From 019de0605bb9b68464b048dd17337f7cfa7f7405 Mon Sep 17 00:00:00 2001 From: jtdauria-shi Date: Thu, 27 Aug 2026 20:11:02 -0400 Subject: [PATCH 1/3] added installation video and updated permission information --- docs/Microsoft-Insights/Usage-Guide.md | 36 ++-- .../Prerequisites/Application-Permissions.md | 2 +- docs/SHIELD/Prerequisites/Installation.md | 177 +++++++++++------- docs/SHIELD/index.md | 32 ++-- ...1-endpoint-detection-and-response-dark.png | Bin 0 -> 11688 bytes ...-endpoint-detection-and-response-light.png | Bin 0 -> 14180 bytes ...ample-2-identity-theft-protection-dark.png | Bin 0 -> 9070 bytes ...mple-2-identity-theft-protection-light.png | Bin 0 -> 9043 bytes .../Videos/shield_installation-chapters.vtt | 21 +++ 9 files changed, 164 insertions(+), 104 deletions(-) create mode 100644 docs/assets/Images/Screenshots/example-1-endpoint-detection-and-response-dark.png create mode 100644 docs/assets/Images/Screenshots/example-1-endpoint-detection-and-response-light.png create mode 100644 docs/assets/Images/Screenshots/example-2-identity-theft-protection-dark.png create mode 100644 docs/assets/Images/Screenshots/example-2-identity-theft-protection-light.png create mode 100644 docs/assets/Videos/shield_installation-chapters.vtt diff --git a/docs/Microsoft-Insights/Usage-Guide.md b/docs/Microsoft-Insights/Usage-Guide.md index 55cf369..a43926f 100644 --- a/docs/Microsoft-Insights/Usage-Guide.md +++ b/docs/Microsoft-Insights/Usage-Guide.md @@ -1,6 +1,7 @@ # Microsoft Insights Usage Guide !!! note + This article has recently been published and is subject to change. ## Overview @@ -15,6 +16,7 @@ The integration between SHI One and Microsoft gives you incredible visibility in - **What do I do with this information?** !!! info + The data found in this report is populated from SHIELD. Data will not be available unless you have deployed SHIELD into your environment. For instructions on how to install SHIELD, see [Overview and Installation Requirements](/SHIELD/Prerequisites/Installation). For more information about SHIELD, see [SHI Environment Lockdown and Defense (SHIELD)](https://www.shi.com/it-lifecycle-services/software-lifecycle-management/shield){:target="_blank"}. --- @@ -87,14 +89,12 @@ Next to each feature you will see summary of the feature in your environment. Th - **MAU (Monthly Active Users)** - Users who actively use the service within the monthly period. - **In Scope** - Users who have the service plan enabled in their license profile. - **Purchased** - The number of licenses that have been purchased by your organization. -To understand this information, consider the following two examples: + To understand this information, consider the following two examples: **Example 1: Endpoint Detection & Response Feature Usage** -- Endpoint Detection & Response - - MAU: **134** - - IN SCOPE: **152** - - PURCHASED: **210** +![Example 1 - Endpoint detection & response - 134/152/210 - Light](../assets/Images/Screenshots/example-1-endpoint-detection-and-response-light.png#only-light){ loading=lazy } +![Example 1 - Endpoint detection & response - 134/152/210 - Dark](../assets/Images/Screenshots/example-1-endpoint-detection-and-response-dark.png#only-dark){ loading=lazy } - **Purchased Licenses**: The organization owns **210** licenses for the **Endpoint Detection & Response** feature. - **Endpoints Enabled**: This feature has been enabled on **152** devices or endpoints. @@ -104,10 +104,8 @@ In this example, the organization is not overconsuming the **Endpoint Detection **Example 2: Identity Theft Protection Feature Usage** -- Identity Theft Protection - - MAU: **220** - - IN SCOPE: **275** - - PURCHASED: **210** +![Example 2 - Identity Theft Protection - 220/275/210 - Light](../assets/Images/Screenshots/example-2-identity-theft-protection-light.png#only-light){ loading=lazy } +![Example 2 - Identity Theft Protection - 220/275/210 - Dark](../assets/Images/Screenshots/example-2-identity-theft-protection-dark.png#only-dark){ loading=lazy } - **Purchased Licenses**: The organization owns **210** licenses for the **Identity Theft Protection** feature. - **Endpoints Enabled**: The feature has been enabled on **275** devices or endpoints. @@ -123,6 +121,7 @@ A warning appears when you have more users using a feature than the number of li ![Microsoft Insights Overview - Dark](../assets/Images/Screenshots/MI-warning-dark.png#only-dark){ loading=lazy } !!! info + Sometimes, you might notice that the number of monthly active users is higher than the number of users "in scope." This is not an error; it's simply a result of how Microsoft calculates and reports these metrics. ### License Types @@ -159,6 +158,7 @@ In total, the feature is being used on **1,180** devices, but the organization h 2. **Reduce the number of devices** using the feature to match the number of licenses owned !!! note + Not every feature displays the associated license type. However, you will still be able to see monthly active users (**MAU**), the number of endpoints with the feature enabled (**In scope**), the number of licenses owned (**Purchased**). ### Activity @@ -168,22 +168,22 @@ Microsoft Insights considers a feature in use when a qualifying activity is dete ![Microsoft Insights Overview - Light](../assets/Images/Screenshots/MI-system-user-admin-light.png#only-light){ loading=lazy } ![Microsoft Insights Overview - Dark](../assets/Images/Screenshots/MI-system-user-admin-dark.png#only-dark){ loading=lazy } -1. **System (S)** - Automatically generated by Microsoft. +1. **System (S)** - Automatically generated by Microsoft. - **Examples**: Policy Checks, Compliance, Security Monitoring, etc. -2. **User (U)** - Activity created by users interacting with Microsoft features. +2. **User (U)** - Activity created by users interacting with Microsoft features. - **Examples**: Sending emails, joining meetings, opening files, applying sensitivity labels, etc. -3. **Admin (A)** - Activity performed by administrators managing or reviewing Microsoft features. +3. **Admin (A)** - Activity performed by administrators managing or reviewing Microsoft features. - **Examples**: Role activations, audit searches, policy changes, investigations, etc. Every feature will have an associated activity. Some features only have one activity, while others may have more than one. **Note**: A feature is considered "active" even if its activity is background or administrative in nature, if qualifying telemetry exists during the reporting period. Some products are measured primarily through user-driven actions. Others reflect value through system-driven and admin-driven activity. Some examples include: -- **User Driven** +- **User Driven** - Teams - Exchange - SharePoint -- **System & Admin** +- **System & Admin** - Defender for Identity - Conditional Access - Intune @@ -201,13 +201,13 @@ The first phase of Microsoft Insights is pulling in data. If you have successful If data is not available in the platform or certain columns are grayed out, it is likely due to one of the following reasons: -- **SHIELD Not Installed** +- **SHIELD Not Installed** - If SHIELD is not installed in your environment, the system will not be able to display any insights in the report. For steps to install SHIELD, see [Overview and Installation Requirements](/SHIELD/Prerequisites/Installation). -- **Permissions Not Granted** +- **Permissions Not Granted** - The Microsoft Graph Reports API requires the `Reports.Read.All` permission to be granted for the workload. To resolve this issue, make sure the required API permissions have been consented to the Entra ID or reach out to the user who oversees granting permissions. -- **API Access Not Available or Enabled** +- **API Access Not Available or Enabled** - This may be because the API has not been turned on yet or does not exist (such as a non-public API access). -- **Organization Does Not Have Service Plan or License** +- **Organization Does Not Have Service Plan or License** - If a service plan or license is not active for the relevant Microsoft products, the system cannot retrieve or display usage information in the report. In this situation, you should check to confirm your organization's current service plans and licenses. --- diff --git a/docs/SHIELD/Prerequisites/Application-Permissions.md b/docs/SHIELD/Prerequisites/Application-Permissions.md index 693eb88..a78055c 100644 --- a/docs/SHIELD/Prerequisites/Application-Permissions.md +++ b/docs/SHIELD/Prerequisites/Application-Permissions.md @@ -109,7 +109,7 @@ Coming Soon! Coming Soon! -## `Grant-MIGraphPermission` Usage +## Grant-MIGraphPermission Usage The Grant MI Graph Permission PowerShell script is an easy way to bulk apply permissions to managed identities using either the command line or a graphical picker. You can find the script here at the [PowerShell gallery](https://www.powershellgallery.com/packages/Grant-MIGraphPermission). diff --git a/docs/SHIELD/Prerequisites/Installation.md b/docs/SHIELD/Prerequisites/Installation.md index e11119e..4486fb4 100644 --- a/docs/SHIELD/Prerequisites/Installation.md +++ b/docs/SHIELD/Prerequisites/Installation.md @@ -5,10 +5,44 @@ SHIELD is a self-hosted application deployed in a customer’s Azure App Service tenant. SHIELD collects and processes all necessary data exclusively within the customer’s environment, then returns only abstracted and fully anonymized results back to SHI for reporting. All requirements can be set up by the delivery team or customer prior to engagement. This guide explains how to install the SHIELD - Desktop application and run your first scan. For more information about requirements, pricing, and more, see [Prerequisites](/SHIELD/Prerequisites). !!! info "Security Considerations" + While this application requires sensitive permissions to conduct the automated scan, by self-hosting the application, SHI does not represent a supply chain risk or path to compromise a customer environment via the SHIELD platform, as there is no control maintained beyond the initial point of installation. All code being run to conduct the automated discovery is available for code and security reviews prior to engagement upon request. Permissions exist for both the user initiating the report and the application itself. Code review is available upon request. --- +## Installation Video + + + + + + + + + + + +--- + ## Installation Prerequisites ### Disable Network Traffic Inspection @@ -19,11 +53,11 @@ Every organization uses different equipment and processes, so the steps to disab **How to Proceed**: -- If you’re not sure how to disable network traffic inspection, please contact your networking team, security team, or the person in charge of information technology at your organization. -- You can also share the following network endpoints with your networking team to have the addresses excluded from inspection: +- If you are not sure how to disable network traffic inspection, please contact your networking team, security team, or the person in charge of information technology at your organization. +- You can also share the following network endpoints with your networking team to have the addresses excluded from inspection: - `https://api.shilab.com` - `https://url.shilab.com` - - `https://*.azurewebsites.net` - *Your specific deployment URL (generated after deployment)* + - `https://*.azurewebsites.net` - _Your specific deployment URL (generated after deployment)_ **Common Network Traffic Inspection Technologies** @@ -40,34 +74,37 @@ For more information about traffic inspection, see [Network Traffic Inspection]( ### Create a Dedicated Azure Subscription -1. Sign in to your Azure portal. +1. Sign in to your Azure portal. - **Enterprise**: [https://portal.azure.com/](https://portal.azure.com/){:target="_blank"} - **Government**: [https://portal.azure.us/](https://portal.azure.us/){:target="_blank"} -2. Navigate to **Subscriptions** and click **+ Add**. -3. If applicable, choose an offer type from the options provided. **Enterprise Agreement (EA) customers** typically do not have to select an offer type. -4. Enter a name for the subscription (e.g., "SHIELD – Production") or similar. -5. **Enterprise Agreement (EA) customers**: Assign a billing account and confirm creation. +2. Navigate to **Subscriptions** and click **+ Add**. +3. If applicable, choose an offer type from the options provided. **Enterprise Agreement (EA) customers** typically do not have to select an offer type. +4. Enter a name for the subscription (e.g., "SHIELD – Production") or similar. +5. **Enterprise Agreement (EA) customers**: Assign a billing account and confirm creation. --- -### Global Administrator +### Permissions -The user installing SHIELD must be a **Global Administrator** in order to grant Microsoft Graph application permissions via admin consent. For more information about permissions, see [Application Permissions](./Application-Permissions). +!!! note -1. Sign in to your Entra ID admin center. + - **Installing User**: The user installing SHIELD must be a `Global Administrator` in order to grant Microsoft Graph application permissions via admin consent. + - **Application**: SHIELD Desktop must be granted `Application.ReadWrite.All` and `AppRoleAssignment.ReadWrite.All` permissions by the user installing SHIELD or another admin. For more information about permissions, see [Application Permissions](./Application-Permissions). + +1. Sign in to your Entra ID admin center. - **Enterprise**: [https://entra.microsoft.com/](https://entra.microsoft.com/){:target="_blank"} - **Government**: [https://entra.microsoft.us/](https://entra.microsoft.us/){:target="_blank"} -2. Navigate to **Roles & admins**. -3. Search for and click on the **Global Administrator** role. -4. If the user deploying SHIELD is already assigned the **Global Administrator** role, no additional action is required. If a user needs to be assigned the **Global Administrator** role, follow the steps below: - 1. At the top, click **+ Add Assignments**. - 2. Click the link under **Select member(s)**. - 3. Check the box next to the desired user and click **Select**. You can also use the search bar if needed. - 4. Select your desired settings. We recommend the following: +2. Navigate to **Roles & admins**. +3. Search for and click on the **Global Administrator** role. +4. If the user deploying SHIELD is already assigned the **Global Administrator** role, no additional action is required. If a user needs to be assigned the **Global Administrator** role, follow the steps below: + 1. At the top, click **+ Add Assignments**. + 2. Click the link under **Select member(s)**. + 3. Check the box next to the desired user and click **Select**. You can also use the search bar if needed. + 4. Select your desired settings. We recommend the following: - Assignment type: **Active** - Permanently eligible: Uncheck - Assignment duration: 24-48 hours - 5. Click **Assign**. + 5. Click **Assign**. --- @@ -75,24 +112,24 @@ The user installing SHIELD must be a **Global Administrator** in order to grant Make sure the user installing SHIELD is the **Owner** on the Azure subscription in order to deploy resources. -1. Sign in to your Azure portal. +1. Sign in to your Azure portal. - **Enterprise**: [https://portal.azure.com/](https://portal.azure.com/){:target="_blank"} - **Government**: [https://portal.azure.us/](https://portal.azure.us/){:target="_blank"} -2. Navigate to **Subscriptions** and select the subscription to be used with SHIELD. -3. Click **Access control (IAM)** in the left navigation bar. -4. Click on the **Role assignments** tab. -5. If the user deploying SHIELD is already assigned the **Owner** role of the subscription, no additional action is required. If a user needs to be assigned the **Owner** role, follow the steps below: - 1. At the top, click **+ Add** and click **Add role assignment** in the drop-down menu. - 2. Click on the **Privileged administrator** roles tab. - 3. Click on the **Owner** role so it is highlighted and click **Next**. - 4. Click **+ Select members**, click on the desired user account, and click **Select**. - 5. Click **Next**. - 6. Select **Allow user to assign all roles (highly privileged)**. - 7. Click **Next**. - 8. If applicable, select your desired Assignment type settings. We recommend the following: +2. Navigate to **Subscriptions** and select the subscription to be used with SHIELD. +3. Click **Access control (IAM)** in the left navigation bar. +4. Click on the **Role assignments** tab. +5. If the user deploying SHIELD is already assigned the **Owner** role of the subscription, no additional action is required. If a user needs to be assigned the **Owner** role, follow the steps below: + 1. At the top, click **+ Add** and click **Add role assignment** in the drop-down menu. + 2. Click on the **Privileged administrator** roles tab. + 3. Click on the **Owner** role so it is highlighted and click **Next**. + 4. Click **+ Select members**, click on the desired user account, and click **Select**. + 5. Click **Next**. + 6. Select **Allow user to assign all roles (highly privileged)**. + 7. Click **Next**. + 8. If applicable, select your desired Assignment type settings. We recommend the following: - Assignment type: **Active** - Assignment duration: **Permanent** - 9. Once finalized, click **Review + assign**. + 9. Once finalized, click **Review + assign**. 10. (Optional) Confirm the role appears in the **Role assignments** tab. --- @@ -100,54 +137,64 @@ Make sure the user installing SHIELD is the **Owner** on the Azure subscription ## Install and Deploy SHIELD Discover !!! info "SHIELD Installation Has Changed" + The **SHIELD - Desktop** application is now the preferred method, for faster and easier installation.

