Onboarding Guide
- 1 Interactive Onboarding Demo
- 2 Join Our Weekly Consultant Lead Onboarding Sessions
- 3 V4 Agent Prerequisites
- 4 Accessing ConnectSecure V4
- 5 Setup Users and Security
- 6 Configure Global Settings
- 7 Configure Global Scheduler
- 7.1 Scan Scheduler
- 7.2 Patch Scheduler
- 7.3 Report Scheduler
- 8 Company Management
- 9 Agent Deployment
- 10 Review Scan Results
- 11 Review Dashboard and Reporting
- 12 Need Onboarding Help?
- 13 Need Support?
Interactive Onboarding Demo
Click on the image below to use the interactive demo at your pace.
Join Our Weekly Consultant Lead Onboarding Sessions
Join one of the ConnectSecure Consultants for a live walk-through of the steps for onboarding.
http://www.connectsecure.com/onboarding
V4 Agent Prerequisites
We have a dedicated page with the V4 agent prerequisites for a smooth-running ConnectSecure agent and portal. This includes the dependencies, domains, IPs, ports, and more.
Agent Dependency and Whitelisting
Accessing ConnectSecure V4
The ConnectSecure portal login can be accessed here: https://portal.myconnectsecure.com/sign-in
If you know your tenant's name, you can use the direct link here, but please replace the CHANGEME with your tenant’s name.
https://portal.myconnectsecure.com/sign-in?tenant_name=CHANGEME
If you have an account created but are having trouble logging in, please check out our user password and MFA reset guide; tap the link below.
Setup Users and Security
Configure Global Settings
Global Settings apply to all companies in your portal and auto-apply to any new ones created.
Reviewing each one is important to become familiar with what's available and set by default.
See the complete Global Settings documentation here: https://cybercns.atlassian.net/wiki/x/uICUgQ
Configure Global Scheduler
The Global Scheduler is where you can configure automatic jobs for Scans, Patching, and Reporting. Remember, you can also configure the Company Scheduler for company-level jobs if you do not want it globally.
Navigate to Global > Settings > Scheduler to add, edit, and delete the settings.
Scan Scheduler
Refer to our KB for additional information and setup help if needed: Scheduler (Global) | Scan Scheduler
Below is a sample scan recommendation.
Scan Scheduler Examples | ||||
Scan Job Name | Scan Type | Frequency | Target Time | Agent Type |
Daily Full Scan - All Companies (Includes Active Directory, Compliance, Firewall, and Network Scans) | Full Scan | Once Per Day | During business hours, we want assets to be online for scanning | Probe |
Daily ASM Scan - All Companies | Attack Surface Mapper | Once Per Day | After hours, any time | Non-Agent Scan |
Daily External Scan - All Companies | External Scan | Once Per Day | After hours, any time | Non-Agent Scan |
Weekly Compliance Scan - All Companies (Only needed if you are not using the Probe - Full Scan option) | Compliance | Once Per Week | During business hours, we want assets to be online for scanning | Lightweight or Probe Agent |
NOTE: The lightweight scan is unavailable in the scheduler. It can be configured under the Settings tab for both Global and company-level options.
See: Global Settings | Scan Time Interval/ Company Settings | Scan Time Interval
Patch Scheduler
This is where you configure automatic patching for Applications (third-party) and Operating Systems (OS). You can use one or both of the patching types. If you plan to use both Application and OS patching, you will build at least one schedule for each.
Refer to our KB for additional information and setup help: Scheduler (Global) | Patch Scheduler
You may consider not configuring Patch Scheduler globally but on a per-company basis. The Company vs Global Scheduler can be used to balance these requirements.
Patch Status must be enabled at the Global or Company Settings to use patching.
