This guide rolls out the Security Suite across your organization. Plan a phased deployment — a pilot group first, then the rest — so you can validate before going wide.
Prerequisites
- Network Portal access with the Admin role.
- Your device-management tool (Intune, Jamf, or similar) for at-scale agent deployment, or local admin for manual installs.
- Admin access to your email tenant and identity provider.
Deploy endpoint protection
Get the installer
In the Portal, go to Security Suite → Endpoints → Deploy and download the installer or copy the deployment command and enrollment token.
Pilot
Deploy to a small pilot group first. Confirm each device shows protected in the Portal and that everyday apps behave normally.
Roll out at scale
Push the agent through your device-management tool to the rest of the fleet. Track enrollment progress in the Portal.
Connect email & identity
- Email: add the email-security connector for your mail platform under Security Suite → Email. It begins scanning inbound mail immediately.
- Identity: connect your IdP (if not already connected for the SOC) to enable account-takeover and risky-sign-in detection. See Single sign-on.
Confirm protection
In Security Suite → Overview, verify:
- Endpoint enrollment covers your device count.
- Email scanning shows recent activity.
- Identity protection is connected.
With all three connected you have centralized endpoint and identity security in one inventory — protection status, detections, and user risk in a single view instead of three consoles.
Because Suite telemetry feeds the Managed SOC, you should also see the sources reporting green under SOC → Data health.
Warning
Roll out in waves and keep the pilot running for a few days before going wide. A phased deployment catches app-compatibility issues before they affect everyone.
