DISCOVER training module - 100 minutes
Overview
This training module is designed to give users a practical introduction to DISCOVER.
It covers:
Product architecture, scanning models, and key components
Microsoft 365 integration, target discovery, and Scanning Server setup
Data governance, data types, classifications, and scan configuration
Results review, investigation, remediation, and positioning with PROTECT and INSIGHT
Duration
Session 1 - 45 minutes
Break - 10 minutes
Session 2 - 45 minutes
Session 1 - 45 minutes
Topics covered
DISCOVER overview
How to integrate with Microsoft 365
How to set up a scanning server
How to perform local and remote scans
What a secure move location is
How to set up classifications
What data types and sub data types are available in the system
How to define new data types
How to define complex regular expressions
How to combine regex with other conditions
How to discover what to scan (targets)
1. Product overview and architecture - 5 minutes
Cover the product at a high level.
Explain:
What DISCOVER is
Where it fits in the data security workflow
How data moves from detection to action
Use this workflow:
Data types → Scan → Results → Remediate
Review the main components:
Management Console
Scanning Server
Target devices and services
Then explain the two scanning models:
Local scan
Agent installed on the target device
The device scans itself
Agentless scan
Agent installed on a Scanning Server
Scans remote systems over:
WinRM
SSH
SMB
2. Server installation - 15 minutes (Optional, if included, the session will extend by 15 minutes)
Run a live installation walkthrough.
Cover
What the installation includes
The minimum prerequisites for setup
What trainees should expect after first sign-in
Demonstrate
GuardWare Server installation
Initial setup
First access to the Management Console
Trainer focus
Show the minimum steps required to get to a usable console
Point out any prerequisites that commonly block setup
3. Management Console introduction - 5 minutes
Show the main navigation areas.
Cover
Organisation settings
Setting up a secure location
Setting an investigation password
Integrating with Microsoft 365
Devices
Data Governance
Resources
Demonstrate
Moving through the main Console areas
Locating the settings used later in the session
4. Getting started - Agent/Scanning Server configuration - 10 minutes
Walk through agent preparation for scanning.
Cover
How local and agentless scanning differ
Demonstrate
Agent configuration
Agent download
Agent installation
For local scan, install the downloaded agent on a target device
For agentless/remote scan, install the downloaded agent on a Windows host, which becomes the Scanning Server
Complete the setup
Confirm the Scanning Server appears as Online in the Console
Key points
A local scan runs on the target device itself
An agentless scan uses a Scanning Server to scan remote systems across the network
5. Data governance - 15 minutes
Show how governance settings define what DISCOVER detects, classifies, and escalates.
Cover
Built-in data types such as credit cards, passport numbers, PII, and financial information
Custom data types using Sensitive Words, Regular Expressions, and Filename Expressions
Example inputs such as Confidential, Salary, Acquisition, employee IDs, customer numbers, passport formats, and Payroll_*.xlsx.
Subtypes and how they improve categorisation and reduce false positives
Manual classifications such as Public, Internal, Confidential, and Restricted
Purview synchronisation for existing Microsoft classifications
Needs MIP license for MIP classification.
Data owners and how notifications are assigned
The difference between a data owner and a device owner
Demonstrate
Reviewing built-in data types
Creating a custom data type with Sensitive Words
Creating a custom data type with Regular Expressions
Creating a custom data type with Filename Expressions
Briefly covering how to create a manual classification
Showing where Purview-synchronised classifications appear
Assigning a data owner to a data type
Explain:
Data owners are not necessarily device owners
Data owners receive notifications when sensitive data is discovered
Example: an HR manager receives an alert when employee-sensitive data is found outside approved locations
Trainer focus
Emphasise how better data type design improves scan quality
Explain how subtypes help reduce false positives
Show how notifications reach the right business owner
6. Target discovery - 15 minutes
Show both discovery paths.
Cover
Device discovery for Windows, Linux, and file shares
Service discovery for cloud platforms
The prerequisites that make discovery succeed
Demonstrate
Device discovery over WinRM
Device discovery over SSH
SMB file server discovery
SharePoint Online discovery
Exchange Online discovery
Gmail discovery
Google Drive discovery
Explain steps to connect to Google Wokspace
Key points
Discovery depends on network reachability, permissions, and host-side configuration
Break - 10 minutes
Session 2 - 45 minutes
Topics covered
How to configure scans
What is a one-time scan
What is an ongoing scan
Key considerations when conducting scans
Scan and classify
How to review results
How to delete data
How to classify identified data
How to copy data to a secure location
How to move data
How to move SharePoint data to another SharePoint site
How to move email to a secure email account
7. Create a scan - 15 minutes
Explain the two scan types, then configure a scan live.
Cover
One-Time Scan for quick validation and testing
Ongoing Scan for continuous monitoring and scheduled execution
When to use each scan type
Demonstrate
Creating a One-Time Scan
Creating an Ongoing Scan
Selecting data types
Selecting targets
Archive scanning
OCR Options
Changed files only
Scheduling
Scan and Classify
Running the scan
Reviewing scan progress
Reviewing scan status
Showing where results appear
Trainer focus
Explain when to use Scan and Classify
Show how classification is applied as part of the scan workflow
Explain why this is important for downstream monitoring and protection
Key points
Multiple one-time scans can run
Only one ongoing scan can run at a time
8. Dashboard and Results- 5 minutes
Review discovered data at a higher level before drilling into individual findings, then move from trend views into finding-level review.
Cover
Dashboard for aggregated metrics across scans
Summary Report for findings from a specific scan job
Common metrics such as Potential Sensitive Data, Potential Data by Target, and Discovered vs Investigated vs Remediated Data
How results are grouped across devices, SharePoint, and email
Demonstrate
Dashboard review
Summary Report review
Scan-level filtering
High-level metrics and trend views
Findings review
Device results
SharePoint results
Email results
Trainer focus
Show how to filter by scan, target, data type, and classification
Show how to move from high-level trends into file-level findings
Explain when to use Results instead of Dashboard
9. Investigation - 5 minutes
Show how to inspect sensitive files in a controlled workflow.
Cover
Why an investigation password is required
Demonstrate
Creating an investigation password
Creating an investigation
Moving findings into the investigation
Reviewing files
10. Remediation - 5 minutes
Show how to take action on findings.
Cover
When to use Move, Copy, Delete, and Classify
Who should be notified after remediation
Demonstrate
Setting up a secure location
Move - Move files to a secure location
Copy - Copy files to a controlled location
Delete - Delete approved files
Classify - Apply the appropriate classification action
Email Notifications
Notifying the data owner
Notifying the end user
Trainer focus
Make Classify a required demo item
Explain when classification is the right remediation action instead of move or delete
11. Positioning PROTECT and INSIGHT - 5 minutes
Position DISCOVER as the discovery layer in the wider platform workflow.
Cover
DISCOVER identifies and remediates sensitive data
INSIGHT helps monitor sensitive data
PROTECT provides persistent encryption and protection
Key points
Together, DISCOVER, INSIGHT, and PROTECT support a discovery-to-protection workflow
Discover → Monitor→ Protect
12. Q&A
Leave time for open discussion.
Last updated

