| 1. Confirm the required IT/admin access |
Before creating anything, confirm whether your organisation allows users to create Entra ID app registrations. |
Some tenants allow normal users to register apps; others disable this. If app registration is disabled, ask IT either to create the PnP app for you or temporarily/appropriately assign the Application Developer role. An Application Administrator or Cloud Application Administrator can also create and manage app registrations more broadly. |
Ask IT: “I need an Entra ID app registration for delegated PnP PowerShell administration of SharePoint Online.” |
| -------- |
-------- |
-------- |
-------- |
| 1. Confirm the required IT/admin access |
Before creating anything, confirm whether your organisation allows users to create Entra ID app registrations. |
Some tenants allow normal users to register apps; others disable this. If app registration is disabled, ask IT either to create the PnP app for you or temporarily/appropriately assign the Application Developer role. An Application Administrator or Cloud Application Administrator can also create and manage app registrations more broadly. |
Ask IT: “I need an Entra ID app registration for delegated PnP PowerShell administration of SharePoint Online.” |
| 2. Understand the SharePoint privilege required |
The person running the Search Schema changes also needs appropriate SharePoint rights. |
For site-collection Search Schema changes, the signed-in user should be a Site Collection Administrator. For tenant-wide Search Schema work, involve a SharePoint Administrator. Microsoft documents that tenant administrators and site collection administrators can manage Search Schema at their respective scopes. |
Site-level mapping: Site Collection Administrator. Tenant-level mapping: SharePoint Administrator. |
| 3. Create a dedicated Entra ID app registration |
Go to Microsoft Entra admin center → App registrations → New registration. Give it a descriptive name and normally make it single-tenant: Accounts in this organizational directory only. |
The registration provides the Application (client) ID that PnP PowerShell uses during authentication. It is better to create a dedicated PnP/admin app rather than reuse an unrelated business application. |
Example name: PnP-SharePoint-Search-Admin |
| 4. Configure authentication for interactive use |
Configure the app for a delegated interactive/device-code authentication flow appropriate for PnP PowerShell. |
This solution is intended to run as the signed-in administrator, not as a background daemon. PnP supports both interactive browser authentication and Device Login using your own Client ID. |
No client secret is required for the interactive/device-login approach used here. |
| 5. Configure API permissions using least privilege |
Add only the delegated Microsoft Graph/SharePoint permissions required by the PnP commands you plan to use. |
Do not simply copy a large permission list from another tenant. Current PnP PowerShell includes Get-PnPCommandPermission, which reports the delegated/application permissions and minimum SharePoint role required for a particular cmdlet. |
Example: Get-PnPCommandPermission -CommandName Set-PnPSearchConfiguration |
| 6. Request admin consent where required |
Ask the appropriate Entra administrator to review and grant consent for permissions that require organisation-wide/admin consent. |
Creating the app and granting API consent are separate operations. A user may be able to create an app but still be unable to approve its requested permissions. Cloud/Application Administrators can grant many types of consent; particularly privileged Microsoft Graph permissions may require a higher role such as Privileged Role Administrator. |
IT/security should review the exact permission set before granting consent. |
| 7. Record the Client ID |
From the app's Overview page, copy the Application (client) ID. |
PnP PowerShell requires this when connecting with your own Entra application. |
$ClientId = "<APPLICATION-CLIENT-ID>" |
| 8. Install PowerShell 7 |
Use PowerShell 7 (pwsh), rather than legacy Windows PowerShell 5.1. |
Modern PnP PowerShell is designed for current PowerShell versions, and keeping it separate from old Windows PowerShell avoids module/runtime compatibility issues. |
Open PowerShell 7 and run $PSVersionTable.PSVersion |
| 9. Install PnP PowerShell |
Install the PnP.PowerShell module if it is not already present. |
PnP provides the SharePoint authentication, Search Configuration and Search query cmdlets used by this solution. |
Install-Module PnP.PowerShell -Scope CurrentUser |
| 10. Import/verify PnP PowerShell |
Confirm the module is available before connecting. |
This prevents troubleshooting authentication when the actual problem is simply a missing module. |
Get-Module PnP.PowerShell -ListAvailable |
| 11. Define generic connection variables |
Set the app Client ID and target SharePoint site URL. |
Keeping these in variables makes the later commands easier to read and reuse. |
$ClientId = "<APPLICATION-CLIENT-ID>" $SiteUrl = "https://contoso.sharepoint.com/sites/example" |
| 12. Authenticate with Device Login |
Connect using the dedicated Entra app. |
Device Login opens a Microsoft authentication flow where the administrator signs in normally, including MFA/Conditional Access where applicable. PnP supports -DeviceLogin -ClientId specifically for this scenario. |
$conn = Connect-PnPOnline -Url $SiteUrl -DeviceLogin -ClientId $ClientId -ReturnConnection |
| 13. Verify the connection |
Query the connected SharePoint web before making changes. |
This is an important safety check. It proves you authenticated successfully and are connected to the intended site collection. |
Get-PnPWeb -Connection $conn | Select-Object Title,Url |
| 14. Only then perform Search Schema operations |
Once the connection is proven, use the PnP Search Configuration commands or your mapping script. |
Set-PnPSearchConfiguration -Scope Site changes Search Configuration for the current site collection, whereas -Scope Subscription targets the tenant scope. |
Example site-scope operation: Set-PnPSearchConfiguration -Scope Site ... |