Administration guide

Connect Microsoft and Qualys

Configure PurpleWASP Integration Management, test provider access, activate supported capabilities and validate the first manual and scheduled collection cycle.

Organisation Administrator or Integration Administrator Approximately 20–45 minutes per provider after provider-side prerequisites are ready Updated 4 October 2026

1. Understand the Integration Management model

Provider configuration is managed centrally from Admin → Integrations. PurpleWASP stores provider connections, encrypted credentials, enabled capabilities, jobs, runs, sync state and normalized observations in the tenant Integration Management service. Asset Management and Control Management consume the results according to their own responsibilities.

Collect once, evaluate many. Automated evidence is linked to canonical organisation Controls and can support every framework mapped to those Controls. PurpleWASP does not run the same provider collection separately for each framework.

Manual evidence remains supported. Integrations are an optional value-added collection path, not a prerequisite for using PurpleWASP.

2. Configure Microsoft

PurpleWASP uses one shared Microsoft tenant connection with independently enabled capabilities: microsoft.entra_identity, microsoft.m365_security, microsoft.intune_devices, microsoft.defender_endpoint and microsoft.azure_resources. Register or select a Microsoft Entra application for server-to-server collection, grant the permissions needed by the capabilities you intend to use, then enter the tenant ID, client ID and client secret in PurpleWASP.

  • Entra ID: User.Read.All, RoleManagement.Read.Directory, Policy.Read.All and AuditLog.Read.All for the supported identity streams.
  • Microsoft 365 Security: SecurityEvents.Read.All, SecurityIncident.Read.All and SecurityAlert.Read.All for the supported security streams.
  • Intune: DeviceManagementManagedDevices.Read.All and DeviceManagementConfiguration.Read.All, plus an active Intune service/licence.
  • Defender for Endpoint: Machine.Read.All and Vulnerability.Read.All, plus an active Defender for Endpoint licence.
  • Azure: Azure subscription RBAC such as Reader for inventory and Security Reader where Defender for Cloud posture is required.

Select Test Connection before activation. PurpleWASP reports readiness per capability. A licence-dependent Intune or Defender failure does not invalidate usable Entra ID, Microsoft 365 Security or Azure capabilities. After saving, enable only the capabilities the organisation actually uses; disabled capabilities are not queued by Run Sync or the scheduler.

Keep the client secret private. Enter the secret into the protected PurpleWASP form. Do not paste it into support tickets, screenshots or chat messages.

3. Configure Qualys

  1. Open Admin → Integrations and select Qualys.
  2. Enter the Qualys base/platform URL and API credentials for the organisation.
  3. Run Test Connection and resolve authentication, API-access or TLS problems before activation.
  4. Activate the connection and enable the vulnerability-finding capability.

The connection and runtime are owned by Integration Management. Vulnerability findings, Asset matching and technical-exposure lifecycle remain Asset Management domain data.

4. Activate and run the first collection

  1. Save and activate the connection after the test succeeds.
  2. Run a manual sync so you can validate the provider before relying on the schedule.
  3. Confirm the job moves from queued/running to success or an expected partial state.
  4. Allow at least one scheduled cycle and confirm the scheduler queues due work and the worker processes it.

Manual and scheduled runs use the same Integration Management job queue. The web request queues work; the background worker performs the provider API collection.

5. Understand where collected data goes

Microsoft: enabled capabilities emit normalized observations for their own domains. Entra and Microsoft 365 security facts can feed Control evidence; Intune, Defender and Azure can also hand relevant inventory/security context to Asset or Control consumers. PurpleWASP does not automatically change Control implementation status.

Qualys: the shared integration runtime collects provider data and the vulnerability domain consumes it in Asset Management. Selected technical exposure can then be linked to Risk using the normal Asset/Risk workflow.

Evidence history is preserved. For a recurring automated Control rule, the newest integration-generated evidence is current and older generated evidence is archived, while historical test runs and provenance remain available.

6. Verify the implementation

  • Microsoft Test Connection authenticates the shared connection and reports Entra ID, Microsoft 365 Security, Intune, Defender for Endpoint and Azure readiness independently.
  • Qualys Test Connection passes.
  • A manual job is processed by the canonical Integration Management worker.
  • The scheduler completes without errors and queues only due work.
  • Only enabled Microsoft capabilities create jobs; available/limited capabilities write the expected observation families.
  • Qualys findings appear in the Asset technical-exposure workflow where applicable.
  • Automated Control evidence is created only for adopted/applicable Controls and does not overwrite implementation status.
  • Scheduled collection still works after the manual acceptance test.

7. Know the current scope

The Microsoft multi-capability architecture is implemented and deployed on Windows and Linux. microsoft.entra_identity, microsoft.m365_security and microsoft.azure_resources have passed acceptance on the current test tenant. microsoft.intune_devices and microsoft.defender_endpoint are implemented but await licensed-tenant acceptance testing.

Qualys vulnerability collection is complete under qualys.vulnerability_findings. AWS is the next provider planned for architecture and implementation.

Implementation documentation

Use the handbook for rollout and the technical/runbook documents for implementation, operations and future connector development.

First-Time Implementation Handbook

Technical Implementation Guide

Operations & Troubleshooting Runbook