How to Install SHIELD
SHIELD is the data collection and processing layer that powers Microsoft Insights. If your organization plans to use Microsoft Insights, SHIELD must be installed and configured in your Azure environment using this installation guide. If you need help at any point, contact your IT or cloud team, or reach out to your SHI representative. For more details, see Microsoft InsightsMicrosoft Insights.
Overview
SHIELD is a self-hosted application deployed in a user's Azure App Service tenant. SHIELD collects and processes all necessary data exclusively within the organization's environment, then returns only abstracted and fully anonymized results back to SHI for reporting. This guide explains the installation prerequisites, how to install the SHIELD - Desktop application, and run your first scan.
Installation Video
Installation Prerequisites
Pricing
Azure Cost Estimate associated (As of 9/25/2026)
User Count | Premium v4 Service Plan | vCPU(s) | RAM | Storage | Pay as you go | 1 year savings plan | 3 year savings plan | 1 year reserved | 3 year reserved |
|---|---|---|---|---|---|---|---|---|---|
< 10,000 Users | P0v4 | 1 | 4 GB | 250 GB | $53.29/month | $36.771/month ~31% savings | $24.514/month ~54% savings | $31.420/month ~41% savings | $20.251/month ~62% savings |
> 10,000 Users | P1v4 | 2 | 8 GB | 250 GB | $106.58/month | $73.541/month ~31% savings | $49.027/month ~54% savings | $62.919/month ~41% savings | $40.501/month ~62% savings |
Disable Network Traffic Inspection
Network traffic inspection must be turned off for SHIELD and Microsoft endpoints on the device installing SHIELD. Major cloud service providers do not allow network traffic inspection of their services and SHIELD relies on Microsoft Azure networking. If inspection is not disabled, SHIELD will not install or function properly.
Every organization uses different equipment and processes, so the steps to disable inspection will vary.
How to Proceed:
- If you’re not sure how to disable network traffic inspection, please contact your networking team, security team, or the person in charge of information technology at your organization.
- You can also share the following network endpoints with your networking team to have the addresses excluded from inspection:
- https://api.shilab.com
- https://url.shilab.com
- https://*.azurewebsites.net - Your specific deployment URL (generated after deployment)
Common Network Traffic Inspection Technologies
- Firewalls (Palo Alto, Fortinet, Cisco)
- Secure Web Gateways (SWG) & Proxies (Zscaler, ProxySG)
- Cloud Access Security Brokers (Netskope, Microsoft Defender for Cloud Apps)
- Data Loss Prevention (DLP) (Microsoft Purview DLP, Symantec DLP)
- WAN Acceleration and Optimization (Riverbed, Cisco WAAS, nginx caching)
- VPN & Traffic Redirection (VPN gateways, SASE platforms)
For more information about traffic inspection, see Network Traffic Inspection.
Create a Dedicated Azure Subscription
- Sign in to your Azure portal.
- Enterprise: https://portal.azure.com/
- Government: https://portal.azure.us/
- Navigate to Subscriptions and click + Add.
- If applicable, choose an offer type from the options provided. Enterprise Agreement (EA) customers typically do not have to select an offer type.
- Enter a name for the subscription (e.g., "SHIELD – Production") or similar.
- Enterprise Agreement (EA) customers: Assign a billing account and confirm creation.
Permissions
Installing User: The user installing SHIELD must be a Global Administrator in order to grant Microsoft Graph application permissions via admin consent.
Application: SHIELD Desktop must be granted Application.ReadWrite.All and AppRoleAssignment.ReadWrite.All permissions by the user installing SHIELD or another admin. For more information about permissions, see Application Permissions.
- Sign in to your Entra ID admin center.
- Enterprise: https://entra.microsoft.com/
- Government: https://entra.microsoft.us/
- Navigate to Roles & admins.
- Search for and click on the Global Administrator role.
- If the user deploying SHIELD is already assigned the Global Administrator role, no additional action is required. If a user needs to be assigned the Global Administrator role, follow the steps below:
- At the top, click + Add Assignments.
- Click the link under Select member(s).
- Check the box next to the desired user and click Select. You can also use the search bar if needed.
- Select your desired settings. We recommend the following:
- Assignment type: Active
- Permanently eligible: Uncheck
- Assignment duration: 24-48 hours
- Click Assign.
