지금 지원 담당자와 채팅
지원 담당자와 채팅

Security Guardian Current - User Guide

Introducing Quest Security Guardian Using the Dashboard Security Guardian Inteligence Tier Zero Objects Shields Up Protection Privileged Objects Assessments Managing Workload Identities Findings Security Settings Appendix - Security Guardian Indicator Details Appendix - Data Collection Details

Setting Workload Identity Category

Categories help administrators classify service principals in Entra ID based on compliance, security tiers, or functional roles. This classification improves filtering, reporting, and risk management.

Best Practices

  • Assign categories consistently across similar identities.

  • Use Tier levels to indicate privilege and risk.

  • Regularly review categories for accuracy.

To access category setting:

  1. Navigate to Security | Workload Identities.

  2. Select one or more service principals from the list.

  3. Click Set Category in the toolbar.

  4. From the Set Category window, assign up to five labels from a predefined list.

  5. Click Save to apply the changes.

Available Categories

Category Description
Agentic AI AI-related workloads or agents.
FISMA Federal Information Security Management Act compliance.
GDPR General Data Protection Regulation compliance.
GLBA Gramm-Leach-Bliley Act compliance.
HIPAA Health Insurance Portability and Accountability Act compliance.
PCI Payment Card Industry standards.
SAS Statistical Analysis System or similar workloads.
Security Scanning Identities used for vulnerability or compliance scanning.
SOX Sarbanes-Oxley Act compliance.
Tier 0–Tier 4 Security tiers indicating privilege level and criticality.

Setting Privileged Status for Workload Identities

The Set Privileged action allows administrators to classify selected service principals as Privileged, marking them as critical assets that require enhanced security measures.

Best Practices

  • Use Privileged classification only for identities that:

    • Have elevated permissions.

    • Are critical for organizational security.

  • Regularly review privileged identities for compliance and risk.

To access set a service principal as a critical asset:

  1. Navigate to Security | Workload Identities.

  2. Select one or more service principals from the list.

  3. Click Set Privileged in the toolbar.

  4. Confirm by selecting Set Privileged Object.

NOTE:Certification Status column will not reflect changes immediately. Updates occur after:

  • Identity Reload or

  • Entra ID collection completion.

Certifying Privileged Status

The Certify Privileged action confirms that selected privileged service principals have been reviewed and validated as qualified for privileged status. This step is part of maintaining compliance and security assurance.

Best Practices

  • Certify only after thorough review of:

    • Permissions.

    • Ownership.

    • Risk assessment.

  • Maintain audit records for certification decisions.

NOTE:Certification Status column will not reflect changes immediately. Updates occur after:

  • Identity Reload or

  • Entra ID collection completion.

To certify a service principal as a critical asset:

  1. Navigate to Security | Workload Identities.

  2. Select one or more service principals from the list that is marked as Not Certified.

  3. Click More in the toolbar and choose Certify Privileged.

  4. Confirm that the selected objects should be qualified as privileged, by selecting Certify Privileged Objects.

To uncertify a service principal as a critical asset:

  1. Navigate to Security | Workload Identities.

  2. Select one service principal from the list that is marked as Certified.

  3. Click More in the toolbar and choose Uncertify Privileged.

  4. Confirm that the selected objects should not be qualified as privileged, by selecting Uncertify Privileged Objects.

Reloading Workload Identities

The Reload Identity feature allows administrators to refresh the details of selected service principals from Entra ID without waiting for a full data collection cycle. This ensures that recent changes in Entra ID are immediately reflected in Security Guardian.

Best Practices

  • Use Reload Identity after making changes in Entra ID to ensure data accuracy.

  • Avoid frequent reloads for large selections to minimize API load.

  • Monitor Last Reloaded timestamps for auditing and troubleshooting.

To reload workload identity properties:

  1. Navigate to Security | Workload Identities.

  2. Select up to 10 service principals from the list.

  3. Click Reload Identity in the toolbar.

  4. Click Reload Now to collect and view latest property values for the selected workload identities.

관련 문서

The document was helpful.

평가 결과 선택

I easily found the information I needed.

평가 결과 선택