> For the complete documentation index, see [llms.txt](https://docs.powermonitor.com.br/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.powermonitor.com.br/en/readme/como-instalar-o-power-monitor/instalacao-manual.md).

# Manual Installation

Step-by-step guide to the Power Monitor manual installation using an App Registration that already exists in your Microsoft Entra ID.

In the **Manual Configuration** (Advanced), you provide Power Monitor with the credentials of an **App Registration that already exists** in your Microsoft Entra ID. This is the recommended option when:

* company policy does not allow an external wizard to create applications and groups in Entra ID;
* you want **full control of the credentials** (application name, secret validity, group used);
* the person installing is not a Global Administrator.

This page continues from the **Installation Type** step. The previous steps (region, organization and billing) are in [How to install Power Monitor?](/en/readme/como-instalar-o-power-monitor.md)

The manual mode track has 6 steps: **Organization › Billing › Installation › Credentials › Workspaces › Done**.

***

## Part 1: Prepare the application in your tenant

Make these configurations **before** opening the Credentials step. They require, respectively, an Entra ID administrator and a Fabric administrator.

{% stepper %}
{% step %}

### Register the application in Entra ID

In the [Azure portal](https://portal.azure.com), go to **Microsoft Entra ID › App registrations › New registration**, give the application a name (for example, *PowerMonitor-APP*), keep **Accounts in this organizational directory only** and click **Register**.

Write down the **Application (client) ID**: this is the *Client ID* that Power Monitor will ask for.

{% hint style="warning" %}
Do not add **Power BI Service** permissions that require admin consent to the application. Microsoft does not allow a Service Principal with this type of permission to use the read-only admin APIs, which Power Monitor uses for the inventory.
{% endhint %}
{% endstep %}

{% step %}

### Create a client secret

In the application, go to **Certificates & secrets › New client secret**, set the expiration and copy the secret's **Value** (it is displayed only once). This is the *Client Secret*.

Write down the expiration date: when the secret expires, Power Monitor stops collecting data until the credential is updated in **Settings**.
{% endstep %}

{% step %}

### Create a security group and add the application

In **Microsoft Entra ID › Groups › New group**, create a group of type **Security** (for example, *PowerMonitor-Group*) and add the **enterprise application (Service Principal)** created in step 1 as a member. Write down the group's **Object ID**: this is the *Group ID*, optional in Power Monitor.

The group is Microsoft's recommended way to enable the Fabric APIs for Service Principals without enabling them for the whole tenant.
{% endstep %}

{% step %}

### Enable the Fabric tenant settings

With a **Fabric Administrator** account, go to the **Fabric admin portal › Tenant settings** and enable the following, **applying them to the security group** created in the previous step:

**Required** (without them, data collection does not work):

* **Service principals can access read-only admin APIs**
* **Enhance admin APIs responses with detailed metadata**
* **Enhance admin APIs responses with DAX and mashup expressions**
* **Service principals can call Fabric public APIs**

The complete list, including the optional settings, is in [Prerequisites](/en/technical-documentation/instalacao/pre-requisitos.md#fabric-tenant-settings).

{% hint style="info" %}
Microsoft may take a few minutes to propagate changes to tenant settings.
{% endhint %}
{% endstep %}
{% endstepper %}

***

## Part 2: Complete it in Power Monitor

{% stepper %}
{% step %}

### Azure Credentials

In the **Azure Credentials** step, fill in:

| Field                          | What to enter                                                      |
| ------------------------------ | ------------------------------------------------------------------ |
| **Client ID (Application ID)** | The App Registration's Application (client) ID                     |
| **Client Secret**              | The client secret's value                                          |
| **Group ID** (optional)        | The Object ID of the security group the application is a member of |

Click **Save Credentials**. Power Monitor **tests the Client ID and Client Secret against Entra ID before saving**; if they are rejected, the error message appears on the screen and nothing is saved. Accepted credentials are stored encrypted.
{% endstep %}

{% step %}

### Terms of Acceptance

Read the **Terms of Use, Privacy Policy and Commercial Terms**, check **I have read and accept the terms of use** and click **Proceed**. Acceptance **activates the organization** and starts the 30-day trial period.
{% endstep %}

{% step %}

### Select Workspaces

Choose the workspaces that will be monitored (search by name, **Select all**, **Clear selection**):

* **Scan Full Environment:** all workspaces, including those created in the future, are monitored.
* **Prepare Environment (N):** only the selected ones. New workspaces are added outside monitoring until an administrator includes them.

If the list does not load, click **Consent to Power BI**: the list is read with your Power BI access, and each user needs to authorize this access only once.

