Guides for administrators
Step-by-step procedures for tenant and CMDB administrators — switching Discovery on, connecting and commissioning sources, handling runs and granting access.
These guides are for the tenant administrator, who switches Discovery on, connects integrations and grants roles, and for the CMDB administrator or platform owner, who commissions sources and watches their runs. The review and audit procedures are in Guides for CMDB reviewers and auditors.
Before you start. Discovery is a preview module, tested with simulated data only. Run a pilot in a test tenant first. Commissioning (connection test, observe-only, pause, retry, run ledger) applies today to sources that use the run ledger, such as Microsoft Intune; the vulnerability scanner source does not yet use the run ledger and commissioning gate. See Availability.
Switch on Discovery for your tenant
Purpose: make Discovery available in your tenant. Prerequisite: tenant administrator.
- Open Settings and select Regulatory features.
- Find the flag
discovery_sources(group DORA) in the list. - Switch it on.
- Reload the page. Under Assets & Risk the entry Discovery sources now appears for users with discovery rights.
Afterwards: scheduled pulls start for enabled integrations that support polling. Nothing changes in the CMDB until a source is commissioned.
Important. After the first attestation is sealed the flag shows sticky. Switching it off then needs Request off... and a second person's approval.
Connect a vulnerability scanner
Purpose: use Tenable.io, Qualys VMDR or Rapid7 InsightVM as a discovery source. Prerequisite: integration.config.manage; an API key from the scanner.
- Open Settings → Integrations.
- Select Add integration.
- In Integration type, choose the Tenable / Qualys / Rapid7 connector.
- Enter a Display name and check Data residency and Capabilities.
- Select the scanner vendor and, if you do not use the vendor's public SaaS endpoint, its base URL. Set the minimum CVSS score to record if you want a floor.
- Store the API credential. TENSOR encrypts it and keeps only a reference in the configuration.
- Select Add, then Test connection. Wait for Connection successful.
- Select Enable.
Afterwards: the scanner is pulled on its schedule (6 hours by default), its assets are staged as evidence and the hourly sweep links them to CIs and records CVEs (with cve_detection_ui on).
Current limitation. Credentials are stored encrypted, but the integrations screen does not yet offer a field to enter them (step 6).
Tip. The scanner confirms CIs you already have. It never creates CIs, so unmatched scanner assets remain visible as unmatched rather than filling your CMDB with guesses.
Acknowledge non-EU data residency
Purpose: record that an integration processes data outside the EU before you enable it. Prerequisite: integration.config.manage.
- Open Settings → Integrations and select the integration.
- If it shows Non-EU data residency - acknowledgement required before enabling, read the warning.
- Select Enable. The acknowledgement dialog opens.
- Select Acknowledge and enable. The acknowledgement is recorded in the audit trail with your name and time.
Compliance. Scanner vendors default to their public SaaS region, which may be outside the EU. Check the vendor region with your data protection officer and set the base URL to an EU pod where one is available.
Onboard Microsoft Intune
Purpose: add Intune as a second, independent origin. Prerequisites: an Entra app registration (tenant ID, application (client) ID, client secret) and a Global Administrator for consent; integration.config.manage and discovery.source.manage in TENSOR.
- Open Settings → Integrations, select Add integration and choose Microsoft Intune / SCCM in Intune mode.
- Enter the Entra tenant ID and application (client) ID, and store the client secret.
- Enable the integration.
- Open Assets & Risk → Discovery sources and scroll to the Microsoft Intune onboarding panel.
- Check Required Graph scopes:
DeviceManagementManagedDevices.Read.All,DeviceManagementConfiguration.Read.All,DeviceManagementApps.Read.All. - Select Open the Entra admin-consent page and let a Global Administrator grant consent for exactly this tenant and application.
- Back in TENSOR, select Verify Graph access. Wait for Microsoft Graph accepted the read - admin consent is in place.
- Copy the scope, manifest version, fields and data classes shown in the panel into the commissioning form (see Approve a source for observe-only).
Current limitations. The integrations screen does not yet offer a field to enter the client secret (step 2). Intune pulls, stages and uses the run ledger, but its observations are not yet linked to CIs by the apply sweep.
