Skip to main content

Preliminary Guide

Customer Preparation 1 | Microsoft Admin Rights and Licenses

Security 365 Portal registration and service usage requires permissions: When registering for the Security365 Portal, administrator permissions are required to use the service. A global administrator or an administrator account with specific permissions that has been assigned a **Microsoft license (E3 recommended)** is needed.

[Required Microsoft Management Permissions]
If you are unable to become a global administrator or receive global administrator privileges, you need the following permissions: 'Privileged Role Administrator', 'Cloud Application Administrator', 'Office Apps Administrator', 'Teams Administrator', 'SharePoint Administrator' permissions.

[How to Check MS Administrator Privileges]
Access with an administrator account at Portal.azure.com > Azure Active Directory > Users > Search and select the administrator account > Select assigned roles

Customer Preparation 2 | Microsoft MIP Label Verification

Check and create MIP labels: When converting to MIP documents in SHIELD DRM, the MIP labels created/used by the customer are required. If MIP labels are not created, log in to the Microsoft Compliance Center with an administrator account and create labels in the [Information Protection] – [Labels] menu.

Click the 'Create Label' button to generate a sensitivity label. (Administrators who can set labels must have 'Global Administrator' or 'Compliance Administrator' permissions.)

Label creation, publication, and policy updates may take 4 to 8 hours to reflect for users. Detailed information on how to create and publish labels can be found on Microsoft Learn.

Customer Preparation 3 | Confirm Tenant Name

Check the tenant name in the Azure Portal: The name written before '.onmicrosoft.com' in the 'Custom domain names' menu of the Azure Portal is the [tenant name]. For example) In security365demo.onmicrosoft.com, security365demo is the tenant name.

Customer Preparation 4 | Security365 Portal Membership Registration and Settings

Adding and Configuring Users in the Security365 Portal: Add Microsoft users through the 'User Sync' menu on the User Management page. Only users registered with Microsoft can be added, and all users within the organization will be automatically added. We are currently working on improvements to allow synchronization of only group users through AD policy groups.

Customer Preparation 5 | Firewall Allowance

Service Configuration/Operation Related Allowed Processing URL:

Product ClassificationURLUsageUser FirewallAdministrator FirewallNote
Commonlogin.security365.comIntegrated Authentication ServiceOO
Commonlogin.security365.comIntegrated Authentication ServiceOO
Commonlogin.security365.comIntegrated Log TransmissionOO
Commonportal.security365.comSecurity365 Management Center Page (Front)XO
Commonspsvr.security365.comSecurity365 Management Center Page (Backend)XO
SHIELD DRMSHIELD DRM.security365.comSHIELD DRM Admin Page (Front)XO
SHIELD DRMssevtr.security365.comSHIELD DRM User/Admin Backend ServiceOO
SHIELD DRMskms.security365.comSHIELD DRM Admin Page Key Retrieval Backend ServiceXO
SHIELD Driveshieldrive.security365.comSHIELDrive User/Admin Page (Front)OOExclusion when SHIELD Drive is not in use
SHIELD Drivewebdav.security365.comFile Upload/Download Used in SHIELDriveOOExclusion when SHIELD Drive is not in use
SHIELD Drivedms.security365.comDocument web viewer service used in SHIELDriveOXExclusion when SHIELD Drive is not in use

* The service URL for using Microsoft365 services must be allowed by the customer company itself.

** For customers using SHIELD DRM *, if there is a policy that prohibits web access on the client, it may be necessary to partially allow sklogin.security365.com.