GuardWare INSIGHT Video Guide
Learn GuardWare INSIGHT through structured video tutorials.
GuardWare INSIGHT provides visibility into how sensitive information is accessed, used and moved across Microsoft 365, endpoints, email, web applications, removable media, printing and AI tools.
The purpose of this training is to teach participants how to:
Understand the role of INSIGHT within GuardWare’s data-centric security platform.
Recognise the data movement activities monitored by INSIGHT.
Navigate the INSIGHT management environment.
Deploy and validate endpoint and Microsoft 365 monitoring.
Review and investigate data-handling events.
Configure monitoring rules, alerts and appropriate responses.
Identify shadow AI and sensitive information entered into AI tools.
Use contextual user education to improve employee behaviour.
Establish an ongoing operational monitoring and reporting process.
INSIGHT is designed to work alongside existing security and DLP investments by addressing visibility gaps across channels including endpoints, AI tools, personal cloud services, remote-working environments and shadow IT.
Course Information
Duration
1 hour
Format
Self-paced video tutorials
Skill level
Beginner to Intermediate
Prerequisites
Basic system administration knowledge
Course Outline
Session 1: Creating User Policies
User Policies define how GuardWare INSIGHT monitors, alerts on, and controls user activity involving sensitive information. They allow organisations to apply different monitoring and protection settings to different users or groups based on their roles, risk levels, and business requirements.
This session explains:
What User Policies are
Creating a User Policy and importing settings from an existing policy
Configuring application, website, USB, and network monitoring
Enabling archive file scanning, OCR detection, and document and email classification
Adding Data Types with Block, Monitor, and Warn actions
Assigning policies to users and Security Groups
Viewing, editing, and deleting User Policies
Session 2: Configuring Advanced Settings
Advanced Settings define the global monitoring configuration that controls how GuardWare INSIGHT captures user activity and monitors the movement of sensitive information across endpoints. They provide organisation-wide settings that complement User Policies and ensure consistent monitoring behaviour across managed devices.
This session explains:
What Advanced Settings are
Creating an Advanced Setting, including copying an existing configuration and setting a default policy
Configuring environment, browser, USB, file system, and client responsiveness settings
Managing monitored and excluded applications, websites, IP addresses, and file extensions
Configuring Chromium extension monitoring, keystroke monitoring, copy and paste monitoring, and encrypted website monitoring
Assigning Advanced Settings to devices
Viewing, editing, and deleting Advanced Settings
Session 3: Understanding Risk Definitions
Risk Definitions determine how GuardWare INSIGHT assesses and categorises the severity of user activity across the organisation. They help organisations prioritise potentially risky activities across areas such as SharePoint, email, storage devices, printing, and AI tool usage.
GuardWare INSIGHT uses these risk levels to automatically score activities, helping organisations prioritise incidents that require attention without having to manually review every event.
This session explains:
Understanding the six risk levels, from No Risk through Highest
Reviewing the thirteen activity categories, including SharePoint External, SharePoint Internal, Email, Storage Device Risk, Printing Incidents, Keystroke Capture, Copy Paste, and Usage of AI Tools
Navigating each category's submenu to review the specific activities and their assigned risk levels
Changing default risk levels to match your organisation's requirements
Saving updated Risk Definitions and understanding how the changes are reflected in the Incident Risks dashboard
Session 4: Organisation Settings
Organisation Settings define how GuardWare INSIGHT classifies and manages resources across the organisation, including websites, applications, printers, USB devices, email domains, AI tools, and SharePoint resources. These classifications help INSIGHT accurately interpret user activity and apply the appropriate monitoring and risk evaluation.
This session explains:
Configuring Working Days, the setting that is configured directly rather than populated through user activity
Understanding how Printers, Websites, Applications, USBs, AI Usages, and SharePoint are populated automatically as users interact with them, and how to classify these resources
Classifying Email Domains as Organisational, Insecure, or Undefined
Manually classifying AI Websites and AI Applications, as AI tools are not detected automatically
Marking SharePoint libraries as Sensitive or Undefined
Adding and removing Trusted Emails and OneDrive Folders, which are configured directly rather than populated through user activity
GuardWare INSIGHT uses these classifications to improve monitoring accuracy, reporting, and risk evaluation across the organisation.
