Skip to content

Updated customer onboarding + policy structure - #74

Open
jtdauria-shi wants to merge 3 commits into
mainfrom
jtd/installationUpdates
Open

Updated customer onboarding + policy structure#74
jtdauria-shi wants to merge 3 commits into
mainfrom
jtd/installationUpdates

Conversation

@jtdauria-shi

Copy link
Copy Markdown
Contributor

Updated installation, prereqs, network inspection, & app permissions to enhance customer onboarding and converted multiple policy pages into a single page

Updated installation, prereqs, network inspection, & app permissions to enhance customer onboarding and converted multiple policy pages into a single page

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the SHIELD documentation to improve customer onboarding (installation, prerequisites, network inspection, and app permissions) and consolidates many Conditional Access policy pages into a single, unified policy reference page, updating site navigation accordingly.

Changes:

  • Updated SHIELD prerequisites and installation guidance, including new/expanded sections for application permissions and network traffic inspection.
  • Consolidated Conditional Access policy documentation into Entra-Conditional-Access.md and removed the prior per-policy page structure.
  • Updated the documentation navigation (zensical.toml) to reflect the new prerequisites pages and the consolidated policies page.

Reviewed changes

Copilot reviewed 24 out of 24 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
zensical.toml Updates site nav: adds new prerequisites pages and points policy nav to the consolidated Conditional Access page.
docs/SHIELD/Prerequisites/Network-Traffic-Inspection.md Adds a dedicated page describing network traffic inspection expectations and constraints for SHIELD.
docs/SHIELD/Prerequisites/Installation.md Reworks installation/onboarding content to focus on SHIELD Desktop installation and networking requirements.
docs/SHIELD/Prerequisites/index.md Expands prerequisites landing page with pricing, network inspection note, and data security/structure content.
docs/SHIELD/Prerequisites/Application-Permissions.md Renames/reframes permissions guidance and updates links to the revised installation doc.
docs/SHIELD/Deploy/Reference/Policies/Entra-Conditional-Access.md Adds consolidated Conditional Access policy documentation (enterprise + privileged) in one page.
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/User-Risk.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Token-Binding.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Sign-In-Risk.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Session-Persistence.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/OS-Enforcement.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/MFA.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Location.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Legacy-Auth.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Join-Type.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Hardware-Enforcement.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Disable-CA-Resilience-Downgrade.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Compliance.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Block-Non-Priv.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Authentication-Methods.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Enterprise/Conditional-Access/MFA.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Enterprise/Conditional-Access/MDCA.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Enterprise/Conditional-Access/Location.md Removes legacy per-policy page (content moved into consolidated policy doc).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Enterprise/Conditional-Access/Compliance.md Removes legacy per-policy page (content moved into consolidated policy doc).
Comments suppressed due to low confidence (2)

docs/SHIELD/Prerequisites/Installation.md:13

  • This paragraph contains a duplicated phrase ("tools like tools like") and the sentence "Traffic inspection must be excluded from network inspection" is self-contradictory. Tighten wording so it clearly states what must be excluded from inspection.
For a smooth installation, network traffic inspection must be disabled on the device installing SHIELD. If inspection is enabled, Microsoft will drop the traffic, and SHIELD will not function properly. This includes tools like tools like Palo, Zscaler, or nginx (caching). Traffic inspection must be excluded from network inspection according to Microsoft's terms and conditions. For more information, see [Microsoft Documentation](http://aka.ms/pnc){:target="_blank"}.

docs/SHIELD/Prerequisites/Application-Permissions.md:26

  • Subject/verb agreement: "The permission … are" should be plural ("permissions … are") since multiple items are referenced. This reads like a typo in a customer-facing note.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

## Overview

This application is a self-hosted application that exists in the customer tenant on an Azure App Service, collecting and processing the requisite data only within the customer tenant before provided abstracted & fully anonymized data results back to SHI for reporting. All requirements can be set up by the delivery team or customer prior to engagement.
SHIELD is a self-hosted application that exists in the customer tenant on an Azure App Service, collecting and processing the requisite data only within the customer tenant before provided abstracted & fully anonymized data results back to SHI for reporting. All requirements can be set up by the delivery team or customer prior to engagement. This guide explains how to install the SHIELD - Desktop application and run your first scan. For more information about requirements, pricing, and more, see [Prerequisites](./).
Comment thread docs/SHIELD/Prerequisites/index.md Outdated

## How it Works

- **Data Collection**: Traffic inspection tools intercept and record packets or flows of strategic points in the network. This can be done in the perimeter (edge), within core segments, or in cloud environments.
Comment thread docs/SHIELD/Deploy/Reference/Policies/Entra-Conditional-Access.md Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 24 out of 24 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (9)

docs/SHIELD/Prerequisites/Installation.md:13

  • Duplicate wording (“tools like tools like”) and unclear phrasing (“Traffic inspection must be excluded from network inspection”). This reads like an editing artifact and is confusing for customers trying to implement the requirement.
For a smooth installation, network traffic inspection must be disabled on the device installing SHIELD. If inspection is enabled, Microsoft will drop the traffic, and SHIELD will not function properly. This includes tools like tools like Palo, Zscaler, or nginx (caching). Traffic inspection must be excluded from network inspection according to Microsoft's terms and conditions. For more information, see [Microsoft Documentation](http://aka.ms/pnc){:target="_blank"}.

docs/SHIELD/Prerequisites/Application-Permissions.md:26

  • Grammar: “The permission marked with '✅' are …” mixes singular/plural and reads incorrectly.
    docs/SHIELD/Prerequisites/Network-Traffic-Inspection.md:18
  • Grammar: “packets or flows of strategic points” is missing a preposition and reads incorrectly (should be “at strategic points”).
- **Data Collection**: Traffic inspection tools intercept and record packets or flows of strategic points in the network. This can be done in the perimeter (edge), within core segments, or in cloud environments. 
- **Analysis**: Captured data is analyzed for patterns, threats, and performance bottlenecks. Deep packet inspection (DPI) may be used by tools to examine the contents of packets, or flow monitoring to summarize communication between endpoints. 

docs/SHIELD/Prerequisites/index.md:116

  • Spelling/terminology: “Principle Object ID” should be “Principal Object ID” (principal = identity/object; principle = concept).
- Principal ID that saved the report
- Principal ID that ran the report
- Principle Object ID
    - Assigned License – The Service Plan IDs of the license(s) that are assigned (direct or indirect) to the specific principal
    - Assigned Services – The service configuration assignment determining 'benefitting' from a service. This includes the service configuration type if possible (feature, such as 'Conditional Access,' a service within the Entra ID license)

docs/SHIELD/Deploy/Reference/Policies/Entra-Conditional-Access.md:125

  • There are two consecutive horizontal rules before the Privileged section, and the Privileged heading is another H1. This creates redundant separators and inconsistent heading hierarchy.
---

---

# Privileged

---

zensical.toml:16

  • This nav change removes the old Required-Graph-API-Permissions page, but there are still in-repo links pointing to it (e.g., docs/SHIELD/Reference/Settings/Configure-Managed-Identity.md links to ../../Prerequisites/Required-Graph-API-Permissions). That link will now be broken in the published site.
    {"Prerequisites" = [
        {"Overview" = "SHIELD/Prerequisites/index.md"},
        {"Installation" = "SHIELD/Prerequisites/Installation.md"},
        {"Application Permissions" = "SHIELD/Prerequisites/Application-Permissions.md"},
        {"Network Traffic Inspection" = "SHIELD/Prerequisites/Network-Traffic-Inspection.md"}
    ]},

docs/SHIELD/Prerequisites/Installation.md:5

  • Grammar/link target: “before provided” is ungrammatical, and linking to a directory via (./) is non-standard in this repo (other internal links point to explicit .md files). This may produce a broken link depending on the site generator.

This issue also appears on line 13 of the same file.

SHIELD is a self-hosted application that exists in the customer tenant on an Azure App Service, collecting and processing the requisite data only within the customer tenant before provided abstracted and fully anonymized data results back to SHI for reporting. All requirements can be set up by the delivery team or customer prior to engagement. This guide explains how to install the SHIELD - Desktop application and run your first scan. For more information about requirements, pricing, and more, see [Prerequisites](./).

docs/SHIELD/Prerequisites/index.md:22

  • This page already has a top-level H1 (“# Prerequisites”). Additional H1 headings (“# Pricing”, “# Network Traffic Inspection”) can break page structure/TOC and is inconsistent with other SHIELD docs (generally a single H1 per page). These should be H2 headings.

This issue also appears on line 112 of the same file.

# Pricing

## Azure Cost Estimate Associated (as of 7/28/2026):

| Premium v4 Service Plan | vCPU(s) | RAM | Storage | Pay as you go | 1 year savings plan | 3 year savings plan | 1 year reserved | 3 year reserved |
|-----------------|-------------------|---------------------|-----------------|-------------------|---------------------|-----------------|-------------------|---------------------|
| P0v4 | 1 | 4 GB | 250 GB | **$53.29**/month | **$36.771**/month ~ 31% savings | **$24.514**/month ~ 54% savings | **$31.420**/month ~ 41% savings | **$20.251**/month ~ 62% savings |
| P1v4 | 2 | 8 GB | 250 GB | **$106.58**/month | **$73.541**/month ~ 31% savings | **$49.027**/month ~ 54% savings | **$62.919**/month ~ 41% savings | **$40.501**/month ~ 62% savings |


---

# Network Traffic Inspection


Network traffic inspection must be turned off on the device where SHIELD is being installed. This ensures the installation process proceeds without interruption and prevents any disruption to the application’s functionality. To disable network traffic inspection, reach out to your networking team, security team, or the person in charge of information technology at your organization. Each organization manages its own inspection tools and policies, and there is no universal method.

docs/SHIELD/Deploy/Reference/Policies/Entra-Conditional-Access.md:5

  • This page uses multiple H1 headings (“# Enterprise”, later “# Privileged”) under an existing H1 (“# Entra Conditional Access”). This can break the generated TOC and is inconsistent with other docs pages using a single H1. Use H2 for these section dividers.

This issue also appears on line 119 of the same file.

# Entra Conditional Access

# Enterprise

---

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants