Skip to main content

Before you log in

ThreatAware Protect is provisioned by your ThreatAware account team. You’ll receive:
  • Your Cloud ID — the unique subdomain you’ll use to access Protect (e.g. https://acme.threataware.com)
  • Initial credentials — typically a Super Admin account for an internal IT contact
  • A welcome packet outlining onboarding sessions
No self-service signup. Protect is enterprise-only. If you reached this page without an account, get in touch via the website or your security partner.

First login

1

Browse to your Cloud ID

https://<your-cloud-id>.threataware.com
2

Sign in

Either:
  • Username + password from your welcome email
  • Single Sign-On (SSO) via the SSO button on the login screen (only works if SSO has been pre-configured — usually not on day one)
3

Land on Device Explorer or Dashboard

Default landing page is configurable in Settings → Misc. New tenants typically land on the dashboard.
4

Run the dashboard tour

A 9-step in-product tour appears on first visit. Two minutes; introduces every Dashboard panel. See Tour.

What ThreatAware connects to

Protect’s mission is to connect to every platform that knows about devices in your environment. On day one, focus on the foundational connections:

Identity

  • Microsoft Entra ID (Azure AD)
  • Okta
  • On-prem Active Directory
  • Google Workspace

EDR (Endpoint Detection and Response)

  • CrowdStrike Falcon
  • Microsoft Defender ATP
  • SentinelOne
  • Cortex XDR (Extended Detection and Response)

MDM (Mobile Device Management)

  • Microsoft Intune
  • JAMF Pro
  • Workspace ONE

Network scanning

  • Lansweeper
  • PDQ Inventory
Each connection has its own setup. The Connection Guides tab has step-by-step instructions for every supported integration.

Day-one priorities

The recommended order:
1

1. Microsoft Entra ID (5 min)

OAuth-based. Provides cloud-device discovery, Multi-Factor Authentication (MFA) tracking, conditional access state.Settings → Integrations → search “Azure AD” → Connect → Global Admin consent.
2

2. Microsoft Intune (5 min)

Same OAuth flow as Entra ID, shares credentials. Provides MDM compliance, software inventory, encryption state.
3

3. Microsoft Defender ATP (5 min)

Same OAuth flow. Provides EDR Vitals + vulnerability data.
4

4. Your primary EDR (5-10 min)

If you use CrowdStrike, SentinelOne, or Cortex XDR rather than Defender, connect it now. Provides EDR coverage data — critical for Vitals.
5

5. On-prem Active Directory (15 min)

Requires the PowerShell Relay. Provides on-prem device discovery and user information.
6

6. Wait for initial syncs

Each integration’s first sync takes 15-60 minutes depending on estate size.
7

7. Validate via X-Ray

Open any known device → X-Ray → confirm the expected sources are reporting.
After these five integrations, you have ~80% of typical estate visibility. Add more in week 2.

Microsoft integrations need Global Admin (once)

Microsoft Entra ID, Intune, and Defender all require a Global Admin to authorise the initial application consent. After that, Protect only requests read-only permissions for ongoing operation.
The Microsoft integrations share OAuth — once you’ve authorised one, the others connect with one click.

On-prem tools need the PowerShell Relay

For Active Directory, System Center Configuration Manager (SCCM), or any on-prem tool without a cloud API, you’ll deploy the PowerShell Relay — a small PowerShell script that runs on a Windows server inside your network and relays queries to Protect over outbound HTTPS only. No inbound firewall changes. No DMZ. No port forwarding.

Single Sign-On setup

For organisations that prefer SSO over passwords:
  1. [Settings] → Single Sign-On in Protect
  2. Click Enable Single Sign-On
  3. Authorize the setup application as Global Admin
  4. Wait 30 seconds (critical — for the setup app to propagate)
  5. Click Enable in stage 2 — Protect auto-creates the Enterprise Application
  6. Existing users with matching Entra ID mail attributes get SSO automatically
See Access Control → SSO for the full walk-through.
SSO matches on the mail attribute, not User Principal Name (UPN). Confirm your users have mail populated before enabling SSO — otherwise sign-ins will fail with “user not found”.

Multi-tenancy

If you have multiple instances of the same tool (multiple Entra ID directories, separate CrowdStrike instances, etc.), enable Multi-Tenancy on the integration once the first tenant is connected. For MSPs / MSSPs with truly separate customer environments, strict tenant isolation is available (contact support).

Configuring tags

After your first integrations are syncing, decide on a tag strategy:
  • Walk through Settings → Tags — review the defaults
  • Build a 4-6 tag taxonomy that captures your estate (End-User, Server, VM, Mac, plus regional or business-unit tags)
  • Define Logic Engine rules for each
  • Check the Coverage Explorer to confirm no devices fall into zero tags
Tags drive Vitals scope, Action targeting, and access control — get them right early.

Validating onboarding is complete

You’re ready to move to the Getting Started phase when:
  • ✓ At least 4 integrations show CONNECTED with recent syncs
  • ✓ Device Explorer globe shows devices in expected regions
  • ✓ Device count on the Dashboard looks plausible (within 10% of your IT estate)
  • ✓ Tag rules apply correctly (verify via Coverage Explorer)
  • ✓ At least one Vital column shows healthy/unhealthy split as expected
  • ✓ Sample devices in X-Ray show data from multiple sources
If any of these look wrong, the Troubleshooting page covers common causes.

What happens next

After onboarding:
  1. Getting Started — your first 24 hours of operation
  2. Configure Vitals for each connected control
  3. Build your first saved view and Scheduled Report
  4. Wire your first Action
  5. Explore Reporting for custom dashboards

Support during onboarding

The ThreatAware team will be in close contact during initial onboarding — typically 2-4 calls in the first two weeks.

See also

Getting Started

Your first 24 hours of operation

Platform Overview

Architecture and concepts

Connection Guides

Step-by-step per integration