MIP Scanner deployment - watch our video!

Published Dec 30 2020 12:26 PM 5,537 Views

Attached is quick video that walks you through our scanner architecture and deployment steps!

FYI - when referring to "Discover and Protect" video we are referring to the Ignite one: Discover and protect your on-premises data using Microsoft Information Protection

 

 

Enjoy!

 

 

9 Comments
Regular Visitor

Good video Mavy :D

Occasional Contributor

Hello @Mavi Etzyon-Grizer 

 

Would it possible to have the checklist file

 

Thanks in advance

 

Happy new year 2021

Best Regards

Respected Contributor

Thanks for doing this, watching someone else go through all of the steps is very helpful. Please do more of these for all of the various MIP installation/configuration tasks.

 

Please share the checklist also. 

@Mavi Etzyon-Grizer 

Occasional Contributor

Hello @Mavi Etzyon-Grizer @Dean Gross you can use this

AIP Client: (deployed/in-progress)
Whitelist AIP URLS : (Yes/No)
SQL DB =  (Name) or (SERVER\Instance)

Label Configuration Req
##########################
Create and publish at least one lable to the scanner
Recommended to set up automatic rules, or if not, must use info types to be discovered = All
##########################

Create Scanner cluster = CLUSTERNAME
COntent Scan Job
Network Scan Job (optional)


Configure AAD App and grand permissions
##########################
AppName		=	AIP-ScannerUL
Web URI 	=	https://localhost
AppId		=
AppSecret	=
TenantId	=	XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Rights to give
Azure Rights Management Services (3)
Content.DelegatedReader
Content.DelegatedWriter
Content.SuperUser

Microsoft Information Protection Sync Service (1)
UnifiedPolicy.Tenant.Read

Accounts and apps
###########################
Service Account (AD account) 						= 
DelegatedUser (AAD Account)							= 
Share Admin Account									=
Standard (Weak) Account	(only domain user group)	= 


Installing scanner service
##########################
Installing account
sysadmin + local admin on the scanner

Scanner service account
granted all rights by installing user

$serviceaccount = Get-Credential -Username SERVICEACCOUNTNAME -Message -ScannerAccount

Install-AIPscanner -SqlServerInstance SQLDBNAME -Cluster CLUSTERNAME - ServiceUserCredentials $serviceaccount

Set-AIPAuthentication -AppId "" -AppSecret "" -TenantId "" -DelegatedUser "DELEGATEDUSERNAME" -onBehalfOf $serviceaccount

Verify the installation
##########################
Start-AIPscannerDiagnostics -onBehalfOf $serviceaccount


Network Discovery
##########################
$shareadminaccount = Get-Credential -Username SHAREADMINACCOUNTNAME -Message -ShareAdminAccount
$publicaccount = Get-Credential -Username STANDARDACCOUNTNAME -Message -PublicUser

Install-MIPNetworkDiscovery -SqlServerInstance SQLDBNAME -Cluster CLuSTERNAME - ServiceUserCredentials $serviceaccount -ShareAdminUserAccount $shareadminaccount -StandardDomainUserAccount $publicaccount
Occasional Contributor

BTW the install of MIPnetworkDisovery is not necessary. You better put the Install AIPScanner with all the users necessary. It installs the AIPnetworkdiscovery in the same time

 

BTW try to avoid having proxy on your scanner...this is a real pain..

Occasional Contributor

Hello @Mavi Etzyon-Grizer 

it seems that the SharedAdminAccount  is not use against shared folder/path during a content scan...Is this a bug?

 

Thanks

Microsoft

@ChristopheHumbert Can you please explain what do you mean in your last comment?

Occasional Contributor

Hello @Hen David 

 

I have setup the scanner with 3 different accounts as explained

The service account

The sharedadmin account which has access to the share file

the simple user

 

The content scan was not able to crawl the content of the shared folder. As a temp measure we have allowed the service account to access the fileshare

 

Best regards

Microsoft

@ChristopheHumbert got it.

Can you please raise a support ticket on this?

