title: Microsoft Graph App Secrets: Client Secret Expiration
agents: check_graph_secrets
catalog: cloud/other
license: GPLv2
distribution: check_mk
description:
 This check monitors the expiration of client secrets (passwordCredentials)
 of Microsoft Entra app registrations, retrieved via the Microsoft Graph API
 by the {check_graph_secrets} special agent.

 One service is discovered per app registration that has at least one client
 secret. The service reports the remaining validity of the secret that
 expires next. Once a secret's remaining validity drops below the configured
 warning or critical threshold, the service changes state so you can rotate
 the secret before it expires.

 To use this check, set up the special agent {check_graph_secrets}. It
 requires an app registration with the application permission
 {Application.Read.All}, granted with admin consent.

item:
 The display name of the Microsoft Entra app registration. If multiple app
 registrations share the same display name, the object ID suffix is
 appended to make the item unique.

discovery:
 One service is created for each app registration that has at least one
 client secret.
