Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 9 additions & 8 deletions docs/Microsoft-Insights/Usage-Guide.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# Microsoft Insights Usage Guide

!!! note

This article has recently been published and is subject to change.

## Overview
Expand All @@ -15,6 +16,7 @@ The integration between SHI One and Microsoft gives you incredible visibility in
- **What do I do with this information?**

!!! info

The data found in this report is populated from SHIELD. Data will not be available unless you have deployed SHIELD into your environment. For instructions on how to install SHIELD, see [Overview and Installation Requirements](/SHIELD/Prerequisites/Installation). For more information about SHIELD, see [SHI Environment Lockdown and Defense (SHIELD)](https://www.shi.com/it-lifecycle-services/software-lifecycle-management/shield){:target="_blank"}.

---
Expand Down Expand Up @@ -87,14 +89,13 @@ Next to each feature you will see summary of the feature in your environment. Th
- **MAU (Monthly Active Users)** - Users who actively use the service within the monthly period.
- **In Scope** - Users who have the service plan enabled in their license profile.
- **Purchased** - The number of licenses that have been purchased by your organization.

To understand this information, consider the following two examples:

**Example 1: Endpoint Detection & Response Feature Usage**

- Endpoint Detection & Response
- MAU: **134**
- IN SCOPE: **152**
- PURCHASED: **210**
![Example 1 - Endpoint detection & response - 134/152/210 - Light](../assets/Images/Screenshots/example-1-endpoint-detection-and-response-light.png#only-light){ loading=lazy }
![Example 1 - Endpoint detection & response - 134/152/210 - Dark](../assets/Images/Screenshots/example-1-endpoint-detection-and-response-dark.png#only-dark){ loading=lazy }

- **Purchased Licenses**: The organization owns **210** licenses for the **Endpoint Detection & Response** feature.
- **Endpoints Enabled**: This feature has been enabled on **152** devices or endpoints.
Expand All @@ -104,10 +105,8 @@ In this example, the organization is not overconsuming the **Endpoint Detection

**Example 2: Identity Theft Protection Feature Usage**

- Identity Theft Protection
- MAU: **220**
- IN SCOPE: **275**
- PURCHASED: **210**
![Example 2 - Identity Theft Protection - 220/275/210 - Light](../assets/Images/Screenshots/example-2-identity-theft-protection-light.png#only-light){ loading=lazy }
![Example 2 - Identity Theft Protection - 220/275/210 - Dark](../assets/Images/Screenshots/example-2-identity-theft-protection-dark.png#only-dark){ loading=lazy }

- **Purchased Licenses**: The organization owns **210** licenses for the **Identity Theft Protection** feature.
- **Endpoints Enabled**: The feature has been enabled on **275** devices or endpoints.
Expand All @@ -123,6 +122,7 @@ A warning appears when you have more users using a feature than the number of li
![Microsoft Insights Overview - Dark](../assets/Images/Screenshots/MI-warning-dark.png#only-dark){ loading=lazy }

!!! info

Sometimes, you might notice that the number of monthly active users is higher than the number of users "in scope." This is not an error; it's simply a result of how Microsoft calculates and reports these metrics.

### License Types
Expand Down Expand Up @@ -159,6 +159,7 @@ In total, the feature is being used on **1,180** devices, but the organization h
2. **Reduce the number of devices** using the feature to match the number of licenses owned

!!! note

Not every feature displays the associated license type. However, you will still be able to see monthly active users (**MAU**), the number of endpoints with the feature enabled (**In scope**), the number of licenses owned (**Purchased**).

### Activity
Expand Down
2 changes: 1 addition & 1 deletion docs/SHIELD/Prerequisites/Application-Permissions.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,7 +109,7 @@ Coming Soon!

Coming Soon!

## `Grant-MIGraphPermission` Usage
## Grant-MIGraphPermission Usage

The Grant MI Graph Permission PowerShell script is an easy way to bulk apply permissions to managed identities using either the command line or a graphical picker.
You can find the script here at the [PowerShell gallery](https://www.powershellgallery.com/packages/Grant-MIGraphPermission).
Expand Down
144 changes: 79 additions & 65 deletions docs/SHIELD/Prerequisites/Installation.md

Large diffs are not rendered by default.

