Provision a SharePoint Online Delegate Account in Office 365 to allow Cloud App Security to scan files stored in SharePoint Online or OneDrive. Cloud App Security uses the Delegate Account to run advanced threat protection and data loss prevention scanning when files are updated.
Before you begin provisioning, follow these steps to make sure that Control access from apps that don't use modern authentication is correctly set on the Microsoft 365 admin center:
The SharePoint admin center page appears.
Cloud App Security uses a single SharePoint Online Delegate Account for both SharePoint Online and OneDrive. If you have already manually provisioned the Delegate Account for one of the two services, you do not need to create a Delegate Account and change the Delegate Account password again. Go directly to Verifying the Delegate Account and Managing SharePoint Online Site Collections or Managing OneDrive Site Collections based on which service you are manually provisioning at the moment.
Creating a Delegate Account can fail due to an internal Office 365 issue. If this should occur, try again in a few hours or in twenty-four hours.
The New user screen appears.
Display name and User name of the delegate account.
Password: Keep the default setting.
Roles: Keep the default setting.
Product licenses: Turn on Create user without product license by moving the slider to the right.
The Delegate Account can now be used to log on to Office 365.
Complete this task if you license the SharePoint Online service.
The SharePoint admin center page appears.
Repeat this procedure to add additional site collections.
To find a Delegate Account, click the address book, select Tenant, and then click the magnifying glass to look for existing accounts.
To create a Delegate Account, see Creating a Delegate Account.
If the message "SharePoint Online protected." appears on the Notifications screen, the provisioning is successful.
Complete this task if you license the OneDrive service.
The SharePoint admin center page appears.
Repeat this procedure to add other site collections.
To find a Delegate Account, click the address book, select Tenant, and then click the magnifying glass to look for existing accounts.
To create a Delegate Account, see Creating a Delegate Account.
The Delegate Account successfully adds to the Site Collection Administrators.
If the message "OneDrive protected." appears on the Notifications screen, the provisioning is successful.