Skip to main content

Preliminary Guide

info

Document Scope
Customer Preparation 1 ~ 2 is independent of the cloud services in use.Commonis applied.
Customer preparation 3 ~ 5 isMicrosoft 365 Environment StandardsThis is. The prerequisites for the Google Workspace environment (service account, domain-wide delegation, adding shared drive members, etc.) are provided in a separate document.

Preparation #1 | Security365 Portal Membership Registration and Setup

Adding and Configuring Users in the Security365 Portal: Users are added through the 'User Synchronization' menu on the User Management page. Only users registered in the cloud service being used can be added, and all users within the organization are automatically added.

  • Microsoft 365— Synchronizing users registered with Microsoft. We are working on improvements to allow synchronization of only group users through AD policy groups.
  • Google Workspace— Synchronize users registered in the Google Workspace domain.

To sign up and set up, you need the administrator account of the cloud service you are using. For detailed permission requirements in the Microsoft 365 environment, please refer to [Customer Preparation 3].

Preparation in Advance #2 | Allowing Firewall

Service Configuration/Operation Related Allowed Processing URL:

Product ClassificationURLPurposeUser FirewallAdministrator FirewallNote
Commonlogin.security365.comIntegrated Authentication ServiceOO
Commonlogin.security365.comIntegrated Authentication ServiceOO
Commonlogin.security365.comIntegrated Log TransmissionOO
Commonportal.security365.comSecurity365 Management Center Page (Front)XO
Commonspsvr.security365.comSecurity365 Management Center Page (Backend)XO
SHIELD DRMSHIELD DRM.security365.comSHIELD DRM Admin Page (Front)XO
SHIELD DRMssevtr.security365.comSHIELD DRM User/Admin Backend ServiceOO
SHIELD DRMskms.security365.comSHIELD DRM Admin Page Key Lookup Backend ServiceXO
SHIELD Driveshieldrive.security365.comSHIELDrive User/Admin Page (Front)OOExclusion when SHIELD Drive is not in use
SHIELD Drivewebdav.security365.comFile Upload/Download Used in SHIELDriveOOExclusion when SHIELD Drive is not in use
SHIELD Drivedms.security365.comDocument web viewer service used in SHIELDriveOXExclusion when SHIELD Drive is not in use
  • The service URL for using Microsoft 365 or Google Workspace services must be allowed by the customer company itself.
  • For customers using SHIELD DRM, if there is a policy that prohibits web access on the client, it may be necessary to partially allow sklogin.security365.com.

Preparation in Advance #3 | Microsoft Admin Rights and Licenses

Security 365 Portal registration and service usage requires permissions: When registering for the Security365 Portal, administrator permissions are required to use the service.**Microsoft License (Recommended E3)**You need a global administrator assigned or an administrator account with specific permissions.

[Required Microsoft Management Permissions]
If you are not a global administrator or do not have global administrator privileges, you need the permissions of 'Privileged Role Administrator', 'Cloud Application Administrator', 'Office Apps Administrator', 'Teams Administrator', 'SharePoint Administrator'.

[How to Check MS Administrator Permissions]
Access with an admin account at Portal.azure.com > Azure Active Directory > Users > Search and select the admin account > Select assigned roles

Preparation in Advance #4 | Check Microsoft MIP Labels

Check and create MIP labels: When converting to MIP documents in SHIELD DRM, the MIP labels created/used by the customer are required. If MIP labels are not created, log in to the Microsoft Compliance Center with an administrator account and create labels in the [Information Protection] – [Labels] menu.

Click the 'Create Label' button to generate a sensitivity label. (Administrators who can set labels must have 'Global Administrator' or 'Compliance Administrator' permissions.)

Label creation, publishing, and policy updates may take 4-8 hours to reflect for users. For detailed information on label creation and publishing methods, please refer to Microsoft Learn.

Preparation in Advance #5 | Check Microsoft Tenant Name

Check the tenant name in the Azure Portal: The name written before '.onmicrosoft.com' in the 'Custom Domain Name' menu of the Azure Portal is the [tenant name]. For example) in security365demo.onmicrosoft.com, security365demo is the tenant name.