PROTECT Quick Start Guide
Overview
GuardWare PROTECT encrypts and secures all file types, including MS Office documents, PDFs, images, videos, and AutoCAD files. It ensures files remain protected from unauthorised use and theft, whether stored locally or shared externally via USB, cloud drives, email, or other methods. Only authorised users and applications can open protected files. These users and applications are configured in the GuardWare Management Console by administrators.
End users interact with GuardWare PROTECT Client through the Windows Explorer right-click menu. From there, users can protect sensitive files by applying classifications, restricting access to specific Security Groups, limiting file circulation, adding an expiry date, and so on.
For Microsoft Office files, PROTECT works with Microsoft Purview Information Protection (MIP) to apply protection based on the file's classification. See PROTECT and MIP for more details.
What this guide covers
Console sign-in and admin access
Microsoft 365 integration and key setup
Agent download and endpoint rollout
Security Groups and User Policies
Applications and Office protection
Before getting started, make sure you have installed the GuardWare Server and can access the GuardWare Management Console URL.
Microsoft 365 integration
Before integrating, ensure you have:
An active Microsoft Azure subscription. We recommend using a Pay-As-You-Go subscription.
Access to the Microsoft Azure Portal with the required administrative permissions.
Without an active Azure subscription, GuardWare PROTECT cannot be implemented.
Navigate to ORGANISATION > Integrations.
Click Connect Microsoft 365.
Sign in with a Global Administrator account.
Review the requested permissions.
Select Consent on behalf of your organisation.
Click Accept.
This creates the Azure application that PROTECT uses for Azure Key Vault setup.
Set up Azure Key Vault and Key Server
We recommend creating the key vault from the Management Console.
Navigate to PROTECT > Key Vault.
Click Log in with Azure.
Sign in with an account that has Azure admin permissions.
Select the Subscription.
Choose or create the Resource group.
Enter a unique Key Vault name.
Select the Region and Pricing tier.
Click Create.
See Key Vault for more details.
Download the PROTECT Agent
Navigate to Resources > Agent Download.
Go to PROTECT Agent.
Enter your Azure external and internal domains and location.
Click Submit. The Download link only appears after the configuration is complete.
Once the installation settings are complete, the Download Installer link becomes available. Click it to download the agent with the configured settings.
Whitelist PROTECT on endpoints
Whitelist PROTECT in the endpoints' AV, EDR, or XDR platforms.
Add
C:\Program Files\GuardWare\PROTECTto the allowlist.Add
C:\ProgramData\Guardwareto the allowlist.Allow
GWProtectDesktop.exeto reach<KeyVaultName>.vault.azure.netover the port443.
See Whitelist GuardWare PROTECT for the full list of files, services, and network exceptions.
Install PROTECT Agent on endpoints
Run the PROTECT Agent installer on the endpoint.
Complete the setup wizard.
Install Azure CLI or Visual C++ if prompted.
Restart the device when installation finishes.
In the Welcome wizard, click Login with Azure.
Select the correct Tenant ID and Subscription.
Allow GWProtectDesktop through the Windows firewall if prompted.
After the agent is installed and the user signs in, the device appears in PROTECT Devices. From there, admins can enable or disable the agent, uninstall the agent, and open user details to enable or disable a user, enable or disable Force Encrypt, and decrypt files for that user.
See Install PROTECT Agent for full device setup.
Create Security Groups and assign users
Security Groups define who can open protected files.
Navigate to PROTECT > Security Groups.
Click +New Security Group.
Create the group manually or import it from AD.
Choose the encryption mode.
Save the group.
Click +Assign Users to add members.
Any new user who signs in successfully is added to All Users by default.
See Security Groups for more details.
Create a User policy and assign users
User Policies control which client actions users can access.
Navigate to PROTECT > User Policies.
Click +New User Policy.
Enter the policy title and description.
Enable the features your users need.
Save the policy.
Assign the policy to users.
See User Policies for more details.
Add applications
Applications define which programs can open, edit, and save protected files.
Navigate to PROTECT > Applications.
Click +New Application.
Enter the Executable Name and Application Suite.
Add the Folder Path if needed.
Define which extensions the application can encrypt and decrypt.
Enable Network Drive Support if required.
Click Save.
See Applications for more details.
PROTECT Office
Choose how Office files are protected.
You can use:
MIP only
MIP and PROTECT
PROTECT only
To configure this:
Navigate to ORGANISATION > Integrations.
Enable Protect Office files using MIP if required.
Enable Protect Office files using both MIP and PROTECT if you want layered protection.
Click Submit.
See Protection Mode for more details.
Optional next steps
After the baseline setup, you can expand the rollout.
Configure Data Types and classifications
Configure Websites and Office Add-in
Set up SCAN & ENCRYPT if you need to locate and encrypt files with sensitive data located in file servers and SharePoint.
With these steps complete, PROTECT is ready to protect files across your organisation using the policies, groups, and applications you configured.
Last updated