**Why?** The desktop application automates most steps, making setup much simpler.

**Manual Installation**: If you prefer the manual method, please reach out to an SHI employee for guidance and support. -0. Run the installer to set up SHIELD automatically using the following link: [https://url.shilab.com/shield-install](https://url.shilab.com/shield-install) +1. Run the installer to set up SHIELD automatically using the following link: [https://url.shilab.com/shield-install](https://url.shilab.com/shield-install) - **Note**: The download will not work if network traffic inspection is enabled, especially in Microsoft/Azure environments. -1. After installation, launch the SHIELD - Desktop application. -2. Log in using the account manager in the top right corner. Be sure to log in with the account that has the necessary **Owner** and **Global Administrator** permissions in Azure. These are required to grant the necessary permissions for deployment. -3. After you are successfully logged in, click on the **Installer** module. +2. After installation, launch the SHIELD - Desktop application. +3. Log in using the account manager in the top right corner. Be sure to log in with the account that has the necessary **Owner** and **Global Administrator** permissions in Azure. These are required to grant the necessary permissions for deployment. +4. After you are successfully logged in, click on the **Installer** module. - **Note**: An additional tab may open, and another log in may be required. -4. Select the **Azure Subscription** that is dedicated for SHIELD. -5. Select your desired **Azure Region** from the drop-down menu. **West US 3** is recommended, but other regions can be selected depending on company policy. -6. Click on the toggle switch to display **Advanced Options**. -7. For **Operation Mode**, select **Discover** from the drop-down menu. -8. Click on the **Deploy** button for the SHIELD installer to begin the installation process. +5. Select the **Azure Subscription** that is dedicated for SHIELD. +6. Select your desired **Azure Region** from the drop-down menu. **West US 3** is recommended, but other regions can be selected depending on company policy. +7. Click on the toggle switch to display **Advanced Options**. +8. For **Operation Mode**, select **Discover** from the drop-down menu. +9. Click on the **Deploy** button for the SHIELD installer to begin the installation process. - **Note**: An additional tab may open, and another log in may be required. -9. The installer will do the following: +10. The installer will do the following: - Download the SHIELD Deploy ZIP file - Create a SHIELD App Service and managed identity in Azure - Upload and configure the SHIELD application, including permissions and security settings such as disabling basic auth, enabling encryption, and setting quantum-resistant cryptography. -10. After deployment, verify the following required permissions are granted to the SHIELD managed identity in Azure: +11. After deployment, grant the following required permissions to the SHIELD managed identity in Azure: - `Application.ReadWrite.All` - `AppRoleAssignment.ReadWrite.All` -11. Lastly, assign the Read and Write Everything role to the user who will run SHIELD scans via the "SHIELD End User Login" enterprise app in Entra. - 1. Sign in to your Entra ID admin center. +12. Lastly, assign the Read and Write Everything role to the user who will run SHIELD scans via the "SHIELD End User Login" enterprise app in Entra. + 1. Sign in to your Entra ID admin center. - **Enterprise**: [https://entra.microsoft.com/](https://entra.microsoft.com/){:target="_blank"} - **Government**: [https://entra.microsoft.us/](https://entra.microsoft.us/){:target="_blank"} - 2. Navigate to **Enterprise apps** in the navigation bar. - 3. Clear out the **Enterprise Applications** filter. - 4. Search for 'SHIELD End User Login' and click on the name of the application. - 5. Click **Users and groups** in the left navigation bar. - 6. Click **+ Add user/group**. - 7. Click the link under **Users and groups**. - 8. Check the box next to the desired user and click **Select**. You can also use the search bar if needed. - 9. Click on the link under **Select a role**. + 2. Navigate to **Enterprise apps** in the navigation bar. + 3. Clear out the **Enterprise Applications** filter. + 4. Search for 'SHIELD End User Login' and click on the name of the application. + 5. Click **Users and groups** in the left navigation bar. + 6. Click **+ Add user/group**. + 7. Click the link under **Users and groups**. + 8. Check the box next to the desired user and click **Select**. You can also use the search bar if needed. + 9. Click on the link under **Select a role**. 10. Search for 'Read and Write Everything', click on the name of the role, and click **Select**. 11. Click **Assign**. ## Running the SHIELD Web Instance -1. Navigate to your SHIELD web instance in your browser: [https://portal.azure.com/](https://portal.azure.com/){:target="_blank"} -2. Click **Resource groups**. -3. Click **SHIELD**. -4. Click on the App Service that starts with "shield-xxxxxxxxx" (the x's are a random set of lower-case letters and numbers). -5. In the top right corner, click on the **Default domain** link. **Example**: shield-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx-xxxxxxxxxxxxxxxx.eastus-01.azurewebsites.net -6. Log in to the SHIELD web instance with the account that has the necessary Azure permissions. -7. Click on **Discover Module**. -8. Click **Start Authentication Sync**. Then click **Start Report Collection** to start scanning the tenant environment. -9. During the first scan, SHIELD - Desktop will open and request account credentials multiple times. Log in each time as required. You will also need to accept each set of permissions. -10. Once the scan is complete, reports are available on the SHIELD web instance. - 1. Click **Discover** in the left navigation pane and click **Overview**. +1. Sign in to your Azure portal. + - **Enterprise**: [https://portal.azure.com/](https://portal.azure.com/){:target="_blank"} + - **Government**: [https://portal.azure.us/](https://portal.azure.us/){:target="_blank"} +2. Navigate to **Subscriptions** and select the subscription dedicated to SHIELD. +3. Click **Resource groups**. +4. Click **SHIELD**. +5. Click on the App Service that starts with "shield-xxxxxxxxx" (the x's are a random set of lower-case letters and numbers). + - **Deactivate Health Check (One time only)** + 1. Click on the link next **Health Check**. + 2. Uncheck the box next to **Health check** and click **Apply**. + 3. Click **Save**. +6. Click **Overview** in the left navigation bar. +7. In the top right corner, click on the **Default domain** link. + - **Example**: shield-xxxxxx-xxxxxxxx.eastus-01.azurewebsites.net +8. Log in to the SHIELD web instance with the account that has the necessary Azure permissions. +9. Click on **Discover Module**. +10. Click **Start Authentication Sync**. Then click **Start Report Collection** to start scanning the tenant environment. +11. During the first scan, SHIELD - Desktop will open and request account credentials multiple times. Log in each time as required. You will also need to accept each set of permissions. +12. Once the scan is complete, reports are available on the SHIELD web instance. + 1. Click **Discover** in the left navigation pane and click **Overview**. \ No newline at end of file diff --git a/docs/SHIELD/index.md b/docs/SHIELD/index.md index fbe2eca..7cd435f 100644 --- a/docs/SHIELD/index.md +++ b/docs/SHIELD/index.md @@ -2,24 +2,20 @@ ## Overview +SHIELD is a hybrid SaaS solution with a customer-installed app in their Azure tenant. The SHIELD app service is an orchestration tool that simplifies the deployment, management, and maintenance of Microsoft's Secure Privileged Access architecture. With SHIELD, you can automate the deployment of complex security infrastructures, device management, and user management while adhering to security best practices. SHIELD helps organizations to reduce the time and expertise required for deployment from a year or more to just a few minutes. -SHIELD is a hybrid SaaS solution with a customer-installed app in their Azure tenant. The SHIELD app service is an orchestration tool that simplifies the deployment, management, and maintenance of Microsoft's Secure Privileged Access architecture. With SHIELD, you can automate the deployment of complex security infrastructures, device management, and user management while adhering to security best practices. SHIELD helps organizations to reduce the time and expertise required for deployment from a year or more to just a few minutes. - - -SHI operates a centralized SaaS service in its own Azure tenant known as the Data Gateway. This is a SaaS component shared by multiple customers using tenant isolation via access token claims cryptographically signed by Microsoft Entra ID. It provides storage, analysis, and reporting services for SHIELD data. The SHIELD app service collects and processes data within the customer tenant before providing abstracted & fully anonymized data results back to the Data Gateway for reporting and analysis. - +SHI operates a centralized SaaS service in its own Azure tenant known as the Data Gateway. This is a SaaS component shared by multiple customers using tenant isolation via access token claims cryptographically signed by Microsoft Entra ID. It provides storage, analysis, and reporting services for SHIELD data. The SHIELD app service collects and processes data within the customer tenant before providing abstracted & fully anonymized data results back to the Data Gateway for reporting and analysis. !!! info "Security Considerations" - SHI does not manage or access the SHIELD app service runtime. Where authorized by the customer, the SHIELD app service may initiate configuration changes in the customer's tenant using delegated or application permissions explicitly consented to by the customer. All requirements can be set up by the delivery team or customer prior to engagement. Note that these configuration changes are deployed as security policies which will need further customer action to associate them with users. + SHI does not manage or access the SHIELD app service runtime. Where authorized by the customer, the SHIELD app service may initiate configuration changes in the customer's tenant using delegated or application permissions explicitly consented to by the customer. All requirements can be set up by the delivery team or customer prior to engagement. Note that these configuration changes are deployed as security policies which will need further customer action to associate them with users. ## Architecture Topology The following diagram shows the high-level SHIELD deployment and trust boundaries between the customer tenant, SHI's SaaS tenant, and Microsoft Entra ID. SHIELD components that are deployed to customer environments are outlined in red. -![This diagram illustrates a multi-tenant Microsoft Azure topology showing a vendor (SHI) tenant and a customer tenant within the Microsoft Azure Global boundary. Key components: the SHI tenant contains a Data Gateway and ShiLab.com; Microsoft Entra ID is shown as the identity service bridging or present in the environment; the Customer Tenant contains a SHIELD Resource Group which houses SHIELD, auxiliary components (SHIELD VNet, PS Proxy service, Key Vault, network interfaces, DNS zones) and customer resources. The relationships indicate the logical grouping of resources by tenant and resource group and highlight where identity and gateway components reside relative to the customer SHIELD deployment.](../assets/images/Overview/Overview-Light.png#only-light){ loading=lazy } -![This diagram illustrates a multi-tenant Microsoft Azure topology showing a vendor (SHI) tenant and a customer tenant within the Microsoft Azure Global boundary. Key components: the SHI tenant contains a Data Gateway and ShiLab.com; Microsoft Entra ID is shown as the identity service bridging or present in the environment; the Customer Tenant contains a SHIELD Resource Group which houses SHIELD, auxiliary components (SHIELD VNet, PS Proxy service, Key Vault, network interfaces, DNS zones) and customer resources. The relationships indicate the logical grouping of resources by tenant and resource group and highlight where identity and gateway components reside relative to the customer SHIELD deployment.](../assets/images/Overview/Overview-Dark.png#only-dark){ loading=lazy } - +![This diagram illustrates a multi-tenant Microsoft Azure topology showing a vendor (SHI) tenant and a customer tenant within the Microsoft Azure Global boundary. Key components: the SHI tenant contains a Data Gateway and ShiLab.com; Microsoft Entra ID is shown as the identity service bridging or present in the environment; the Customer Tenant contains a SHIELD Resource Group which houses SHIELD, auxiliary components (SHIELD VNet, PS Proxy service, Key Vault, network interfaces, DNS zones) and customer resources. The relationships indicate the logical grouping of resources by tenant and resource group and highlight where identity and gateway components reside relative to the customer SHIELD deployment.](../assets/Images/Overview/Overview-Light.png#only-light){ loading=lazy } +![This diagram illustrates a multi-tenant Microsoft Azure topology showing a vendor (SHI) tenant and a customer tenant within the Microsoft Azure Global boundary. Key components: the SHI tenant contains a Data Gateway and ShiLab.com; Microsoft Entra ID is shown as the identity service bridging or present in the environment; the Customer Tenant contains a SHIELD Resource Group which houses SHIELD, auxiliary components (SHIELD VNet, PS Proxy service, Key Vault, network interfaces, DNS zones) and customer resources. The relationships indicate the logical grouping of resources by tenant and resource group and highlight where identity and gateway components reside relative to the customer SHIELD deployment.](../assets/Images/Overview/Overview-Dark.png#only-dark){ loading=lazy } ## Audience @@ -44,7 +40,7 @@ Check out this page for more details: [Getting Started - Prerequisites](Prerequi ## Installation -The SHIELD installer ('SHIELD - Desktop') is downloaded to the customer tenant and executed by an administrator. During installation, the administrator is required to authenticate interactively to the customers' Azure tenant. The installer uses this authenticated session to provision an Azure App Service and associated resources directly into the tenant under the customers' ownership and governance. No resources are deployed without explicit customer action and consent, and the resulting App Service operates entirely within the customers' Azure subscription. +The SHIELD installer ('SHIELD - Desktop') is downloaded to the customer tenant and executed by an administrator. During installation, the administrator is required to authenticate interactively to the customers' Azure tenant. The installer uses this authenticated session to provision an Azure App Service and associated resources directly into the tenant under the customers' ownership and governance. No resources are deployed without explicit customer action and consent, and the resulting App Service operates entirely within the customers' Azure subscription. The installer provisions the SHIELD UI web application and associated components to the customer's tenant. ## SHIELD Module Overview @@ -53,7 +49,7 @@ Depending on licensing, the following components will be available from the UI: [SHIELD Discover](https://docs.shilab.com/SHIELD/Discover/) The Discover module enables advanced licensing intelligence and compliance reporting for Microsoft 365 services. It interrogates the Graph API, Defender API and Purview API to extract licensing information for the customer's tenant. It can then generate compliance reports for later analysis. -```mermaid +``` mermaid flowchart TD subgraph m365["Primary Inputs"] graphApi[Microsoft Graph API] @@ -89,12 +85,7 @@ flowchart TD Click this link to see more on [Secure Privileged Access](https://learn.microsoft.com/en-us/security/privileged-access-workstations/overview) - - - - - -```mermaid +``` mermaid flowchart TD B[SHIELD Defend] B --> C[Security and readiness checks] @@ -110,13 +101,13 @@ flowchart TD ``` +

-[SHIELD Deploy](https://docs.shilab.com/SHIELD/Deploy/) SHIELD's Deploy module provides the foundation for a secure environment using Microsoft's Securing Privileged Access (SPA) architecture. This module automates the provisioning of security-critical components such as identity boundaries, privileged access zones, Conditional Access policies, and more. - +[SHIELD Deploy](https://docs.shilab.com/SHIELD/Deploy/) SHIELD's Deploy module provides the foundation for a secure environment using Microsoft's Securing Privileged Access (SPA) architecture. This module automates the provisioning of security-critical components such as identity boundaries, privileged access zones, Conditional Access policies, and more. -```mermaid +``` mermaid flowchart TD B[Deploy Module] @@ -136,6 +127,7 @@ flowchart TD D2 --> H D2 --> I ``` +