32 changes: 12 additions & 20 deletions docs/SHIELD/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,24 +2,20 @@

## Overview

SHIELD is a hybrid SaaS solution with a customer-installed app in their Azure tenant. The SHIELD app service is an orchestration tool that simplifies the deployment, management, and maintenance of Microsoft's Secure Privileged Access architecture. With SHIELD, you can automate the deployment of complex security infrastructures, device management, and user management while adhering to security best practices. SHIELD helps organizations to reduce the time and expertise required for deployment from a year or more to just a few minutes.

SHIELD is a hybrid SaaS solution with a customer-installed app in their Azure tenant. The SHIELD app service is an orchestration tool that simplifies the deployment, management, and maintenance of Microsoft's Secure Privileged Access architecture. With SHIELD, you can automate the deployment of complex security infrastructures, device management, and user management while adhering to security best practices. SHIELD helps organizations to reduce the time and expertise required for deployment from a year or more to just a few minutes.


SHI operates a centralized SaaS service in its own Azure tenant known as the Data Gateway. This is a SaaS component shared by multiple customers using tenant isolation via access token claims cryptographically signed by Microsoft Entra ID. It provides storage, analysis, and reporting services for SHIELD data. The SHIELD app service collects and processes data within the customer tenant before providing abstracted & fully anonymized data results back to the Data Gateway for reporting and analysis.

SHI operates a centralized SaaS service in its own Azure tenant known as the Data Gateway. This is a SaaS component shared by multiple customers using tenant isolation via access token claims cryptographically signed by Microsoft Entra ID. It provides storage, analysis, and reporting services for SHIELD data. The SHIELD app service collects and processes data within the customer tenant before providing abstracted & fully anonymized data results back to the Data Gateway for reporting and analysis.

!!! info "Security Considerations"
SHI does not manage or access the SHIELD app service runtime. Where authorized by the customer, the SHIELD app service may initiate configuration changes in the customer's tenant using delegated or application permissions explicitly consented to by the customer. All requirements can be set up by the delivery team or customer prior to engagement. Note that these configuration changes are deployed as security policies which will need further customer action to associate them with users.

SHI does not manage or access the SHIELD app service runtime. Where authorized by the customer, the SHIELD app service may initiate configuration changes in the customer's tenant using delegated or application permissions explicitly consented to by the customer. All requirements can be set up by the delivery team or customer prior to engagement. Note that these configuration changes are deployed as security policies which will need further customer action to associate them with users.

## Architecture Topology

The following diagram shows the high-level SHIELD deployment and trust boundaries between the customer tenant, SHI's SaaS tenant, and Microsoft Entra ID. SHIELD components that are deployed to customer environments are outlined in red.

![This diagram illustrates a multi-tenant Microsoft Azure topology showing a vendor (SHI) tenant and a customer tenant within the Microsoft Azure Global boundary. Key components: the SHI tenant contains a Data Gateway and ShiLab.com; Microsoft Entra ID is shown as the identity service bridging or present in the environment; the Customer Tenant contains a SHIELD Resource Group which houses SHIELD, auxiliary components (SHIELD VNet, PS Proxy service, Key Vault, network interfaces, DNS zones) and customer resources. The relationships indicate the logical grouping of resources by tenant and resource group and highlight where identity and gateway components reside relative to the customer SHIELD deployment.](../assets/images/Overview/Overview-Light.png#only-light){ loading=lazy }
![This diagram illustrates a multi-tenant Microsoft Azure topology showing a vendor (SHI) tenant and a customer tenant within the Microsoft Azure Global boundary. Key components: the SHI tenant contains a Data Gateway and ShiLab.com; Microsoft Entra ID is shown as the identity service bridging or present in the environment; the Customer Tenant contains a SHIELD Resource Group which houses SHIELD, auxiliary components (SHIELD VNet, PS Proxy service, Key Vault, network interfaces, DNS zones) and customer resources. The relationships indicate the logical grouping of resources by tenant and resource group and highlight where identity and gateway components reside relative to the customer SHIELD deployment.](../assets/images/Overview/Overview-Dark.png#only-dark){ loading=lazy }

