For the complete documentation index, see llms.txt. This page is also available as Markdown.

DISCOVER training module - 100 minutes

Overview

This training module is designed to give users a practical introduction to DISCOVER.

It covers:

  • Product architecture, scanning models, and key components

  • Microsoft 365 integration, target discovery, and Scanning Server setup

  • Data governance, data types, classifications, and scan configuration

  • Results review, investigation, remediation, and positioning with PROTECT and INSIGHT

Duration

  • Session 1 - 45 minutes

  • Break - 10 minutes

  • Session 2 - 45 minutes

Session 1 - 45 minutes

Topics covered

  • DISCOVER overview

  • How to integrate with Microsoft 365

  • How to set up a scanning server

  • How to perform local and remote scans

  • What a secure move location is

  • How to set up classifications

  • What data types and sub data types are available in the system

  • How to define new data types

  • How to define complex regular expressions

  • How to combine regex with other conditions

  • How to discover what to scan (targets)

1. Product overview and architecture - 5 minutes

Cover the product at a high level.

Explain:

  • What DISCOVER is

  • Where it fits in the data security workflow

  • How data moves from detection to action

Use this workflow:

  • Data types ScanResults Remediate

Review the main components:

  • Management Console

  • Scanning Server

  • Target devices and services

Then explain the two scanning models:

Local scan

  • Agent installed on the target device

  • The device scans itself

Agentless scan

  • Agent installed on a Scanning Server

  • Scans remote systems over:

    • WinRM

    • SSH

    • SMB

2. Server installation - 15 minutes (Optional, if included, the session will extend by 15 minutes)

Run a live installation walkthrough.

Cover

  • What the installation includes

  • The minimum prerequisites for setup

  • What trainees should expect after first sign-in

Demonstrate

  • GuardWare Server installation

  • Initial setup

  • First access to the Management Console

Trainer focus

  • Show the minimum steps required to get to a usable console

  • Point out any prerequisites that commonly block setup

3. Management Console introduction - 5 minutes

Show the main navigation areas.

Cover

  • Organisation settings

    • Setting up a secure location

    • Setting an investigation password

    • Integrating with Microsoft 365

  • Devices

  • Data Governance

  • Resources

Demonstrate

  • Moving through the main Console areas

  • Locating the settings used later in the session

4. Getting started - Agent/Scanning Server configuration - 10 minutes

Walk through agent preparation for scanning.

Cover

  • How local and agentless scanning differ

Demonstrate

  • Agent configuration

  • Agent download

  • Agent installation

  • For local scan, install the downloaded agent on a target device

  • For agentless/remote scan, install the downloaded agent on a Windows host, which becomes the Scanning Server

  • Complete the setup

  • Confirm the Scanning Server appears as Online in the Console

Key points

  • A local scan runs on the target device itself

  • An agentless scan uses a Scanning Server to scan remote systems across the network

5. Data governance - 15 minutes

Show how governance settings define what DISCOVER detects, classifies, and escalates.

Cover

  • Built-in data types such as credit cards, passport numbers, PII, and financial information

  • Custom data types using Sensitive Words, Regular Expressions, and Filename Expressions

  • Example inputs such as Confidential, Salary, Acquisition, employee IDs, customer numbers, passport formats, and Payroll_*.xlsx.

  • Subtypes and how they improve categorisation and reduce false positives

  • Manual classifications such as Public, Internal, Confidential, and Restricted

  • Purview synchronisation for existing Microsoft classifications

    • Needs MIP license for MIP classification.

  • Data owners and how notifications are assigned

  • The difference between a data owner and a device owner

Demonstrate

  • Reviewing built-in data types

  • Creating a custom data type with Sensitive Words

  • Creating a custom data type with Regular Expressions

  • Creating a custom data type with Filename Expressions

  • Briefly covering how to create a manual classification

  • Showing where Purview-synchronised classifications appear

  • Assigning a data owner to a data type

    • Explain:

      • Data owners are not necessarily device owners

      • Data owners receive notifications when sensitive data is discovered

      • Example: an HR manager receives an alert when employee-sensitive data is found outside approved locations

Trainer focus

  • Emphasise how better data type design improves scan quality

  • Explain how subtypes help reduce false positives

  • Show how notifications reach the right business owner

6. Target discovery - 15 minutes

Show both discovery paths.