Azure Subscription Owner
Make sure the user installing SHIELD is the Owner on the Azure subscription in order to deploy resources.
- Sign in to your Azure portal.
- Enterprise: https://portal.azure.com/
- Government: https://portal.azure.us/
- Navigate to Subscriptions and select the subscription to be used with SHIELD.
- Click Access control (IAM) in the left navigation bar.
- Click on the Role assignments tab.
- If the user deploying SHIELD is already assigned the Owner role of the subscription, no additional action is required. If a user needs to be assigned the Owner role, follow the steps below:
- At the top, click + Add and click Add role assignment in the drop-down menu.
- Click on the Privileged administrator roles tab.
- Click on the Owner role so it is highlighted and click Next.
- Click + Select members, click on the desired user account, and click Select.
- Click Next.
- Select Allow user to assign all roles (highly privileged).
- Click Next.
- If applicable, select your desired Assignment type settings. We recommend the following:
- Assignment type: Active
- Assignment duration: Permanent
- Once finalized, click Review + assign.
- (Optional) Confirm the role appears in the Role assignments tab.
Install and Deploy SHIELD
SHIELD Installation Has Changed
The SHIELD - Desktop application is now the preferred method, for faster and easier installation. Why? The desktop application automates most steps, making setup much simpler.
- Run the installer to set up SHIELD automatically using the following link: https://url.shilab.com/shield-install
- Note: The download will not work if network traffic inspection is enabled, especially in Microsoft/Azure environments.
- After installation, launch the SHIELD - Desktop application.
- Log in using the account manager in the top right corner. Be sure to log in with the account that has the necessary Owner and Global Administrator permissions in Azure. These are required to grant the necessary permissions for deployment.
- After you are successfully logged in, click on the Installer module.
- Note: An additional tab may open, and another log in may be required.
- Select the Azure Subscription that is dedicated for SHIELD.
- Select your desired Azure Region from the drop-down menu. West US 3 is recommended, but other regions can be selected depending on company policy.
- Click on the toggle switch to display Advanced Options.
- For Operation Mode, select Discover from the drop-down menu.
- Click on the Deploy button for the SHIELD installer to begin the installation process.
- Note: An additional tab may open, and another log in may be required.
- The installer will do the following:
- Download the SHIELD Deploy ZIP file
- Create a SHIELD App Service and managed identity in Azure
- Upload and configure the SHIELD application, including permissions and security settings such as disabling basic auth, enabling encryption, and setting quantum-resistant cryptography.
- After deployment, grant the following required permissions to the SHIELD managed identity in Azure:
- Application.ReadWrite.All
- AppRoleAssignment.ReadWrite.All
- Lastly, assign the Read and Write Everything role to the user who will run SHIELD scans via the "SHIELD End User Login" enterprise app in Entra.
- Sign in to your Entra ID admin center.
- Enterprise: https://entra.microsoft.com/
- Government: https://entra.microsoft.us/
- Navigate to Enterprise apps in the navigation bar.
- Clear out the Enterprise Applications filter.
- Search for 'SHIELD End User Login' and click on the name of the application.
- Click Users and groups in the left navigation bar.
- Click + Add user/group.
- Click the link under Users and groups.
- Check the box next to the desired user and click Select. You can also use the search bar if needed.
- Click on the link under Select a role.
- Search for 'Read and Write Everything', click on the name of the role, and click Select.
- Click Assign.
Running the SHIELD Web Instance
- Sign in to your Azure portal.
- Enterprise: https://portal.azure.com/
- Government: https://portal.azure.us/
- Navigate to Subscriptions and select the subscription dedicated to SHIELD.
- Click Resource groups.
- Click SHIELD.
- Click on the App Service that starts with "shield-xxxxxxxxx" (the x's are a random set of lower-case letters and numbers).
- Deactivate Health Check (One time only)
- Click on the link next to Health Check.
- Uncheck the box next to Health Check and click Apply.
- Click Save.
- Click Overview in the left navigation bar.
- In the top right corner, click on the Default domain link.
- Example: shield-xxxxxx-xxxxxxxx.eastus-01.azurewebsites.net
- Log in to the SHIELD web instance with the account that has the necessary Azure permissions.
- Click on Discover Module.
- Click Start Report Collection to start scanning the tenant environment.
- Once the scan is complete, reports are available on the SHIELD web instance.
- Click Discover in the left navigation pane and click Overview.