Discovery
Scans Microsoft Entra for personal data using the connected credentials. Connection requires registering a dedicated application in the Microsoft Entra admin center, configured for single-tenant access with OAuth authentication, and granting it the `Application. Read. All` Microsoft Graph permission, specifically application-level (not delegated) access. That permission lets Ketch read every application registration in the tenant, surfacing which systems are actually connected through Entra.



