Administration guide

Operate and troubleshoot integrations

Monitor the shared Integration Management worker and scheduler, interpret jobs/runs, rotate credentials and resolve common Microsoft capability and Qualys integration problems.

Organisation Administrator, Integration Administrator or Technical Support Ongoing operations Updated 4 October 2026

1. Runtime model

The scheduler discovers due integrations and queues jobs; it does not perform provider API calls. The persistent worker claims queued jobs and performs provider collection. Manual Run Sync and scheduled collection therefore converge on the same job queue.

Expected service behaviour: the worker stays running. The scheduler is short-lived and can correctly appear inactive between successful runs.

2. Check runtime health

  • Confirm the worker process/service is running from the canonical assets/integration_management/integration_worker.php path.
  • Confirm the scheduler/timer continues to run and its latest result has no errors.
  • Review queued/running jobs for unexpected accumulation.
  • Review recent provider runs for repeated errors or unexpected partial results.
  • Review provider credential expiry and rotation ownership regularly.
  • Confirm disabled Microsoft capabilities are not being queued by manual or scheduled execution.

3. Triage jobs and runs

  1. Identify the integration ID, provider and capability.
  2. Check whether the job is queued, running, successful or failed.
  3. If queued for too long, check the worker and the job availability time.
  4. If failed, use the friendly operator message first, then the protected server logs for the technical cause.
  5. Inspect run metrics and sync state before resetting any watermark.

A partial run can still contain usable observations. Do not treat every partial result as equivalent to a failed connection.

4. Microsoft capability issues

A shared token failure affects the Microsoft connection, but capability readiness is independent after authentication. Entra user/role/Security Defaults failures are required Entra problems; MFA registration, Conditional Access and sign-in activity can remain limited. Microsoft 365 Security may succeed with partial stream coverage. Request not applicable to target tenant for Intune usually points to tenant provisioning/licensing, while Defender 403 / No active license found is a licence condition. Azure authentication with zero visible subscriptions should trigger a Reader/Security Reader RBAC check.

Disable capabilities that the tenant cannot currently use. PurpleWASP preserves the per-capability selection, and Run Sync/scheduled execution should queue only is_enabled=1 capabilities.

5. Qualys issues

If Test Connection fails, verify the Qualys platform/base URL, API credentials, provider API access and TLS/CA configuration. If a run succeeds but Asset findings do not change, inspect the Asset-domain ingestion/matching step rather than moving provider credentials or scheduling logic back into Asset Management.

6. Control evidence automation

If provider collection succeeds but no automated Control evidence appears, confirm the Control is already adopted, applicable and active; the canonical rule is active and mapped; and the run contains the observation types the rule requires. A repeated evaluation of the same run/rule is intentionally idempotent.

Do not repair evidence by changing implementation status. Integration evidence and test outcomes are assurance facts. Management still controls the organisation Control implementation decision.

7. Rotate credentials safely

  1. Create the replacement provider secret/password.
  2. Update PurpleWASP without exposing the secret in logs or support channels.
  3. Run Test Connection.
  4. Run one manual sync and confirm a successful or expected partial result.
  5. Revoke the old provider credential only after the replacement is proven where overlap is supported.

8. Canonical service paths

Windows/WAMP: C:\wamp64\compout\assets\integration_management\integration_worker.php and integration_scheduler.php.

Linux: /var/compout/assets/integration_management/integration_worker.php and integration_scheduler.php, normally using purplewasp-integration-worker.service and the scheduler service/timer.

Legacy Asset Management integration-worker/scheduler paths are retired and should not be restored.

Operations documentation

Download the Operations & Troubleshooting Runbook

Download the Technical Implementation Guide

Download the Provider Development Guide