diff --git a/docs/assets/Images/Screenshots/example-1-endpoint-detection-and-response-dark.png b/docs/assets/Images/Screenshots/example-1-endpoint-detection-and-response-dark.png new file mode 100644 index 0000000000000000000000000000000000000000..e487b531b4e83f368522e8625d35cfbc279a5a40 GIT binary patch literal 11688 zcmb_?bx<796DA3PBxrC5!QI_01oyxqK^B+b?y>h4!}byqbz{pRiTbkD1O+uh&Spmv|D_2c5%sLO-V^XK}BsTK!iJWiCR!l@bTlv zmCW4dO2&UPryk;jZ{U*o7yCQ7_=aNi0WKqQ1w=O^b_* zGC&6SO}jVTK^P>9Jazf`y`7yuNEvu|cw}Vy1)R5U@9ubbd7n=}FT?^)dFkmZJ)t;P zmzQB-Vf*|0q_*hr7yVnMp{kl)UcSoKon?{f>o%DqMM_GFgoN~PeI(?xDJvlnSW?2o z1m(9&u!A5B?muxAn$myj@dygdWS z(vKNCEztS5WKb6S z*hVKOIaDGpDIM@bz;8U_uM>Ajid9%eh8V6dea$otCk?@uXTb8+hiOdj&`+Sy39KpdIJm;-RoA`AsikKAITwbC87X4FazNkrO(Ue||L! zV4Rp;XX_CixezmN?~85NZAmgMc;V?@L&j#n+O6EJYON%h*#50XBsX=rF`$!NOiNUY zlaqIuq4DzK8fYOkf=V@hcL7;U{U{qOJ_*|a9}7{(Y0h>zKkIc=^~JoZuh01l##u^U zYfFtb_!E&UVLz}i3f5!%E~|}GrKR>ZRC%6P9p6BZl%>e@tH*C*mE)jUzhUCJDq0@A zrmmBYMYcF|s~2P0A558$irJJUl@_;jhF!rVrdG&D3r#^mwpp<&@+;o)IY@iB?w#h9hS*YqzQHwB`~%vCqZaDNnN3qzuFt#NjE77k!T!KP`}5uB)wY*7y+2$4c&k z(XnK88i@ba6Y3yvHKLK@g<&5zpL2uQNR7V|m!_xFoi?jZ6{EkT-(SCM`ee9?hrelN zKVr$8=%P*)%x9;$dtk@to?e|&yAg@;t{RZv{pv>q|8}IPtwD=GvO6$vSFm<9)iPJf zmFc;Cf#&z_Z=oT!5ExLj0!eAxxz0MQhRtkSW5ST@k3u-&@1(C3-{pREc73jq7u2+N zvTY5(mk$=NsGQJ#je{YFq4AwCDI)di7;f_SqdI_*PcxCR(ee~n)~JM}EymQCS*Ne7 zCVnscM!k8-^;%dtcT+dS_M*2FeTy4al8?JjjZ?&8E-fi#?hO$taz;&^h(Xav zTAh*7DH+w!d`W4)lk&?dZr9{3FM9Kus3zHu#q&FKWwA;^o~{FB=r24f?V_qiQ^91U zhJHz(@a=tkOa0?JFT&~bfqdG>_jXn>Q*M#?DyPPsp&b}SxIV8DQn_b%zwf0)W=PY4 zjQfcF<6q74a_@5TP1ps^d9RyT7i&bj%JEV%K+GuLy%VmY&_DaOB@h6SQop!)zh_8z z>i0XbD7lS*gfWwmeJ&?#1d+*vl^qY`Tiw*~$c!H&i6F;(1d*Y_FQK_(n(z0~TaerHqo%b|pxlY|^TM~p0o@7-38Sz|`1|qd>1!c5$ z*~Ed;M5i{byO7r%J4u5{0h^e7pG@z2L_JIf2m`UkGFNj&0G?og}xjHWe z%CMd`ja2COBE=AfgmBhZpfv?A7JtQ270>ohF50nfmm|}HNsJ+MBI_7O%O+X~4uSmy z<)=TD@l!YJ7h2dd2(7gTYj#W)=-`12j9v<9~#u<<{uhJ>(isnd5IQ10!%NrlXU$Ysrxfy{$zo)JaDQHlH8`iX(XE+I%frZY_v zX@^UNpP+^4VkCWK*LYmaJ^eLj*&lPw1jSlr#t+!Z3?)Ii?fQ`665@}cwP;QHk}Du@ z!f%l{wVG{tM)T3A$X;#t?=4N{fJ%8EQT#qwwH=!aFbo{@KQN#mWXK{V{}NWYP<`c6 zyEvyF9#$jyiO)Kw^x)>tgnYXXU?r^71&`H|f!{@ysb^)%Ia2H4JKKr+3}o~ou(dx0 z+IR;)H1JVrh|QWY0y(E%)n{wtmzZks$r}e5t^9se(`i)=m_rxhK}G@^zkYT$UoHq3 z;X=tJw-nAcGc-3dqa5TZ+nKYLx9VEciKyfyFTNFG38fFoT{_}%YUom~16-HW*ge%6 z=}*jXnESYkwYL~3MW61j0_8jzd6HQ*)yH$+UM|leLMeUMx{ydn(i08*1elpey1Le{ zkCsyT?8}Rb)kNM_eLLLTG_|&7QfP8JT1;TkHD$~6y@n#8;x9KjL+0ZTtEF@tdnUfd z)ow^M@uZih`T!xP5g}F|2h7?tr6tg#|Ag%L>~;<6zcEGU=_LRkFUHQ|BQq3Ai<|MN z1`jfcuxu;ghI^q!Z}GY)s4KX!Tx+#d ze1pT&8BqG}B3*`3+g)z7A$4}D(u4#-92{BfTdxrWZK`%TZbj$-+id%TE>=6_S2bQ0 z#+hUwx8}n^1}zdJ=M9J%I{S5HLULx54&NP0S=NPKMQ%ABM7@5#l6jG~D=;U?Zv7r& zWcC|HiT0yK7Wb-;O@k~v6})dbX|JiTFE1=ys5Tp3X>mWC)ycgj+4>KL-n$NS1P3c~b;Naj$?Gn~#(d$hy z_4A~x2|!b%5kW*CmvK40S=QksKCvuPK!Vz$UW%ZV$x&{*TPYpQ5mU|Ed~l9x+H&js zEsKZ5SQ=6{wET?2rJ0<}NLUi^OoD@hb5+h3TFv$;B0_e+mfV;Z;oXIl;-|}6jRW~a z)z0EkxY;#v$(?+}(tLvhinl6Utf~NQM{_V0sNpcl2c?`z7pr72%zoHa>dl2ALGHH^ zm&gSD12;>y!Jv?!AjZ3tQaNVRk7lAVY#nW*++_mlWt3qCF>4o=M- zPz>8FU8va?_{EN8`j=)g&*Eq_R21gGRWh#CLwbmK0a3}cg9qvjuoxpFYv4saIrmO{RIg*l~aJ#7@(W_VLFJ<;pSlcl2#X*P?9ptIy-<6b*c` z%~gAi?Cx>k{9p4A(bwyOQ{E~4Bf;D6V%1BNig}toT!epK!?{K1^rB-UP_C<;%UN88 zZER&4ob8!^$J1xRC%j;8;|tQ=3BMXG`<;Y$TUryQ*)w%)h6VR_@-7xZ2+1T~FI1qn zXM+p#3(rhQh@YV2AdRFUx7%c&gDOoOdf*5$^5iP2b}r(rbbu7`sARk?;$eK=_1l5? zm?e4%b)d`I=P#NNyeimI{b3>P*-%80kI?bLujrHQWy;le3K*(V&-vk!yw%Q3c#Gj6wVw9l+}RGg-iFU3$y{x^4UBATVxZ^NE(t3u zE9dPIRRBQ9^W6V3q_xL)2lZo!$p+7`hM&0l#I=2?Mi$kDei%y3A}y(u*bcjjXY%3$ zR3yvFwAU7_FoHk(-Pw~?xZEv*UZ|?OI$do9JGJ!Oq%2u!l5V(#pG7>t;^#RCMZ8`F%TZZ&OY*7(|h}tKNoj^=cLSc`}$5nD3p1LOIok%hq%Zb_UmNl$SO&MP=8ML?^E!lVY z-fblw9UijkHGUun#-u`qm+=oMfuz$N473{h`WXocyfzE$tcfKR6=I&}rXnJ3z7N;w z{MonB((ob{VfLk9!9;|Z+610{A0FzdtH-6K=>YQ#~`?k)Do`EyN{s=peLzdMJqh!Atv~0g{k+BnDg^O~wN~Ujn3&u(VZD zj!HoyXWw*)v{f>WY^X)*s;cQX4xu*NZ)j*@e2kqnEX{|C#D)dyKeLKS$JgTKh|l3H zrz>907Uj1eo~ZviQe%){R9XV1ErOcC$4oc!U2e|S)87kTJ@t25+zj&y6+=IB_;=|-LQ z$*Jk`;C`sS#`=PlTECs;uDU8^mto5y#=k7w)otBX?%RYv{f385Q&V7gVC?wjb}q!! z!ez`Ngt=;{^In@z_pN(kb$3xd@SLf|=aG+Al)@?+x59kwc*|z$Tb$#y7oPnlKe0R6 zXiYGPDTYmI7L6t%PK}S`h?APF4zMsYM+dTwaB-=1yGgh-4EHhEOGa7lUsQ5oN_?Y= zNJ1-SQD%@4o1#-_yTv_cxp~2-)<5oM;);Ap zfK_#G9ZVPLAqEeYZ>uMrJJQ!3W= zM@LDtP3eK8rYgIbrK-MZi7Rv_h+jaLp1!K8{akr6Qw~zTs=-%XllVqx=pveWm7&>1 zLNc$!KC2LE)YVo?gCo&$Nz|kms^_wIm??i|cvllB5Bmp^fX<)Q+ z(2~NJi6GdYWS{0JbFoi4XZyaKq`X$|X^j?HUBidxM0v07HAgh7jNLXm9GmLcduS8a zn4Qfl;FIO-=>9rAHJeD7#p0e&Fo$4S++J>eW1)$^9f!pgm{ZyrHe{9a3OTTF$%i^L zP^k}N2RlA7p79VheU5QYp`42_OFGtsG;Fw(P)6 z#Ok1Ad$Ia}K+S%l&9XT?C0k^9cF=R7O~0sC4|p&bE3>O*PG?@*X9V9HPinAWam35Z z!u(Rb<`am5;&j2eSJxT0YCm_c1?PnbQP;utYCZ3$Bo7e$arXdALnF>T6Eil6<9kd; z%_PDv)Nknlcm*@XIysO_WNePB8B)$~nJK6*C(0*Waf3Jo;G{JhYp5di5+}7qRtBl6 zwx>3quZAjcn7J37+W0kAE(9&KXA8w5k9sS=K=)2)2}4UQgEMTEiWWJA{YX1^|KA^z zcNi{wnHH+)`3YoerX`Soem`d7q0tqI+4ZjLI4l)s(%i;roMT>K)Y3++P% z6-(L2uJhC7nuYF`;5h{I_|ajgWZS-1A8ci|>~cIU3?Gr0kAMjWN7tQz3D_K)x#Ak@ z>@D(7!IiawFNoh;#5za&dBBE0Qmo;$Q@5YDCn}=UG^Ss@pC2vGxMP@;Uzra zUjdc=IYG(@08EpP|M~xezW;aQ@-GF12(p%Fb@SC{njkCwqN_`52?ghiBVu&ud!+_W zGPNy)dps>IEgYQKoSdAvxHuUg0RpmlAVPC4$BceI&$o2zS!Xm!Nvr*RJtmTQ!-(u_ z%v>jgr-;zd(8CS{a3CEUT9`ams9L?~zD{TCm*KvLY#@BinK1*C$O~%Hy0bAWUXzw| z2sDA>Wlp#j7PFBA5>@(How9<*OlF^BVWsV0a~H!Z7m!zEo(PQqgwLzway1@z>#<&} zEBIc>oaNBy-}5k`8;yLjY4~l%7Say~&Dd+*OnQIUC>;KJP6ut;sf5d8Ax(;wAE^D3 z>Fp|GYJZF!h!XQ%4d{#rwq@Q{y3cw*W7y|Y{m|>!AAD85nl0l*DQ)pn_fAG3bxlz|7?X;2{9o(<7u7zXZiTL z%JycIdoB_Z5;)fB>gozl17(1T{jzXM#l*zK*Vh*aT*)n00P&1?9tZS3lTx8O)qB1L zO{eU(8^i8DFZriP&hq_&`Qm$Pc(o38%+InPXLo(S ztA!~1$&;^M;PJAAdoNZ?Wi0xk?08W{6lZF{M^<)O%)rCE5?M9&b`eb65dkgp59+oD2LPNio2n*8Sl%;bPUD*;MrXKr7sD)GFh04t_NVbVjRI@FvPTs<|DLwX+bA3w&U6ZVs0&{qMnUro9v(^4^T zHvXHlut1Yd7JQVBBgNFAlxgY7$Jg*hhLsV^=XO=`pc-e*S<}Gr8`;%K^6=bCO0CYq ziFqJ54^M7R4nB*H%ia0b!=Mc3QZxx0_j$&5qe3}##@~KRbdPzP3kzls?rj^km=> zBj@>^-hb&@dxyAP*Dd62Oz^PiAg8v(mh6=518=(W{sQ%I31>UqQ%Fg zM`+etH!ENl2C3u+nTLTz(&OH`gxEX@C=G3UR3bA~@7Ecf2uX}Mc-f5o!;SW!9%dY0 zA;TCJ1Z=MCHY+I5?Cu)OvdlJ93w_9T$OX2s4vgH~P7#olwbt2MCb_O4q{Xa<#g-nh zFXbE;H$_o0H)hH>8>?!s%*~4fyEO!1L4``49T)Z=5<7Az5WX3=wm^!O6mUfJ<5Wtc z9`1X=22Jx4=~LeBvb}<}wTGGjfVHJ1yxNWh`@5ZJo-_GXIPj-!Z*Pl^MA3|aE}qjG zerYj0K3pp}sEq5dY61<2zoDQWA8fV(()?j^GsASkj1a-L$}VKZA6Kams-^W93`Pq`?zzgS4GY5A@TbC7qJK0kor3=0ez}w{Qk{G zCF}?iy`u;9>#_Jhe-!5ExSM|3LCL5sZDtyx{b_0XdD-{+nV4VCA4OK8Id3_2kB7>o zeHuGzR^Gv?yQx8nF zazE`TtqNMqzc{<;ft3>6(mT+>`#n-9g3BJ}o5!w-BniHxMBg=7%XIZb$GvBdzrhK} zN|(x}M;QF=4=~NA7m!j#(T`mJ{RBBm^i1R|il?e|99g0>vfIQ*i%4Wf@ku_T^_T}{ zcr89QC6)^HeSQje!K(nE)mn^ah#IU+&n2XeBg`%<;&A>^mU$~7obCgQe)FcDOAHIG z#raC_z!%jdl?r1wjodnM?SG{bL5k` zEFKL+$AD)F@x0R_5Kic?dTc~|3-!F%-r8n_s#Eq)2yoA7U(2UG{y8(Hi0mKGY1 zExqdT9>GV_ZhC{=JFfTFSeZyjKkbI$!rSLj9QAE9wP6&nebxer%NvUfG|Kq&61n;lkP%f{M$| z(BY6S=0-v4=1(`4KCe}MitJXH!>^%9%O=%)AtoBNBaZi0VfwI=ZF<&xfF@jpRH$Ya zc5(gj@ckzaA%~&EANL0YT>4Lp#No!JvkS{MLVITWXcT zMpVmJ&D@nq#5E4TZz1k;?^zm{TE0gO)7#A@i)par-Y!PGW>k1)%>NTc_kLZEYgC;g5Lg zE{*9jX>(4;X}0ovtLXMR2c|db%^%w@#nhYk*Ehg>LKLO(+soLjg>D!coRP(0pS~UC z$2LpZuO4BlileNC07=H3<5le=@GuwhhH59K0V0wa8pF&=+lgrSIE z{^jhUmFLX71QhX@ySg~*XsvtJ`9(=dX=a=u?QP8dMZi6;L_+vG2PdZ#oHJ)=l9WLy znaZX7;TK4lK`!McuY&toTyBK^HJJcoqNB^7`Ec6D%d2A{h}P37P=_U1>;hab@e-n2 zdnqth=i4&p=Qxg(tOO*(6O{JxxLTiknhcv!rLwd}%cUbnOX0O$d^qU<{q6KmN+LAQ zror!%>}@)eY|eu+3;0D@|Ag^FhyK z)pNdMtIst<`!D1yei)@MAL^`%Lom=|gmDrZW?^=%poRLMKAbmxRQoR1YhU9N@{c3d z)sjN!*jAe)^5cZ>=c7wx?jr@XR*5&n0s!-!K3zGH`mlMTdsNq)gTdfJu>(QOnW-tt z2Ya&p3p8!(Q($b{D9;dlrQ7>|&yv_KSUrpdHcvPx}ozMv;5vw)P z2ht}u^_BZ_MKv(NqU6u>yrUkH+-HOdx*69v%t0H zi+8nxapWUf6Mbo(qOyNus|I7(*Vv3F$91F9vvMwg!eVDzH}dtsS$s_|dwi_1o3Z0zBn za}kz_^o+TI+VeYYf)0qD-6sEo%_6(YRL~w*nk&Q0BAaA=W^1$6$CDSom4=(v1VE=D z-K2{Ot*YZU0v_z z$2&N)x7vKAFFLPX-yvCCF6kk8*AM&jTePK1=yaCs8W-eIIUVSL>;%%5ABi2bBD| zBHx3l-GNclJQ!$ca;EFpgoL|KiniyAhI<nIelRMGL>1wps$vb>^3@_R2mETz%kx3+Kt)B5>(N)ABHmSU9_?zr@hR_@db7;5F+LZa+ddDHvt*M4 zZ|EnQ{KF8@`cA1BjoU;^SKjtvt?