Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideConfigure PurpleWASP Integration Management, test provider access, activate supported capabilities and validate the first manual and scheduled collection cycle.
Provider configuration is managed centrally from Admin → Integrations. PurpleWASP stores provider connections, encrypted credentials, enabled capabilities, jobs, runs, sync state and normalized observations in the tenant Integration Management service. Asset Management and Control Management consume the results according to their own responsibilities.
Manual evidence remains supported. Integrations are an optional value-added collection path, not a prerequisite for using PurpleWASP.
PurpleWASP uses one shared Microsoft tenant connection with independently enabled capabilities: microsoft.entra_identity, microsoft.m365_security, microsoft.intune_devices, microsoft.defender_endpoint and microsoft.azure_resources. Register or select a Microsoft Entra application for server-to-server collection, grant the permissions needed by the capabilities you intend to use, then enter the tenant ID, client ID and client secret in PurpleWASP.
Select Test Connection before activation. PurpleWASP reports readiness per capability. A licence-dependent Intune or Defender failure does not invalidate usable Entra ID, Microsoft 365 Security or Azure capabilities. After saving, enable only the capabilities the organisation actually uses; disabled capabilities are not queued by Run Sync or the scheduler.
The connection and runtime are owned by Integration Management. Vulnerability findings, Asset matching and technical-exposure lifecycle remain Asset Management domain data.
Manual and scheduled runs use the same Integration Management job queue. The web request queues work; the background worker performs the provider API collection.
Microsoft: enabled capabilities emit normalized observations for their own domains. Entra and Microsoft 365 security facts can feed Control evidence; Intune, Defender and Azure can also hand relevant inventory/security context to Asset or Control consumers. PurpleWASP does not automatically change Control implementation status.
Qualys: the shared integration runtime collects provider data and the vulnerability domain consumes it in Asset Management. Selected technical exposure can then be linked to Risk using the normal Asset/Risk workflow.
The Microsoft multi-capability architecture is implemented and deployed on Windows and Linux. microsoft.entra_identity, microsoft.m365_security and microsoft.azure_resources have passed acceptance on the current test tenant. microsoft.intune_devices and microsoft.defender_endpoint are implemented but await licensed-tenant acceptance testing.
Qualys vulnerability collection is complete under qualys.vulnerability_findings. AWS is the next provider planned for architecture and implementation.
Use the handbook for rollout and the technical/runbook documents for implementation, operations and future connector development.
First-Time Implementation Handbook