Can Microsoft Authenticated Scans Work with Entra ID-Joined Devices?
Question details
The user needs to know whether Microsoft authenticated scanning supports Entra ID-joined workstations, how unauthorized assets are handled, and if scan policies can include predefined credentials.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Determining network and asset scanning capabilities and credential configurations for workstations joined to a Microsoft Entra ID environment.
- Observed behavior
- Seeking official clarification on specific enterprise authenticated scanning features and proper routing for technical support.
Before troubleshooting, identify the specific Microsoft security product you are using (e.g., Microsoft Defender for Endpoint or a third-party vulnerability scanner), as scanning capabilities and authentication methods vary by tool.
Consult Product-Specific Documentation and Microsoft Q&A
Because scanning capabilities depend entirely on the specific security product deployed, you must route your query to the correct documentation and specialist forums.
The term 'authenticated scanning' applies to various vulnerability and network discovery tools. The ability to scan Entra ID-joined devices, handle unauthorized assets, and use predefined credentials relies entirely on the architecture of the specific tool you are using.
Ensure you do not mistakenly post infrastructure and vulnerability scanning questions in the Microsoft Authenticator app forum, as that team only handles multi-factor authentication app queries.
Determine the exact software or service you are using to perform network and asset scans (e.g., Azure Security Center, Microsoft Defender, or a third-party application).
Navigate to the official Microsoft Learn website and search for documentation specific to your tool by querying its name alongside 'authenticated scan Entra ID credentials'.
If the documentation is unclear, go to the Microsoft Q&A platform and select the specific tags for your security product to ask specialists about predefined credentials and unauthorized asset discovery.

Need a Reliable, Secure Alternative for Daily Office Tasks?
While managing enterprise security policies and authenticated scans in Entra ID requires specialized tools, handling your daily documents doesn't have to be complicated. WPS Office provides a secure, lightweight, and highly compatible alternative to Microsoft Office for your workplace.
- 1. Download the software: Visit the official WPS Office website and download the secure, lightweight installer for your operating system.
- 2. Install the suite: Run the installer and follow the on-screen instructions to set up the software in seconds.
- 3. Open your files: Double-click your existing Microsoft Office documents to open them directly in WPS Office with all formatting flawlessly preserved.

Frequently Asked Questions
Does the Microsoft Authenticator app perform network asset scans?
No, the Microsoft Authenticator app is strictly designed for identity verification and multi-factor authentication (MFA). It does not perform network, vulnerability, or authenticated asset scanning.
Can I scan unauthorized assets on an Entra ID network?
Scanning unauthorized or unmanaged assets typically requires dedicated network discovery features, such as those found in Microsoft Defender for Endpoint's Device Discovery, rather than standard Entra ID identity policies.
Do authenticated vulnerability scans support predefined credentials?
This depends entirely on the vulnerability scanner you are using. Many enterprise-grade scanning tools allow administrators to configure predefined service account credentials to authenticate and inspect devices during a scan.