>p~-+8<1d68?mtu=c;f#vHx5(LDn+LDUL^BI8U z6cl$4pfx3N9^I26;%&Nje(*JYN>@k6RBP~hci{ZcrO?{zWPhTrR21wVQrOSS>>8#S(N@blkGA5j_~i$V{Q5g zWSM-rjty;|k~8^yf3ZGz{&|%Et648UKtEY1UhHdXLAe-bJkeC>Zn;Ca&9sY5*NvDU zVZ*A}`hvPrG27q*aow4D2WsH{!NJaGDjk0K$zE}!ZXV6B#L7?cxKFJPZENN3KJz{I zoZu`v(-7Y+x22E^r{9P#I4z%L&O0Bs|FRFx#cnoObU+D-1*}~UQK#N+=fct^+cjj7 zgf_<8K5;mTANKPyMN+$ms-Pn&m>`Xuh`O#%mEOi1{Snf+7+cyW8(AUau=rD8kIx?8 z;`Z2K&%yB_cH?G{4fMClaLIy~2~2kqat)gHcv;LsBEI3;39Sa(W9a@l6jylnu=8=H zt;9f|fH-eZSeERm08~ru6%KnCb^?>bBC2=|+|dH*1#FH}T{C5n%fhbWMUC38lwQhi zCgye%10ujaxZEJXA!R{@Jl6&v43{|-$D7|JF740f7+;-8hMRkrG5?%Op5wdQv3 zxais!Q4F4sFF4Y>cvWLff0)VSa#Nns&d3{eCmE==rp44{Y7LU|q}hOlq+2fBcRmVD zw%ICI$EZ=K-)#v^YaJO?7c=7dwQaX$n2`S%Qv(2IXJ_H?2b|&FvH&#u@q%rf6(K73 z(J*eRa4|uVl350)7!tMXpNadfyE=1$A^vd2^7MV!4aGVQ-Cc5e>f8BN7l(+cnj6;Z zL+o$6&HU&c(WJ0D@jK;um5|-aHo*>N^RBtb2W^!3MaH{t(s(HMvStPZt!qk;hkYiw<8 z;gQ+J6Q_HCxzb6C0p(g2qp)x>J zghsyGVHt!K%XZ(5|B7#6LUBZhYe!)y!$wbl1&`xg1I*a(1IiPQ=*PVpm<57x)G?8r z_{~Imfo`%ZL)B=`r}()hos?850r=HF;7uA1yrt&kP(nekNZ+bl+I;wI@Vz-cv=TW> zB`+^ec%Ko$ IFNOjC1-b5B_5c6? literal 0 HcmV?d00001 diff --git a/docs/assets/Images/Screenshots/example-1-endpoint-detection-and-response-light.png b/docs/assets/Images/Screenshots/example-1-endpoint-detection-and-response-light.png new file mode 100644 index 0000000000000000000000000000000000000000..627214f070b6b546dc8b8f2780c72342d52635d8 GIT binary patch literal 14180 zcmcJ$bx<6^*Y8b2f)gyb1-Ibt!QCM^1b3IkNpSbY-Q8V-JBu&wZVSQv?(g~Uz4hLw z>Q+5>Yj;j>ch5|3&rF~5{d8}*vZ53!5&;qn3=FD_w74n^4D3f}8i??pt*ORJI1CID zpOu)HvWu#e=rF_KyfR-8nSLlA@tXDSdcT{bP?H?F&iZe2` z%U5rf5fRwCUYZ?2n;CQYW^l6UNuP1MC6+fnp+Wi?XEH0 z6u$7yx#mCI*!0|VfwBBRM(%`D{xOa&S%%`ZYuV`v(bgC(_Xpg^r4N@6%L&u8J(e)P ze;6|H^UrP)z6GVg{-)i~toqouZ2Rz@JC-7C1|!V_!-EjC>;pqd3d81XhAH7g1e1z9 zi%m30*UG^p^Z{l;`7#OQvr>`?T2t%&oM!w1ro6R5JdRHJQV~WghXNM~rWPHBb_4^_ zVAfDzFd6reySI>;u$U6) z(s#^daO5QD%GjFmH#6-HclwOr5nR}V*wQq3VsoYvk(Smf_H2!QfH8V_0}*vSTIWm!p6vBA9TPUE!UnX z%o_=R@RH^h-ADRqMR>{pM=7hhxZ2v<7Rkvrb;yn&4>^eMForK6ovXIZeWPcDM9+UH z__}$7!VDC0OlB5x9zJBNCpBU(HOTL8By;4!qoQTX6S(yz;(dDYJi(Kbn8@O6D#@vg znC~=L?`F$}m!8!heycoxNWHESDM~?H0Y4$$yd&l` zKZ1TlV#nI5jFs@&n{s3@ryTeQsZ~;K{rNcd_mjf(XE7F7hFW+FM_8rH;BN?lmSLfu ze?!$rKGE&#IOE?b6%8~qtD1P*u;@ws+X!2<<*f8&gc_KKTl_n%qNjB z1Y)Ca>0uHN8MN1y$(;bPrBBsaMi;hnd+h>q&n3~IGcf$I;Jyvt}wygjV%NoxR~gMzP9a; zjtx#eYocpNYm$1OFJP)agTp%_2>YUUg|?18>^iA7ut~#W`%AW5u0B7gz6klSzkTl} z6%O#1`G&6bNiBe#>^HiSG{tu+Tgo#^4h%(%CxreWMDqAjnMTTXto|^8{3xv--)TrF zvndV8V$cl}ODP2t1V>|&eqbj4lP)Usnnj$&o~5-)s1)U*?nvk#`S{P+nYAr>P4R*% zHjaj_{Ht07KUI2yq_zTG0f*|8>VlB#J1HK-W~ z8NBI0Y6kgwig|uLG)q^ik$MCYHkJAT_>LxLaoI) zu{aGm|LAnD7&Nh4_oGA^jclv?vgJYXZm6&iy6`XK#K&xj-Mr4Qs_R^aZo1@llD9)tqa7yr)^(PI{X%=_Rrj~D)k6m$g@-EE|U2jn- z&0#~Se6?y9$-{6aIj|bH0wCi8ah+8#WJ6vseuJwk(JOZ8#Fp6|t|MxFlmrZ3M4L`I zh0H)^ayVExQ|;m`rcE8eamFL8@?2}?OGZ5Qg%)3}8z)M8kCIuJQ%y3hJNsM5AAsRy zGL@rzi9ZuViwTPV6wApI%0p6TCIu#N(ic+o*=bT;Cgvsq>4wce7>O8F8R;3l7**tG zmPreT4osO z+IX)jPBM)!fvVRpG`*3%yM2pZIpNy_bNXdNxk4@G7)y{#AnAVn@!NPOty6XVS6zt> ziSuPMRuju3yrXSnk9?t{h=;a&nSkC7kB&-L-h+Qb3!@qbUQ4&Q+zc(QEnY35?D7@} z7V}eh?%a-tZ4f8Y%+c&L4ww505j0=4Y^msBUnMc6KZimf6=s(jj+#INr7pX!qK(Oo zn%3&I{WUeA)Yu-SJf+y0bcpRH(x$f`oFAPZs^9Kg%$wY+(&sJM0NCbFdT8^Ad+>{& zW8it=8PQHqia$$z*8H@IR)-KD(iobbCz7Wt2AN>XrpjI*fHV4Iq}zWHk`cm;@-7sB zjzOY=fAwva$ywV}^DBk5pSth-xFzIh=V-NI(tO+kFhDy@IW#}m8F3rV7)~735UxuC zpfg}F__~?=Lq1GqDTRe~7%+9mOA#Iu{y7}hMd6Ss-Pci~I4PVEq!gi0 zuH-e0yt{Bojq{1AREK5i@E_ok6j|W&>L(LXfKj+3$Fg7><)cxA_t;`moqFv2>^u#5 zb*bphcgAm3eCHZoT2F5`vG{fP3TcHCg%btFoKEen>~h>TDnD}uR8_y>>m9W_KKD6U z)w&vTB?xkNC=4aZn65jsKk7UxPfcWwWrEvS+oW*Hm@t`73~cK>`gdli{N%a~B6Pbmru;Z#=DXs+J7pwYV%Esw#Qz86csO;#99j4S=~>e0;`<~owzo};Ksw#y_zvn zgVUboydPyhbR2!NR@+Z*TW|Ak1qq3`k{lkCX=yvPOm)?DZtN-icL!_Ey6K-!c8m8E z1P2udJGij8BDv9Qua=y1#hXlJMlTnqs~A_8R*_n|mW2GDgJ+M67WirT_xRz)MaNdg zqQ|&XdMc!=j%seIZOdn?SCnt9OMV>!^|Lz&D%{E=%Qr7@&b#Y|{gvdRWfYDL`ZhAV z(5y|YJGu{i^jnl{3}?FUp9i1e(ZorPDqX58D!|pu_CE;sP)*>m&cqo!5NXGj*Y=Ub)Zn6=Vv0^XaYu%~<4a!Ka9K$axUJ>9etiF~8{e0v+Cz`m zcj54)&E^l7=@xVXAxsr?-1XYI?IjE#L~}4-^KoZ5T--a?09*o)AmwX}T_wIX2U6Fh z8E{!}v1pGdZkw^~{@$s=FApVWIUCV?!nwk<#0!K~-j?r|OR1Yn`%*3>(E`Z=**>b5 z4JRNCrO9l+`^ZD)^5NQF z&Hkn$ZW@iZV3E-YS)_o|v~w>e#+NW!d2)1=k8I@i2z5ubqvWvfr=I3`aH;rkqF9H| zZS9>~+81_5etv7?fs&el1zCOpmQ#f#$#{;RK05 zO>Qwd+y`idbWyxd(681=M(9veO85U;C@VJ;UR_;%cXtPmMl#~tLk_L_H&I?p%;d&M z*~Fya0ol&(oRty#KiL%bm)reDHNAy+|L5cVw)a{U%eHyjaxo4+Y4dp>=k%L)L`98LFvWhlUb#b#)C64)(nK zlQT2hPoh(^wX^dS$bL}jYHw@v^ztIW!+WWtg7(30n#KN5G{*1Whs^L?cZZ@I8ymgv zFL-%)CNj7kPUg$@_xCq_@3U?`qN1W&SR4*U;!@y28}xf7SVZZlP)kxWBqnAm=l#XP z#Kfcx_vY^I;P8-tdXL6QnBnP{^KM*!W?YuY-i_3ik6KREwgL4{U;sPmAa?4LJ>q>P z<;2s;4`<)a1%mePF-p@&n(T~ih|Y^=D8`XJm2&)!JYpk`hAr!xKh@F?;?B~#bvG}Q z_GA&-WPpY5l}zJQzZ8BKd?1U66hSyXF5RKZRAj)2KrpK1>3(~2sd9y1C*SWhx5!&909%3?M3_H;dPA_5=kTIIVQ**aX@1Bw!go25OTgR_x--cgS4kPirKr;w3Z5`k22 zAJNNI6|gaE+ggwMVvvdZmk-zfrHYZf3C~{KNtzp7-go7;-1&>Db8J+^z+~N0`_MP) z;^_)+V|lub+Zc4R0lax}CLw~=5j!D!AD}6rLHWLy>+Qy<_t5|;7nzRdRfWj#;LpPQ zNCl}f<`AVWbI&iP40{AozVZevthonH;)HpFOF(8JXCr&coUyY|(;pBrs_&}jcz_QP zDhIaua$V~?tGM8Ywl}|vos#iXZ_)m5al(|#SCosd%&zS@h7I*<>2g+H{o zK_E*W3gSTZZV0ccs6r%LcN=^O$ob-?5att3VMS-6n{qsxBQ19H(6Rf_>#|EvNtU3<`=MRIlRIutFF zN%OeY=ZbAc?Doy)Kb<6*0MZB7b6HL^U`IKFgd|QJ{&~{ezc)jhzzsVn*u&!wXH(2x z0f~3$OHwPn$dI5yxp#B+D?96GspxKHf$SO8A5?97{|YIjtlDo2h-xj^yRFi55hbYa ze&%cY*`IVSD@^Kqtw{2<`eB?8yq&H(Q?lszcvLqoYCLwO|7*cH%eqfYaP}}bfIgD6 zwF>C@Ieb{QV$l}$Byu|YjHR@pft{UwZgo{xt-+sA$Ib1w%lkevD{IumI%x|crp=g1X0-Do#(r8lmiI94^Py0a>kDd)zD7lHmxh0u76y&yCy5B~+ zhwht-jH#1#f55mYI;JB9K4B)6^w=u4llrG*X=;)D%D{J%Ygz?X%JiNQxPdDRV zwVOCW#Dl1u(r9h8D)D1UqW

OS1n@58ZE+1FlyLBI*_+Mz=mbXFBc%X+1!dpT;8a zbvK)xqgfI5UV1n0o>2fsr7erW?leiaTE*V&3gR-07Bv2gxw!yj{C%dkW+ZPvCp5c0 zZK7`^N2<9U50Z%eX8P|x8M$hNeQy=8QtpG#0O(Uo|Ts^Y~(JMnVKoHe#U zf&3ZocTobhZvJ>W%cG;_f6uE^S^Tg|g&p0=Ud{aVRN9t0jGnqaA@e`ii}{w)Tv5c` zYGa7_Ma5feGD6ND%SsXpYr5B`1sgfgA|I(xz-j#`F~=uS&U>aG7mBz!ra|z{H;RnD_fyQ^&YsQNKTn(|x1*}6s`eHX7x(WW4Irr<~CGBagmZT`hM; z_7p|8mCGhbuH39nN{U-sI{GRvy8;3R0#KOLlq5J%w&X~S{c5Rkf%aAplbN@gGL1#6 zx+3tENTE@^oQ;*m$2B95WOU^lE^Z1mx+*LzTv}R6PbV-j*+nJfIyzQ4l~XshwA4~p zcYWrexsnnS>sP^b9>KJF#0cy@ZFgMe&B}}P$+)ftq8nRZ zDl6-)6@bVK`4~Eks!f}{O+TbDjqeZsdQa1ljWGJf5gsQwJ4ea{XjF@D4L+_78n zT)q-m(Hs^Lpq_?NkYM`!w7Q?A$eY3`)%!V-D5Vmh_pi3;PI9HpB_Wv2oi9Y4n>O}O zo)DQ`p}$92N8rgf1#NlJ6X5;JYemogG1CF^*NHIHFdA1zy#T{YKp`%iRT&@cujBU= zw`xgx0n(7~@jti!l$x=*jJBuAwP)BMGvz$d-S7SJW@xSgXylElEAyUcCkxw#-*kFj zdwF{^8+6jf{JFWkm2&MUDl$`1iBCWt8yma1xsg|R_Ort?aUGb>d|p2k2I69Ke{X0~ z6^Nqx-YLm=YBTYC9NPW*LS8v-e}2yRdP17$ren0Q2tI zM9^Ge^!8XC)ww6VYZbM*dC`~y9T}7zNpk7CX3~W&e@#$ znsHvK_wve~t)`YX9JopgSOaS&Vb`)3MMkHldN#8CXn;MyV`k1%Py-h_oP!VQ%`IS7 ztqI6p^7D=TrMwI(3sMbb5ljfiwJ_o6E*^niS`*A>t<`EA6x7_=EbIlwH8C-vLCPvB zV(0qSjUpuu$BlIQ3FXK+BppBXzgxPM;5ey)LeCObTPhG&6WWV+HLdN?ZAKSaifjVE z`di=FbH08ya&Xa>{0_!uZUPd^c8GE2(F5(fw6zo`E9#^+4E&E2S<%qY6ciNT;X_qA zS1cAQwdv^Spb@$=h>M$hv(>48L8It^P>=!)lT!&xw~Ux}u?L~Qrs29EYn$dWa z98;MFVwPqe9pS@SKQgwP*7r|TiVkgeR)6JHYodg!{?H9ZqekoTK!ll(!MA9Z88Rbd zHQ2IO7*ROBf}_%}s7j2q7cr1r16O5FncpL^A(a(H6Fpf8I!aC?^Se+gky3zvQ-RU+ zlIAo=_jtg`2uvkvk?8XB2(0&ee5RR9k91E<#QeoL3#iSvRRy(&Pdb;0$V!sjPG?71 z#_I5=EkAl`r>4UhN4eYOo2w?im|R6I6~_x2$P?*njpBYTi5=pcFiD)PjFJ>B=37R! zC9D_}$;{+=3*Ot&7Kv%s$^4AWlwx{001B;sn(ga;WHVDk7!%^0veozV8@eCX={i_S zs2{gd2*S&_nIuLjV-tJ&i@kVYI8JLv*-qq-)^OEgwR?smsGBPqbdH&?aYvk$R z0C~JVL?pXD1kuE%Lc^EL==+t+r5VfOVZ>4bm(oTqJVBry#hTch zON0oc!oe>~?cp+AzGSga*dqhIG?qmv^tyGXi*Pa?K0fkuJl=|n|~`$x~lr7Awvy)S>R?S`D1a{~ffNoW1zqtct)*b^oldQ{6)7rlsNnGTz zK9|2tG?%>vX5aL)r4bHH@+bXdu4z~uk(HMnm*dTn>M|Ve1uV!aSqEk?9S+**9PUo- zUtO0!wTqyQUeJJ|brnkQ;bux)wV8SoQeaV~%=4l=N{ju=I(`*BRx4jX4G%Lsp}5GfL0mGDefmzpugnWlc!n zqF+hp{*#4=`+va>{x>=Q|J@S`77*Fl8-{f;p@;p=s-~vKe#VK1`X8Oo8O(wJHS=Hl zzCn$$8bTn{{7@i6`JXM+F^QL!+g>JZfXo@Pq1fr+2n@4=NnA6{*$#t$#26vJPsDSBF5yCd>+FRp66wp&#?5w=M{K?{|y@~YD^ z1Id9pz4|$|$}p8-d;#4k#!$WY$*@TtC0gZ_(Jq4xF=!Cz-eDNc4?Q$+qP=mH>DEyKV3k z8kh@slNHMt>n@1_a5bre?cb2#16N)ePY*$EpF6kA=`$kB5odv4PwA&704SM)w6-TU ziB|f9oi}IKxH4O8G*}AD%_o(hHwSu%&t0LWKr#C4&-5pkJHg21ZqRC&y%`jC319jR z0#>HE@~;_O5nPiQiO1O~O_|6TC1ehfqdLU|v|$PLngs&?*)c09w39jOJbml{0xqnr zlLy-+<_1*oq0s7q-Mwer#`^R)O{@LEi5M>$d|lyf8Y^e1bkw7#E9I4x_aaN)?n~98 zs2GD{CkP9@)XAQyZtGKYMS;YF$J6krlSJoL2v&AhiJGt>H$wX5()s+sgZd~^phtJ} zVjLm|CBj)}v1!8?45}qV8PPBn?uthJjoTGIFY4rKKRqc)G55E15j!*E>&igH4|39fGo+>jB4#CD!g%@yhzy_Hu(G)u?e$7W67LV}DfJhE6~ znVNP`W7FIf!+(Ae$DJAh99&4y8gBEQ@8;YB(;`_yS7n8obE{n8i!2sRi&g&4#0#|q z{s}$-hI3C{8m&U8(9*23PeTNH@}Q|FV))a=sh70xb8b}{x)`kQl}rf!Tu|7_sjd_- zS6-yJtu0*{R!