Cover

  • Device discovery for Windows, Linux, and file shares

  • Service discovery for cloud platforms

  • The prerequisites that make discovery succeed

Demonstrate

  • Device discovery over WinRM

  • Device discovery over SSH

  • SMB file server discovery

  • SharePoint Online discovery

  • Exchange Online discovery

  • Gmail discovery

  • Google Drive discovery

  • Explain steps to connect to Google Wokspace

Key points

  • Discovery depends on network reachability, permissions, and host-side configuration

Break - 10 minutes

Session 2 - 45 minutes

Topics covered

  • How to configure scans

  • What is a one-time scan

  • What is an ongoing scan

  • Key considerations when conducting scans

  • Scan and classify

  • How to review results

  • How to delete data

  • How to classify identified data

  • How to copy data to a secure location

  • How to move data

  • How to move SharePoint data to another SharePoint site

  • How to move email to a secure email account

7. Create a scan - 15 minutes

Explain the two scan types, then configure a scan live.

Cover

  • One-Time Scan for quick validation and testing

  • Ongoing Scan for continuous monitoring and scheduled execution

  • When to use each scan type

Demonstrate

  • Creating a One-Time Scan

  • Creating an Ongoing Scan

  • Selecting data types

  • Selecting targets

  • Archive scanning

  • OCR Options

  • Changed files only

  • Scheduling

  • Scan and Classify

  • Running the scan

  • Reviewing scan progress

  • Reviewing scan status

  • Showing where results appear

Trainer focus

  • Explain when to use Scan and Classify

  • Show how classification is applied as part of the scan workflow

  • Explain why this is important for downstream monitoring and protection

Key points

  • Multiple one-time scans can run

  • Only one ongoing scan can run at a time

8. Dashboard and Results- 5 minutes

Review discovered data at a higher level before drilling into individual findings, then move from trend views into finding-level review.

Cover

  • Dashboard for aggregated metrics across scans

  • Summary Report for findings from a specific scan job

  • Common metrics such as Potential Sensitive Data, Potential Data by Target, and Discovered vs Investigated vs Remediated Data

  • How results are grouped across devices, SharePoint, and email

Demonstrate

  • Dashboard review

  • Summary Report review

  • Scan-level filtering

  • High-level metrics and trend views

  • Findings review

  • Device results

  • SharePoint results

  • Email results

Trainer focus

  • Show how to filter by scan, target, data type, and classification

  • Show how to move from high-level trends into file-level findings

  • Explain when to use Results instead of Dashboard

9. Investigation - 5 minutes

Show how to inspect sensitive files in a controlled workflow.

Cover

  • Why an investigation password is required

Demonstrate

  • Creating an investigation password

  • Creating an investigation

  • Moving findings into the investigation

  • Reviewing files

10. Remediation - 5 minutes

Show how to take action on findings.

Cover

  • When to use Move, Copy, Delete, and Classify

  • Who should be notified after remediation

Demonstrate

  • Setting up a secure location

  • Move - Move files to a secure location

  • Copy - Copy files to a controlled location

  • Delete - Delete approved files

  • Classify - Apply the appropriate classification action

  • Email Notifications

  • Notifying the data owner

  • Notifying the end user

Trainer focus

  • Make Classify a required demo item

  • Explain when classification is the right remediation action instead of move or delete

11. Positioning PROTECT and INSIGHT - 5 minutes

Position DISCOVER as the discovery layer in the wider platform workflow.

Cover

  • DISCOVER identifies and remediates sensitive data

  • INSIGHT helps monitor sensitive data

  • PROTECT provides persistent encryption and protection

Key points

  • Together, DISCOVER, INSIGHT, and PROTECT support a discovery-to-protection workflow

  • Discover MonitorProtect

12. Q&A

Leave time for open discussion.

Last updated