From 723442505b3bd5bde730a625b3ff08e377518583 Mon Sep 17 00:00:00 2001 From: Kevin McKinnerney <40665896+kemckinnmsft@users.noreply.github.com> Date: Wed, 23 Jan 2019 21:43:43 -0600 Subject: [PATCH] lab setup --- Media/asc-edit1.png | Bin 0 -> 4022 bytes Media/save.png | Bin 0 -> 5979 bytes instructions.md | 54 +++++++++++++++++++++++++++----------------- 3 files changed, 33 insertions(+), 21 deletions(-) create mode 100644 Media/asc-edit1.png create mode 100644 Media/save.png diff --git a/Media/asc-edit1.png b/Media/asc-edit1.png new file mode 100644 index 0000000000000000000000000000000000000000..3a2ae3dd2cfc92db04bc7dadd57814aa090c3ba6 GIT binary patch literal 4022 zcmXw6cU%*}){PCMgCJc|P>LWO=|(yzRf-hpgb*O1B=ja#kt#euYD7dtn)Kd9dMJ?& z0gMnjhS2Lvc;ENO?#`Zj=FZtWv%fhLt*@&=L&;7F003yTG*w>$09OZz?fW;$h<9$2 zR0HCJ!d=r04glPFOS-NkEa5>!kQ||x!IT*b}Z&l3W6LI8^C2IPn+?Ir37vL#XPAs|o? zKwf*7G7MGV~>5k9t_Ab_R&1&K~|nH&PQceN!_Jpr|CRS87+CJBCJ>j{Ivz<@T6 zWuk1N+ROf4p7tQX-bMKO|I<|5pimGD0oWf%Z6#u4B$^Qf;R*tL+ZyE~Dhkz7RWkC; z+MEk<<-qy1;kW1T1x!BU`uCVeKgmt4c3f?@vu{`Crf~E>%43hcvQ^P8nn?Q@YSYht zkFpWSnfHuJ>X~RS*);1lAv8?{{}GQ<)U)g#xg&+03gYgK{AyvMYL;A!V~MZ3e>kd* zq;vb7V1rjQwIo4W@CS-q3!kv~t)-K@N-OnmhnkICXKEOfZ{ClfS1#t4JZk^jycJG= z`EKp>-XSBB)UM&BAY>Raa+-l*$VoaR&xk&XHO{T!Qe6-@EJbWdbOY)Z$Re>+QkAA3~7a@W<3ii#>i zIai(xwU+ewa%?-povX`{k&yv&DLVGHwxQ0|&r3{P8s?+G88H&fM-VE4A(e}54k}(I zI$O-Y!5g;wf{LWemC7o0it6Lze(qbo=c8O_S7&P0#lIERQ@|vs#^C`to1ro;LakZq zjb}2P>IO_k#+LiDuBOAT#x{RPsiXWVVJE+TD{Six+MjOm4k=DY2V1-5HQXb8a5;3c z#*#%cMBv|SiAC+{oAQ)QOij|lU}78#?ZWlJjIX)hALZ&hb!GBO7c1}_^zJ6Tk#%xr z4%Yu@_iOsw-OB>I23d)&fHDPBD3?6zVMxzAjGJ2E(WfQ&T#ljS~hp`%dT{O1lcn?x_e~Ina zwxda4DGyoM*2GbJ06H)bo^wz(Bw^pKTR3`|qE0YwYWY{22oog(?b~Qo?ubs?R!-ZZ zG$+Y%|Fr(4hf45&SyGup{wiUPgs;h<^JSGgOu*{HLq|e!rL29qPnzoB<>a_9P-lgA zEQ;cNvz#QKOS113n9c|*!Si1(?r+X`q5EzePzVc}9qdpSU6r1bTT%(|PCBe$r1trF zuSNOYQ&6?Zr0cH0m#BdS<_efnW75E)qCIW?sq(>s_ko#bP$-nq>_1QK@%0YO;qv@T zntO8|Wi+<7x7IkBOmrT-CXvDNr4Gk|XfAiJT8Aa`W-P|KdpKj_$IH=v-`+Yh6!;(XkIa;t`ysyV+*dt%`Fx+k%v|)d|W?d(!fI!Q0u?+S0p^VYnYwY1)Lzd^Uefmcu6-J7bfO zCd_js!cW#C48w7v}BG`7SD-?kj%=>YSHNybhYGy`qyxE-`5} zUilxMv9yOpUwV#2RvloKjG-Ie;%`?Si{V}~?iJHCDy#_ncAPOsar41UjOwm z+x-`EZ)W#+ZJ#*adfdFVUNVF_DQ!-V^oJGYL)dfmd&;1+!uLx&EK(*~eNt+$ue1{0 z>Q~V(3QB7tv$1RPuU6BGhvBD>%B(3k;Y(zzSd>_qbz#WqXqV_>jP&7gtMTE+WY6dt0+-U1mt1@bxN;QgLKpEpb5*s&tQS`sn_% zXYZ#j^ODP^;fkf9f7t1_MF%TJh&YTMdM-pBfEdV4wyCRrOqR79R*fFE$Mx2U*zDd3 zm4=e-XR>xtr$IRy6Fsa$5;=J$YX+AvoM7HJXV+lO12TmKGG4MNMhcvayx!OT2hwYb zTLp)mylRw;;GR7z?