![This diagram illustrates a multi-tenant Microsoft Azure topology showing a vendor (SHI) tenant and a customer tenant within the Microsoft Azure Global boundary. Key components: the SHI tenant contains a Data Gateway and ShiLab.com; Microsoft Entra ID is shown as the identity service bridging or present in the environment; the Customer Tenant contains a SHIELD Resource Group which houses SHIELD, auxiliary components (SHIELD VNet, PS Proxy service, Key Vault, network interfaces, DNS zones) and customer resources. The relationships indicate the logical grouping of resources by tenant and resource group and highlight where identity and gateway components reside relative to the customer SHIELD deployment.](../assets/Images/Overview/Overview-Light.png#only-light){ loading=lazy }
![This diagram illustrates a multi-tenant Microsoft Azure topology showing a vendor (SHI) tenant and a customer tenant within the Microsoft Azure Global boundary. Key components: the SHI tenant contains a Data Gateway and ShiLab.com; Microsoft Entra ID is shown as the identity service bridging or present in the environment; the Customer Tenant contains a SHIELD Resource Group which houses SHIELD, auxiliary components (SHIELD VNet, PS Proxy service, Key Vault, network interfaces, DNS zones) and customer resources. The relationships indicate the logical grouping of resources by tenant and resource group and highlight where identity and gateway components reside relative to the customer SHIELD deployment.](../assets/Images/Overview/Overview-Dark.png#only-dark){ loading=lazy }

## Audience

Expand All @@ -44,7 +40,7 @@ Check out this page for more details: [Getting Started - Prerequisites](Prerequi

## Installation

The SHIELD installer ('SHIELD - Desktop') is downloaded to the customer tenant and executed by an administrator. During installation, the administrator is required to authenticate interactively to the customers' Azure tenant. The installer uses this authenticated session to provision an Azure App Service and associated resources directly into the tenant under the customers' ownership and governance. No resources are deployed without explicit customer action and consent, and the resulting App Service operates entirely within the customers' Azure subscription.
The SHIELD installer ('SHIELD - Desktop') is downloaded to the customer tenant and executed by an administrator. During installation, the administrator is required to authenticate interactively to the customers' Azure tenant. The installer uses this authenticated session to provision an Azure App Service and associated resources directly into the tenant under the customers' ownership and governance. No resources are deployed without explicit customer action and consent, and the resulting App Service operates entirely within the customers' Azure subscription.
The installer provisions the SHIELD UI web application and associated components to the customer's tenant.

## SHIELD Module Overview
Expand All @@ -53,7 +49,7 @@ Depending on licensing, the following components will be available from the UI:

[SHIELD Discover](https://docs.shilab.com/SHIELD/Discover/) The Discover module enables advanced licensing intelligence and compliance reporting for Microsoft 365 services. It interrogates the Graph API, Defender API and Purview API to extract licensing information for the customer's tenant. It can then generate compliance reports for later analysis.

```mermaid
``` mermaid
flowchart TD
subgraph m365["Primary Inputs"]
graphApi[Microsoft Graph API]
Expand Down Expand Up @@ -89,12 +85,7 @@ flowchart TD

Click this link to see more on [Secure Privileged Access](https://learn.microsoft.com/en-us/security/privileged-access-workstations/overview)






```mermaid
``` mermaid
flowchart TD
B[SHIELD Defend]
B --> C[Security and readiness checks]
Expand All @@ -110,13 +101,13 @@ flowchart TD


```

<br>
<br>

[SHIELD Deploy](https://docs.shilab.com/SHIELD/Deploy/) SHIELD's Deploy module provides the foundation for a secure environment using Microsoft's Securing Privileged Access (SPA) architecture. This module automates the provisioning of security-critical components such as identity boundaries, privileged access zones, Conditional Access policies, and more.

[SHIELD Deploy](https://docs.shilab.com/SHIELD/Deploy/) SHIELD's Deploy module provides the foundation for a secure environment using Microsoft's Securing Privileged Access (SPA) architecture. This module automates the provisioning of security-critical components such as identity boundaries, privileged access zones, Conditional Access policies, and more.

```mermaid
``` mermaid
flowchart TD
B[Deploy Module]

Expand All @@ -136,6 +127,7 @@ flowchart TD
D2 --> H
D2 --> I
```

<br>
<br>

Expand Down
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.