For the complete documentation index, see llms.txt. This page is also available as Markdown.

GuardWare INSIGHT Video Guide

Learn GuardWare INSIGHT through structured video tutorials.

GuardWare INSIGHT provides visibility into how sensitive information is accessed, used and moved across Microsoft 365, endpoints, email, web applications, removable media, printing and AI tools.

The purpose of this training is to teach participants how to:

  • Understand the role of INSIGHT within GuardWare’s data-centric security platform.

  • Recognise the data movement activities monitored by INSIGHT.

  • Navigate the INSIGHT management environment.

  • Deploy and validate endpoint and Microsoft 365 monitoring.

  • Review and investigate data-handling events.

  • Configure monitoring rules, alerts and appropriate responses.

  • Identify shadow AI and sensitive information entered into AI tools.

  • Use contextual user education to improve employee behaviour.

  • Establish an ongoing operational monitoring and reporting process.

INSIGHT is designed to work alongside existing security and DLP investments by addressing visibility gaps across channels including endpoints, AI tools, personal cloud services, remote-working environments and shadow IT.

Course Information

Duration

1 hour

Format

Self-paced video tutorials

Skill level

Beginner to Intermediate

Prerequisites

Basic system administration knowledge

Course Outline

Session
Topic

1

Creating User Policies

2

3

4

Organisation Settings

5

Setting up Cloud Monitor

6

INSIGHT Devices

7

INSIGHT Dashboard

8

Session 1: Creating User Policies

User Policies define how GuardWare INSIGHT monitors, alerts on, and controls user activity involving sensitive information. They allow organisations to apply different monitoring and protection settings to different users or groups based on their roles, risk levels, and business requirements.

This session explains:

  • What User Policies are

  • Creating a User Policy and importing settings from an existing policy

  • Configuring application, website, USB, and network monitoring

  • Enabling archive file scanning, OCR detection, and document and email classification

  • Adding Data Types with Block, Monitor, and Warn actions

  • Assigning policies to users and Security Groups

  • Viewing, editing, and deleting User Policies

Session 2: Configuring Advanced Settings

Advanced Settings define the global monitoring configuration that controls how GuardWare INSIGHT captures user activity and monitors the movement of sensitive information across endpoints. They provide organisation-wide settings that complement User Policies and ensure consistent monitoring behaviour across managed devices.

This session explains:

  • What Advanced Settings are

  • Creating an Advanced Setting, including copying an existing configuration and setting a default policy

  • Configuring environment, browser, USB, file system, and client responsiveness settings

  • Managing monitored and excluded applications, websites, IP addresses, and file extensions

  • Configuring Chromium extension monitoring, keystroke monitoring, copy and paste monitoring, and encrypted website monitoring

  • Assigning Advanced Settings to devices

  • Viewing, editing, and deleting Advanced Settings

Session 3: Understanding Risk Definitions

Risk Definitions determine how GuardWare INSIGHT assesses and categorises the severity of user activity across the organisation. They help organisations prioritise potentially risky activities across areas such as SharePoint, email, storage devices, printing, and AI tool usage.

GuardWare INSIGHT uses these risk levels to automatically score activities, helping organisations prioritise incidents that require attention without having to manually review every event.

This session explains:

  • Understanding the six risk levels, from No Risk through Highest

  • Reviewing the thirteen activity categories, including SharePoint External, SharePoint Internal, Email, Storage Device Risk, Printing Incidents, Keystroke Capture, Copy Paste, and Usage of AI Tools

  • Navigating each category's submenu to review the specific activities and their assigned risk levels

  • Changing default risk levels to match your organisation's requirements

  • Saving updated Risk Definitions and understanding how the changes are reflected in the Incident Risks dashboard

Session 4: Organisation Settings

Organisation Settings define how GuardWare INSIGHT classifies and manages resources across the organisation, including websites, applications, printers, USB devices, email domains, AI tools, and SharePoint resources. These classifications help INSIGHT accurately interpret user activity and apply the appropriate monitoring and risk evaluation.