=|TMC@jeafz+ADriBXB{-;;t%&ASM+bqGB`IlgU@bFl<;mMwE#u&X zuPhm$FXM-VI;shpa@dvhYFE~BE=aE>D!v01KuKijRbeW*!sFrYHT?J1JcMh198#*e z(gk|iYDzD)L$9^yo^*{9)+@l?lK-^TGPzgT3_5noF2f#U5UQ=4Nzb6LN!lcFN*olbvq9=~2rq)<;d%KXF+p&(Ug~ws2&D_IZsh99V3l^U|Jt z^CH6sxyF`N`osisdHU1u7g>`yij;;mu@Do!G zrz_`I=-}w37@?9V&KONqW<^Cl$J@Zj87i-GtH4F4AkqtzR5XY|iMKq;Osq{$>9d*6 zJ}|f7@!>-mx6oIRc4O*M0V1&$^YL0oMl@6>b8#$Q&Na}7ZGY!#8kF1rRFr58TQZ1{ z_KO!BNJXGWYK>W5l*hwarDb{`^o(z2#$M-Q9{;q)(6)dYjolgb^3&K#SmPorsW8+2 z-#^0O;=aP9S$DbE&+M)tKarthw7yi}K%)5kr?L9O!qov&n%IymTUD&Souxt8!z8L0yt3aR_!w$aaRExi9)G*EM`F6yk~Y0t+Na%97cNlvvlB^sWa z!^@I$T~+1ljSLQwve$j?^FMe$KU3$Go*$2AC)#7F{n)gh`B%+=-!>||j}>y$_F@vvPfcg+TC64y?y~?brva-5bykl}`A43sv zFnuqIfge0H{ofPu|JJMh-xM}}%_=P|_2{I6-i9!E>`;b{=ZnW-G89$EfC$a`Yf?1! z`wR6TH2FX0`;z*4=-^dS4kn=5gUdn}OqpcKgr+Vrpme1Oh4go>!6v!}k#j16o4p6YA$z51M0 zp!7|m8IB#dI=bEQ5KzdallA%Pc?W6u`>yWQcBJ_%whlgUxpEeY-Rs%Nxuj;Ac870u zZ)4AyU|>8ZvIm+(&Mp&&xwY^8Ys?0Ge9|@rAXW0KDA25HV6!7ABKIs-S#m}=xysGvf!;em#)42g?wxPiZPdQ_xnE`uUceBN^E6OU zTSPQu7`fbw9XG9e(tNSVaPW9%j4|LB_5*EWC94qX4GUO%?rpb8Q$9VN)@=G*D-aTT zMsw89#QZ(dd{FUbQg_EBzGobcm23@%omLb%Yi{abn#Y2hgVg-V3X=q11+3N!X@Gj1Q(DY_+)R%;9d(T_cT`m9(wo7wx}Mn=U`LnkbZ2P&h^^dF}Ts&4}@5w-m{qP3|68 z;WaJFH)CojNzpmE7V+zJZy0auFo{d1k9Pfc3Bp5jB~^$&x1mVOLf6WuPaHF^(JdOSR}+hA=R^p(dew7!(4 zb;DNk5HhvirL?s3C%^p$!fp$T6Yrvcq&<;FH%_w(OcuWO)qI~R zzCh~pFiQW!i~T082eNTk%zn5!q2mf#`oux})RP?H9kf)M9G{yC`WL>ZoEMKXz5sN~ zYX|b#cAWK>{$QLR> z)fXh8Y>ngk#@IW<&d1O6&*OL)P|FVZY_H_~gZNxN^5#o4rx#85@UDJ@wnh_;$GMS{ zbzqk7`)@_lkFkK`2b&>_&8Mw1SmReOs9v3*7yU_0$3VygmoIMyBG3Bxp-XFTYUbDb zh%T}T)0IbO4*5t*@3zyesWl#O$6EB~a1wBa6}?P=pq@kZZ?w$em4^(*-Va9)0bhTY z6>qsd_AH^taK7$UKGrpV&6u!`p2{;-%8VsQt2&o!b~XFC!$#gFo`iCXUWB#*_U+C} zLCe#s#pXptWVh_$Rl?nOT7ic}49}{+8&5_EkJKK;<9(&gVTGya8d4|rdLS}+o9jH( zDMl2-dWMXtx9hFToGSNevq%F+la%-7h8uYC$Hx(koLzN6v`<{aL2&OC&hrZ@apQjr zad2j%%VY=n()ke5EGJm4-y!i0iy7~Mc+y$xHukZTH1ChMXj&h6esXYd47`6KAjc#n z6x znL+qB5(f=iHZkVwET$cBXJ$!s#=YI#1`_Df*eIe9gKp5iM(0V9WU%8!fepOv#**lu zB%!+Eln`H87M=KPhMDIlfe>rU01<)_dz$=n9O}4?nfn)P{CS!;8VL(uSJyDX#8K1d z^Yt$4AI4{4Ao9-2RC$J)S}{^*evn_rtc>()8pTzXO+i6m*+69%c?@J9=Yltm8iFzM zdgc+7!s)iaKxUiZ?%PQC`y_)OfsA+f4!iv#=8*wNJ|{%EgX(^8Z?QK~VoJKMxz+s4 z(7q?{KGKn~oK|O1UOGm?TZDDDOd{M~PX;ffy+B0hukATx5tDg#W_O4;1q>$xF1phXqNpe}sUw}Tn4nlRM)sHH8q&Gvd; zu55ZS4Gk(M-94q0=;s!HV&Ph&WR5amPFRfv^X9b~kJ@F;L*L9#DLMD(k4n-yj7FV(qU7rkFJ;IU1?yF^v&e`iHBD59xfO_WF~QeuSNc zV7$pJ5cO36eIGIAEP+Cj?-_uLj=-Gg%bavd+*oF&qH689$y4%&7l`laSw9*ZAlp}zvE=b9W04!}7<9TT znsQ+uBfZD#+eCRYXs3Am+{O){s)+w`6YS)meUe2eS+F z!fV3kj@PlSPT~7-@ZCgsBl=8OW>&ZU$9o47`3$F0y2OudFXVLUl@q8H>IA6ddtj*E zJixrBtAY3KgzP^_tSg`(lvS1d%C|V;nI_dCQU>m(cX@+dTlR7uT;E#~g;%y#5=b&^ zyZL5SV$qki%ziijo5guPoKTZCLw66b*PnMVifhtj$onX=DwdVQ-i`+O)5Aqq;-t7Z+r%})MUWI#M<}t zq_0A2*2fo$Y!u|jJITG^(VSNALV6IKDZJk9z7Y(4Zmcvz$hPt+PZrMMi9=-YT z%sj;oRiV&9wKXtKW5(<`)bEYGPZ6i4rYGM0V8Z`Pka+MaMEZ#}s_GZv%F*bggg9=w zYtN>1!?l+X&Ag73@KEd)gGLYm3nu z&^>vY&+))oU_;)VMFj3Lt@yh0_6hUr{^$fII?Y|!fm0Of(I0#`{_kAo3t6SpvCf?a zi0bJ9Gvz&ytFfrH>~DTf(MKvyx9P3~k9q zKveS9B`c-n1>bPtW9EJrswbyC8|jE0vMU+}O}&rk*R;JH2=7Q`BM2~}+%`6UXGs^< zF2aAO$#fNrd)Q1$V)er~S7UL$3raoP65wT~DoXb1blYSc=>laNDG-U>$x2kS(AejB z!w>xk;z$PKEiK3Vnrj1fhD$P5K{B7J^50tgsT&upP9FH6l&xVu@>y7kRaVPtX=Yvr z41IH1E~F$xt$en4^9<t;pw!sT^CyKCK%61m$-hY@I5Lq?#5A(BxJu(^~;@xqkusGBIj886X;@`L4_;soE{Ey3g z3T31|j=i*$LsFsb7B152mL3lcG{Sn8Yh*lFk1FYErV06g?GY2xO0n5$v&D|KQAXXl zuBWGPDCeRiiC%LX^BR^IwfDRrqBQdpzCLj||->!`Dy5!L*aS3y}@K95{Efkw5i+x${LaU0?LEo_wNfKxgMyPo1@YwW&Y*5}TVMkn;eY~jzOdZ2&(TKd{JZ@rnFIRa!)$EE<@ zqWKl5<&VA170#hAJ4tp{HTR?{9Tstufx!xH6}voNHB{$2M{y!BbNjkyjE!0M1d}yS z^XF&b1(?ErB@W;DaqnrHJF+QTDBD%XJpgT9*TG_Zd=65@QiC2_JQ7ndB8l1E-95Wo zf2|xCbANXy3rV!@US% zSKqEqpCxyB=A`htjR~}Sl4}8Hm0eGe4=5i7vQ#X16_Q^GHHnsXdTwuYbMH-Ybaaf0 z7DW-%WOX~&1p9O_Na>{fmOjou{?n*u;MMid@oaPRxjFP``LPq@LE3=-+R~r4sj;!y zex1*0XXF6I6r7@bq;MR;4AyQEF0)!)k@iRPLiQ40ijq#-9AA1f2q=Y#?KAi4_j$2r z(#Ijb$iBfde~2j}frN8U#Q#Y;7WK^w;QlP!2aubX%8dRp2cHZ!$e5H|lK@x|~lE6(<+ zriXY0AoU%cm>M7|_u+JUm!_kohqyhCDWVCya`b8Vy>hKH*@acalTT6Cy(R*2-Ocf} zsD}^#@vH}rxXJEbHRT?`h^6c8D^^1Y!P@qPLaZNDUm=zA1?@Lc9Z+_u#0=e<&~zSj z0lfqR)GQ~iq8AIQVqyaHj)q=5R^b`+$OngG2TIXlKcJX9C^23!(9t%O*L&9&UJd7R@&%I9v<;gnl^KNOc?#y^As9_VwjRbdK8TTpWNx+O2Vm<9 zdTw`k!;@kGvDedC=Uh@Z@Aa1eRKkPCC@uhZ)%R6wTCTT-izfydQ7g&f4amjqPY(vS zpLgDZcVjK?HI%VQlA0-*bm!^m>6?$~IW!+%$c7I4>f>(FJPvCC?&9mu!t=2VdpTcd;P+-Jz~B#FX|8Mi06DUwd$ z0=h3y6igKb_knhofA!y~FmvX(c{v-Xs7&ObKF#pmGY?|>^m+-yf*v`T@L!0lJVhE7 zN)6k~m5stVB>#sdsERI?D%{=NpuSDm0Dwn(T^l05dA(m{SAzk7cf6LO zqDoFGk|N~N;-Z|aJe-^$HfB};Kq@R#)lEy)4PWqf_2{=u==X@KWE+0~CDjpyYEtnZ z;OCDNKi)3GW8#+6G1TCQm%hO(Poi+4{23Tfyxu@AE>_XYz)b9uJ3hTA_}o!xuqJfk zlYPmzySnDF<^-^Sqo8!aD}56~pCnE7+`iy&j$&hk@#{0IJdo2Fl{BpS*ielTxb*J&{UxgD%BzwayHBJtW zH8qV5k0Qk{o_82IXE*F#r00X|L9@@2N2eDxRse2n!2FJo5$X_}4)l%1@&lDw9nohV zvR?(a;l5fwJ){!{fe=p4=H})(N{TfdioMgjY?K#(!PB_TdGp$~;UjXq#|0XJZVr(U zBb6+(skyAXH^tIHrRY;7>I;l?nlgA$q(o^1zs6Xs`%5f$@aQNOsu-JcQVIy`g%5Z8D)Na<-4&Goa}Oe{j=Me$N=lF`8KWg$#JI_lVsxmOJDmhKjvBVqIRD+;by3KO(@ zT#s-gI&{-q-eMH1Ku0AOj*pQNySemxBF-pj(RL!k6NFdfivd{@EIH46xUl2|J5Cmvg>rbNY$W6iZeRtb7>Q!8_(CD6`b*FQLJC!FvZ*~|{2boZSpEUUg zt+%QH>=fTWC`wT=QQH8IfE<_#m=DN3K`4~5#nN@a7VMr-{@e(y&rGzWz$~CXMbrm_ z_+p?yoWNjo!e^}b3#o#9&nc8C+$lQCxN;Frn%20Ufj1XMj;zf|%L*sd(J{32r8ufT z`KZ(4B(&w}^Egz-R8Ew#R7=$0OHsiA47rfpBxMZcan+FGZx&V@sD#N$Qt{KAlQ+`} zlXg>C)BDcYEwlpu%z58(p_Ahir;`SZtO@0bZxY|iFeWl2>Lftu1k`C5i5R`;$5r)n zzm$55HEZ67z0>X$3oh$c)y`2Vaa7xG846+$omBwKfmL1dtlAF{W<#vRz}R2|u)j{n zqJBNQRS#N(;lMiET?9Bnr%$^NIlha-6p?K@MSSF2iol423;25ffb}4JhH*B!45Q{# z5(;BX;%^2s5;OFwRfWma4X`-3X-`5Qy=GzCR7&aJ5{enR8H=essC(Jq+|{fcbUAmS z)I$@s$TSBxC$X$v_ON^|zGS4tPW4_DwTLv!QIQnTMcGFKJi zB(WRDEDKfTl6Ol#L0MrH_^~P{5WC9R9`6}Fe_+Gnir5;lGDr%A&S6X>AD&L0PG)m_ z0;kx zoh9@1pJ}T?y~bQ^5AAI&uok*@ZMkUqWw~xe_Tt9{;Ji)se$D;YLyL4nU2Cr;g;C}K z=5ff%iKZ8-SBFo*GZ?8QFuO-4gfql^8dQW@beiVd6Z`k$LDN`u&v|=%ZTw8hq~*xM z0MB6a&^>R+Aj+=IR)*W}R`=F&XP%vlzS%+b9nbk|d@jaD=SI)Q5Oz6pWb>J^kFH$y zyUnK#WEq25sT@wXBf=Oy7+I2${XUAKivGKT=x%Cu9PwRdY?zKFi`zUaQ2uqc@9vm(Med;omI+bPD~6sE@Oj z^jR)cdOrCRYrosr4G&dVR2V`Syp#McbDEc7)?8bJNB=J4`0l7sT#({V`BFvCe$>s` zGa9_N%*8sN#&$2<&d5;t5tiN>i?|tv*>fxiGz0Gqe|ingB~+_L&rHqGQbLMFu9!gN z6}-plo>~vEt7w910{PVZk^GT7Bd|kD6T2*zwX#O`9~BjHf-ie5_K)2TmQ~IMoN)qN zt@3>d(k3g8?DsnNN@F7#LmAL!)@Dh(5@sxx1AUun_nwVOYG2t7{hzu+28-2lehUYt zqQmV;r`rDIT2;Bm1%HR05~<3bG)c7NwKF>&Lim^3;@a@7ji7bAhg+3HWcr7l4LP4n zKI_=~WG=NFTsK|kUJDQrb0&PdQ=+45(=yRj)48&v^4sjKJnCS0JlHJUk{9Sz=xyc1 z<_zb;usNT1{3TXzB0YFEH&FpvnqPX?*gh}l_ZU32Uogu@$G63YI4m->I21X=mE2h- zRk2rj1+gief-EXsTNQoXP1MV3B`k9(4KH0g!8`7#?)Ouajg*$(*Y94M8Xgw-79y3l$AjtEOwuXw$P1{urc&ueY@!m5@me?^5uoOqV`h0 zdy|dQYwwBQ3obhZIpv@8ZJw5<5sU_dq=q+=&gW+4emC4TbmR$3@-40`rgt{Nd|z0f zjT8H4qw%wUWefZk9-rCWgJx@g zDD(CB!6{LSfc>WD#`SNa03wWUX3O5LjJtDN$LelpZtqS@mqG1CK9xI?mt^UPnTXLC z_h>F_(Jg*nDMC+oMMv4Iky}E)gy=|Si7LD-Ue4xI*5m)l!q-O#j3jJCgR`<_IPuFhz)g5k~gl#(Der9FzSE&;=5%gf3}e58J*P0OAjE z|A3nu2=@y1pZ_<~_n5b@Ru>!v$}4<_7r}Z308$X}AG}AF{s;e`jd18xl~pMS{*WWt zz=rCU^5SxZrLv4!9T)P>@<~P}PvKv>Zk9gUH#s|SRt;)ThXz0KDBpRzOQ-10`umth z;(V+Ijx4Fw*QytAJLbogOejXr)J{yy*_YmZ70zXj(U&B zSyXESEkVPAYO{}#$5xlc(^S=L80zOQq{@V0Cn(WAbl;SN5(wDI>sPj0bWA@_YpBn8SYqi^Cs?K#eB&W7Jj%;d&sSNWidz2z&Km2y zO{6EESise_jehbr!>{GcG#Q1 zgFmtF5@ob~#d2tJfWN$mIXULb&S}(pV=Kq&klO;i&>C8&Pq+dG_V7N?)LPX}JIgOx zOWbtJk)VQcT``Y#)ek}iLGQHF{I8aY&wv(fWy z2oj2=g#{zdtd3#VatOTGj634A)N28`T$(F{n5R4@Rmvg-(Q=$2B{Ox{=HJuuE0}pU z@AncuX@^8!l4Tq_#yxF%kGh111ga_eOLbz#UzWpC9C$qqy5CjVvIg7A_Sf_r9BK?JEVN8U}v`qce#VqN<^rTZAILc8O0#(!uZX3 zLQY7Rxp;GAp+%u%ZRB3{=_x#FGQ+_4|*0*FiPeY-Su zErNRL3#oX%r`CwC^t5D0Gg$XzGQp{Vi+i2XU(FN5$g<^(>Rc2_ovbJ-V!z*_zcnh())@3mATvXi8aXu26 zB+brC0uo572+K{ID^BxO!gKRwtgglWvF=C5wwRa?OV)?io=8X`e~JG?t)FTHM!wFz zCiPz+&Hn@2z7qcZ!^5K2KV75?lna5_HHoN1K_;(69NUIgo&GVpL{evGXC%0K`Cn51 zB|`5~@^&NY3bjAW-1&$zNXG8(9!Tw#_uKw{xqj&RA-u?LY8`N5go%kM=6tsPJC+o= zYobREYZ;N)yNG98ddmwDEh{E8w13wNk$YU)`7G0w9TCaijcAl`Um1WF&PNV3#Vecb z)!oxbs%zBI%S<-e)t)l1`N=qIRo~)S*p-sIPhQ)Z#9VuUjTe`hZ_u?GDv4%HlT$qsiZJ<%= zhPsfd5+S+?xhDm z=}OoaJ-slCkrYvLZ@el5oT{5**Qw*lBRXP~Li+Q+; z_=pD}Zu~7{kRT53*Xg8x`B)RxYI>_vy2$p>BA-|R?OKkwdKJzNUFdOPoRE-^n1qCc zn3ySeI0?kwK3{LGS^4lxQj>sjPqEZLv6eGYZA|8d*};})jk;cz#wf;5nYVvh8M*=j z8_d?}428Lu+`2b5wd$Q+t3JqTRO+vkv3%4DN|$VzQQi1Mm6uacBAC~33{Mps_{l3^ z{7WoVtTJ@p zrlsAIS2WHt$!mrryBl@DY};I%aWf5$%A#TVf?4ux@<`zlUE@Ko%>whBb?;aoT}2W1T&`nWjcBzB?~-}rx> zE|kaMKkIVI5^_?%aloyuQmbTGW4x>qtUJ_#b|)XW>wBu*2B_U55riJJ?VVTHNo1q#v)wcX17*&98_9vv z4RplIXt9}Ew|%&7R$8yJlzB)dWuQa29g^$`Wm-$O)9woYlC7z4t2f3fa@cMpAcQ|` z>WW@T9)6ig5VTZdp4;i?wts&tJ8s_VbFM3tE`2bWwDiu(( zxpIE891-3Ub5>XV%2T?