%3CLINGO-SUB%20id%3D%22lingo-sub-2023588%22%20slang%3D%22en-US%22%3ERe%3A%20MIP%20Scanner%20deployment%20-%20watch%20our%20video!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2023588%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20video%20Mavy%20%3AD%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2024429%22%20slang%3D%22en-US%22%3ERe%3A%20MIP%20Scanner%20deployment%20-%20watch%20our%20video!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2024429%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F115980%22%20target%3D%22_blank%22%3E%40Mavi%20Etzyon-Grizer%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20it%20possible%20to%20have%20the%20checklist%20file%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHappy%20new%20year%202021%3C%2FP%3E%3CP%3EBest%20Regards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2023277%22%20slang%3D%22en-US%22%3EMIP%20Scanner%20deployment%20-%20watch%20our%20video!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2023277%22%20slang%3D%22en-US%22%3E%3CP%3EAttached%20is%20quick%20video%20that%20walks%20you%20through%20our%20scanner%20architecture%20and%20deployment%20steps!%3C%2FP%3E%0A%3CP%3EFYI%20-%20when%20referring%20to%20%22Discover%20and%20Protect%22%20video%20we%20are%20referring%20to%20the%20Ignite%20one%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fwww.youtube.com%252Fwatch%253Fv%253DD8kyAlbstws%26amp%3Bdata%3D04%257C01%257CMavi.Etzyon-Grizer%2540microsoft.com%257C83583904e43b46dbbb2908d8b1b26760%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637454727085289812%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C1000%26amp%3Bsdata%3DDJ3gGfQz9ANE%252B1AjLpCbnDYuvHs800uFocbZ2pyK%252Fxo%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EDiscover%20and%20protect%20your%20on-premises%20data%20using%20Microsoft%20Information%20Protection%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EEnjoy!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2023277%22%20slang%3D%22en-US%22%3E%3CP%3Eprefer%20the%20movie%20and%20not%20the%20book%3F%3C%2FP%3E%0A%3CP%3EWell%20-%20watch%20the%20video%20instead%20of%20the%20article%20and%20learn%20how%20to%20deploy%20our%20scanner!%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2023277%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Information%20Protection%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2068805%22%20slang%3D%22en-US%22%3ERe%3A%20MIP%20Scanner%20deployment%20-%20watch%20our%20video!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2068805%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20doing%20this%2C%20watching%20someone%20else%20go%20through%20all%20of%20the%20steps%20is%20very%20helpful.%20Please%20do%20more%20of%20these%20for%20all%20of%20the%20various%20MIP%20installation%2Fconfiguration%20tasks.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20share%20the%20checklist%20also.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F115980%22%20target%3D%22_blank%22%3E%40Mavi%20Etzyon-Grizer%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2070114%22%20slang%3D%22en-US%22%3ERe%3A%20MIP%20Scanner%20deployment%20-%20watch%20our%20video!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2070114%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F115980%22%20target%3D%22_blank%22%3E%40Mavi%20Etzyon-Grizer%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1096%22%20target%3D%22_blank%22%3E%40Dean%20Gross%3C%2FA%3E%20you%20can%20use%20this%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-markup%22%3E%3CCODE%3EAIP%20Client%3A%20(deployed%2Fin-progress)%0AWhitelist%20AIP%20URLS%20%3A%20(Yes%2FNo)%0ASQL%20DB%20%3D%20%20(Name)%20or%20(SERVER%5CInstance)%0A%0ALabel%20Configuration%20Req%0A%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%0ACreate%20and%20publish%20at%20least%20one%20lable%20to%20the%20scanner%0ARecommended%20to%20set%20up%20automatic%20rules%2C%20or%20if%20not%2C%20must%20use%20info%20types%20to%20be%20discovered%20%3D%20All%0A%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%0A%0ACreate%20Scanner%20cluster%20%3D%20CLUSTERNAME%0ACOntent%20Scan%20Job%0ANetwork%20Scan%20Job%20(optional)%0A%0A%0AConfigure%20AAD%20App%20and%20grand%20permissions%0A%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%0AAppName%20%20%