지금 지원 담당자와 채팅
지원 담당자와 채팅

Security Guardian Current - User Guide

Introducing Quest Security Guardian Audit
Configuring Audit Working with Audit
Using the Audit Dashboard Searching for specific event data (Quick Search) Working with critical activity Working with searches Working with alerts and notification templates Auditing Microsoft Entra Auditing Microsoft 365
Findings Tier Zero Objects Shields Up Protection (Prevention) Privileged Objects Managing Workload Identities Assessments Hybrid Audit Security Settings Appendix - Available Audit Search Columns and Filters Appendix - Security Guardian Indicator Details Appendix - Data Collection Details Documentation Roadmap

Disabling Shields Up

Disabling Shields Up will remove the temporary restrictions and restore standard permissions for Tier Zero and other protected objects and will trigger an alert to the configured email recipients.

To disable Shields Up for a domain

  1. From the left navigation menu, choose Security | Prevention.

  2. Select the Shields Up tab.

  3. Navigate to the Prevention section and open the Shields Up tab.

  4. Select the domain where Shields Up is currently enabled.

  5. Click Disable Shields Up.

  6. Acknowledge that you understand the significance of the action and click Disable Shields Up.

Override Access for Protected Objects

You can grant specific Active Directory users, groups, or computers permission to access objects protected by Shields Up. This allows for controlled exceptions during a Shields Up activation, ensuring that essential accounts retain access to critical resources.

Removing an object from the Override Access list revokes its ability to access protected Tier Zero and system resources when Shields Up is enabled.

To override access:

  1. From the left navigation menu, choose Security | Prevention.

  2. Select the Shields Up tab.

  3. Click the Add Override Access button in the action bar or select a protected domain.

  4. From the Add Override Access flyout, enter Active Directory users, groups, or computers that should be allowed to access protected objects while Shields Up is active. Selecting an object will add it to the grid.

  5. Use the Remove button to delete entries from the grid.

  6. Click Save to confirm your selections.

To remove override access:

  1. From the left navigation menu, choose Security | Prevention.

  2. Select the Shields Up tab.

  3. Select a domain.

  4. From the domain details, select the required user, computer, or group and select Remove.

  5. Select Remove Override Access to confirms the action and revoke the override access.

 

Privileged Objects

Privileged objects are the most critical assets within Microsoft Entra ID. Within the Microsoft enterprise access model, Privileged objects in Entra ID include permissions that can delegate management of resources, modify credentials, authentication or authorization policies, and access restricted data.

Security Guardian supports the following Privileged types:

  • Groups

  • Roles

  • Service Principals

  • Tenants

  • Users

The Privileged Objects provider (Security Guardian or BloodHound Enterprise), identifies Entra ID Privileged objects within the Microsoft 365 tenant(s). These objects are then collected and displayed in Security Guardian.

Privileged Objects List

The Privileged Objects list displays all of the Privileged objects that have been collected by the Privileged objects provider (Security Guardian or BloodHound Enterprise) as well as any that have been manually-added by users.

NOTE: If BloodHound Enterprise is configured and you see the message No New Privileged Objects, check the BloodHound Enterprise Configuration Status. Review the configuration connection message details to determine whether the connection to SpecterOps has been successful. Review the Last Configuration Received, Next Configuration Synchronization, and the status of the configuration.

 

To access the Privileged Objects list:

From the On Demand left navigation menu, choose Security | Privileged Objects. The following information displays for each Privileged object:

  • Display Name
  • Principal Name
  • Tenant
  • Object Type
  • Date Added

    NOTE: This field displays the signed-in user's local date and time.

  • Added By (Security Guardian, BloodHound Enterprise, or User)

  • Certification Status

NOTE: If you click the Filter button, you can filter displayed results by any one of these criteria.

From the Privileged Objects list, you can:

관련 문서

The document was helpful.

평가 결과 선택

I easily found the information I needed.

평가 결과 선택