Important. A token is issued even without consent, and every read then fails. Only Verify Graph access proves consent. Do not retype the scope digest by hand: one wrong character quarantines every run.
Run a connection test for a source
Purpose: prove that a registered source can be reached before it may stage data. Prerequisite: discovery.source.manage.
- Open Assets & Risk → Discovery sources.
- Find the source in the table. The Commissioning state column shows disabled, paused or quarantine.
- Select Connection test in the source's row.
- Check the Run ledger below for the resulting run and its Outcome.
Afterwards: the source is in state connection test. Its runs are not applied and do not count for absence.
Approve a source for observe-only
Purpose: let a source stage evidence within a scope you approve. Prerequisite: discovery.source.manage; the source is in connection test or paused.
- Open Assets & Risk → Discovery sources.
- Select Approve observe-only in the source's row. The form Approve [source] for observe-only opens.
- Enter the Approved scope digest (16 to 128 characters, copied from the onboarding panel or the source configuration).
- Enter the Manifest version.
- In Allowed fields and Allowed data classes, list the permitted values separated by commas.
- Set Maximum new records and Maximum changed records per run (defaults 1000 and 5000).
- Select Approve observe-only. Select Cancel to leave without changes.
Afterwards: the source shows observe_only and its scope digest. Runs stage evidence and appear in the run ledger, but the CMDB is not changed.
Tip. Start with low caps. A run that would exceed a cap is stopped as capped before anything is written, which protects you from a misconfigured source flooding the CMDB.
Current limitation. Moving a source from observe-only to active is supported by the service but has no button yet.
Pause a source
Purpose: stop a source temporarily without losing its approval. Prerequisite: discovery.source.manage.
- Open Assets & Risk → Discovery sources.
- Select Pause source in the source's row.
Afterwards: new runs end as paused. To resume, approve the source for observe-only again or run a new connection test. Moving a paused source straight back to active is supported by the service but has no button yet.
Read the run ledger and retry a run
Purpose: explain what a source did and re-run a pull that did not complete. Prerequisite: discovery.source.read; retry needs discovery.source.manage.
- Open Assets & Risk → Discovery sources and scroll to Run ledger.
- Read Run, Outcome (with the failure reason underneath), Mode, Received / rejected and Started.
- For a run with outcome failed, partial, quarantined, capped or paused, select Retry run.
Afterwards: a new attempt of the same run is recorded. A run can be attempted three times in total; after that TENSOR refuses further retries.
Current limitation. The run ledger tables are not yet paginated or filterable.
Recover a quarantined source
Purpose: bring a source back after a run broke its approved scope. Prerequisite: discovery.source.manage.
- Open Assets & Risk → Discovery sources. The source shows quarantine.
- In the Run ledger, read the failure reason of the quarantined run: scope mismatch, manifest version mismatch, field not allowed or data class not allowed.
- Fix the cause at the source, or decide that the new scope is acceptable.
- Select Connection test.
- Select Approve observe-only and approve the correct scope, fields and data classes.
Important. Widening a scope is a governance decision. Record the reason with your change process before you approve a larger scope.
Grant discovery access to a user
Purpose: let a colleague run or audit discovery. Prerequisite: tenant administrator.
- Open Settings → Roles to check which role carries the permissions you need (for example
cmdb_adminorauditor). - Open Users and select the user.
- Assign the role and save.
Custom roles can include individual discovery permission keys; the full list is in Roles and permissions. Platform-wide approval rules for role assignment are in Segregation of duties.
Important. Do not give the auditor role any discovery write permission. Auditors must not control the figures they attest to.
Check discovery import health
Purpose: spot failed or partial imports outside the Discovery pages. Prerequisite: access to system health.
- Open Settings → System health.
- Look for discovery import entries (failed or partial runs).
- Open Assets & Risk → Discovery sources and read the run's failure reason in the Run ledger.
- Retry the run or fix the integration under Settings → Integrations (Recent health events).
Compliance
The regulatory requirements Discovery provides evidence for, the evidence it produces, and the feature flags each piece needs.
Guides for CMDB reviewers and auditors
Step-by-step procedures for working the review inbox, deciding topology links, deviations, ambiguous identities and absent CIs, and reading and sealing the attestation.