Step 1 of 8
Jump to step
1
Platform Mode
2
Workspace
3
Microsoft
4
SSO
5
Branding
6
Compliance
7
Remediation
8
Team & Roles
โ๏ธ Step 1 of 8
Platform Mode
Understand whether your platform is running in demo mode or connected to live Microsoft security services.
ProPera runs in two modes. Demo mode uses sample data so you can explore every feature without credentials. Live mode connects to your Microsoft Defender, Sentinel and Entra ID โ requiring Azure tenant credentials. You can switch by setting environment variables.
Current mode
ModeDEMO MODE
Microsoft configuredNo โ demo data in use
Set AZURE_TENANT_ID, AZURE_CLIENT_ID and a credential in .env to switch to live mode.
๐ข Step 2 of 8
Workspace
Your tenant workspace โ plan, status and Microsoft connector configuration.
Each organisation has a workspace (tenant). Your plan determines your device limits, and the connector status shows whether Microsoft APIs are reachable. A green "Configured" badge means everything is connected.
TenantProPera Demo (propera-demo)
PlanBasic
StatusActive
Microsoft connectorNot configured
๐ Step 3 of 8
Microsoft Connector Credentials
Connect ProPera to your Microsoft security stack โ Defender for Endpoint, Sentinel, Graph and Entra ID.
This is the most important step. You need an Azure app registration with permissions for Microsoft Defender, Sentinel and Graph. Enter your Tenant ID, Client ID and Client Secret below. Hover the ? icon on any field in the Configuration Centre for step-by-step Azure instructions.
๐ Step 4 of 8
Microsoft Single Sign-On (SSO)
Let your team sign in with their own Microsoft Entra account โ no separate passwords.
Register your own Entra app so users authenticate with your Microsoft tenant. In Azure, add a web redirect URI for
https://demo.propera.online/auth/entra/callback and grant User.Read (delegated). Users then enter the workspace slug on the login page before clicking Sign in with Microsoft.๐จ Step 5 of 8
White-Label Branding
Customise how the platform looks โ logo, name and accent colour apply across the whole console.
Your team sees your brand, not ours. Set a workspace name, subtitle, logo emoji and accent colours. The primary accent drives buttons, highlights and the sidebar glow. The secondary accent is used for gradients and badges.
๐ Step 6 of 8
Compliance Profile
Tell us where you operate and what you handle โ the compliance dashboard then shows only the frameworks that apply to you.
Compliance is geo-sensed. Select your primary country and industry, then tick what your organisation handles (personal data, financial data, health records, etc.). The platform automatically determines which frameworks โ like NZ NISM, ISO 27001, SOC 2 or HIPAA โ apply to you and hides the rest.
๐ก๏ธ Step 7 of 8
Endpoint Remediation Consent
Control whether ProPera can execute patch remediation on unpatched devices.
ProPera Online never patches devices automatically. To execute remediation after the approval workflow, an Administrator with full cloud and domain control must grant consent. Until then, ProPera posts patch instructions as comments. This is an audited, revocable action.
โ
Consent granted โ by demo
(2026-08-20) ยท scope
cloud_domain_full.
Granted by Administrator from Settings.
Unpatched devices: corp-dc01 (CVE-2024-38063)corp-srv-app02 (CVE-2024-38063)corp-srv-file01 (CVE-2024-38063)corp-wks-1187 (CVE-2024-38063)corp-wks-0421 (CVE-2024-38063)corp-wks-0913 (CVE-2024-38063)corp-lap-2210 (CVE-2024-20653)
Granting consent is an audited action (who, when, scope). Only Administrators can change it. Consent can be revoked at any time.
๐ฅ Step 8 of 8
Team Management & Roles
Invite teammates and understand role-based access control.
Invite your team by email. Each role grants specific permissions โ from Viewer (read-only dashboards) to Administrator (everything). Invites are single-use and expire after 7 days.
Send an invite
Pending invites
| Role | Expires | ||
|---|---|---|---|
| No pending invites. | |||
Role-based access control
| Role | Key permissions |
|---|---|
| Administrator | Everything incl. settings & users |
| Security Administrator | Investigation, remediation, integrations |
| Automation Administrator | Automation rules, remediation execution |
| SOC Analyst | Incident management, approvals, hunting |
| Security Analyst | Investigation, hunting |
| Auditor | Read-only + audit log |
| Viewer | Read-only dashboards |