3D%20AIP-ScannerUL%0AWeb%20URI%20%20%3D%20https%3A%2F%2Flocalhost%0AAppId%20%20%3D%0AAppSecret%20%3D%0ATenantId%20%3D%20XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%0A%0ARights%20to%20give%0AAzure%20Rights%20Management%20Services%20(3)%0AContent.DelegatedReader%0AContent.DelegatedWriter%0AContent.SuperUser%0A%0AMicrosoft%20Information%20Protection%20Sync%20Service%20(1)%0AUnifiedPolicy.Tenant.Read%0A%0AAccounts%20and%20apps%0A%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%0AService%20Account%20(AD%20account)%20%20%20%20%20%20%20%3D%20%0ADelegatedUser%20(AAD%20Account)%20%20%20%20%20%20%20%3D%20%0AShare%20Admin%20Account%20%20%20%20%20%20%20%20%20%3D%0AStandard%20(Weak)%20Account%20(only%20domain%20user%20group)%20%3D%20%0A%0A%0AInstalling%20scanner%20service%0A%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%0AInstalling%20account%0Asysadmin%20%2B%20local%20admin%20on%20the%20scanner%0A%0AScanner%20service%20account%0Agranted%20all%20rights%20by%20installing%20user%0A%0A%24serviceaccount%20%3D%20Get-Credential%20-Username%20SERVICEACCOUNTNAME%20-Message%20-ScannerAccount%0A%0AInstall-AIPscanner%20-SqlServerInstance%20SQLDBNAME%20-Cluster%20CLUSTERNAME%20-%20ServiceUserCredentials%20%24serviceaccount%0A%0ASet-AIPAuthentication%20-AppId%20%22%22%20-AppSecret%20%22%22%20-TenantId%20%22%22%20-DelegatedUser%20%22DELEGATEDUSERNAME%22%20-onBehalfOf%20%24serviceaccount%0A%0AVerify%20the%20installation%0A%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%0AStart-AIPscannerDiagnostics%20-onBehalfOf%20%24serviceaccount%0A%0A%0ANetwork%20Discovery%0A%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%0A%24shareadminaccount%20%3D%20Get-Credential%20-Username%20SHAREADMINACCOUNTNAME%20-Message%20-ShareAdminAccount%0A%24publicaccount%20%3D%20Get-Credential%20-Username%20STANDARDACCOUNTNAME%20-Message%20-PublicUser%0A%0AInstall-MIPNetworkDiscovery%20-SqlServerInstance%20SQLDBNAME%20-Cluster%20CLuSTERNAME%20-%20ServiceUserCredentials%20%24serviceaccount%20-ShareAdminUserAccount%20%24shareadminaccount%20-StandardDomainUserAccount%20%24publicaccount%3C%2FCODE%3E%3C%2FPRE%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2073198%22%20slang%3D%22en-US%22%3ERe%3A%20MIP%20Scanner%20deployment%20-%20watch%20our%20video!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2073198%22%20slang%3D%22en-US%22%3E%3CP%3EBTW%20the%20install%20of%20MIPnetworkDisovery%20is%20not%20necessary.%20You%20better%20put%20the%20Install%20AIPScanner%20with%20all%20the%20users%20necessary.%20It%20installs%20the%20AIPnetworkdiscovery%20in%20the%20same%20time%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBTW%20try%20to%20avoid%20having%20proxy%20on%20your%20scanner...this%20is%20a%20real%20pain..%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2078851%22%20slang%3D%22en-US%22%3ERe%3A%20MIP%20Scanner%20deployment%20-%20watch%20our%20video!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2078851%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F115980%22%20target%3D%22_blank%22%3E%40Mavi%20Etzyon-Grizer%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eit%20seems%20that%20the%20SharedAdminAccount%26nbsp%3B%20is%20not%20use%20against%20shared%20folder%2Fpath%20during%20a%20content%20scan...Is%20this%20a%20bug%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2078960%22%20slang%3D%22en-US%22%3ERe%3A%20MIP%20Scanner%20deployment%20-%20watch%20our%20video!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2078960%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F28672%22%20target%3D%22_blank%22%3E%40Hen%20David%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20setup%20the%20scanner%20with%203%20different%20accounts%20as%20explained%3C%2FP%3E%3CP%3EThe%20service%20account%3C%2FP%3E%3CP%3EThe%20sharedadmin%20account%20which%20has%20access%20to%20the%20share%20file%3C%2FP%3E%3CP%3Ethe%20simple%20user%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20content%20scan%20was%20not%20able%20to%20crawl%20the%20content%20of%20the%20shared%20folder.%20As%20a%20temp%20measure%20we%20have%20allowed%20the%20service%20account%20to%20access%20the%20fileshare%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20regards%3C%2FP%3E%3C%2FLINGO-BODY%3E
Version history
Last update:
‎May 11 2021 02:04 PM
Updated by: