Data Governance Edition supports the scanning of folders hosted on SharePoint Online and OneDrive for Business.
NOTE: Before adding a cloud managed host, One Identity Manager must be configured to use Azure Active Directory and SharePoint Online. See the following One Identity Manager documents for instructions on configuring and synchronizing the data from these target systems with the One Identity Manager Service:
- One Identity Manager Administration Guide for Connecting to Azure Active Directory
- One Identity Manager Administration Guide for Connecting to SharePoint Online
These One Identity Manager documents can be found on the One Identity support site: https://support.oneidentity.com/identity-manager/technical-documents
To add a cloud managed host
- In the Navigation view, select Data Governance | Managed hosts.
-
In the Managed hosts view, select Manage Cloud host from the Tasks view or right-click menu.
You are redirected to Microsoft to sign in to your account and grant access to Office 365 data.
-
On Microsoft's Sign in to your account dialog, enter the administrator account login credentials to be used to authenticate with the Data Governance Edition API cloud proxy.
Note:Data Governance Edition only supports one Office 365 domain per cloud provider at this time. That is, you can deploy only one managed host for the SharePoint Online administrator account and one managed host for the OneDrive for Business administrator account. Data Governance Edition does not currently block you from deploying a second SharePoint Online or OneDrive for Business managed host; however, it will not work.
Note: You must use a separate administrator account for this purpose. This administrator account must be, or have equal access as, a SharePoint Online Administrator. Each site will be modified to list this account as a Site Collection Administrator for the site. This provides the account with access to the site's contents.
-
Email, phone, or Skype: Enter the email address of the administrator account to be used to grant access to your Office 365 domain. For example: Administrator@MyDomain.onmicrosoft.com.
Click Next.
-
Password: Enter the password associated with the specified email.
Click Sign In.
After successfully signing in, the Managed Host Settings dialog appears allowing you to configure your cloud managed host.
-
- At the top of the Managed Host Settings dialog, specify the following information:
- Managed Host: This field will remain blank.
- Host Type: Select the type of cloud provider: SharePoint Online or OneDrive for Business.
-
Agent Install Path: (Optional) Use this field to specify an alternate installation location. This must be a local path (for example, C:\MyPath) and cannot exceed 512 characters.
NOTE: By default, this field displays Use default install directory and the agent is installed in the Data Governance agent services installation directory (%ProgramFiles%\One Identity\One Identity Manager Data Governance Edition\Agent Services).
- Keywords: (Optional) Enter a keyword which can be displayed and used to group managed hosts in the Managed hosts view.
- The Cloud Provider page displays a green check mark and message indicating you are authenticated with your Office 365 domain. If you do not see this green check mark and authentication message, use the Re-authenticate button to authenticate with the cloud API proxy.
-
Use the Agents page to select the remote agent and service account to be used to scan the target host.
Note: You can only specify one agent to scan a cloud host.
To add a remote agent:
- Open the Agents page.
- Select the agent: Select the agent host computer to be used to scan the target managed host.
-
Select the service account: Select a service account with sufficient permissions on the selected agent host.
Only previously configured service accounts that are registered with Data Governance Edition are available for selection. For more information, see Readying a service account and domains for deployment.
-
Click Add to add the agent to the agents list.
-
Use the Managed Paths page to specify the folders under the Documents site to be to be scanned by the agent to create and maintain the security index.
Note: OneDrive for Business support is limited to the Documents folder for the Administrator account. Therefore, all managed paths are selected within the scope of the Administrator's Documents folder.
For SharePoint Online, a site is available for managing, only if it can be navigated on the SharePoint Online website.
To add managed paths:
- Open the Managed Paths page.
- Click the Add button.
-
In the Managed Paths Picker dialog, click the check box to the left of the folders to be scanned.
TIP: A check box appears to the left of the folders that can be selected. Click the expansion box to the left of a container to expand it and navigate to the folders available for scanning.
-
Click OK to save your selections and close the dialog.
The selected paths appear on the Managed Paths page.
-
By default, remote agents scan cloud-based managed hosts daily at 2:00 A.M. Use the Security Scanning page to set the time and frequency with which the agent scans the target computer.
To modify the scanning schedule and settings:
- Open the Security Scanning page.
- Use the controls in the Scanning Schedule pane to define the time and frequency of the agent scans.
-
Use the options at the bottom of the page to modify the default security scanning behavior:
- Immediately scan on agent restart or when managed paths change: Select this check box to perform a full scan whenever the agent restarts or there are changes made to the managed paths.
- Ignore all files and only store folder security data: Clear this check box if you want to include file security data in the security index.
- Click the OK button at the bottom of the Managed Host Settings dialog to save your selections.
Scanning of the specified managed paths begins on the configured schedule. Once the managed host is successfully added (Status is Managed), you are able to see and manage security information for the resources on the target managed host using the Resource browser. Double-click the managed host in the Managed hosts view to display the Resource browser.