This session explains:

  • Configuring Working Days, the setting that is configured directly rather than populated through user activity

  • Understanding how Printers, Websites, Applications, USBs, AI Usages, and SharePoint are populated automatically as users interact with them, and how to classify these resources

  • Classifying Email Domains as Organisational, Insecure, or Undefined

  • Manually classifying AI Websites and AI Applications, as AI tools are not detected automatically

  • Marking SharePoint libraries as Sensitive or Undefined

  • Adding and removing Trusted Emails and OneDrive Folders, which are configured directly rather than populated through user activity

GuardWare INSIGHT uses these classifications to improve monitoring accuracy, reporting, and risk evaluation across the organisation.

Session 5: Setting up Cloud Monitor

Cloud Monitor enables GuardWare INSIGHT to monitor user activity and data movement across Microsoft 365 and Google Workspace environments. It provides visibility into cloud-based services such as email, file storage, and collaboration platforms, helping organisations extend monitoring beyond endpoint devices.

This session explains:

  • Connecting Microsoft 365 using a Global Administrator account, which is required for Cloud Monitor functionality

  • Connecting Google Workspace, including the prerequisite configuration of a Google Service Account

  • Enabling monitoring for Exchange, SharePoint, Gmail, and Google Drive

  • Assigning users for Exchange and Gmail monitoring

  • Performing manual synchronisation of Microsoft 365 data

  • Assigning Data Types to define what Cloud Monitor monitors within SharePoint

  • Understanding where Exchange, Gmail, SharePoint, and Google Drive activities are displayed within the INSIGHT dashboard

Cloud Monitor provides centralised visibility into cloud activity, helping organisations monitor sensitive information, identify risky behaviour, and investigate incidents across their Microsoft 365 and Google Workspace environments.

Session 6: INSIGHT Devices

INSIGHT Devices provides a centralised view of all endpoints running the GuardWare INSIGHT Agent. It enables administrators to monitor device status, manage endpoint configurations, and perform administrative actions directly from the Management Console.

This session explains:

  • Viewing device status and inventory information, including hardware details, installed software, and agent versions

  • Assigning Advanced Settings to control device monitoring behaviour and policies

  • Sending endpoint commands, including Update Client and Uninstall Client

  • Managing device logs through Maintenance Mode, including enabling logging, disabling logging, and retrieving log files

  • Viewing detailed device and agent information from the Management Console

  • Updating or uninstalling the INSIGHT Agent directly from the device management interface

INSIGHT Devices gives administrators complete visibility and control over monitored endpoints, helping ensure consistent policy enforcement, efficient troubleshooting, and effective device management across the organisation.

Session 7: INSIGHT Dashboard

The INSIGHT Dashboard provides a centralised view of user activity, data movement, and risk across the organisation. By bringing together endpoint, cloud, and behavioural monitoring data, it helps administrators and security teams identify unusual activity, investigate incidents, and gain actionable insights from a single interface.

This session explains:

  • Navigating the risk category tabs: Risk Summary, Data Type Risks, SharePoint Risks, AI Usage Risks, Behaviour Risks, Label Events, Location Risks, Protected Files, and System Risks

  • Understanding dashboard widgets, from high-level summary views to detailed incident records

  • Interpreting colour-coded risk levels and their relationship to configured Risk Definitions

  • Exporting dashboard data to Excel or PDF for reporting and analysis

  • Creating Custom Dashboards focused on specific devices, users, data types, or risk categories

  • Viewing, editing, deleting, and switching between dashboards

The INSIGHT Dashboard transforms monitoring data into meaningful insights, enabling organisations to quickly identify risks, investigate incidents, and make informed security decisions.

Session 8: Configuring INSIGHT Reports

Reports in GuardWare INSIGHT deliver risk and activity information to the right stakeholders automatically, reducing the need for manual dashboard reviews. They help security teams, managers, and end users stay informed about risky behaviour through scheduled and customised reporting.

This session explains:

  • Configuring the Risk Summary Report, which provides an organisation-wide overview of risky activities for security teams

  • Configuring the User-Based Risk Report, designed to track risk trends and incident activity for specific users

  • Configuring the Cyber Awareness Report, which is sent directly to end users with information and guidance related to their own activities

  • Setting Incident Thresholds, Data Type Occurrence Thresholds, and Duration Thresholds to determine when reports are generated

  • Customising report branding and content, including cover images, introductory messages, footers, and privacy statements

  • Sending test emails to preview report content before deployment

  • Enabling, editing, and deleting report configurations

INSIGHT Reports ensure that critical risk information is delivered automatically and consistently, helping organisations improve visibility, strengthen security awareness, and support proactive risk management.

Last updated