Provision a SharePoint Online Delegate Account in Office 365 to allow Cloud App Security to scan files stored in SharePoint Online or OneDrive. Cloud App Security uses the Delegate Account to run advanced threat protection and data loss prevention scanning when files are updated.
Before Provisioning
Before you begin provisioning, follow these steps to make sure that Control access from apps that don't use modern authentication is correctly set on the Microsoft 365 admin center:
Creating a Delegate Account
Cloud App Security uses a single SharePoint Online Delegate Account for both SharePoint Online and OneDrive. If you have already manually provisioned the Delegate Account for one of the two services, you do not need to create a Delegate Account and change the Delegate Account password again. Go directly to Verifying the Delegate Account and Managing SharePoint Online Site Collections or Managing OneDrive Site Collections based on which service you are manually provisioning at the moment.
Creating a Delegate Account can fail due to an internal Office 365 issue. If this should occur, try again in a few hours or in twenty-four hours.
Changing the Delegate Account Password
Verifying the Delegate Account
- Go back to the Delegate Account (Manually) tab on the Cloud App Security management console.
- Scroll down the instructions, and then specify the SharePoint Online Delegate Account credentials in the email address and password text boxes.
- Click Verify.
Managing SharePoint Online Site Collections
Complete this task if you license the SharePoint Online service.
Managing OneDrive Site Collections
Complete this task if you license the OneDrive service.