Additional components need to be configured to make Security Guardian fully functional.
To configure additional components:
-
From the On Demand left navigation menu, choose Security | Dashboard.
-
From the Configuration Status tile, configure the necessary components.
NOTE: Once an additional component is configured in On Demand, it's available to any other module that uses it.
Component | Purpose | Instructions | ||
---|---|---|---|---|
Hybrid Agent | Gives Security Guardian access to the Active Directory domain(s) that you want to keep secure. |
On Demand Global Settings User Guide - Managing your on-premises domains When configuring the agent, ensure that:
| ||
Entra ID Data Collector | A Service Principal that gives Security Guardian access to Entra ID objects in the tenant(s) that you want to keep secure. |
On Demand Global Settings: When configuring the tenant, ensure that Core | Collectors consent is granted to each tenant for which you want Entra ID object data to be collected.
| ||
Quest Change Auditor (via On Demand Audit) |
Sends Active Directory events to On Demand Audit for reporting in Security Guardian
|
Instructions are provided via a tool tip in the Security Guardian UI. You can also find instructions at On Demand Audit User Guide - Change Auditor Integration
| ||
SpecterOps BloodHound Enterprise (Optional) |
Identifies Tier Zero assets in your organization's Active Directory domain(s) and Privileged assets in your Entra ID tenant(s), which you can monitor and
|
On Demand Audit User Guide - SpecterOps BloodHound Integration | ||
SIEM solution:
(Optional) |
Allows Security Guardian Findings to be forwarded to a configured SIEM tool for further analysis
|