Workspaces represent individual customer tenants in ContraForce. Each workspace has its own data, configurations, and user permissions.
What Can You Do Here?
Pre-Onboard Customers
Create workspace placeholders before full deployment
Manage Configurations
Edit module settings and integration configurations
Monitor Status
Track onboarding progress for all tenants
Control Permissions
Manage module consents and access settings
Accessing the Workspaces Page
1
Locate the Icon
Find the Workspaces icon (triangle) in the left navigation bar—it’s the 3rd icon from the top
2
Click to Open
Click the icon to open the Workspaces Page
Workspaces Overview
The Workspaces Page displays all your customer tenants in a filterable table.
Filter Options
| Filter | Description |
|---|---|
| All | Shows all workspaces regardless of status |
| Onboarded | Shows only fully onboarded, active tenants |
| Pre-Onboarded | Shows workspaces created but not yet fully deployed |
Table Columns
| Column | Description |
|---|---|
| Workspace Name | Customer/tenant identifier |
| Status | Onboarded or Pre-Onboarded |
| Modules | Which ContraForce modules are enabled |
| Created | When the workspace was created |
| Actions | Edit and expand controls |
Viewing Workspace Details
Click the dropdown arrow on any workspace row to expand and view additional details:
Expanded Information
- Tenant ID — Microsoft tenant identifier
- Enabled Modules — XDR, SIEM, or both
- Data Connectors — Connected integrations
- Onboarding Date — When the tenant was fully onboarded
- Last Activity — Most recent data received
Pre-Onboarding Customers
Pre-onboarding lets you prepare customer environments before full deployment, streamlining the onboarding process.Why Pre-Onboard?
Faster Deployment
Configuration is ready when the customer is
Reduced Errors
Verify settings before going live
Better Planning
Schedule onboardings in advance
Creating a Pre-Onboarded Workspace
1
Click Add Workspace
Click the Add Workspace or Pre-Onboard button
2
Enter Customer Details
Provide the workspace name and basic configuration
3
Select Modules
Choose which ContraForce modules to enable (XDR, SIEM, etc.)
4
Save
The workspace is created with “Pre-Onboarded” status
Completing Onboarding
When ready to fully deploy:- Open the pre-onboarded workspace
- Complete the required consent flows
- Configure data connectors
- The status automatically updates to “Onboarded”
Learn More
Complete guide to the pre-onboarding process
Editing Workspace Configuration
Modify settings for any workspace using the edit function.Accessing the Edit Panel
Click the edit icon (pencil) next to any workspace’s dropdown arrow.Configuration Panel
The edit panel opens with all configurable options:
- General
- Modules
- Permissions
- Integrations
Basic workspace settings:
- Workspace name
- Display preferences
- Notification settings
Module Management
Each workspace can have different modules enabled based on customer needs.Available Modules
| Module | Description | Key Features |
|---|---|---|
| XDR Module | Microsoft Defender integration | Endpoint detection, response actions, device management |
| SIEM Module | Microsoft Sentinel integration | Log analysis, custom alerts, threat hunting |
Configuring Modules
1
Open Edit Panel
Click the edit icon for the workspace
2
Select Module Tab
Navigate to the module you want to configure
3
Adjust Settings
Enable/disable features, set thresholds, configure options
4
Consent Permissions
Click Consent to authorize required permissions for the module
5
Save Changes
Apply the configuration

Module-Specific Settings
Different modules expose different configuration options:XDR Module Settings
XDR Module Settings
- Defender for Endpoint — Device isolation permissions, scan options
- Defender for Identity — User action permissions
- Defender for Office 365 — Email response actions
- Gamebook Actions — Which response actions are enabled
SIEM Module Settings
SIEM Module Settings
- Sentinel Workspace — Connection details
- Log Analytics — Query permissions
- Custom Rules — Alert configuration
- Notifications — Alert routing settings
QRadar Settings
QRadar Settings
- QRadar Console — Connection URL
- API Credentials — Authentication details
- Offense Mapping — How QRadar offenses map to ContraForce incidents
Permission Consent
Some features require explicit consent to Microsoft enterprise applications.Why Consent is Required
ContraForce uses Microsoft Graph API and other APIs to:- Read security alerts and incidents
- Execute response actions (isolate devices, disable users)
- Access log data for analysis
Granting Consent
1
Open Workspace Configuration
Click the edit icon for the workspace
2
Find Consent Section
Look for the Consent or Permissions area
3
Click Consent Button
A Microsoft authentication window opens
4
Sign In as Admin
Sign in with a Global Administrator or appropriate admin role
5
Review & Accept
Review the requested permissions and click Accept
Learn More
Complete guide to enterprise applications and permissions
Best Practices
Use consistent naming conventions
Use consistent naming conventions
Name workspaces consistently (e.g., “CustomerName - Primary”) so they’re easy to identify in filters and reports.
Pre-onboard before customer meetings
Pre-onboard before customer meetings
Create pre-onboarded workspaces before onboarding calls so you can complete setup efficiently during the meeting.
Verify consent status regularly
Verify consent status regularly
Periodically check that all required permissions are still consented. Token expirations or policy changes can affect access.
Document module configurations
Document module configurations
Keep records of which modules and settings are enabled for each customer for support and renewal conversations.
Review inactive workspaces
Review inactive workspaces
Periodically review workspaces that haven’t received data recently. This may indicate connector issues or offboarded customers.
Troubleshooting
Common Issues
| Issue | Possible Cause | Solution |
|---|---|---|
| Workspace shows no data | Consent not completed | Re-run consent flow with admin credentials |
| Module won’t enable | Missing permissions | Verify required permissions are granted |
| Pre-onboarded stuck | Consent incomplete | Complete all required consent steps |
| Configuration won’t save | Validation error | Check for required fields or invalid values |
If you encounter persistent issues with workspace configuration, contact [email protected] with the workspace name and error details.
Related Guides
Pre-Onboarding Process
Complete pre-onboarding guide
Enterprise Applications
Understanding permissions and consent
Module Overview
Learn about XDR and SIEM modules
Multi-Tenant Features
Managing multiple workspaces
Questions about the Workspaces Page? Contact us at [email protected].