Enterprise Recon 2.2

SharePoint Online

This section covers the following topics:


For Sitewide Licenses, all scanned SharePoint Online Targets consume data from the Sitewide License data allowance limit.

For Non-Sitewide Licenses, SharePoint Online Targets require Server & DB Licenses, and consume data from the Server & DB License data allowance limit.

See Target Licenses for more information.


Component Description
Proxy Agent ER 2.0.28 Agent and newer.

Recommended Proxy Agents:

  • Windows Agent with database runtime components
  • Windows Agent
  • Linux Agent with database runtime components
  • Linux Agent
  • FreeBSD Agent

TCP Allowed Connections Port 443 for cloud services.

Set Up SharePoint Online as a Target

To add a SharePoint Online Target:

  1. From the New Scan page, Add Targets.
  2. In the Select Target Type dialog box, select Microsoft 365 > SharePoint Online.
  3. Fill in the following fields:
    Dialog box to configure the path, credentials, and proxy agent for a SharePoint Online Target

    Field Description
    SharePoint Online Domain Enter your SharePoint Online organization name.
    For example, if you access SharePoint Online at https://mycompany.sharepoint.com, enter mycompany.
    New Credential Label Enter a descriptive label for the credential set.
    New Username Enter a SharePoint Online user's email address.
    User must have Read permissions to the top-level root site collection, and minimum Read permissions to all site collections, sites and lists to be scanned.
    New Password Enter the password for the SharePoint Online user.
    Agent to act as proxy host Select a Proxy Agent.
    Recommended Least Privilege User Approach

    To reduce the risk of data loss or privileged account abuse, the Target credentials provided for the intended Target should only be granted read-only access to the exact resources and data that require scanning. Never grant full user access privileges or unrestricted data access to any application if it is not required.

  4. Click Test. If ER2 can connect to the Target, the button changes to a Commit button.
  5. Click Commit to add the Target.

Edit SharePoint Online Target Path

  1. Set Up SharePoint Online as a Target.
  2. In the Select Locations section, select your SharePoint Online Target and click Edit.
  3. In the Edit SharePoint Online dialog box, enter the site collection to scan in the Path. Use the following syntax:
    Description, Syntax and Example

    Scan all resources for the SharePoint Online web application.

    This includes all site collections, sites, lists, list items, folders and files.


    Leave Path blank.

    Scan a site collection.

    This includes all sites, lists, list items, folders and files for the site collection.





    Scan a site in a site collection.





    Scan all lists in a site collection.





    Scan a specific list in a site collection.





    Scan all folders and files in a site collection.





    Scan a specific folder in a site collection.





    Scan a specific file in a site collection.





    Scan a specific file within a folder in a site collection.





  4. Click Test and then Commit to save the path to the Target location.

Deleted SharePoint Online Sites

In SharePoint Online, deleted sites or site collections are retained for 93 days in the site Recycle Bin, unless deleted permanently. These deleted sites or site collections in SharePoint Online Targets are still discoverable by ER2, but will result in "HTTP 404" errors when attempting to probe or scan them.