Documentation

Managed SOC · Getting Started

Getting started

Stand up the intSignal Managed SOC: connect telemetry, enable detections, and verify end-to-end that alerts reach an analyst.

This guide takes you from a signed order to a live, monitored environment. Most teams complete it in one to two working sessions — after which every source you connect is under analyst-led triage, investigation, and response around the clock. You will need administrative access to the identity provider, endpoint management, and cloud accounts you want covered.

Tip

Have your onboarding engineer on the call for the first source connection. They confirm data is parsing correctly before you invest time connecting the rest.

Prerequisites

  • An active Managed SOC subscription and access to the Network Portal.
  • Admin rights on the systems you will forward logs from (identity, endpoints, firewall, cloud).
  • Outbound TLS (443) allowed from collectors to *.ingest.intsignal.com.

Deploy the SOC

Confirm your tenant

Sign in to the Network Portal and confirm your organization tenant is provisioned. If you manage multiple entities, verify you are in the correct one (the tenant name appears in the top bar).

Connect identity

Connect your identity provider first — it produces the highest-value signals (sign-ins, MFA, privilege changes). Follow Single sign-on to authorize the read-only connector for Microsoft Entra ID, Okta, or Google Workspace.

Forward endpoint telemetry

Enable the endpoint connector from your EDR/MDM. If you use the intSignal Security Suite, telemetry is on by default — no agent to install. For third-party EDR, add the intSignal integration and paste the ingest key from Portal → Settings → Integrations.

Add network and cloud sources

Point firewall, DNS, and cloud audit logs (AWS CloudTrail, Azure Activity, GCP Audit) at the ingest endpoint. See Supported log sources for per-source steps.

Verify end to end

In the Portal, open SOC → Data health. Each connected source should show a green status and a recent event timestamp. Then trigger the built-in test detection (SOC → Run test alert) and confirm it appears as a case within a few minutes.

Confirm coverage

Once sources are healthy, your onboarding engineer reviews the detection coverage map with you and tunes noisy rules against your baseline. Expect a short tuning period — typically the first two weeks — while the SOC learns what "normal" looks like in your environment.

Warning

Until data health is green for identity and endpoints, coverage is partial. Do not consider onboarding complete until the test alert reaches a case and your escalation contacts are confirmed.

Next steps

Need a hand with Managed SOC?Talk to our team →