Additional components need to be configured to make Security Guardian fully functional.

 

To configure additional components:

  1. From the On Demand left navigation menu, choose Security | Dashboard.

  2. From the Configuration Status tile, configure the necessary components.

    NOTE: Once an additional component is configured in On Demand, it's available to any other module that uses it.

Component Purpose Instructions
Hybrid Agent Gives Security Guardian access to the Active Directory domain(s) that you want to keep secure.

On Demand Global Settings User Guide - Managing your on-premises domains

When configuring the agent, ensure that:

  • the action Collect Active Directory object data is selected
  • any domain for which you want object data to be collected is added.

NOTE: In addition to the permissions required for the hybrid agent, the service account (which the Collect Active Directory object data action uses) requires an additional permission to assess certain vulnerabilities.

Entra ID Data Collector A Service Principal that gives Security Guardian access to Entra ID objects in the tenant(s) that you want to keep secure.

On Demand Global Settings:

When configuring the tenant, ensure that

Core | Collectors consent is granted to each tenant for which you want Entra ID object data to be collected.

NOTE: An additional consent, Audit | Basic is needed for the On Demand Audit Entra ID Service Principal to collect Critical Activity, which contributes to Detected Indicator findings in Security Guardian.

Quest Change Auditor

(via On Demand Audit)

Sends Active Directory events to On Demand Audit for reporting in Security Guardian Findings and allows you to protect Tier Zero objects.

NOTE: A minimum of version 7.3 is required to send critical activity events to On Demand Audit, and a minimum of version 7.4 is required to protect Tier Zero objects.

 

Instructions are provided via a tool tip in the Security Guardian UI. You can also find instructions at On Demand Audit User Guide - Change Auditor Integration

 

SpecterOps BloodHound Enterprise

(Optional)

Identifies Tier Zero assets in your organization's Active Directory domain(s) and Privileged assets in your Entra ID tenant(s), which you can monitor and assess for security vulnerabilities in Security Guardian.

NOTE: If BloodHound Enterprise is not configured, Security Guardian will be used as your organization's provider.

On Demand Audit User Guide - SpecterOps BloodHound Integration

SIEM solution: 

  • Microsoft Sentinel

  • Splunk Cloud or Enterprise

 

(Optional)

Allows Security Guardian Findings to be forwarded to a configured SIEM tool for further analysis

NOTE: Regardless of whether your organization uses a SIEM solution, you can also have Finding alerts sent via email.