For the complete documentation index, see llms.txt. This page is also available as Markdown.

INSIGHT Training Course - 100 Minutes

Overview

This training gives users a practical introduction to INSIGHT.

The objective is to help attendees deploy INSIGHT, configure core settings, and start monitoring user activities.

It covers:

  • Product architecture and key components

  • Microsoft 365 and endpoint monitoring setup

  • Users, devices, policies, and organisation settings

  • Risk definitions, reporting, dashboards, and troubleshooting

Duration

  • Session 1 - 45 minutes

  • Break - 10 minutes

  • Session 2 - 45 minutes

Session 1 - 45 minutes

Topics covered

  • INSIGHT overview

  • How to connect Microsoft 365/Cloud Monitor

  • How to deploy the INSIGHT Agent

  • How users and devices appear in INSIGHT

  • How to configure Organisation Settings

  • How to create and assign a User Policy

  • How to define risk levels

1. Product overview and architecture - 5 minutes

Cover the product at a high level first.

Explain:

  • What INSIGHT is

  • Where it fits in the data security workflow

  • How monitored activity becomes actionable risk

Review the components:

  • Management Console

  • INSIGHT Agent

  • Cloud Monitor

Then explain the two monitoring models.

Endpoint monitoring

  • Agent installed on the endpoint

  • Monitors local user activity and data movement

Cloud monitoring

  • Microsoft 365 integration connected in the console

  • Monitors Exchange Online and SharePoint Online activity

2. Microsoft 365 integration and console access - 5 minutes

This section introduces the first cloud setup steps in INSIGHT. It helps attendees understand how Microsoft 365 activity becomes visible in the console.

Cover:

  • Admin sign-in flow

  • Microsoft 365 connection path

  • Exchange monitoring

  • SharePoint monitoring

  • Cloud activity visibility

Demonstrate:

  • Signing in to the Management Console

  • Connecting Microsoft 365

3. Agent download and installation - 5 minutes

Walk through agent preparation for monitoring.

This section shows how to move from console setup to live endpoint monitoring. It should help attendees understand how to deploy and validate one test device.

Cover:

  • Agent configuration

  • Agent download path

  • Agent installation flow

Demonstrate:

  1. Configure the agent package from the console.

  2. Download the installer.

  3. Install the agent on a demo endpoint.

  4. Confirm the device appears as online in INSIGHT.

Trainer focus:

  • Show the minimum steps needed to get one device reporting

  • Point out any endpoint or security software exclusions needed

4. Users and devices - 10 minutes

This section explains where users and devices appear after deployment. It also shows how to maintain the device and assign commands.

Cover:

  • Devices

    • Device Maintenance

    • Assigning commands

    • Retrieving logs

  • End Users

Demonstrate:

  • How synced users appear

  • How to uninstall and update the agent

  • How to retrieve logs

  • How to assign commands

5. Organisation Settings - 5 minutes

Show the main organisational settings used to improve the monitoring context.

This section explains how organisational context improves the quality of monitoring. It helps attendees understand which settings make alerts and activity more meaningful.

Cover:

  • Working days

  • Websites and applications

  • Email domains and trusted emails

Demonstrate:

  • Opening Organisation Settings

  • Reviewing working days

  • Reviewing websites, applications, and trusted domains

6. User Policies - 10 minutes

This section shows how INSIGHT moves from visibility into control. It gives attendees a practical example of how to build a user policy that monitors and responds to user behaviour.

Cover:

  • Policy structure

  • Monitored activities and data types

  • Control actions

  • User assignment

Demonstrate:

  • Creating a policy

  • Configuring monitored activities and data types

  • Setting control actions

  • Assigning users

  • Building one simple demo example:

    • Monitor the AI website uploads

    • Warn on sensitive email attachments

    • Block selected file transfers

Trainer focus:

  • Keep the example simple and realistic

  • Show how policy settings affect captured events

7. Risk Definitions - 5 minutes

Explain how severity is assigned across monitored activities.

This section explains how INSIGHT prioritises monitored events. It helps attendees understand how risk levels support review, reporting, and operational response.

Cover:

  • How severity is assigned

  • How risk levels support prioritisation

Demonstrate:

  • Reviewing a sample risk definition

  • Showing how severity appears in reporting

Key points:

  • Easier dashboard prioritisation

  • Better reporting context

  • Closer alignment with business risk

Break - 10 minutes

Session 2 - 45 minutes

Topics covered

  • How to configure Advanced Settings

  • How to assign settings to devices

  • How to configure Cyber Awareness and Risk Summary reports

  • How to review dashboard data and drill into incidents

  • How to validate endpoint health

  • Common troubleshooting checks

8. Advanced Settings - 15 minutes

This section explains how device behaviour is fine-tuned after the main policy is in place. It helps attendees focus on the settings that matter most for initial rollout and troubleshooting.

Cover:

  • Communication and upload behaviour

  • Monitoring scope

  • Network and file-system monitoring

  • Device assignment

Demonstrate:

  • Creating an Advanced Setting

  • Changing one or two key monitoring options

  • Assigning the setting to a device

Trainer focus:

  • Keep the demo to the highest-value settings

  • Show how to confirm the assigned setting on the endpoint

9. Reports - 10 minutes

Show the two main reporting paths.

This section shows how INSIGHT supports both awareness and oversight. It helps attendees choose the right report for coaching users or reviewing risk.

Cover:

  • When to use Cyber Awareness

  • When to use Risk Summary

Demonstrate:

  • Cyber Awareness for end-user guidance

  • Risk Summary for admin visibility

Key points:

  • Cyber Awareness drives behaviour change

  • Risk Summary supports operational oversight

10. Dashboard and incident review - 10 minutes

Show how to move from high-level views into incident detail.

This section introduces the main workflow for reviewing activity in INSIGHT. It shows how to start from summary data and move into the details needed for investigation.

Cover:

  • Risk Summary

  • Data Type Risks

  • Behaviour Risks

Demonstrate:

  • Opening the main dashboard

  • Reviewing high-level risk views

  • Drilling into incidents

Trainer focus:

  • Show how to filter by user, device, and time

  • Show how to move from summary widgets into incident detail

11. Endpoint health and troubleshooting - 5 minutes

Show the main checks to use when data looks missing.

This section gives attendees a simple validation path when endpoints are not reporting as expected. It focuses on the quickest checks to confirm status, sync, and applied settings.

Cover:

  • INSIGHT Status Monitor

  • Device online status

  • Last sync and applied settings

Demonstrate:

  • Opening INSIGHT Status Monitor

  • Reviewing device online status

  • Reviewing last sync and applied settings

Trainer focus:

  • Position this as the first check when data looks missing

  • Show how to confirm a policy or setting has applied

12. Q&A - 5 minutes

Overview

Leave time for open discussion.

This section gives attendees time to clarify setup, policy, and reporting questions. It also reinforces the workflows that matter most in their own environment.

Cover:

  • Open questions from attendees

  • Follow-up scenarios from the demo

Demonstrate:

  • Revisiting one workflow if attendees need clarification

If time is tight, prepare one policy example, one report example, and one dashboard drill-down in advance.

Last updated