Skip to main content
The Workspaces Page is your administrative control center for managing customer tenants. Pre-onboard new customers before deployment, configure module settings, and manage integrations—all from one place.
Workspaces represent individual customer tenants in ContraForce. Each workspace has its own data, configurations, and user permissions.

What Can You Do Here?

Pre-Onboard Customers

Create workspace placeholders before full deployment

Manage Configurations

Edit module settings and integration configurations

Monitor Status

Track onboarding progress for all tenants

Control Permissions

Manage module consents and access settings

Accessing the Workspaces Page

1

Locate the Icon

Find the Workspaces icon (triangle) in the left navigation bar—it’s the 3rd icon from the top
2

Click to Open

Click the icon to open the Workspaces Page
Workspaces navigation icon

Workspaces Overview

The Workspaces Page displays all your customer tenants in a filterable table.
Workspaces page overview

Filter Options

FilterDescription
AllShows all workspaces regardless of status
OnboardedShows only fully onboarded, active tenants
Pre-OnboardedShows workspaces created but not yet fully deployed

Table Columns

ColumnDescription
Workspace NameCustomer/tenant identifier
StatusOnboarded or Pre-Onboarded
ModulesWhich ContraForce modules are enabled
CreatedWhen the workspace was created
ActionsEdit and expand controls

Viewing Workspace Details

Click the dropdown arrow on any workspace row to expand and view additional details:
Workspace expanded details

Expanded Information

  • Tenant ID — Microsoft tenant identifier
  • Enabled Modules — XDR, SIEM, or both
  • Data Connectors — Connected integrations
  • Onboarding Date — When the tenant was fully onboarded
  • Last Activity — Most recent data received
Use the expanded view to quickly verify a workspace’s configuration without opening the full edit panel.

Pre-Onboarding Customers

Pre-onboarding lets you prepare customer environments before full deployment, streamlining the onboarding process.

Why Pre-Onboard?

Faster Deployment

Configuration is ready when the customer is

Reduced Errors

Verify settings before going live

Better Planning

Schedule onboardings in advance

Creating a Pre-Onboarded Workspace

1

Click Add Workspace

Click the Add Workspace or Pre-Onboard button
2

Enter Customer Details

Provide the workspace name and basic configuration
3

Select Modules

Choose which ContraForce modules to enable (XDR, SIEM, etc.)
4

Save

The workspace is created with “Pre-Onboarded” status

Completing Onboarding

When ready to fully deploy:
  1. Open the pre-onboarded workspace
  2. Complete the required consent flows
  3. Configure data connectors
  4. The status automatically updates to “Onboarded”

Learn More

Complete guide to the pre-onboarding process

Editing Workspace Configuration

Modify settings for any workspace using the edit function.

Accessing the Edit Panel

Click the edit icon (pencil) next to any workspace’s dropdown arrow.
Workspace edit icon

Configuration Panel

The edit panel opens with all configurable options:
Workspace configuration panel
Basic workspace settings:
  • Workspace name
  • Display preferences
  • Notification settings

Module Management

Each workspace can have different modules enabled based on customer needs.

Available Modules

ModuleDescriptionKey Features
XDR ModuleMicrosoft Defender integrationEndpoint detection, response actions, device management
SIEM ModuleMicrosoft Sentinel integrationLog analysis, custom alerts, threat hunting

Configuring Modules

1

Open Edit Panel

Click the edit icon for the workspace
2

Select Module Tab

Navigate to the module you want to configure
3

Adjust Settings

Enable/disable features, set thresholds, configure options
4

Consent Permissions

Click Consent to authorize required permissions for the module
5

Save Changes

Apply the configuration
Module configuration options

Module-Specific Settings

Different modules expose different configuration options:
  • Defender for Endpoint — Device isolation permissions, scan options
  • Defender for Identity — User action permissions
  • Defender for Office 365 — Email response actions
  • Gamebook Actions — Which response actions are enabled
  • Sentinel Workspace — Connection details
  • Log Analytics — Query permissions
  • Custom Rules — Alert configuration
  • Notifications — Alert routing settings
  • QRadar Console — Connection URL
  • API Credentials — Authentication details
  • Offense Mapping — How QRadar offenses map to ContraForce incidents

Some features require explicit consent to Microsoft enterprise applications. ContraForce uses Microsoft Graph API and other APIs to:
  • Read security alerts and incidents
  • Execute response actions (isolate devices, disable users)
  • Access log data for analysis
These permissions must be granted by a tenant administrator.
1

Open Workspace Configuration

Click the edit icon for the workspace
2

Find Consent Section

Look for the Consent or Permissions area
3

Click Consent Button

A Microsoft authentication window opens
4

Sign In as Admin

Sign in with a Global Administrator or appropriate admin role
5

Review & Accept

Review the requested permissions and click Accept
Consent requires administrator privileges in the customer’s Microsoft tenant. Work with your customer’s IT team if you don’t have admin access.

Learn More

Complete guide to enterprise applications and permissions

Best Practices

Name workspaces consistently (e.g., “CustomerName - Primary”) so they’re easy to identify in filters and reports.
Create pre-onboarded workspaces before onboarding calls so you can complete setup efficiently during the meeting.
Keep records of which modules and settings are enabled for each customer for support and renewal conversations.
Periodically review workspaces that haven’t received data recently. This may indicate connector issues or offboarded customers.

Troubleshooting

Common Issues

IssuePossible CauseSolution
Workspace shows no dataConsent not completedRe-run consent flow with admin credentials
Module won’t enableMissing permissionsVerify required permissions are granted
Pre-onboarded stuckConsent incompleteComplete all required consent steps
Configuration won’t saveValidation errorCheck for required fields or invalid values
If you encounter persistent issues with workspace configuration, contact [email protected] with the workspace name and error details.


Questions about the Workspaces Page? Contact us at [email protected].