This document describes the steps to create a custom eSHARE Collaboration Attack Surface Report for Email and SharePoint applications in Microsoft Entra (Azure AD) portal. At a high level, the steps involved are:
REQUIREMENT
The Person performing these steps must have an administrator role assignment of Application Administrator, Cloud Application Administrator, or Global Administrator in the destination M365 tenant.
NOTE:
Depending on the size of your organization’s M365 tenant, multiple App Registrations may be required for optimal performance. The recommended number of App Registrations to create and provide to your eSHARE Customer Success Manager is 3 apps.
Application Registration
To register the custom App Registration for the Email Risk Report, login to Microsoft Entra console (https://entra.microsoft.com or https://entra.microsoft.us) and navigate to ‘Applications‘ > ‘App Registrations‘.
In ‘App Registrations‘ page, click the ‘+ New registration‘ button in top menu bar.
Input a recognizable unique name for the custom eShare app and select the ‘Register‘ button at bottom of the page.
In a few moments, a shell application is created and ready for further configuration.
Modify Application Manifest - Commercial Cloud
requiredResourceAccess
In the newly registered application page, navigate to the ‘Manage‘ > ‘Manifest‘ tab.
In the applications’ manifest, look for ‘requiredResourceAccess‘.

Replace the above string (including the comma at the end) from line 53 to 63 with the below text.
"requiredResourceAccess": [
{
"resourceAppId": "00000003-0000-0ff1-ce00-000000000000",
"resourceAccess": [
{
"id": "d13f72ca-a275-4b96-b789-48ebcc4da984",
"type": "Role"
}
]
},
{
"resourceAppId": "c5393580-f805-4401-95e8-94b7a6ef2fc2",
"resourceAccess": [
{
"id": "594c1fb6-4f81-4475-ae41-0c394909246c",
"type": "Role"
},
{
"id": "4807a72c-ad38-4250-94c9-4eabfe26cd55",
"type": "Role"
}
]
},
{
"resourceAppId": "00000003-0000-0000-c000-000000000000",
"resourceAccess": [
{
"id": "5e1e9171-754d-478c-812c-f1755a9a4c2d",
"type": "Role"
},
{
"id": "98830695-27a2-44f7-8c18-0c3ebc9698f6",
"type": "Role"
},
{
"id": "19da66cb-0fb0-4390-b071-ebc76a349482",
"type": "Role"
},
{
"id": "810c84a8-4a9e-49e6-bf7d-12d183f40d01",
"type": "Role"
},
{
"id": "40f97065-369a-49f4-947c-6a255697ae91",
"type": "Role"
},
{
"id": "332a536c-c7ef-4017-ab91-336970924f0d",
"type": "Role"
},
{
"id": "df021288-bdef-4463-88db-98f22de89214",
"type": "Role"
}
]
}
],Click the ‘Save‘ button in top menu bar.
Modify Application Manifest - Government Cloud
requiredResourceAccess
In the newly registered application page, navigate to the ‘Manage’ > ‘Manifest’ tab.
In the applications’ manifest, look for ‘requiredResourceAccess’.