Session 5: Setting up Cloud Monitor
Cloud Monitor enables GuardWare INSIGHT to monitor user activity and data movement across Microsoft 365 and Google Workspace environments. It provides visibility into cloud-based services such as email, file storage, and collaboration platforms, helping organisations extend monitoring beyond endpoint devices.
This session explains:
Connecting Microsoft 365 using a Global Administrator account, which is required for Cloud Monitor functionality
Connecting Google Workspace, including the prerequisite configuration of a Google Service Account
Enabling monitoring for Exchange, SharePoint, Gmail, and Google Drive
Assigning users for Exchange and Gmail monitoring
Performing manual synchronisation of Microsoft 365 data
Assigning Data Types to define what Cloud Monitor monitors within SharePoint
Understanding where Exchange, Gmail, SharePoint, and Google Drive activities are displayed within the INSIGHT dashboard
Cloud Monitor provides centralised visibility into cloud activity, helping organisations monitor sensitive information, identify risky behaviour, and investigate incidents across their Microsoft 365 and Google Workspace environments.
Session 6: INSIGHT Devices
INSIGHT Devices provides a centralised view of all endpoints running the GuardWare INSIGHT Agent. It enables administrators to monitor device status, manage endpoint configurations, and perform administrative actions directly from the Management Console.
This session explains:
Viewing device status and inventory information, including hardware details, installed software, and agent versions
Assigning Advanced Settings to control device monitoring behaviour and policies
Sending endpoint commands, including Update Client and Uninstall Client
Managing device logs through Maintenance Mode, including enabling logging, disabling logging, and retrieving log files
Viewing detailed device and agent information from the Management Console
Updating or uninstalling the INSIGHT Agent directly from the device management interface
INSIGHT Devices gives administrators complete visibility and control over monitored endpoints, helping ensure consistent policy enforcement, efficient troubleshooting, and effective device management across the organisation.
Session 7: INSIGHT Dashboard
The INSIGHT Dashboard provides a centralised view of user activity, data movement, and risk across the organisation. By bringing together endpoint, cloud, and behavioural monitoring data, it helps administrators and security teams identify unusual activity, investigate incidents, and gain actionable insights from a single interface.
This session explains:
Navigating the risk category tabs: Risk Summary, Data Type Risks, SharePoint Risks, AI Usage Risks, Behaviour Risks, Label Events, Location Risks, Protected Files, and System Risks
Understanding dashboard widgets, from high-level summary views to detailed incident records
Interpreting colour-coded risk levels and their relationship to configured Risk Definitions
Exporting dashboard data to Excel or PDF for reporting and analysis
Creating Custom Dashboards focused on specific devices, users, data types, or risk categories
Viewing, editing, deleting, and switching between dashboards
The INSIGHT Dashboard transforms monitoring data into meaningful insights, enabling organisations to quickly identify risks, investigate incidents, and make informed security decisions.
Session 8: Configuring INSIGHT Reports
Reports in GuardWare INSIGHT deliver risk and activity information to the right stakeholders automatically, reducing the need for manual dashboard reviews. They help security teams, managers, and end users stay informed about risky behaviour through scheduled and customised reporting.
This session explains:
Configuring the Risk Summary Report, which provides an organisation-wide overview of risky activities for security teams
Configuring the User-Based Risk Report, designed to track risk trends and incident activity for specific users
Configuring the Cyber Awareness Report, which is sent directly to end users with information and guidance related to their own activities
Setting Incident Thresholds, Data Type Occurrence Thresholds, and Duration Thresholds to determine when reports are generated
Customising report branding and content, including cover images, introductory messages, footers, and privacy statements
Sending test emails to preview report content before deployment
Enabling, editing, and deleting report configurations
INSIGHT Reports ensure that critical risk information is delivered automatically and consistently, helping organisations improve visibility, strengthen security awareness, and support proactive risk management.
Last updated