Cloud Monitoring
Cloud Monitoring monitors user activities within your organisation's Microsoft 365 and Google Workspace environments. These data are then analysed within GuardWare INSIGHT to provide dashboards, alerts, and reports on cloud usage and potential security incidents.
It monitors key cloud events such as:
Files accessed or downloaded from sensitive libraries
Access and download actions by anonymous, invited, or external users
Files accessed via shared links
Creation of anonymous links and external file access activities
Cloud storage file access, download, and link creation activities
Outgoing emails
Set up Integrations
Microsoft 365 and Google Workspace must each be connected to the Management Console before Cloud Monitoring can be set up for that service. Only once a service is connected can its monitoring be enabled or disabled.
Connect Microsoft 365
Navigate to ORGANISATION > Integrations or from within Cloud Monitoring by clicking Configure Integrations.
Click Connect Microsoft 365. You'll be redirected to Microsoft's sign-in page.

Select your Global Administrator account or click Use another account if it is not listed.

Enter your Global Administrator email address and password. Click Next and sign in.
If your account is protected by multi-factor authentication (MFA), you'll need to approve the sign-in request. This might involve:
Approving a notification in the Microsoft Authenticator app.
Entering the code from your authenticator app.
Responding to a text message or phone call, depending on your MFA settings.

After authenticating, you'll see a permissions consent screen listing what DISCOVER is requesting access to. Select Consent on behalf of your organisation and click Accept.

You'll be redirected back to the GuardWare Management Console, saying that the configuration was completed successfully.
Connect Google Workspace
Navigate to ORGANISATION > Google Workspace or INSIGHT > Cloud Monitoring and click Add Google Workspace.

In Admin Email, enter the Google Workspace admin email address that is used to create the JSON Key.
Enter the Security Group.
Enable Gmail Monitoring and Google Drive Monitoring.
Upload the Google Service Account JSON credentials you generated while setting up the Google Cloud Service Account.
Click Submit.

Configure Cloud Monitoring
Cloud Monitoring Settings controls monitoring for Microsoft 365 and Google Workspace services. Enable or disable monitoring per service, manage which users' activities are monitored and sync cloud data here.
Configure Exchange Monitoring
Use this option to enable or disable monitoring of Microsoft Exchange activities.
Navigate to INSIGHT > Cloud Monitoring.
Toggle Exchange Monitoring to enable or disable Exchange monitoring.

Click Save to apply the configuration.
Add Users to Security Group
The Security Group identifies the Microsoft 365 security group used for Exchange monitoring and is displayed when Exchange Monitoring is enabled.
Click Assign Users.

Select the users to be included in the monitoring group.

Click Save to assign the selected users, or click Assign All Users to assign all the listed users.
Configure SharePoint Monitoring
Use this option to enable or disable monitoring of SharePoint activities.
Navigate to INSIGHT > Cloud Monitoring.
Toggle SharePoint Monitoring to enable or disable SharePoint monitoring.

Click Save to apply the configuration.
Configure Gmail Monitoring
Use this option to enable or disable monitoring of Gmail activities.
Navigate to INSIGHT > Cloud Monitoring.
Toggle Gmail Monitoring to enable or disable Gmail monitoring.

Click Save to apply the configuration.
Assign Users to Security Group
Use this option to assign the users whose Gmail activities are monitored.
Click Assign Users.

Select the users to be included in the monitoring group.

Click Save to assign the selected users, or click Assign All Users to assign all the listed users.
Configure Google Drive Monitoring
Use this option to enable or disable monitoring of Google Drive activities.
Navigate to INSIGHT > Cloud Monitoring.
Toggle Google Drive Monitoring to enable or disable Google Drive monitoring.

Click Save to apply the configuration.
Sync Cloud Monitoring
Manually refresh configuration and user information rather than waiting for the next scheduled sync.
Navigate to INSIGHT > Cloud Monitoring.
Click the Sync button to synchronise the latest configuration and user information from Microsoft 365.

The Last Synced field displays the date and time of the most recent successful synchronisation.
Assign Data Type
Control which sensitive data types Cloud Monitoring monitors.
Click + Assign Data Type.
Select the data types to monitor.

Filter data types by category, including PCI, PII, SPI, and PHI, if required.

Click Save to apply the changes.
Last updated