Skip to main content

Guides

Each guide covers one platform from start to finish: the service account, the source, the scans, the first run, and where the results appear. Follow a guide once, right after installing Access Analyzer. After that, the reference sections for Sources, Scans, and Dashboards and reports cover the day-to-day detail.

Before you start, ensure you can sign in to Access Analyzer with the Admin role.

GuideSource type labelService account typeScans you createWhere results appear
Scan SMB file serversFile ServerUsername/passwordAccess scan, then Sensitive data scanData security dashboard, File system reports
Scan Active DirectoryActive DirectoryUsername/passwordIdentity syncActive Directory dashboard, Active Directory identity reports
Scan Entra IDEntra IDClient ID/secretIdentity syncEntra ID identity reports
Scan Microsoft 365SharePoint OnlineClient ID/certificateAccess scan, then Sensitive data scanData security dashboard, SharePoint reports

The guides are independent, but they work best in pairs. File system permission reports show account and group names only after an Active Directory Identity sync has run for the domain, so follow the Active Directory guide alongside the SMB file servers guide. SharePoint permission reports expand group membership using the latest Entra ID Identity sync for the same tenant; without it, Access Analyzer calculates permissions from SharePoint data alone. Pair the Microsoft 365 guide with the Entra ID guide.