hold. You can inspect exactly what it did at any time in your Microsoft 365 audit log, and revoke it in a click.
The table above is the whole list. Certaria asks for nothing else, and the Microsoft consent screen in Step 3 shows you exactly the same set before you approve it.
Step 3: Grant admin consent
Section titled “Step 3: Grant admin consent”- Still on the API permissions page, select Grant admin consent for [your organisation].
- Select Yes to confirm.
- Confirm that the Status column now shows a green tick reading Granted for [your organisation] against all ten permissions.
If the Grant admin consent button is greyed out, your account does not hold a role that can consent. Ask a Global Administrator or Privileged Role Administrator to complete this step.
Partial consent is a real failure mode. Certaria’s first readiness scan checks that the permissions are genuinely consented, and will tell you if any are missing, so it is worth confirming all ten show the green tick before you move on.
Step 4: Create a client secret
Section titled “Step 4: Create a client secret”- On the app, under Manage, select Certificates & secrets.
- Select New client secret.
- Enter a description, for example
Certaria evidence reader, and choose an expiry period. Choose a period you are comfortable managing. See “Keeping the secret valid” below. - Select Add.
- Copy the secret from the Value column immediately. Microsoft shows this value only once. If you navigate away without copying it, you will need to create a new secret.
Paste the secret into Certaria where the onboarding page asks for it, alongside the client ID and tenant ID from Step 1. The secret is stored inside your own environment. Talastron does not receive it, store it, or have any way to read it.
Keeping the secret valid
Section titled “Keeping the secret valid”The client secret has an expiry date that you set in Step 4. When it expires, Certaria’s scheduled readiness scans will stop working until you create a new secret and paste it into Certaria again. This is the one piece of routine maintenance this setup requires.
We recommend two things:
- Set a calendar reminder a couple of weeks before the expiry date you chose.
- When the reminder fires, repeat Step 4 to create a fresh secret and update it in Certaria. Certaria also surfaces a warning in its health log as the expiry approaches, so you have notice from inside the product as well.
If something does not work
Section titled “If something does not work”“Grant admin consent” is greyed out. Your account cannot consent. A Global Administrator or Privileged Role Administrator needs to complete Step 3.
A permission still shows “Not granted” after consent. Select Grant admin consent again and confirm. If one permission stubbornly refuses, remove it, add it again from Step 2, and re-consent.
The readiness scan reports missing consent. Return to API permissions and confirm all ten show the green Granted tick. The scan checks each one, so a single missing permission is enough to flag it.
A sign-in or redirect error mentioning the Certaria Graph connection (for example a redirect-URI mismatch). The Certaria document-generation feature uses a separate Microsoft-managed connection that has its own redirect address. If you see a redirect-URI error when setting up that connection, add the exact redirect address shown in the error to your app registration under Manage, Authentication, Add a platform, Web. Your onboarding contact can confirm the address for your environment.
What you can revoke, and when
Section titled “What you can revoke, and when”You are always in control:
- You can revoke admin consent, or delete the app registration entirely, from the Microsoft Entra admin center at any time, without contacting Talastron.
- Revoking consent or deleting the app stops Certaria reading any signals immediately.
- Certaria holds no credentials of its own and has no standing access. Everything runs inside your tenant, on your Microsoft 365 licences, using the identity you created here.