You can accomplish this by configuring the following:
- Log into Microsoft Entra
- Create a Entra User dedicated to Lansweeper scanning or a Service Principle Account (Workload Identity)
- Grant the following role permanently to the new account
Microsoft Entra Joined Device Local Administrator | Users assigned to this role are added to the local administrators group on Microsoft Entra joined devices. | | |
- Add the Scan Credentials into Lansweeper as Windows device credentials
- Create a new Scan Target for Windows Devices and the Domain as WORKGROUP
- Assign the Scan Credentials to the new Scan Target and wait about 2-4 hours for the role you assigned to propagate
You can now scan workstations joined to your Entra environment as long as they are reachable via your Scan Server
I hope this helps!