Skip to main content
Common questions that come up repeatedly in onboarding, support, and evaluation. Grouped by topic. If you don’t see your question here, check Troubleshooting for symptom-driven answers or Glossary for terminology.

Setup

There is no self-service signup. Protect is provisioned by the ThreatAware account team. Get in touch via threataware.com or your security partner — see Onboarding.
Your tenant’s unique subdomain on *.threataware.com (e.g. https://acme.threataware.com). Provided in your welcome email at provisioning.
Connecting one OAuth integration (e.g. Microsoft Entra ID) takes about five minutes. A full first-day setup — identity + EDR + MDM + on-prem AD — usually takes 30-60 minutes plus first-sync wait time. See Onboarding for the step-by-step.
No. Protect is 100% API-based. The only optional install is the PowerShell Relay — a small Windows service that lets Protect query on-premises tools without inbound firewall rules.
Microsoft Entra ID if you’re a Microsoft shop — it’s OAuth, fast, and gives you cloud-device discovery plus identity in one step. Otherwise your primary EDR. See Onboarding for the recommended order.
Typically 15-60 minutes depending on estate size. Live integration cards show “Last synced N minutes ago” on the Settings → Integrations page.

Devices

Three usual causes:
  1. Protect deduplicates across tools (right answer; the total will look lower than the sum of all tool counts)
  2. Active vs. Inactive filter (Protect defaults to Active — devices not seen within the Inactive device threshold are hidden)
  3. The other tool counts archived / deleted devices that Protect filters out
Use X-Ray on a specific device to see exactly which tools see it.
A device is Active if at least one connected source has seen it within the Inactive device threshold (default 30 days, configurable in Settings → Misc). Beyond that threshold it becomes Inactive and is hidden from default views, dashboard counts, and Vitals calculations.
No — and that’s intentional. Protect reflects reality from your tools. If a device should be gone, decommission it in the source tool; it’ll drop out of Protect within the Inactive threshold. You can also configure a Device retention policy to clean up records that have been removed from all source tools.
The matching algorithm couldn’t fuse the records. Open X-Ray on each row — if no integration overlaps, they’re genuinely different devices. If they overlap, contact support. See Troubleshooting → Devices.
Geolocation comes from public IP. VPN egress or NAT’d IPs often geolocate to the wrong country. Configure overrides in Settings → IP Locations.
A device detected by network-scanning integrations (Lansweeper, Qualys, etc.) that isn’t visible in any of your management tools. See Stealth Devices and the Network Inventory page.

Integrations

Hourly from every integration as a default cadence. Processing adds 5-30 minutes after each sync. To force a sync immediately, go to Settings → Integrations → click the integration → Sync Now.
Possibly — contact your account manager with the vendor name and their API documentation. Typical turnaround for a new integration is a few weeks.
Credentials have been revoked or expired. Open the card → Modify → re-enter credentials or re-run the OAuth flow. See Troubleshooting → Integrations.
You have multiple tenants of the same vendor tool (e.g. two Entra ID directories). Enable Multi-Tenant on the integration so devices match across tenants — see Multi-Tenancy.
Only for on-premises tools that aren’t exposed to the internet — typically Active Directory, SCCM, and similar. Cloud SaaS integrations connect directly. See PowerShell Relay.
Read scopes only — Protect never writes back to the source tools through its integrations. See the Microsoft Graph Required Permissions guide for the exact scope list.

Security & access

The Protect platform reads from your tools through API integrations. Actions can write to downstream systems you opt in to (e.g. open a ServiceNow ticket, post to Teams, call a custom webhook), but those are explicit outbound automations you configure. See Trust & Security.
ISO 27001 and Cyber Essentials. Full details in Trust → Certifications.
Four default roles (Super Admin, Analyst, Viewer, Limited Viewer), plus custom roles, plus per-user data filters and field-level hiding. See Access Control and Role Permissions.
Yes — Microsoft Entra ID (self-service), Okta (manual setup), and generic SAML / OIDC. See Access Control.
Yes. The Audit Log permission is role-gated — Analysts see their own entries by default; Viewer and Limited Viewer see nothing. Configure in Settings → Roles. See Audit Log Events for what’s recorded.
See Trust → Architecture for the hosting and data-residency picture.
An EDR or security agent that’s deployed and looks healthy in its own console but has stopped reporting. Protect detects these via cross-tool correlation. See Silent Failure.

Billing & licensing

Pricing is per-tenant and varies with scale and tier. Speak to your account team — there’s no public price list.
Evaluation access is arranged through the account team rather than self-service. See Quickstart.
A unified device record in the Devices grid after deduplication. Five integrations all reporting the same laptop count as one device.

Cross-references

Troubleshooting

Symptom-driven fixes

Glossary

A-Z terms

Onboarding

First-day setup

Trust & Security

Architecture, certifications, data handling

Support

When the docs don’t have it