How to Install SHIELD
10 min
overview shield is a self hosted application deployed in a user's azure app service tenant shield collects and processes all necessary data exclusively within the organization's environment, then returns only abstracted and fully anonymized results back to shi for reporting this guide explains the installation prerequisites, how to install the shield desktop application, and run your first scan installation prerequisites disable network traffic inspection network traffic inspection must be turned off for shield and microsoft endpoints on the device installing shield major cloud service providers do not allow network traffic inspection of their services and shield relies on microsoft azure networking if inspection is not disabled, shield will not install or function properly every organization uses different equipment and processes, so the steps to disable inspection will vary how to proceed if you’re not sure how to disable network traffic inspection, please contact your networking team, security team, or the person in charge of information technology at your organization you can also share the following network endpoints with your networking team to have the addresses excluded from inspection https //api shilab com https //url shilab com https // azurewebsites net your specific deployment url (generated after deployment) common network traffic inspection technologies firewalls (palo alto, fortinet, cisco) secure web gateways (swg) & proxies (zscaler, proxysg) cloud access security brokers (netskope, microsoft defender for cloud apps) data loss prevention (dlp) (microsoft purview dlp, symantec dlp) wan acceleration and optimization (riverbed, cisco waas, nginx caching) vpn & traffic redirection (vpn gateways, sase platforms) for more information about traffic inspection, see network traffic inspection https //url shilab com/network traffic inspection create a dedicated azure subscription sign in to your azure portal enterprise https //portal azure com/ https //portal azure com/ government https //portal azure us/ https //portal azure us/ navigate to subscriptions and click + add if applicable, choose an offer type from the options provided enterprise agreement (ea) customers typically do not have to select an offer type enter a name for the subscription (e g , "shield – production") or similar enterprise agreement (ea) customers assign a billing account and confirm creation global administrator the user installing shield must be a global administrator in order to grant microsoft graph application permissions via admin consent for more information about permissions, see application permissions https //url shilab com/application permissions sign in to your entra id admin center enterprise https //entra microsoft com/ https //entra microsoft com/ government https //entra microsoft us/ https //entra microsoft us/ navigate to roles & admins search for and click on the global administrator role if the user deploying shield is already assigned the global administrator role, no additional action is required if a user needs to be assigned the global administrator role, follow the steps below at the top, click + add assignments click the link under select member(s) check the box next to the desired user and click select you can also use the search bar if needed select your desired settings we recommend the following assignment type active permanently eligible uncheck assignment duration 24 48 hours click assign azure subscription owner make sure the user installing shield is the owner on the azure subscription in order to deploy resources sign in to your azure portal enterprise https //portal azure com/ https //portal azure com/ government https //portal azure us/ https //portal azure us/ navigate to subscriptions and select the subscription to be used with shield click access control (iam) in the left navigation bar click on the role assignments tab if the user deploying shield is already assigned the owner role of the subscription, no additional action is required if a user needs to be assigned the owner role, follow the steps below at the top, click + add and click add role assignment in the drop down menu click on the privileged administrator roles tab click on the owner role so it is highlighted and click next click + select members , click on the desired user account, and click select click next select allow user to assign all roles (highly privileged) click next if applicable, select your desired assignment type settings we recommend the following assignment type active assignment duration permanent once finalized, click review + assign (optional) confirm the role appears in the role assignments tab install and deploy shield shield installation has changed the shield desktop application is now the preferred method, for faster and easier installation why? the desktop application automates most steps, making setup much simpler manual installation if you prefer the manual method, please reach out to an shi employee for guidance and support run the installer to set up shield automatically using the following link https //url shilab com/shield install https //url shilab com/shield install note the download will not work if network traffic inspection is enabled, especially in microsoft/azure environments after installation, launch the shield desktop application log in using the account manager in the top right corner be sure to log in with the account that has the necessary owner and global administrator permissions in azure these are required to grant the necessary permissions for deployment after you are successfully logged in, click on the installer module note an additional tab may open, and another log in may be required select the azure subscription that is dedicated for shield select your desired azure region from the drop down menu west us 3 is recommended, but other regions can be selected depending on company policy click on the toggle switch to display advanced options for operation mode , select discover from the drop down menu click on the deploy button for the shield installer to begin the installation process note an additional tab may open, and another log in may be required the installer will do the following download the shield deploy zip file create a shield app service and managed identity in azure upload and configure the shield application, including permissions and security settings such as disabling basic auth, enabling encryption, and setting quantum resistant cryptography after deployment, verify the following required permissions are granted to the shield managed identity in azure application readwrite all approleassignment readwrite all lastly, assign the read and write everything role to the user who will run shield scans via the "shield end user login" enterprise app in entra sign in to your entra id admin center enterprise https //entra microsoft com/ https //entra microsoft com/ government https //entra microsoft us/ https //entra microsoft us/ navigate to enterprise apps in the navigation bar clear out the enterprise applications filter search for 'shield end user login' and click on the name of the application click users and groups in the left navigation bar click + add user/group click the link under users and groups check the box next to the desired user and click select you can also use the search bar if needed click on the link under select a role search for 'read and write everything', click on the name of the role, and click select click assign running the shield web instance sign in to your azure portal enterprise https //portal azure com/ https //portal azure com/ government https //portal azure us/ https //portal azure us/ navigate to subscriptions and select the subscription dedicated to shield click resource groups click shield click on the app service that starts with "shield xxxxxxxxx" (the x's are a random set of lower case letters and numbers) deactivate health check (one time only) click on the link next to health check uncheck the box next to health check and click apply click save click overview in the left navigation bar in the top right corner, click on the default domain link example shield xxxxxx xxxxxxxx eastus 01 azurewebsites net log in to the shield web instance with the account that has the necessary azure permissions click on discover module click start authentication sync then click start report collection to start scanning the tenant environment during the first scan, shield desktop will open and request account credentials multiple times log in each time as required you will also need to accept each set of permissions once the scan is complete, reports are available on the shield web instance click discover in the left navigation pane and click overview