icon-itdr.svg
ITDR

Adding an Entra ID Object to the Safelist

On the Detailed Findings and Recommendations page for an Entra ID issue in the Entra ID dashboard, you can view the list of Entra ID objects (users and service principals) that are vulnerable to attack. You can review these objects to confirm that they are not a risk and mark them as safe.

Adding objects to the safelist impacts the unified risk score on the Entra ID Dashboard.

After you add objects to a safelist, they disappear from the Who is affected? section on the Detailed Findings and Recommendations page and vulnerability report for that particular issue only. These objects are not marked safe if you select a different issue in the same Entra ID tenant.

To add an object to the safelist:

  1. Go to ITDR > Dashboard > Entra ID.
  2. On the Entra ID Dashboard:
    1. Select an Entra ID tenant from the Result for drop-down menu.
    2. Select a timestamp from the scanned on drop-down menu.

      The scan result for the Entra ID tenant appears.

  3. Under Detailed Findings and Recommendations, click an issue.

  4. On the Detailed Findings and Recommendations page, scroll down to the Who is affected? section for the selected issue.
  5. Add objects to the safelist using one of the following methods:
    • To add a specific item to the object safelist, click the Shield icon to mark an object safe.

    • To add multiple items to the object safelist, select the items, and click Add Objects to Safelist.

  6. In the Add to Safelist window, enter a reason for marking this Entra ID object safe and set an expiration date if needed.

    If you are adding multiple objects to the safelist simultaneously, the same reason and expiration date are applied to all those objects.

  7. Click Save.

    The Entra ID object is added to the safelist. You can view and manage it from the Entra ID Object Safelist.

A screenshot of adding object to safelist option in remidiation chart

Related Articles
About the Entra ID Object SafelistAdding an Entra ID Object to the SafelistDeleting an Object from the Entra ID Object Safelist