See Global Settings | Patching Statusor Company Settings | Patching Status
Check out our Patch Management Guide: Patch Management Guide
Watch on YouTube: https://youtu.be/hZ-yjR08lWI
Report Scheduler
Refer to our KB for additional information and setup help: Scheduler (Global) | Report Scheduler
Report Schedule Examples | ||
Report Schedule Name | Report Type | Frequency |
Monthly Assessment Report - All Companies | Monthly | |
Monthly External Scan Vulnerability Detailed | Word | Monthly |
Monthly Compliance Report | Word | Monthly |
Company Management
Companies can be created manually in the portal (Local) or imported from one of the support PSA Integrations using the import options. This does require an integration setup. It’s easier to create the local company first and then map the company to an integration later.
Add Local Company
Refer to our KB for additional information and setup help: https://cybercns.atlassian.net/wiki/x/DQB0gQ
Configure Company Settings
NOTE: Setting a value in the Company Settings will override the Global Settings. When adding a new Company to the ConnectSecure portal, it is recommended to confirm the Company Settings for any needed overrides or changes based on what is inherited from the Global Settings.
Refer to our KB for additional information and setup help: https://cybercns.atlassian.net/wiki/x/74qfgQ
Configure Company Discovery
The Discovery section stores the company's Discovery Settings and Credentials. These settings are necessary to create a probe agent and are used by the agent to determine which network(s) or IP addresses it will scan. Additionally, the agent may use these credentials to access the network and obtain additional information.
Refer to our KB for additional information and setup help: https://cybercns.atlassian.net/wiki/spaces/CVB/pages/2102919235/Company+Agents#Discovery
Configure Company External Asset(s)
You must set up the company-level External Assets > Configurations so ConnectSecure agent(s) know what and where to scan externally.
We recommend adding your client's public domain/website (IE: xyz.com) and any public-facing IP addressing (Static IP or Range).
Refer to our KB for additional information and setup help: https://cybercns.atlassian.net/wiki/spaces/CVB/pages/2072282057
Configure Company Scheduler
Review and update Company Scheduler options. If you have configured the Global Scheduler, you will see those options in the Company Scheduler window, as shown below. You may consider not setting a company-level schedule if you have it covered by the global.
NOTE: You can view any inherited Global options within the company scheduler under ‘Is Global’
Agent Deployment
Select a company
Navigate to Overview > Agents
Tap on the download Agent icon
Refer to our KB for additional information and setup help: https://cybercns.atlassian.net/wiki/x/y4BffQ
To use the Probe Agent, you must map the Discovery Settings and Credentials section; tap below for the guide on converting a lightweight agent to a probe.
Review Scan Results
Now that we have configured all our settings and deployed agents, data should flow into our Assets, Vulnerabilities, Compliance, Active Directory, and PII modules where applicable.
External Endpoint Name Example | Example |
---|---|
Public Domain / Website | IE: xyz.com (domain) |
Static IP / Public IP | IE: 66.54.58.100 (static) |
IP Range (Public Block) | IE: 66.54.58.100-66.54.58.105 (range) |
Refer to our Active Directory Least Privelages KB if you are not using domain admin credentials:
https://cybercns.atlassian.net/wiki/x/AYC_gQ
Refer to the Azure Integration Guides here: https://cybercns.atlassian.net/wiki/x/HoHXfQ
This integration will also populate the Microsoft Secure Score data.
Review Dashboard and Reporting
Now that you have collected data from the various scans use the dashboard and reporting to get the information into the hands of the people who matter.
We have prebuilt Standard Reports and a customizable Report Builder.
Any report can be scheduled for automatic delivery to your email inbox or through various integration points using the Report Scheduler.
You can also use the in-app Company Dashboard and/or Global Dashboard to see your data in different views with additional filtering and sorting options in our dashboards.
Need Onboarding Help?
We have an onboarding team dedicated to your success. Please use the link below to schedule a time that works for you. We will be happy to assist in your onboarding and answer any questions you have to get your implementation up and running smoothly.
Group bookings (held multiple times a week)
https://connectsecure.com/onboarding
Need Support?
Contact our support team by sending an email to support@connectsecure.com or by visiting our Partner Portal, where you can create, view, and manage your tickets.
https://cybercns.freshdesk.com/en/support/login
Add label