(bz~_sFf$k5D}aqPx_Y-!LqHNTWh5e+Y$rtJ`Dq{ID!);n zI3%QB>z<3sbDJ`idi@X{4o}pnkB{9#cWf=+wV_UAK1sqA5Bz}4#?GG1V&HqRCC#T8 zxqKa6Cq-rov#vZM%1=C1ZG~2W)_js|o(;IVkR2Ty9IQK@64IUCR;n&LWgh2srox)%tH*hgMBkh^ zM%8+f*1RzB^-a8Jzdx2AVc9U7)yd*JcjwQGb?0YeV;xZ0olVl%5%@YBCV42n5~BaD z?PzmrrilIHfU1!jX0+9~fp>Xoaikx^yi<92Oa^gL^9L{&f1yCm5ShK?B>TnU8e){7NB7Qf#kq_!-)*h0hM?Z#}UEMa6xiTdu8 zhv|d*NiC>>{d&r6@f!C2dm@Xg^B(lSQNv{R-@lX2%*}XbEMC&TFE(jIS3HdP}6o?cq zv(wlW@>{@78ZLRQWa?(&5l|a|V^yr;D2u{fXge1zpy0+tJ9OPX*u{7vi*i3wP(S82 zvx4WA;O>bvJ-UGs9)5G&+_V1?%~hB#aeqhL0Ji2pFK=)EPVuBh3m7=Wv3S+v=+Fa8 zFvzd@&DuD#spQ}&H+4z>_;@5L^Af2ppB+**ZQe^gVYk2OSk2%!m^xzA4ssCe#R57hs*sXhw6z>9pp0X1t&O*ecYLi|+j%)5fcRb+6{ z`~vimWE*9wu8cUW*o_$hr{o=qw_}8Pm5T>}1dD}Ugngigp~@ndlLee0mpXYqyDV0F z`x`eJt9H+XfhB)!wu6aUvPj`dDl8t9P|pzH;8BV5LA;JG??K=286IDJQfiaY%^D9I zD&NVg@ahwW28z74W~tk*Ubz8g;PMJLhzHkIFZdBpiF2Iq4=v8DP|Mu7;Zs z=4az(F+HOA7^eB&SFy)VsD_4t**h`e=XU&Sp(%*W_&g70(q6Vrc~E^?Ai-_P$z{oI zWF>8oaWUeg1Y9$ia30h0jpvY#X*ML@1ZygTi9^1E^|wR2NGj81>QrO<+f=exbCW`y z6(8B0A3=Jcgik18^@*vGL}F9U^p-fmHX=qd<*LPTCW68~KcJhL1Zq9!yN(j=w|jS6 zYalt8?O`WIGH9?~E)y<-zvMg1F43M{_gJ#Sk!Vc<_IY_>GKZ$S4G+ex))$sRy690X zO{;GsRx@tN7a2A1KEQlF9cY}S$&%m_{jH+qGfc1EhlJ;+uV9*DTH&qSW7OTlkGb~; z6T~*G5w{mDe&wgbEop7C0tdQy*Y9tIj)h=@CYsd(?1IMJU1IO z%ASvE$ET*I@R+~cowS~=x(ABD#TMG@eLnit*-+X4cclRA;83g48=d;Mg8u$+N%Z=L z(WyrS+cqlnc@n1rRf{7C3If8Jr%O}8Ea1W~L!z1a^FvlkGn{7n+}ra!a9c2KvL-U|%t4md3maNC{G`KXTu zQ)}AVSsx@wU*j6oElp!i>SVJT?=SlKTJc#uG(XGy(Y~bho&7uGqi?(t6enw29|$^d zA?ma@Hk(3|Up?4uakX`tRHo(OiJ)pB;IRZ=KITOWwwR5k33%PiC&&CuLip=}5C???ZY3cJOGAhA z^GkLI@N^Ry%F;AIQr+7-+0z|rC5q<#=*x%F1+%+sta>|=X%9n0EeTD*>PyL_dZajq zW#0@7brC4}iV)#`sGBa$_CQY{YtQ^Nh|RZ)A%BcHDOq(B%imW!NfkPhP7a~OVG>^0 zMxZmV8t==vii?)6GEj&&DXT}aiA;lI7k-)RbMsWOdwL_8Q|d`pf*B0m_kx_Zsdbk4 zC@GO{=~$4gtXGYrG!*Y6D$!Ax2#wQtw|v(TT8lNiJ-(4lwz;HMK4rk_A2j#H;q^Sn z5Wr#HDJ(sPp&6O`3TV>dcp%T?dZ?qLZxIM4 zJRP`VVaLMj?|l|ze55DHTxoP6>c6(DnTd!S#;;gZFH|8JOA)Wz%nl}e9bLSpHt_nX z+mvHINF*Y;ZoTL4u5aEM4}KmHj7UadxV3Gq&PerQx^xfc2HFg>JH^BAJ-HP@@z#{Q z0HP9kSd_D&O)X$t3()xi)y=lr%E#^eYff!lbI{zf3S zB;Rzs>gXI%+!v9;yC<#l_G1#(IG;W#cQvmP>ZKb0{hGez*vBFmDP`{Bj_V;mhh-no zb{l0(yxoJvr{-Mw;bAtx9~)~kycG4MW~b}%J(ygj zb5QNCyA-Q?b$AtmRkQj|W<}THT4ML;&T9MV&cMtB;b;u>^>n^e8pNMTetFNlR@1&C zajbZMJluV&+5cpzS@*rTBIhbF+2H9{wm+=)3~IfNvc!qho?zgP7B zui@>%jOEx)$CJsBFXT|&E=>MvM8O~}<{a}<-)d~9^Z8ND42eWF>vl)AtOoCcixq>D zzJ6SrUlpcZq~1~6;WtLC)d3musS-vfDD!?x{qY0X)`RP14#r8?w3NujVW(8GI}*lk zzurZ1#-9)4l_B5x&CN>c>v}9|w3|Yw%?k@bfvfl3^h5_B{@tK4^!4JC^7a|2wb!hZ zubBQbg6D2tty%72)?V6j0Foaj^K1vDd*_yS_HOush%@p~Y?Q2@GLCZ~U zhEREBO_?>1Pv@eLmICY5k%e|vPMbi`m+b325`Z1=>xfEAOY8sHzDUr4 zkC!(s^x_f;c9XvvAz}RbNKz6ht4UxAh^on-`+WB-njF$fWq23Q2;Ba*>!_f;@&yKi z31px0e#czWac`vtmUvGF+{?!Acro7EN{Y1XNBlUvkHXwsaruV1oHoz0+7$2fS(oTi zDPuS}N=#muX6WSF8*#*JNQ@q z!ns!)(WPFV(Ly3nSg(R{Y|4P&DDNp;TNSZxfd;8_p q`#rV*dT3i7w$1r!{D1WMhX=p@0=M-VOk9zFJEg@H#2_MH1O5jeicdQL literal 0 HcmV?d00001 diff --git a/docs/assets/Images/Screenshots/example-2-identity-theft-protection-light.png b/docs/assets/Images/Screenshots/example-2-identity-theft-protection-light.png new file mode 100644 index 0000000000000000000000000000000000000000..ecd9ea33aa6e288b8a57d57c517fb3b6bb7f9ec9 GIT binary patch literal 9043 zcmb_=^;eW#)Hc$k2nZ-CA>G{|A&f(ZG{ex{oq{0Jor81@9nvXC4-DO%14wtj_wm?Ce6Brk|0h#5TRi$q6-#O-WGAnQwxl!`M> zMBc;H$jdJN0%=O+I1%nUUz7n~RR4{ZX8Z!Fq_I{emPzGU2}wJPmINEA>NOH$KR%Yr ziz*u=qeN=>n-@lvM0IIWhWtp;g+GRZ?=_Gz*pNo^$Kv#n7IBdX*tT%mS8>=0+2fhg z*UbUMKv^azcm2DS47;86E-(hB3r{e2nxO>|&V$mU8RcRTp?xcHw9;1!Bmp z#>L6Grlz6(POA9H`x-Cj_>#wm@??M~cmjb zmqRAOLJMR!vjBSfQZMXPO5a!FJUvoQ(1Z*~K~-QRH6}7$`f-9G!@~qPGTf@kscZyK z41`Z+bD(3diWgs1?_Q*ym47Tq!J36HeKk>e0bDF_eDGM2>gURyZPjiYgS$LoW!2xn zB_oJpY*hz~gzZgvAsi{&zT)a-A65gA2Rl&}N71A?QCO-lEF4jkk3-&LezW`$>eU&l z(T~cs*~P8>5={ja0v6Gb=tYd2B3cYfk^>= zpZSq)lJXsRiPw zO>u9CydsPlUz+6#7h_p}b5`NteH-;@CzlB!<%*RaV=px{N_zf&J}C1ON6rJ{{q5VI zok)4ctO``MU4m~(aJmVqOclb*JF%tlOE_6q)Q0%#uBTn=hh-wFA2HoUt1c&K*J}6TzC4et?Nky$ z0f6_fwNcfBc&NX=R+gt_{a{P?myQ=-3I7(eI~a>5t{Cu(u9>j=hiGo3wj?V9C0!<+ zA$9a?P(m@CSiIOkOrj(~!l`^gzV|rRIMFzxReYHgKYdGlcR%u}u`^dw@}kn=hnQFf zrjj@6;UXW><3H&rGUf5Aji?=}WU50oP)cz4f|zqFa+6i@RN?BO#SWI%yf~yO$?^#k z{9~6BN@MopnG?INgv|_Mf$Vt>xie$%(W5aC3s+)U5^@siXO<-9B;CXcMlnr#7BUte zCb+s`u6~KHOq1447`9H2Oh{>$x=xN7)LCPzc`%q+dP<2;flu8n&$?|7Z7S4ShL4aB z#22XBK5tmZW8IA#3GQFzzK-OJ)a}*j#Z2hrHACl~NR@>-q>90u-1shb_qg^VCRwIp zO7Utqld)K0lYTRsQ<%T3T2>lMTj!G%H0w_6Wzs5a9ZxM;gHlg2PFjv5W;{y=rq8Do zW)^ejO1!jiip+9|a*|5xfcs_B2~Zf+Uj0TLr-(As8%Q=)KN>x0Skk7|qUR$er_~3N z%T=#%`Lq+p4xCXJQ1pNtVl8oreP31(i(BSzOYn}F-LvIzM{kK-8laq+nZ_GU**_XP z8q4D4lg96G1 zgcH6bgcgz(1{MMp$P|uJ$A(2=#OYJ120RR@F0hGVk91JIBpW%K8XGg4H=8Pu0T{QX zG}LZ&ZN)zEXTrMBpdnYsOJ_@)Py3}#ZJBi0S(#pW*8JN!x>?)m-I^PteM<;f&&Fp# zX_&pA9bU0?sO5v>)9zRBz=zTNEvx%;D1WHM1X~eK(NVg8cih_By~dI1?vu8J+Js5y zm=$cUUud9d@J2Xv0Bgr~GsEL|i)TxjtI+mo@6>?iw)gA>i2zH3YlC+~D35{#rp4sQ zTXzA+ou(rvs*HimG+vi0*hf4+yiB>MK0jq?<-i?rxGINBC2!?7L*+KRwu0s1<;up2 z#jQnk@zj_Ouse{_E)|Cjz7kI|372W7NXlpvIPRDHZjtWAt*v}g<= z3^u$y+(I-tG%eH>ylTw2@4rHGb3W$iNgu(uGe2Zbk)neG!Ft_?-yz>QaG%73UgJ}$ zzB_q8&hD&Zs`ZA}+F!$Oa>()sv5r`%9X21b@c6^nN7p;q(;9ve#ui2qSsSKD>A_^k zV)$kySyJH#U^a!5tIuQPQiwJzIt(og#YJ(4J>3VKIo%rR)wja}-x-#O4^|FWEK&CE z!`YZRrYA;aFV^K8**Wz%ros_LTR=6D@&Jc9^3I7h(cOT;xQphPKt7-Rol?{DJL;;d+Ch`D%rL zxji%Kp|<2Boxn2fs$7$TwZZ!&+R}S13T;K5pY6Ayq6@9@tt2+aGrxBBH!BCJ4EHULdJIsrbHM;Hbu~fqz2~)qXq?1 zI!fis5tZi^wk6{g^C}nCMMgVG2AM6SrEVn=B`b%-2kq5;0m{HAfa0!U*K$T1p0$Z} zOZ&F3L4&dlXsrF}uICN|Plggv=2B5wI#a=6FG;rf(gcGL&+xH#2U7p3v{y{AtT0#F zQQjXh)&N*}MgB^B(J9y^|3qZts3iT}a0r|H(0cO8^yKvK`s@1kypM7s^GoxPj)q77 zC$0yRq`s*blC12Eeu{3Z(`!*eiS^mS+1nch6m^f>mwJ}OycYb)}r+?G3|f}sCI zkHNdabz6yP4)95pxW6v?o3$LZDUmI~NHIlL?qm6MJe#^QyCvsB86}!5n(3={T)PL? zR36Uszlzx5SlV#fpoQnd#UGnbnzqj#I0`!ushC-fSKMb?o26Yd>6Lh`YpuK9WOwea z+*cGQ26H}VR|ix<5{oyfHzykoSHWj@J;h;C&twwIQC`Od35oc_zwZS=jqVr;>1_u< z=A(vZ#=+7{?S!pIjN=u4qg?wSZX*0htZ*sR9~i%7d;u~qd6QVxl!Hm#g>^EN5KK1{ zyEHK&Q=ka7iNp;F*&*H`Eo6Y~E9_4+jD&a&U|bXdGkfl95WKe+9j_6;^7297&~V{l z(E-k5ByqU%fE)d}fF?on%NJoGp)^CP=aXe?F|o1LH8cnm&^PQepgbd^SMTNj5nvCn06*vu@y?kM=c2g@S*2jP{LmGM^7kJ~+WkXT>Sy?7Q? zlCh}Iq7(Te!9NrS74T2|XMym(&743&KhKDc$(suf_KH7F-u;QeV% zCC4;>O1K4k7L9Gu_VL$aBP|=6l53|KDCtU()DoITT=o9sOFPX{>WTylR6#DH`L}Vn zI9}g=GGL$!<8h0BJB>7eDn4-8*5$okViQa8uP@e>)wf|ddOv+;e58^bfLKLacsGP1 zN9ty8wj(UW*lC5dki9AD;+6faaCDGu^Ib;{Oddv5HI+gZ1KwzP4>KrEi#&jBsgvs( z&K8O@K-D^6#jcQxvMjNbV*0E7Zm)CgS#?AHzZ~?>*G8p~f({`4CMq5D^9VFN*ywqV z8ZvxV#l`4hg8YgmGojv(-jauK}1 zPhG+Uyee-HmHg0u5i;!oWY2&N3Vx_EKr9J=a!e->A22-oVbX)UqLSn$SYDiE)45oU z;;>x+67`nhJ7UVB{+{=11spNr7qTVsE_y7wDeD$RqeM%pbO%rUMsh3&=UNw_o z67{8tYdyXm6NPj-cC0D*wU50Hs-|Aco01WL7n$}`zD(m&%HEv_ze=^R_cA=>Q}z+q zA1u9bcE)y<3x4*KQM+CKiln-_sBc=1quR^m5nesFKyy)d*>FJ zlkvU2OrwN0D!n?XRbT378V{DTyUJsFGussP4&W;1pK^ffdF%d=$^-?T;%JIC0A5tM zOaB!^W)OY!Zfb78jfY)Q*pdD6rvs3>99Hm0oKNEN2%`WC+HNUE#uR5@RsyjdI&@jKmt zY;H!G(IFvywO4GY+j3tXOBBtE5|5m3J*q3%EL&=vFjuUh^*BMwv$B}lwm|{kHHNE4VfNT@7vzX3oKW5;iL<~ znEqtp7x1|$p}b$_Wp9V%p995GhP}zS@~NKI#CT;%sKT-9YW-*b-Er-M%h6AYIV~Mz z%65sB6Xqq>EH!GiCFL1@`e=BEp*zQ^4KFn}4cpBIu}(fUwdg=`;8`ps?V4Uf8@^0f zy)B##8E(bW<~4joI=eb*EEX$VLDReZ8^L681>G_oYkSE%|FVBS`wsw!|2kF%eXzpx z%Dj1MvbPaw=~DW95>Xyx709jjnV0GXr=9=T$7%j#f82D;CEuQ=BL9)LHLi)Kivwpi z$I#mlCH0~#u`2_7r}9t({kXDfM zlzE>me^u&Jg~Ddh^mTNs99CRSgr70VEE8|eZ_114&$?0Id#r!c(1M;l;Q1lJjQ=OJ z|2JCyXM@D1h2!IDE|7nlpA#e}CmRsaF%h#*iXS(+4lLIHgT;odU>TX0QHgAE;vF~V(AMz7RPs(Lz4A}WaO7;DDC$SGTheMzMdk~0 zGd+ti3kMFKhPmO5>a*Uko^>6)Vf)+In@vQLy$#xPKxzoeuQ{mgSx-G@r`j?1UdPxS zf5po>Ck}*JPhZAIE6S#yULoEXPG&}yp}>X2ITd&}iR$Tvv_6R`q(6Q%z8xOf-CuXJ zYN&gDM@PFd^UwL#<>$ZLui8`Spn#{xhu+@M%OO>$ zssHKJ)KuC+EYK8eW(E#yphmPEPgw;&nW~*6P*@La;K(YDeT{|RGmMKJRQZ^EsJV|tKI2$%M;b^W@WlbvmJy!zYvrQaGJQCpXCjZNxm51#P}@%Ubn5ZqlYW5bEGwVn*n13ux#Wa#Z#Yh-Rj- z<0@%y7M8NyxZ9l0VauZE#Ng^T8)rs<m*?bwXDSS2Wo0RBD--GD?zqA}XmudU zcOnUZp8=m?39wI;)w3MlKG86vmGR~CU``IZQofbXkb3MeT0BAuLu&hZp2R^7g&EfH zA4MPJ<>NUO6ShritTxuU-SYH-8O)c!`?*#CXpTrslc&~cEvz{VA8NKsC3D?mJ-E|D zIkR1qy5>qqSP7WfJf*=SporvU3)tZX(=eHFFS!>7Z+fJfX1nhspXv^h4u4^&E}co( zj|TEdH0xz@)D`cNwAFbH)+`>3O+*gqm|M1L!B*W)uqS?+Pn?U3k9eC=8m*r8d);J- z>eV02)xe1<{LF*HhLM^Tot&yA->WbuS=Z^d#81x77RT_I!;F$EFSgjEUQeG+m+J<9 z+^*;Ldv)-uMtJ$&AF55X)Jbk>YZOf?EAOGzUd-WOY5VK(FQJX>QdLQbT;(R*%h!3P z6&bIxW~l(~pvFx9%G1K`srvplF%{HaLSMpYP^a+tZQOdRrE8~GZMl8L_-Y^wG4pMU z%j?^EQDsm~AhRKfCQGWAZ z0(eKG-SSIHQ!t{aOy0~EJ6|~f>Tn}g8l6nKKn&Bq7bkIQh1$-ROSe~e`dYDNkL~UD z4+Rf;9JmJe)4fq->m+!?