You can also **Skip** this step. In that case, no scan is started now; choose the workspaces and start the scan later in **Mapping › Inventory**.
{% endstep %}

{% step %}

### Done

Power Monitor starts the first scans and shows the environment preparation screen, with the **Initial scans** list, the real phase of each scan (**Queued**, **Running** or **Retrying**) and the summary *4 of 6 finished*. Independent scans start together and right away, without waiting for the 5-minute cycle of the collection service. If the screen closes before all of them finish, the collection continues in the background and the data shows up as each scan finishes. See the details in [Environment preparation and completion](/en/readme/como-instalar-o-power-monitor/instalacao-automatica.md#environment-preparation-and-completion).

Then the **Credentials Saved!** screen displays the organization ID and the **Open dashboard** button.
{% endstep %}
{% endstepper %}

***

## After the manual installation

The manual mode does **not** include the Additional Permissions and Metrics Source steps. Configure them next:

1. **Settings › Additional Permissions:** check the **Basic Fabric permissions**, grant access to the gateways, Entra ID read access (secret expiration and user import), the Teams bot and the Azure permissions for capacities and costs. The fastest way is **Grant all needed permissions** › **Run all**, followed by **Add Service Principal** on the workspaces card. See [Additional Permissions › How to use](/en/power-monitor/configuracoes/permissoes-adicionais.md#how-to-use).
2. **Settings › Monitoring:** choose the capacity metrics source (Fabric Capacity Metrics app) and enable the monitoring features (step by step in [Monitoring › How to use](/en/power-monitor/configuracoes/monitoramento.md#features)). See also [Enable Capacity Monitoring](/en/power-monitor/monitoramento/capacidades/ativar-monitoramento-de-capacidade.md) and [Enable Gateway Monitoring](/en/power-monitor/monitoramento/gateways/ativar-monitoramento-de-gateways.md).
3. Follow the [First access](/en/readme/primeiro-acesso.md) guide.

{% hint style="info" %}
Features that depend on reading Entra ID groups (for example, expanding group members on the permissions screens) require the application to have the Microsoft Graph **application** permission `GroupMember.Read.All` (or `Directory.Read.All`), with admin consent. It can be granted in **Settings › Additional Permissions** or directly in the Azure portal.
{% endhint %}

## How to use

### How to update the credentials provided during installation

After the installation, the App Registration credentials are maintained in *Settings › Organization* (Administrators only):

1. For a **new secret for the same application**, use **Manual Secret Change**: paste the value, click **Validate** and then **Save**. See [How to change the secret manually](/en/power-monitor/configuracoes/organizacao.md#manual-secret-change).
2. For **another application**, use the pencil icon next to **Application (Client) ID** (**Replace Service Principal**). See [How to replace the Service Principal](/en/power-monitor/configuracoes/organizacao.md#replace-service-principal).
3. For **another security group**, use the pencil icon next to **Group ID**. See [How to replace the security group](/en/power-monitor/configuracoes/organizacao.md#replace-group-id).

### How to renew the secret before it expires

1. With the **App secret expiration** permission granted in *Settings › Additional Permissions*, Power Monitor displays a warning at the top of the pages when fewer than 30 days remain.
2. In *Settings › Organization*, click **Automatic Secret Change** and confirm with **Yes, create and apply** (requires being an Application Administrator or the owner of the registration), or create the secret in the Azure portal and use **Manual Secret Change**.
3. See the complete step by step in [How to renew the secret automatically](/en/power-monitor/configuracoes/organizacao.md#automatic-secret-change).

## Frequently asked questions

<details>

<summary>The installation says the credentials were rejected</summary>

Check that the Client ID is the **Application (client) ID** (not the Object ID), that the Client Secret is the secret's **Value** (not the Secret ID) and that the secret has not expired.

</details>

<details>

<summary>The installation finished, but the inventory is empty</summary>

It is almost always the Fabric tenant settings: check that the four required settings are enabled **for the group the application is a member of** and wait for propagation. Then run a new scan in **Mapping › Inventory**.

</details>

## Related pages

* [How to install Power Monitor?](/en/readme/como-instalar-o-power-monitor.md)
* [Automatic Installation](/en/readme/como-instalar-o-power-monitor/instalacao-automatica.md)
* [Prerequisites](/en/technical-documentation/instalacao/pre-requisitos.md)
* [Configuring Azure permissions](/en/readme/como-instalar-o-power-monitor/configuracao-de-permissoes-no-azure-para-o-power-monitor.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.powermonitor.com.br/en/readme/como-instalar-o-power-monitor/instalacao-manual.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