`a8%zrjubGBB#~%vVC`ym{dYglqub3+jBaVSu}0>cp$_rW+VZ&GCogGO zWcypt4tft*KM0Zb1&;~#ehDLEHDhB*9g7P7i9Utj0g>+8x2+_ksyc*#m;*rd;#@2u z)lY9^*oaTC`NYkeuw}p5B;S;oXKmq%?JJWMpP$nioIB^bC>;SdWlsOQ7I^k*qJHQ1 zwbOkYd6oIO!3BKVu_62W@43$G-#>ev9&G-O;<8zpeoP#rv?+*cuMWLs%@1NSRuL3B zoFPLxvkn>3>Cek_&@-8*0SpMYq5BQ2U?3l{%{5Sk8QUKHXbZGE> zB@Bf^GlcU5m>+?jg_omm#II34_fPEb>n!UXOIRx3WRTf#RHW+4-)jg~EaiCZlizD& zm!US9ccN5frae;0bs+*c3DCSf$85b~CZr`3^d>o)LEI7`myTO}cdJ-B_(QPtKlH&D z_G6DXN;e&96nVSQ8ms&J0v|ud1s&`+T~9BV<7viUpILvN?AJ6UtJBcE{@`xN2%B4) z?)QbNWMEKRujIN0n~+?WV0zeQj!S{aF`BK;!R~b!j+U7%Q&bEuYVV(J)|YIH>-x8%&?C#W5E$7rKMJwN`Wy^Lh5GBovREf0P^Sl40L! z#4i;P#5^&yhxo+r(IB7Qo$mtORahr5 zQr`ehb2_8`t;;I7x7VvP`*Qr5sk<~^%{fw95J-K-k)!>)K{gP#)RM;4w zr16x-l@%?w0l6$-NAKtOme#jFSJ>W1FQ~Qk?O6SDW%hVfN>lOH_Gf8Xid6%WJ~JGy zv>kNv*Ag+UThek-g7%;1xc771K~HaX zk4mImSZdHPwG!}CIniIVWg{v0M>tP3?J;uWZ@q?3HM3}?X~rV{xg;~#LSN?9vIbMIcFk){I-{ou8-qYIAkr>oL zfLOJ%c86>&2WviG7vF&RC*62Sj($TMsSsUYaWlPf)PZs<0Ku(C`N<(EWcwS?`(b+L zYZ#EU-xZe?`ZXY>405EjnnAfhw30KTkK$?fveuK0((MdfTP1J(i_GwpIF3qGKhbyGiDD4& zB3Y`Mss(BWWXQQJ91b5qp(;+2f%t=?&CXVb?)W?BOs+ANVAmYKj5x0J*v&CEQ?-5H zdN_Q2{PF(ju~-PwWN5JAqAuFN{M2ltmX7bJSA*BSHGMH3$|&l_6khE4rk&;2dcmXx zj0=#IB|*3)O0u|iXz_XR)w^C?3ge;8@k`7_)ytobG7~ob@Nwy){j6hiRQcSrb;Y(( zU+`sVUj?jcWp*`j8S)MFD-M*`)@Q#OHjXuone1O${z=YVFk%C|(UIA{gtaBr{z-;a=+%%ZklFqa>|f*2i9V(YBQEq=(hh3ciy^pY13z2;zDgpObBVt z)oT}R-Hr_m|6sn-SN&g1q;mEMPbx;34&CXrqu% zfu$hZidTAp*`>61CE8(*B=Wn*HbrUXu3t=o9WDAKNWJgZyt7$2m~X^@h-V0*-R5WF zz7X?~qDmM5g#Kvq*~)#mxHg->vKFAGT#^}N97abX$dWG-!t2jBl`aG0qH2}gp= zW?O+5Boo@_|;Er~CAvKbp27^fsMD~}l&si_&%YB)~I1FN0mo>%{wr)P^+eW%J@ zRa=Y3V049;d6;94h^9SsHzP#d;(s-jx6(H)H2NVFb9ChA2nMHTXLnTy3H9%|c@n~K zCVdPwSKVgYr&QW{g#wgz;_t{$mfMpPO}DQ?i`}r$65FL2&-}=8`u+R+uMnb}w<~8I zbH1&Ez8R?;oZjJ0k;>tRrL$5{%`^Bs!e4G0>n;=f6{0iLe{sbD!^$s_$?8Wuo&vPg LbX7~0ZNmNwmM6a| literal 0 HcmV?d00001 diff --git a/Media/save.png b/Media/save.png new file mode 100644 index 0000000000000000000000000000000000000000..38bd3e32fcb32381f19b7d95839b5b2f0ebd7031 GIT binary patch literal 5979 zcmXw7bzGC*_a8`%?gpgIS{tp1aibh|X0P)b@>Zjff=pO>8 znz1_o!14j}!TPvyWQzvzVd~l{_-k174<0_T@Qo?