For the complete documentation index, see llms.txt. This page is also available as Markdown.

DISCOVER 3-hour training

Overview

This training module is designed to give users a practical introduction to DISCOVER.

It covers:

  • Product architecture, scanning models, and key components

  • Microsoft 365 integration, target discovery, and Scanning Server setup

  • Data governance, data types, classifications, and scan configuration

  • Results review, investigation, remediation, and positioning with PROTECT and INSIGHT

Duration

  • Session 1 - 50 minutes

  • Break - 10 minutes

  • Session 2 - 50 minutes

  • Break - 10 minutes

  • Session 3 - 50 minutes

Session 1 - 50 minutes

Topics covered

  • DISCOVER overview

  • How to integrate with Microsoft 365

  • How to set up a scanning server

  • How to perform local and remote scans

  • What a secure move location is

  • How to set up classifications

  • What data types and sub data types are available in the system

  • How to define new data types

    • How to define complex regular expressions

    • How to combine regex with other conditions

  • How to discover what to scan (targets)

1. Product overview and architecture - 5 minutes

Cover the product at a high level first.

Cover

  • What DISCOVER is

  • Where it fits in the data security workflow

  • How data moves from detection to action

  • The workflow: Data typesScanResultsRemediation

  • The main components:

    • Management Console

    • Scanning Server

    • Target devices and services

  • The two scanning models:

    • Local scan

      • Agent installed on the target device

      • The device scans itself

    • Agentless scan

      • Agent installed on a Scanning Server

      • Scans remote systems over:

        • WinRM

        • SSH

        • SMB

2. Server installation - 10 minutes (Optional)

Run a live installation walkthrough.

Cover

  • What the installation includes

  • The minimum prerequisites for setup

  • What trainees should expect after first sign-in

Demonstrate

  • GuardWare Server installation

  • Initial setup

  • First access to the Management Console

Trainer focus

  • Show the minimum steps required to get to a usable console

  • Point out any prerequisites that commonly block setup

3. Management Console introduction - 5 minutes

Show the main navigation areas.

Cover

  • Organisation settings

    • Setting up a secure location

    • Setting an investigation password

    • Integrating with Microsoft 365

  • Devices

  • Data Governance

  • Resources

Demonstrate

  • Moving through the main Console areas

  • Locating the settings used later in the session

4. Getting started - Agent/Scanning Server configuration - 10 minutes

Walk through agent preparation for scanning.

Cover

  • How local and agentless scanning differ

Demonstrate

  • Agent configuration

  • Agent download

  • Agent installation

  • For local scan, install the downloaded agent on a target device

  • For agentless/remote scan, install the downloaded agent on a Windows host. The Windows host becomes the Scanning Server and scans multiple remote systems across the network

  • Complete the setup wizard

  • Confirm the Scanning Server appears as Online in the Console

Trainer focus

  • Call out exception list for DISCOVER folders and executables

  • Show where to review agent status, assigned targets, and request logs

Key points

  • A local scan runs on the target device itself

  • An agentless scan uses a Scanning Server to scan remote systems across the network

5. Data governance - 20 minutes

Show how governance settings define what DISCOVER detects, classifies, and escalates.

Cover

  • Built-in data types first

    • Credit cards

    • Passport numbers

    • PII

    • Financial information

  • Custom data types using:

    • Sensitive Words

    • Regular Expressions

    • Filename Expressions

  • Example inputs:

    • Sensitive words: Confidential, Salary, Acquisition

    • Regular expressions: employee IDs, customer numbers, passport formats

    • Filename expressions: Confidential_*.pdf, Payroll_*.xlsx

  • Subtypes and their value:

    • Better categorisation

    • Reduced false positives

  • Manual classifications such as:

    • Public

    • Internal

    • Confidential

    • Restricted

  • Purview synchronisation

  • Data owners and how they are used:

    • Data owners are assigned to data types

    • They are not necessarily device owners

    • They receive notifications when sensitive data is discovered

  • Example:

    • An HR manager receives an alert when employee-sensitive data is found outside approved locations

Demonstrate

  • Reviewing built-in data types

  • Creating a custom data type with Sensitive Words

  • Creating a custom data type with Regular Expressions

    • Define complex regular expressions

    • Combine regex with other conditions

  • Creating a custom data type with Filename Expressions

  • Creating a manual classification

  • Showing where Purview-synchronised classifications appear

  • Assigning a data owner to a data type

Trainer focus

  • Emphasise how better data type design improves scan quality

  • Show how subtypes help reduce false positives

  • Show how notifications reach the right business owner

Key points

  • Existing Microsoft classifications can be synchronised into DISCOVER

6. Target discovery - 10 minutes

Show both discovery paths.

Cover

  • Device discovery for remote systems

  • Service discovery for cloud platforms

  • The prerequisites that make discovery succeed

Demonstrate

  • Device discovery over WinRM

  • Device discovery over SSH

  • SMB file server discovery

  • SharePoint Online discovery

  • Exchange Online discovery

  • Gmail discovery

  • Google Drive discovery

Trainer focus

  • Spend extra time on WinRM and SSH setup

  • Call out the firewall, routing, and credential issues that block discovery most often

  • Explain the minimum host-side setup required before discovery succeeds

Break - 10 minutes

Session 2 - 50 minutes

Topics covered

  • How to configure scans

  • What is a one-time scan

  • What is an ongoing scan

  • Key considerations when conducting scans

  • How to run a classification scan

  • How to use Scan and Classify

  • Key considerations when running classification scans

  • How to review results

  • How to review scan progress and scan status

  • Scan performance considerations

7. Create a scan - 15 minutes

Explain the two scan types, then configure a scan live.

