Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideMonitor the shared Integration Management worker and scheduler, interpret jobs/runs, rotate credentials and resolve common Microsoft capability and Qualys integration problems.
The scheduler discovers due integrations and queues jobs; it does not perform provider API calls. The persistent worker claims queued jobs and performs provider collection. Manual Run Sync and scheduled collection therefore converge on the same job queue.
assets/integration_management/integration_worker.php path.A partial run can still contain usable observations. Do not treat every partial result as equivalent to a failed connection.
A shared token failure affects the Microsoft connection, but capability readiness is independent after authentication. Entra user/role/Security Defaults failures are required Entra problems; MFA registration, Conditional Access and sign-in activity can remain limited. Microsoft 365 Security may succeed with partial stream coverage. Request not applicable to target tenant for Intune usually points to tenant provisioning/licensing, while Defender 403 / No active license found is a licence condition. Azure authentication with zero visible subscriptions should trigger a Reader/Security Reader RBAC check.
Disable capabilities that the tenant cannot currently use. PurpleWASP preserves the per-capability selection, and Run Sync/scheduled execution should queue only is_enabled=1 capabilities.
If Test Connection fails, verify the Qualys platform/base URL, API credentials, provider API access and TLS/CA configuration. If a run succeeds but Asset findings do not change, inspect the Asset-domain ingestion/matching step rather than moving provider credentials or scheduling logic back into Asset Management.
If provider collection succeeds but no automated Control evidence appears, confirm the Control is already adopted, applicable and active; the canonical rule is active and mapped; and the run contains the observation types the rule requires. A repeated evaluation of the same run/rule is intentionally idempotent.
Windows/WAMP: C:\wamp64\compout\assets\integration_management\integration_worker.php and integration_scheduler.php.
Linux: /var/compout/assets/integration_management/integration_worker.php and integration_scheduler.php, normally using purplewasp-integration-worker.service and the scheduler service/timer.
Legacy Asset Management integration-worker/scheduler paths are retired and should not be restored.
Download the Operations & Troubleshooting Runbook