_2dNmrKprrA7dJpj<$xL*B8H(M zWm|V^HwP%p!36@KB4Fb{|5%HwSOk0_t4N#cRCKn|i&B2=9v2f^#e*LYvBXqe3>YkMdC=KW{n z&QX=9jWem(?MjHye_5NKG(A&gWVJ$%(XnE7t>#-kPoVCLPPydx2T7Ng zs~OQwdpYqsyZ)`-?cY-7L;KVS;h;{zHDD~)FCj|Gg(+e$paVWuAy9d0yqmDjot%_| z4yCC6{p2Y#LT%6|!LaQQ$$n>8ig}3xpHzyxq*YL%`>ofb@0A*Z(MD(zNu)$$4r<(N z4Ch?E%Z(&0h4B}bWm8P}CXOnS{BCR( zT)i&i*#2clW1)>8H%J`2Q3prSB2+;FG;H}j_4mco@0AYg)B@U6{|ITG1TN+aDUt){ ztq=^FWi%_zJ^#Io!BLeQBdXn?jXvYbV-XW_O-5ReO9_{64AAY)_A=w=WEJG%37n~{ z+(??@rB;$^DuP7}OvxkMZ&q;3acj?EF2B{>#nVJn%3cm#Mgl%rT}&|TKg7*C9@+gV zop{cS{Iv;n#yi;7cRe*>_eM&%7Pv08#5DzW2ne|4^aRhG&x8~G@_KcO@pG_GnSCsL zM*>WaES&%SIkWOh{B%xfzHKC_rSY+E#d(ozUOh+xB$4$nCiO-x+K4cNgIK6-q|@`o z3=N*uyIyKj(#rC9-Z(sgMh4vW6x;a^?YZt~(w>V#G5t*q zkY;2m*`EIM;NMw9^SDl%2j71&yt-r1xa41x9vl+-^bxr50PYosClwn5Q>@n0zw4(2 zbR$!v&sdq%j{bXT`Mp=P^&`?7E5tpfVbaY@Mu;#SnLErz9c7eI!yY$b;wa>P>HHCa zk`_010^x#+Jw^Gi6>>6eUuSNebo3KBy-)1_F(6d7L7cbDY8P*{tr&G{nz_vYYvGwQ zbQg4I&JmTWeO)oID*UJUU6Kr*%<_hmxac%_Bz)1x_&m1B1LZ-|GS2K}Bx$-CqxpS< zc6NEX`>rW*pjP{G1))Vf88eB+IDbZ8U*Mf;ez6m_{kOu|JGmAP!|B(756Dki73 z^(3SU;!l@6d?4cKpT)1Itt_JzezPSo{?p6bfa-~-82*9Z%P9+IZMT&l>L!m|EbqMo zfd+3wYmNi!57{#nLMXm3=FOwSh$Gq>|zKnu?zrvPIksI{%MGy z8(C7W=lJ%ksBe@sE}tc9)z;9>k%RfUWZWiY6bY4K_SZG$G@+S$-1)~!K2&XkPvT@8 z<}Rhcf^lqV**~0$vR~Dd<)>p+FR~YHrm;a>t|tO?y`bUG{v*!)uYXAItev*Jo!0v@ zY}!aPP1$a({yC(`)Q{ijqs03rvS}#i+l*-R#DV%w4KW?O+0z_kv}uJHGE~Mwbz3FEs@B$ICl$nTc#f&YfcPVn}$c)TalTD`4&OKLb_)8o92aRlzUE__-tBe_8rlT zN#ZigO2>;Wz1dn1@wyIA0iWjre6E_h^OVF)s(Gi4iWKR(N;m_YBZtueKaXg#sva!A2@qw+j8 zqzEI%<{87SOOgdfS3J@?iA9xlK1tY=Gv7-(Tb?O5FMhLhzRHbRJ#goKR#oz&EsX&S zr3XTi>MZCLU{Wn@#^K1Q#ZL75!T1fVF~?_b3cI(-_joj5p9HfA-kzHvlb%Hnx-K{i zE#UPU($1$zzIb-1TR3~WUcX3rU~gvu3$DaV1cK)MHisBB#~wHVi<)b#&TOMnD^+Hu zk+d%?UvUuU8V_`ZI02O$O^FOLef*+$4=yY3DXWXGIfmtAl5GkH#do85i`qKAUwN0e zd%yZ=^uRMe*bY5w&*<^Z5EUxqu z(v1>&q|9v{XY)g0VcQuobpd7m`y;Ok8mffHLPweJN)^X=X>cggLw z`!}?^iKoH+>(B1`Afo$*r;78L5uQ%JiP`BDpM8_OO}y-$O$o{?e7656^TQ^iN!1{& zhmx0eU!-W&npPkGSZ6w}Km0?NRA0B)33AK_Ib9PCe<>5R8&j1dX*dC09BqP2(ZVj< z558Vc_rrJW%yka5&0wi@b?LWzdS7M5v*ox@wR8FT6UBu&D6Uj_Uw*LX*2hC)S=4d1 z*VKqcRBqg+bQ}|R+{or!dt0PPcBg$7uO!Dz)@j?IrV!Tb3UN>9_M&-DGEp?ix0mi$ z!bDaivwnhK@7@8A_-npjTd&IPwfWy#9}k2s9?4wKZRI-(quO2wcq23G`Wa#c*_Swh zU-Fx|n^n0P=0>}(xuaq7#gN7|Y3zBw0xQ}#g)?sC0%tAAebgwMp1L^9#++V+%CLk9 zXWlPl?a=U`RdHByrmcYE@`X}tAEM_#`cErxp}%}Mg?r6~3~r_>;mzveG_?}ZKe#S% zE!vt(>^)3iOlNjqBk|cM(eawPrzp!E-j1i);%nv3oU2w7K%tc7+?3Bq^2MajbN`*8 zdln*-+-hS;W^B5fqCr?