> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/insight/getting-started/insight-training-course-100-minutes.md).

# INSIGHT Training Course - 100 Minutes

## Overview

This training gives users a practical introduction to INSIGHT.

The objective is to help attendees deploy INSIGHT, configure core settings, and start monitoring user activities.

It covers:

* Product architecture and key components
* Microsoft 365 and endpoint monitoring setup
* Users, devices, policies, and organisation settings
* Risk definitions, reporting, dashboards, and troubleshooting

### Duration

* **Session 1** - 45 minutes
* **Break** - 10 minutes
* **Session 2** - 45 minutes

### Session 1 - 45 minutes

#### Topics covered

* INSIGHT overview
* How to connect Microsoft 365/Cloud Monitor
* How to deploy the INSIGHT Agent
* How users and devices appear in INSIGHT
* How to configure Organisation Settings
* How to create and assign a User Policy
* How to define risk levels

#### 1. Product overview and architecture - 5 minutes

Cover the product at a high level first.

**Explain**:

* What INSIGHT is
* Where it fits in the data security workflow
* How monitored activity becomes actionable risk

Review the components:

* **Management Console**
* **INSIGHT Agent**
* **Cloud Monitor**

Then explain the two monitoring models.

#### Endpoint monitoring

* Agent installed on the endpoint
* Monitors local user activity and data movement

#### Cloud monitoring

* Microsoft 365 integration connected in the console
* Monitors Exchange Online and SharePoint Online activity

#### 2. Microsoft 365 integration and console access - 5 minutes

This section introduces the first cloud setup steps in INSIGHT. It helps attendees understand how Microsoft 365 activity becomes visible in the console.

**Cover:**

* Admin sign-in flow
* Microsoft 365 connection path
* Exchange monitoring
* SharePoint monitoring
* Cloud activity visibility

**Demonstrate:**

* Signing in to the Management Console
* Connecting Microsoft 365

#### 3. Agent download and installation - 5 minutes

Walk through agent preparation for monitoring.

This section shows how to move from console setup to live endpoint monitoring. It should help attendees understand how to deploy and validate one test device.

**Cover:**

* Agent configuration
* Agent download path
* Agent installation flow

**Demonstrate:**

1. Configure the agent package from the console.
2. Download the installer.
3. Install the agent on a demo endpoint.
4. Confirm the device appears as online in INSIGHT.

**Trainer focus:**

* Show the minimum steps needed to get one device reporting
* Point out any endpoint or security software exclusions needed

#### 4. Users and devices - 10 minutes

This section explains where users and devices appear after deployment. It also shows how to maintain the device and assign commands.&#x20;

**Cover:**

* **Devices**
  * Device Maintenance
  * Assigning commands
  * Retrieving logs
* **End Users**

**Demonstrate:**

* How synced users appear
* How to uninstall and update the agent
* How to retrieve logs
* How to assign commands

#### 5. Organisation Settings - 5 minutes

Show the main organisational settings used to improve the monitoring context.

This section explains how organisational context improves the quality of monitoring. It helps attendees understand which settings make alerts and activity more meaningful.

**Cover:**

* Working days
* Websites and applications
* Email domains and trusted emails

**Demonstrate:**

* Opening Organisation Settings
* Reviewing working days
* Reviewing websites, applications, and trusted domains

#### 6. User Policies - 10 minutes

This section shows how INSIGHT moves from visibility into control. It gives attendees a practical example of how to build a user policy that monitors and responds to user behaviour.

**Cover:**

* Policy structure
* Monitored activities and data types
* Control actions
* User assignment

**Demonstrate:**

* Creating a policy
* Configuring monitored activities and data types
* Setting control actions
* Assigning users
* Building one simple demo example:
  * Monitor the AI website uploads
  * Warn on sensitive email attachments
  * Block selected file transfers

**Trainer focus:**

* Keep the example simple and realistic
* Show how policy settings affect captured events

#### 7. Risk Definitions - 5 minutes

Explain how severity is assigned across monitored activities.

This section explains how INSIGHT prioritises monitored events. It helps attendees understand how risk levels support review, reporting, and operational response.

**Cover:**

* How severity is assigned
* How risk levels support prioritisation

**Demonstrate:**

* Reviewing a sample risk definition
* Showing how severity appears in reporting

**Key points:**

* Easier dashboard prioritisation
* Better reporting context
* Closer alignment with business risk

### Break - 10 minutes

### Session 2 - 45 minutes

#### Topics covered

* How to configure Advanced Settings
* How to assign settings to devices
* How to configure Cyber Awareness and Risk Summary reports
* How to review dashboard data and drill into incidents
* How to validate endpoint health
* Common troubleshooting checks

#### 8. Advanced Settings - 15 minutes

This section explains how device behaviour is fine-tuned after the main policy is in place. It helps attendees focus on the settings that matter most for initial rollout and troubleshooting.

**Cover:**

* Communication and upload behaviour
* Monitoring scope
* Network and file-system monitoring
* Device assignment

**Demonstrate:**

* Creating an Advanced Setting
* Changing one or two key monitoring options
* Assigning the setting to a device

**Trainer focus:**

* Keep the demo to the highest-value settings
* Show how to confirm the assigned setting on the endpoint

#### 9. Reports - 10 minutes

Show the two main reporting paths.

This section shows how INSIGHT supports both awareness and oversight. It helps attendees choose the right report for coaching users or reviewing risk.

**Cover:**

* When to use **Cyber Awareness**
* When to use **Risk Summary**

**Demonstrate:**

* **Cyber Awareness** for end-user guidance
* **Risk Summary** for admin visibility

**Key points:**

* Cyber Awareness drives behaviour change
* Risk Summary supports operational oversight

#### 10. Dashboard and incident review - 10 minutes

Show how to move from high-level views into incident detail.

This section introduces the main workflow for reviewing activity in INSIGHT. It shows how to start from summary data and move into the details needed for investigation.

**Cover:**

* **Risk Summary**
* **Data Type Risks**
* **Behaviour Risks**

**Demonstrate:**

* Opening the main dashboard
* Reviewing high-level risk views
* Drilling into incidents

**Trainer focus:**

* Show how to filter by user, device, and time
* Show how to move from summary widgets into incident detail

#### 11. Endpoint health and troubleshooting - 5 minutes

Show the main checks to use when data looks missing.

This section gives attendees a simple validation path when endpoints are not reporting as expected. It focuses on the quickest checks to confirm status, sync, and applied settings.

**Cover:**

* **INSIGHT Status Monitor**
* Device online status
* Last sync and applied settings

**Demonstrate:**

* Opening **INSIGHT Status Monitor**
* Reviewing device online status
* Reviewing last sync and applied settings

**Trainer focus:**

* Position this as the first check when data looks missing
* Show how to confirm a policy or setting has applied

#### 12. Q\&A - 5 minutes

Overview

Leave time for open discussion.

This section gives attendees time to clarify setup, policy, and reporting questions. It also reinforces the workflows that matter most in their own environment.

**Cover:**

* Open questions from attendees
* Follow-up scenarios from the demo

**Demonstrate:**

* Revisiting one workflow if attendees need clarification

{% hint style="info" %}
If time is tight, prepare one policy example, one report example, and one dashboard drill-down in advance.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/insight/getting-started/insight-training-course-100-minutes.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
