Threat
Investigations can correlate information from Endpoint Sensor, Cloud App Security,
and Active Directory to display attack information about an endpoint, user account,
and possible email attack vectors throughout your network.
Important
|
Procedure
- Ensure your Customer Licensing Portal account (https://clp.trendmicro.com/) includes Trend Micro Cloud App
Security.
-
If your Customer Licensing Portal account already includes Cloud App Security, proceed to the following step.
-
If you do not have a valid Activation Code for Cloud App Security, contact your sales representative.
-
- Add Microsoft™ Exchange Online with Office 365
to Cloud App Security:
- On the Cloud App Security console, go to .
Tip
You can open the Cloud App Security console from the Products/Services screen on the Customer Licensing Portal website (https://clp.trendmicro.com/). - Click Add and select Exchange Online.
- Enable one of the following policies:
-
Default Exchange Policy ATP: Go toand set the policy status to ON.
-
Default Exchange Policy DLP: Go toand set the policy status to ON.
For more information about Cloud App Security, see the Cloud App Security Online Help at http://docs.trendmicro.com/en-us/enterprise/cloud-app-security.aspx. -
- On the Cloud App Security console, go to .
- Generate an authentication token for the Cloud App Security Threat
Investigation API:
- On the Cloud App Security console, go to .
- Click Add.The Add Authentication Token screen appears.
- Select the Email message check box for the Threat Investigation API type.
- Click Create Token.The generated authentication token appears on the Automation and Integration APIs screen.
- Configure cloud service settings on Trend Micro Apex Central:
-
On the Trend Micro Apex Central console, go to .The Product Servers screen appears.
-
Click Cloud Service Settings.The Cloud Service Settings screen appears.
-
Provide the following credentials:
-
Account: The user name used to activate the cloud service subscription on the Trend Micro Customer Licensing Portal (https://clp.trendmicro.com/)
-
Password: The password for the Customer Licensing Portal account
-
-
Click OK.Trend Micro Apex Central registers your Customer Licensing Portal account and supported cloud services.
-
- Synchronize your Active Directory structure with Trend Micro Apex Central:
- On the Trend Micro Apex Central console, go to .
- Click the Active Directory Settings tab.
- Select Enable Active Directory synchronization.
- Click Save.
- Download and run the Active Directory synchronization tool on the
Active Directory server.
WARNING
Clicking Download the Active Directory synchronization tool will deactivate any previously downloaded Active Directory synchronization tools and stop synchronizing Active Directory servers configured using the deactivated tool.Important
Ensure that .NET Framework 4.6.1 is installed on the Windows endpoint before executing the tool.For more information, see Configuring Active Directory Synchronization.
- Enable Endpoint Sensor on Apex One Security Agents:
- On the Trend Micro Apex Central console, go to .
- Select Apex One Security Agent from the Product drop-down list.
- Click Create.
- Type a policy name.
- Specify targets.
- Expand Additional Service Settings.
- Select the following check boxes:
-
Windows desktop
-
Windows Server platforms
-
- Expand Endpoint Sensor Settings.
- Select Enable Endpoint Sensor.
- Click Deploy.
- Configure Microsoft™ Outlook (outlook.exe) as the email client on each Security Agent endpoint.