>jHmy!Lp%g;-}nY$#`pK`yX&xbn3asXa)=_n40kPBwc&9AobRVHDHBpsXs z?Gsv>DrC0(ik0c7^hgE@LQC8ydw?eBb%I~9w%Oz8taDBBl&~?}W);3rrWN8nnoljc zq4U|c-X&$2wo^L-)93+lDI}6ulO7AJ)gWvB@}c;4y5T7W%)M>e>gX=-Cw2#dyrvk! zx3xIk-kaD9Z*!2|_}U`SYZc=&YMoeChlx$ecKA{9xS1WnE z`opztE%EVFQwX}RMQ}EUb+dc_k^3U>sXEvwMdfKSd%BjeghcNaWaAg15w>4Mnpg{05 z;+{mWl8cHC9}*#u*A;0BZo$FzxX=N-1RFz*J&EY&kttCV%g;ZK8R3xGU=)*}8aJr6WCkzYnnEIzhf%|%kxjI*3`c%`q zAj3Qh9=fE;J%;nd%009r%1GtStLrA?tKe-5o*G~c?}-4 z(UNQv6Ux2DsWP2L@sv+gn}eR%Dub&;KgvR=*-b!ovD%u(?z^WHuH$|$Fo*%VG{TJq z0rBv+Y~oNkcHIUfyygo$FK+2E(a`4|r&HY;y zdy`@eA+6vIiL6NFU>o7|qhmwq$A>KMGU~R6pvH2o#iyA0)Lxtuwrk$3&PlnAjC06% z{h0b)Xrd{P-jhT7XOC&oj}MbJ7dsU+AJ*Zmp21{{;rF5Wh3QD41F|qUZ7ZPvE%@mh zo*C0$iyiIh9$g#!*A<_4%W#C_)n?kBrW$PSxdMMhV_w)ZNEeg}hy(o46ROA-e1FOR z+;tn*^JX{u=0>&Z&#_izYx9=GvQirT{c*lwM1^U;;7oUrU_iXQ)00=dIv%eTDWZFw zbk*J;H(N7y|HK?ZX#zX?KR^6Ui1w(2HFL!C*1Is$>xmw#Rvt_wPh((J1tNq zk%HY!Pl?1*5s$u0TKxXbP?F|G@9g;rPf%k20eE6JZ^;f{3>6>{|u0rE| z%8eHJ+0Jm1cRQOcj?uI2%_@`Hw{Q8e_BAktLI>-@bo^a&xtwW<+*e%*U#n+FjQN6X znckIu=Wy&ZvLCIWhTf3MpFbBclkQfXqSFhmV>Z90c<-9AQzcaz#J$&d8_`vB_jiBuWsz%(HeyA1gWqN= zBObiTS*P)aJGG{;Xu+o+$U>(n4G7=1m2O-1yi-8WyV7v-L%$16-|JP|8IQFWC`4ww zyPVT<3U80`)!y>~%hOZq{`a?z*%NOcuIrf!9vRhtICwhPgxVb`nprqy;XXS43OyKZ z0W*}cE-;RDP~jkejpOdC^i{saaY&^9&{g7aZ0C8Na=vcfDBX@QZU*3$LN&28O@(>!UG z?fTAj^Sz=RG&z2&L+KFwQs>ag`2MJ0vL1z>bzkQ*Q+q*4_zNSM=#y0aZOf^utGSAWjnKBsT< z;K=f`l9?ZlgGpUxb7HB-Z+_0`QdiHxw|8Did^ue2>XK3Xi8&Z4;Oz7Wx3*7 zOk(4YXhL&N%T4dGkM_x}8&WFL?9>3Us*zM=!r0)P`fX}sF zo{^ooU0mPB$S&?t)_QxQ!cfCxZZwDm3bb;85Q=3&IEr|9cnsC1Z=F4*oA7+d9EhrT z>Wo8r*|^-8xKu=T97Q!_FmWi;6>W-~-QV|GM0%8`0=$gbAv~aBJbzfI{1V+NWoOq% z;r}wZm&*^tuWtHPFFJ_+L=IE?1Rk6y=U1{ere67RN1)uRj<)KXhFi9{^OSR|?^CD0 zr~KQucj|8`wqEV8fRCl;-ctJq@>};A`bGNu?G?xA`ha;qvX1ueuANch#PB&|BXLf& z`t>^S>paK^QUFHRlL$)ubIrg~kkEplcxj>c>j!oxbrMIMMQDL6OgMPA0a0TVzf3obp=GU5;a+~~ z-SOJ;0ji-L7-Nr+8YgACY%)Y4*{ERLA>oG&*LM;d?21YDnB;IwU1ozIgor~FSQUim z%{~>GD0hD>bRhc1Mo&yh7$&4mH7=?mYCw;!kvt*`ho8lXIo95pG`xG=Csa!NzJVaD z^?51xmpigB#n2v0MFe@crOh{GBL+;F(bBb|K$rV4#lV9o0=$rd@tqj93WJcH%3M>? z$-HlQCVOuo|JzSIK~Iu&it#5Qsk$JPyJZGfkOJ#*by_pRfD{u~FDYJs8~KuzoHbbk zUf5IYd2__{n3A2E_usa{mQiSHMR_->)1sVb64t|ycQ{XElEXYcJWHtdolz&a19-E15xSmm7{L&Kd>0 zTyfEA>VKao{x?EXd*7!Z+pFZTsLx@?h=&d!