Replace the above string (including the comma at the end) from line 58 to 68 with the below text.
"requiredResourceAccess": [
{
"resourceAppId": "00000003-0000-0ff1-ce00-000000000000",
"resourceAccess": [
{
"id": "d13f72ca-a275-4b96-b789-48ebcc4da984",
"type": "Role"
}
]
},
{
"resourceAppId": "c5393580-f805-4401-95e8-94b7a6ef2fc2",
"resourceAccess": [
{
"id": "594c1fb6-4f81-4475-ae41-0c394909246c",
"type": "Role"
},
{
"id": "4807a72c-ad38-4250-94c9-4eabfe26cd55",
"type": "Role"
}
]
},
{
"resourceAppId": "00000003-0000-0000-c000-000000000000",
"resourceAccess": [
{
"id": "5e1e9171-754d-478c-812c-f1755a9a4c2d",
"type": "Role"
},
{
"id": "98830695-27a2-44f7-8c18-0c3ebc9698f6",
"type": "Role"
},
{
"id": "19da66cb-0fb0-4390-b071-ebc76a349482",
"type": "Role"
},
{
"id": "810c84a8-4a9e-49e6-bf7d-12d183f40d01",
"type": "Role"
},
{
"id": "40f97065-369a-49f4-947c-6a255697ae91",
"type": "Role"
},
{
"id": "332a536c-c7ef-4017-ab91-336970924f0d",
"type": "Role"
},
{
"id": "df021288-bdef-4463-88db-98f22de89214",
"type": "Role"
}
]
}
],Click the ‘Save‘ button in top menu bar.
Review API permissions and complete consent
REQUIREMENT:
Granting admin consent for permissions within an app registration must be performed by a Global Administrator in the destination M365 tenant. Below is a list of all the API permissions required.
Permission | Display Name | Description | Admin Consent Required |
|---|---|---|---|
MailboxSettings.Read | Read all user mailbox settings | Allows the app to read user mailbox settings without a signed-in user. Does not include permission to send mail. | Yes |
Mail.Read | Read mail in all mailboxes | Allows the app to read mail in all mailboxes without a signed-in user. | Yes |
InformationProtectionPolicy.Read.All | Read all published labels and label policies | Allows the app to read published sensitivity labels and label policy settings for the entire organization or a specific user, without a signed-in user. | Yes |
GroupMember.Read.All | Read all group memberships | Allows the app to read memberships and basic group properties for all groups without a signed-in user. | Yes |
AuditLogsQuery.Read.All | Read audit logs data from all services | Allows the app to read and query audit logs from all services. | Yes |
User.Read.All | Read all users' full profiles | Allows the app to read user profiles without a signed-in user. | Yes |
Sites.Read.All (Graph API) | Read items in all site collections | Allows the app to read documents and list items in all site collections without a signed-in user. | Yes |
Activity.Feed.Read | Read activity data for your organization | Allows the application to read activity data for your organization. | Yes |
ActivityFeed.ReadDlp | Read DLP policy events including detected sensitive data | Allows the application to read DLP policy events, including detected sensitive data, for your organization. | Yes |
Sites.Read.All (SharePoint API) | Read items in all site collections | Allows the app to read documents and list items in all site collections without a signed in user. |
For the saved application, navigate to the ‘Manage‘ > ‘API permissions‘ tab.
Select ‘Grant admin consent for <tenant name>‘ in top of the API permissions table.
Confirm when prompted.

Upload Application Certificate
Option 1: Purchase a certificate from well-known certificate authority, extract the private and public portions of the certificate. Upload the public portion in Azure portal for the application and upload the private key in your eShare admin console (or provide the private key to your eShare admin).
Option 2: Create a self-signed certificate by following instructions available at https://learn.microsoft.com/en-us/azure/active-directory/develop/howto-create-self-signed-certificate.
A short summary of the above instructions are below:
# Create a self-signed certificate in PowerShell
$mycert = "eShareApp"
$mycert = New-SelfSignedCertificate -DnsName "eShareApp" -Subject "CN=eShareApp" -CertStoreLocation "Cert:\CurrentUser\My" -NotAfter (Get-Date).AddYears(50) -KeyExportPolicy Exportable -KeySpec Signature -KeyLength 2048 -KeyAlgorithm RSA -HashAlgorithm SHA256# Extract .key file using OpenSSL
openssl pkcs12 -in eShareApp.pfx -nocerts -nodes -out eShareApp.key# Extract crt from pfx using OpenSSL
openssl pkcs12 -in eShareApp.pfx -clcerts -nokeys -out eShareApp.crt# Export certificate to .pfx file
$mycert | Export-PfxCertificate -FilePath eShareApp.pfx -Password $(ConvertTo-SecureString -String "myp@55W0rd" -AsPlainText -Force)When appropriate certificate portions are available, navigate to ‘Manage‘ > ‘Certificates & secrets’
In ‘Certificates’ tab, click on ‘Upload certificate’ button. Upload the CRT file from the above steps and click on ‘Add’ at bottom of the open pane.
Collect Items Required for CAS Report
M365 Tenant ID: Navigate to ‘Identity > Overview’ tab of the Entra admin console, copy the ‘Tenant ID’ and save it.
Application ID: Navigate to ‘Overview’ tab of the application, copy the ‘Application (client) ID’ and save it.
Certificate Thumbprint: For the certificate used during application registration process, copy the certificate thumbprint and save it.
Private Key: The private key (.key file from above steps) for the certificate uploaded in Entra portal for the application registration.
Your Organization’s SharePoint URL: The root URL of your SharePoint tenant, without any site path. Open any SharePoint site, copy the URL, and remove everything after
.sharepoint.comExample: If the site URL ishttps://yourorganization.sharepoint.com/sites/sitename, enterhttps://yourorganization.sharepoint.com/External third party tools URL: If your organization uses third-party file sharing or collaboration tools, such as Box, Kiteworks, or Dropbox, etc, enter the base URL of each one. eSHARE uses these URLs to detect those links in email and show where content is shared outside Microsoft 365, which adds to the insights in your report. Example: If your organization uses Box, enter https://yourorganization.box.com/
Please provide this information to your eSHARE Customer Success Manager for finalizing the configuration.