Cover

  • One-Time Scan for:

    • Quick validation

    • Testing

  • Ongoing Scan for:

    • Continuous monitoring

    • Scheduled execution

  • When to use each scan type

Demonstrate

  • Selecting data types

  • Selecting targets

  • Archive scanning

  • OCR Options

  • Changed files only

  • Scheduling

  • Scan and Classify

  • Running the scan

  • Showing scan progress

  • Showing scan status

  • Showing where results appear

Trainer focus

  • Explain when to use Scan and Classify

  • Show how classification is applied as part of the scan workflow

  • Explain why this is important for downstream monitoring and protection

Key points

  • Multiple one-time scans can run

  • Only one ongoing scan can run at a time

8. Scan scope and file handling options - 10 minutes

Show how to control scan coverage.

Cover

  • How to control scan coverage

  • When a narrow scope is better than broad coverage

Demonstrate

  • Scanning only selected folders and file types

  • Scanning all content except excluded folders and file types

  • Archive file handling

  • OCR for images

  • OCR for documents

  • Exchange date filtering

  • Auto-scan newly discovered devices for ongoing scans

Trainer focus

  • Show when a narrow validation scan is better than broad coverage

  • Show how file and folder filters reduce scan time and false positives

9. Scan performance and scheduling considerations - 10 minutes

Explain the operational impact of scan settings.

Cover

  • OCR adds significant overhead for image-heavy PDFs

  • HTML, HTM, and Markdown files can take much longer than expected

  • Many small files can take longer than fewer large files

  • Ongoing scans should run outside business hours where possible

  • Avoid scan windows and termination settings affect scheduled coverage

Trainer focus

  • Use a small OCR comparison example if possible

  • Explain why representative test scans matter before wider rollout

10. Dashboard - 5 minutes

Start here so trainees can review discovered data at a higher level before drilling into individual findings.

Cover

  • Dashboard for aggregated metrics across scans

  • Summary Report for findings from a specific scan job

  • Potential Sensitive Data

  • Potential Data by Target

  • Discovered vs Investigated vs Remediated Data

Demonstrate

  • Dashboard review

  • Summary Report review

  • Scan-level filtering

  • High-level metrics and trend views

11. Results - 10 minutes

Cover

  • How results are grouped across devices, SharePoint, and email

Demonstrate

  • Findings review

  • Device results

  • SharePoint results

  • Email results

Trainer focus

  • Show how to filter by scan, target, data type, and classification

  • Show how to move from high-level trends into file-level findings

  • Explain when to use Results instead of Dashboard

Break - 10 minutes

Session 3 — 50 minutes

Topics covered

  • How to set up investigation prerequisites

  • How to create and use investigations

  • How to delete data

  • How to classify identified data

  • How to copy data to a secure location

  • How to move data

  • How to move SharePoint data to another SharePoint site

  • How to move email to a secure email account

  • How to review remediation history

  • How to review logs and agent activity

12. Investigation - 10 minutes

Show how to inspect sensitive files in a controlled workflow.

Cover

  • Why an investigation password is required

Demonstrate

  • Creating an investigation password

  • Creating an investigation

  • Moving findings into the investigation

  • Reviewing files

Trainer focus

  • Explain that previously downloaded files keep the password used at the time of download

  • Show why the secure location must be ready before investigation or move actions

13. Remediation - 15 minutes

Show how to take action on findings.

Cover

  • When to use Move, Copy, Delete, and Classify

  • Who should be notified after remediation

Demonstrate

  • Setting up a secure location

  • Move - Move files to a secure location

  • Copy - Copy files to a controlled location

  • Delete - Delete approved files

  • Classify - Apply the appropriate classification action

  • Email Notifications

  • Notifying the data owner

  • Notifying the end user

Trainer focus

  • Make Classify a required demo item

  • Explain when classification is the right remediation action instead of move or delete

14. Remediation history and operational review - 10 minutes

Cover

  • How to review remediation history

  • How to review operational logs and agent activity

  • These log types:

    • Scan Logs

    • Target Discovery Logs

    • Investigation Logs

    • Remediation Logs

    • Service Logs

Demonstrate

  • Remediation history

  • Status tracking

  • Previous comments

  • Remediated by

  • Remediated at

  • Request Logs from the agent

Trainer focus

  • Show how to use logs to troubleshoot scan, connection, and remediation issues

  • Show where to confirm agent health and workload

15. Positioning PROTECT and INSIGHT - 10 minutes

Position DISCOVER as the discovery layer in the wider platform workflow.

Cover

  • DISCOVER identifies and remediates sensitive data

  • INSIGHT helps monitor sensitive data exposure and trends

  • PROTECT provides persistent encryption and protection

Key points

  • Together, they support a discovery-to-protection workflow

16. Q&A - 5 minutes

Leave time for open discussion.

Last updated