{|Fxcz5mf_{Ap){?o0nY&iunG&VxO} h;&pVS?x>@CmM*5Ijn`%MXbl;luJTg3Qqdy#{{XPPPb~ld literal 0 HcmV?d00001 diff --git a/instructions.md b/instructions.md index 88e12b9..a87a3af 100644 --- a/instructions.md +++ b/instructions.md @@ -599,8 +599,6 @@ To prepare the **Information Protection** lab, we have to enable the integration --- - - === # Complete Azure Security Center Deployment [:arrow_left: Home](#lab-environment-configuration) @@ -609,12 +607,9 @@ Now that the template has been deployed, we can continue with the configuration ## Configure the data collection settings in ASC -Now that the workspace has been deployed (you don't have to wait for all the resources to be deployed), do the following: +1. [] On @lab.VirtualMachine(Client01).SelectLink, open a new InPrivate window and navigate to ```https://portal.azure.com/#blade/Microsoft_Azure_Security```. -1. [] Navigate to the **Security Center** blade. - - ^IMAGE[Open Screenshot](\Media\SC.png) -2. [] In the Security Center - Getting started blade, scroll to the bottom of the window and click on **Start Trial**. +2. [] In the Security Center - Getting started blade, scroll to the bottom of the main window and click on **Start Trial**. ^IMAGE[Open Screenshot](\Media\StartTrial.png) 3. [] In the next pane, click on **Install agents**. @@ -624,29 +619,34 @@ Now that the workspace has been deployed (you don't have to wait for all the res !IMAGE[SecPol](\Media\SecPol.png) 1. [] On the line where it lists your **workspace**, click on **Edit settings**. -10. [] In the left pane, click on **Pricing tier**, select **Standard** and click on **Save**. + + !Image[settings](\Media\asc-edit1.png) +10. [] In the left pane, under Policy components, click on **Pricing tier**. +1. [] Select **Standard** and click on **Save**. ^IMAGE[Open Screenshot](\Media\Pricing.png) 13. [] Click on Data collection and select **All Events** and click on **Save**. ^IMAGE[Open Screenshot](\Media\DC.png) -10. [] Switch back to **Security Policy** and click **OK** to dismiss the message **Your unsaved edits will be discarded**. +10. [] At the top, click on **Security Center - Security Policy** and click **OK** to dismiss the message **Your unsaved edits will be discarded**. !IMAGE[SecPol](\Media\SC2.png) -6. [] On the line where it lists your Azure subscription (Azure pass), click on **Edit settings**. +6. [] On the line where it lists **Azure Pass - Sponsorship**, click on **Edit