%gquEnUu{*balFIE;}P6Am6cpfdN=yO?N;VQ3^%t+U&xF zt;0_1l@xEB{Xnj*&vhB9x0Q15E0V{9Ul$R?vN*MuoKPMb;rr?26!!qgmQ*|(^uyEa z;rtyShei2KCGY2kU9=CxBu`VE51Z|iBGhYlFwX$`urJB}tqO0%?^IpP{n(uRF29St zbHFPB_|URmPQkmCI`*XU6+mQfy}AOrJ#;2)j{xo36kH;Qojsmes;Ug(2Dl8w8st;{ z&BNMhbXooC66cp}w1&5iK$xWmeYy^>NMP<&#`5lXCB2=W=Q-gZ#k;VNRrqzOL~ppix~ z`q8Vc-F8TT@I5!bwRB~U2J_v+<-!uJoQ9QERD;9*5W^m2zxZvjEa5}WLhp0*k?4Z)P$$pyY;Btp&>#j;33&&d7$@f+pB}%frc_up=x>iQc@r@+TOMx z<^U@-wd=QW@|y&$TK=f=Q_spRmhWF2+;hL+TiLV%}JkN+ujg^<6xHHkcJ?vH<$w=ZARjpTF1JZV~3I0 z?BaADaKMpMvzbT*rL_mT(e0j;5>{ZPeBTcu8Uu>B{|O$!a;H)f0?}>z^c{KrY|ko10Cpk>13>bS4M-BlU!xuOaDOAm+U= z!MP*D%vCq9uEee@_@bQ>w}ARn!)mi<#_V{b>pc${2#37PuZ%HHqbYJaf0wmPmt*Vx zi>B4Dt8~oWvmYI*i{h|zg@2(uG_B~O=ifYchalo!Ts*B?o0UtY;$de zE~@l$2>QRIeyIq`1+6I*Ks@mcUmDR*ac6_ipIROEbB3I`lh}D4ARa(3jO&EWntZna zGa;eRgHdM_EBRNHE^H9*R79QxNeY6nCp34y<1X5Y$2uIfVFFUNSw+D|B@n@{{r zImb~B)0NjASqpGQq2Q!4tP3~!>!iTvFXftX5Thkz^ST~7%@7GZ(wWO?O1^!`4u5qY z86{;_s=~P&na^=sbQa5#X5R!_MLM%UPe&aZbRmW|M`K)7YB;(#cEH{T2?- z-GQiuXJ*>o-VO?QaI?3!cXV`QIM=SsALC+BYBx2%H%@>2P5t}V_T71ae9Ts)&h78i z5rn#53?nZT(QP!X=(_C~Cgx{sc2^yqmbiI(8%8+BR$<0*`=_wx+=Y5qCMMFKq07gs z>S&uqTOr6WKPM;f(TJ3kOo)8Xp%pKz+g8tbkc^BB!`4n*qk&l$G_vLFZ8_)%x$XVE z&%!^oz*coi)oQN490_3`)nHl>xe-)5QB%muHfr%M4rU20CIn z-SFn`rb2$L!sssO>R8afZEfWg*l!Xf-VE^${ew%P=7ND+}gB3DJY(Qf!rAY)Aq(j<T#L3x9Rr&ovVFae`bRr*-%RyQC_H!BSF9(YVwwv>n_&SMm{5X z2&iZyPj3D$EN}M83{SBMZvvJ5gc-Y9+zyJ(v%QJ-f9WK6 z3x{_lzP#H_oBd#auw2IPiEu25-6K%J4hfpaJiK*{P5k+@&Ev>0AmHidYzH!<_U6*H zid#rnc#E|5Y5RI*w_(l6lj2i1q1n?qQ$=oR*I$G z4@(CJv>oZH*4iY})Vu>dVjUOljF| z1K;WSufT8l>O5szOXj0Hc&pZY_c$2T1B7%Ki}paqT9cX3Z3U2d`E5)gXWgw9DW}k% zaJiB{sbq4OfXC{#IPzOK_wtr+$ENp6L9@!qB$^nS$?sU zeqA|WQSi7~)7LF~pSElTAA2At=5k_v_V|*P?)%W&n3D6!ArC$lWs4D}`?f{O8dp6( zKR;dF`AMky4lK>Y-^L#i%3xm^_T%S)oT%#YK9_2q2}J61CQ#$_g}<-9>1y9+n#b$W z>rJ=E?;>&9*Q|a^3|l`jJ78`_dVkCDhYhRgxSW?XIx;AF$oL@HUXNhl^?(<+_F}=t zp94JFn*cbf(2A}L)Nw1aiooD9~K4?Nx99irE`|Ey*%1J=)4I%zOp@^O7hN=m93Erbk+ zvhxK1T_p_+44#uvXiOYE$GJ$owhM!(D{UW6w}Hvgt`6EUd)4+p2J-N<9@w99rhk5`O`99Nd64j;R*+5)7$MbXL%+SUd*LsVCe zh?7t=*$mRHFwkwIcl?aRgtj;dQQVNx&f;RX{g$S}IKH`Wzow;dwe=;2P^`LRDvOHc z!asa*+9(JcjL%BD-4xkc^LZo+r$Sq@@3K_=|5?0LtSL=ju}M!4+DgUQQ=6VuHp-XK z$fNo%&ovNT%=m1))ZN{xvn?p0flQ(4Xd`(#f@c2abTTb-_9gb{mMyQhH!+gII(Q_p zyW6y|2qlQ}t05yNXH`)V(x_%tJnHi<|5>&C=SjmtV~nUVmsNa0M*sj2)@1juDDO=i zYSKjoJkpNcY!2wSIs1nph?rSe6wAU~$(}p^mpZ+Q%@f||8%&3sb&BPGO98S 00:01:18.000 +Complete Prerequisites + +2 +00:01:18.000 --> 00:03:00.000 +Install SHIELD Desktop Application + +3 +00:03:00.000 --> 00:06:30.000 +Setup SHIELD + +4 +00:06:30.000 --> 00:09:45.000 +Assign Permissions in Entra + +5 +00:09:45.000 --> 00:10:19.000 +Kick off Data Collection \ No newline at end of file From 4662d2ba96676d3f8f6c8734c31c1941451ead04 Mon Sep 17 00:00:00 2001 From: jtdauria-shi Date: Thu, 27 Aug 2026 20:26:23 -0400 Subject: [PATCH 2/3] spacing update --- docs/Microsoft-Insights/Usage-Guide.md | 21 +++++++++++---------- 1 file changed, 11 insertions(+), 10 deletions(-) diff --git a/docs/Microsoft-Insights/Usage-Guide.md b/docs/Microsoft-Insights/Usage-Guide.md index a43926f..f8cd2b7 100644 --- a/docs/Microsoft-Insights/Usage-Guide.md +++ b/docs/Microsoft-Insights/Usage-Guide.md @@ -89,7 +89,8 @@ Next to each feature you will see summary of the feature in your environment. Th - **MAU (Monthly Active Users)** - Users who actively use the service within the monthly period. - **In Scope** - Users who have the service plan enabled in their license profile. - **Purchased** - The number of licenses that have been purchased by your organization. - To understand this information, consider the following two examples: + +To understand this information, consider the following two examples: **Example 1: Endpoint Detection & Response Feature Usage** @@ -168,22 +169,22 @@ Microsoft Insights considers a feature in use when a qualifying activity is dete ![Microsoft Insights Overview - Light](../assets/Images/Screenshots/MI-system-user-admin-light.png#only-light){ loading=lazy } ![Microsoft Insights Overview - Dark](../assets/Images/Screenshots/MI-system-user-admin-dark.png#only-dark){ loading=lazy } -1. **System (S)** - Automatically generated by Microsoft. +1. **System (S)** - Automatically generated by Microsoft. - **Examples**: Policy Checks, Compliance, Security Monitoring, etc. -2. **User (U)** - Activity created by users interacting with Microsoft features. +2. **User (U)** - Activity created by users interacting with Microsoft features. - **Examples**: Sending emails, joining meetings, opening files, applying sensitivity labels, etc. -3. **Admin (A)** - Activity performed by administrators managing or reviewing Microsoft features. +3. **Admin (A)** - Activity performed by administrators managing or reviewing Microsoft features. - **Examples**: Role activations, audit searches, policy changes, investigations, etc. Every feature will have an associated activity. Some features only have one activity, while others may have more than one. **Note**: A feature is considered "active" even if its activity is background or administrative in nature, if qualifying telemetry exists during the reporting period. Some products are measured primarily through user-driven actions. Others reflect value through system-driven and admin-driven activity. Some examples include: -- **User Driven** +- **User Driven** - Teams - Exchange - SharePoint -- **System & Admin** +- **System & Admin** - Defender for Identity - Conditional Access - Intune @@ -201,13 +202,13 @@ The first phase of Microsoft Insights is pulling in data. If you have successful If data is not available in the platform or certain columns are grayed out, it is likely due to one of the following reasons: -- **SHIELD Not Installed** +- **SHIELD Not Installed** - If SHIELD is not installed in your environment, the system will not be able to display any insights in the report. For steps to install SHIELD, see [Overview and Installation Requirements](/SHIELD/Prerequisites/Installation). -- **Permissions Not Granted** +- **Permissions Not Granted** - The Microsoft Graph Reports API requires the `Reports.Read.All` permission to be granted for the workload. To resolve this issue, make sure the required API permissions have been consented to the Entra ID or reach out to the user who oversees granting permissions. -- **API Access Not Available or Enabled** +- **API Access Not Available or Enabled** - This may be because the API has not been turned on yet or does not exist (such as a non-public API access). -- **Organization Does Not Have Service Plan or License** +- **Organization Does Not Have Service Plan or License** - If a service plan or license is not active for the relevant Microsoft products, the system cannot retrieve or display usage information in the report. In this situation, you should check to confirm your organization's current service plans and licenses. --- From a47764dc1b634a8ab00a82bd6fffd2f18fecf133 Mon Sep 17 00:00:00 2001 From: jtdauria-shi Date: Fri, 28 Aug 2026 16:27:33 -0400 Subject: [PATCH 3/3] removed vtt file and video script --- docs/SHIELD/Prerequisites/Installation.md | 33 ------------------- .../Videos/shield_installation-chapters.vtt | 21 ------------ 2 files changed, 54 deletions(-) delete mode 100644 docs/assets/Videos/shield_installation-chapters.vtt diff --git a/docs/SHIELD/Prerequisites/Installation.md b/docs/SHIELD/Prerequisites/Installation.md index 4486fb4..4b58e78 100644 --- a/docs/SHIELD/Prerequisites/Installation.md +++ b/docs/SHIELD/Prerequisites/Installation.md @@ -10,39 +10,6 @@ SHIELD is a self-hosted application deployed in a customer’s Azure App Service --- -## Installation Video - - - - - - - -

    -
  • -
  • -
  • -
  • -
  • -
- - - ---- - ## Installation Prerequisites ### Disable Network Traffic Inspection diff --git a/docs/assets/Videos/shield_installation-chapters.vtt b/docs/assets/Videos/shield_installation-chapters.vtt deleted file mode 100644 index 9628baa..0000000 --- a/docs/assets/Videos/shield_installation-chapters.vtt +++ /dev/null @@ -1,21 +0,0 @@ -WEBVTT - -1 -00:00:05.000 --> 00:01:18.000 -Complete Prerequisites - -2 -00:01:18.000 --> 00:03:00.000 -Install SHIELD Desktop Application - -3 -00:03:00.000 --> 00:06:30.000 -Setup SHIELD - -4 -00:06:30.000 --> 00:09:45.000 -Assign Permissions in Entra - -5 -00:09:45.000 --> 00:10:19.000 -Kick off Data Collection \ No newline at end of file