This guide takes you from a signed order to a live, monitored environment. Most teams complete it in one to two working sessions — after which every source you connect is under analyst-led triage, investigation, and response around the clock. You will need administrative access to the identity provider, endpoint management, and cloud accounts you want covered.
Tip
Have your onboarding engineer on the call for the first source connection. They confirm data is parsing correctly before you invest time connecting the rest.
Prerequisites
- An active Managed SOC subscription and access to the Network Portal.
- Admin rights on the systems you will forward logs from (identity, endpoints, firewall, cloud).
- Outbound TLS (443) allowed from collectors to
*.ingest.intsignal.com.
Deploy the SOC
Confirm your tenant
Sign in to the Network Portal and confirm your organization tenant is provisioned. If you manage multiple entities, verify you are in the correct one (the tenant name appears in the top bar).
Connect identity
Connect your identity provider first — it produces the highest-value signals (sign-ins, MFA, privilege changes). Follow Single sign-on to authorize the read-only connector for Microsoft Entra ID, Okta, or Google Workspace.
Forward endpoint telemetry
Enable the endpoint connector from your EDR/MDM. If you use the intSignal Security Suite, telemetry is on by default — no agent to install. For third-party EDR, add the intSignal integration and paste the ingest key from Portal → Settings → Integrations.
Add network and cloud sources
Point firewall, DNS, and cloud audit logs (AWS CloudTrail, Azure Activity, GCP Audit) at the ingest endpoint. See Supported log sources for per-source steps.
Verify end to end
In the Portal, open SOC → Data health. Each connected source should show a green status and a recent event timestamp. Then trigger the built-in test detection (SOC → Run test alert) and confirm it appears as a case within a few minutes.
Confirm coverage
Once sources are healthy, your onboarding engineer reviews the detection coverage map with you and tunes noisy rules against your baseline. Expect a short tuning period — typically the first two weeks — while the SOC learns what "normal" looks like in your environment.
Warning
Until data health is green for identity and endpoints, coverage is partial. Do not consider onboarding complete until the test alert reaches a case and your escalation contacts are confirmed.
Next steps
- Complete the Onboarding checklist.
- Set escalation contacts and response authorizations in Alert handling & escalation.