settings**. ^IMAGE[Open Screenshot](\Media\EditSettings.png) 7. [] Verify that **Auto Provisioning** is set to **On**. -8. [] Under Workspace configuration, select **Use another workspace** and select your workspace **ASC-Workspace-xxxx** (which has been created by the template). +8. [] Under Workspace configuration, select the option button for **Use another workspace**, and select your workspace **ASC-Workspace-xxxx** (which has been created by the template). ^IMAGE[Open Screenshot](\Media\Workspace.png) 1. [] Under Windoews secuity events, select **All events**. 9. [] Click on **Save** at the top of the page. 9. [] Click on **Yes** on **Would you like to reconfigure monitored VMs?**. 10. [] Click on **Pricing tier** on the left and click **OK** to ignore the dialog. -11. [] Under Settings - Pricing tier, click **Standard** and click **Save**. +11. [] Under Settings - Pricing tier, verify that it is set to **Standard**. If not, select **Standard** and click **Save**. ->[!HINT] It can take some time for the VMs to become visible in Security Center +>[!HINT] It can take some time for the resources (VMs) to become visible in Security Center. + +--- === # Azure Advanced Threat Protection Setup @@ -675,26 +675,30 @@ Now that the workspace has been deployed (you don't have to wait for all the res --- ## Deploy the Azure ATP Sensor -1. [] Click the **Download Sensor Setup** link. +1. [] Scroll up and click the **Download Sensor Setup** link. 1. [] Click **Download** to download the Sensor installer package. 1. [] Copy the **Access key**, this will be needed during the installation of the Sensor. 1. [] Extract the installation files from the Zip file and run **Azure ATP sensor setup.exe**. >[!NOTE] Do not run the installer from within the Zip file, you need to extract the files before running the installer. -1. Click **Run** in the Open File Security Warning page. -1. Select the installation language of choice and click **Next**. -1. Click **Next** on the Sensor deployment type page. -1. **Paste the Access key** copied from above and click **Install**. +1. [] Click **Run** in the Open File Security Warning page. +1. [] Select the installation language of choice and click **Next**. +1. [] Click **Next** on the Sensor deployment type page. +1. [] **Paste the Access key** copied from above and