A Checkmk special agent that monitors the expiration of Microsoft Entra (Azure AD) app registration client secrets via the Microsoft Graph API, so you can rotate them before they expire and break an integration.
What it does
Queries all app registrations in a tenant and finds those with client secrets (passwordCredentials). Creates one service per app registration, named "Graph Secret" followed by the app's name. Reports the remaining validity of the secret expiring next, with configurable WARN/CRIT thresholds (default 30 / 14 days). Full details for all of an app's secrets in the service output; optional regex exclude list for secrets you don't want monitored.
Requirements
Checkmk 2.3+ (plug-in API v2) A dedicated Entra app registration with the Application.Read.All application permission (admin consent required)
Free, MIT-licensed. Full setup guide (Entra app registration walkthrough, install via git or .mkp, WATO configuration) in the README:
https://github.com/sebfeldm/checkmk/tree/main/special_agents/check_graph_secrets