click **Install**. +1. [] Click **Finish** to complete the installation. +--- ## Configure Domain Synchronizer -1. In the Azure ATP console **click on the deployed Sensor** and **toggle the Domain synchronizer candidate switch** to **On** and click **Save**. +1. [] In the Azure ATP console **click on the deployed Sensor (ContosoDC)** and **toggle the Domain synchronizer candidate switch** to **On** and click **Save**. ## Configure Windows Defender ATP Integration -1. In the Azure ATP console click **Windows Dender ATP** and then toggle the **Integration with Widnows Defender ATP** to **On** and click **Save** +1. [] In the Azure ATP console click **Windows Dender ATP** and then toggle the **Integration with Widnows Defender ATP** to **On** and click **Save** >[!NOTE] This requires that you have already enabled the Windows Defender ATP service. +--- + === ## Adding Guest User access to Azure ATP Console. [:arrow_left: Home](#lab-environment-configuration) @@ -712,7 +716,7 @@ To allow users not in the companies Azure Active Directory to access the Azure A 4. [] Click **Users**. 5. [] Click **New guest user**. 6. [] Enter email address for guest user such as ```@lab.User.Email``` and click **Invite**. -7. [] Close the Users blade by clicking the **X** in the right-hand side. +7. [] At the top of the window, click on the **Contoso** link or browse to ```https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade```. 8. [] Click **Groups**. 9. [] Click **Azure ATP {workspace name} Administrators group** (the first Azure ATP Group). 10. [] Click **Members**. @@ -720,6 +724,14 @@ To allow users not in the companies Azure Active Directory to access the Azure A 12. [] Select the **guest user added above** and click **Select**. > [!NOTE] After the user accepts the invitation the user will be able to access the Azure ATP console for this workspace using their email account. +--- + +=== +# Lab Environment Setup Complete + +The lab environment setup is now complete. The next section will cover Azure Information Protection (Roadmap discussion then Hands On Lab). If you decide to close out of the Lab during the roadmap discussion, please ensure that you **Save** the lab using the menu in the upper right corner of the browser. + +!IMAGE[Save](\Media\save.png) === # Azure Information Protection Lab