Get your service-provider organization up and running on ContraForce: grant Microsoft access, set up the Agent Center, connect your own security tools, and pre-onboard customer workspaces.
This guide walks you through getting your service-provider organization up and running on ContraForce. By the end, you’ll be ready to pre-onboard your first customer.
Who is this for?
MSP/MSSP partners setting up your parent tenant before onboarding customers
Internal security teams deploying ContraForce for your own organization
Required the very first time anyone from your tenant signs in, to grant ContraForce permission to read security data
ContraForce sign-up link
Provided by your account team
Pop-ups allowed for portal.contraforce.com
Microsoft consent prompts open in popup windows
If your tenant has a “Do not allow user consent” policy, the consent must be completed by a Global Administrator. Non-admin users will see a Sign In Failed page. See Troubleshooting: Sign-in failed below.
Before anyone in your organization can sign in, a Microsoft Entra Global Administrator has to grant ContraForce permission to read security data from your tenant. This is a one-time approval.
1
Open the ContraForce sign-up link
Use the link your account team shared with you.
2
Sign in with Microsoft
You’ll be redirected to Microsoft. Sign in with your Global Admin credentials.
3
Review the requested permissions
Microsoft displays a consent screen listing the permissions ContraForce needs. Review the list and click Next.
Initial Microsoft consent screen
4
Accept the second consent
Microsoft may ask you to consent a second time: once for the ContraForce platform API and once for the ContraForce Portal. Check Consent on behalf of your organization and click Accept.
Second Microsoft consent: Portal and Consent on behalf of your organization
The Get started with ContraForce panel is your home base for setup. It lists the activities your organization still needs to complete.
Item
What it does
Create your account
Already done by signing in for the first time
Setup agent center
Choose where ContraForce-hosted automation runs
Connect sources
Connect your own security tools so your SOC team can use ContraForce internally
Add customer workspaces
Pre-onboard the customers you’ll be managing
Each unchecked item has a Start button on the right that takes you straight to the relevant page. You can dismiss the panel at any time using the ✕ in the top right; it will also self-hide once every item is complete.
Click Start next to Setup agent center. This is where you choose how the ContraForce automation engine runs for your organization.
Agent Center setup page
You can either deploy your agent here or skip it and continue with the other items. If you deploy an agent, the Setup agent center item shows a green checkmark when you return to the Command page.
Agent Center Deployment Reference
Detailed Agent Center setup, requirements, and configuration options
Step 5: Connect Detection Sources to Your Own Workspace
Click Start next to Connect sources. This jumps you straight to the detection-source picker for your own workspace.
Detection-source picker for your own workspace
Select the security tools your team uses, then follow the prompts to authorize ContraForce to read from each one. Once at least one detection source is connected, the Connect sources item on the checklist will check off.
Connecting Microsoft Sentinel triggers ContraForce to deploy the supporting Azure infrastructure in your subscription automatically. You don’t need a separate Azure deployment step. Provisioning runs in the background after you grant consent.
Click Start next to Add customer workspaces. You’ll land on the Workspace Center with the Onboarding tab active and the Add workspace rail panel already open on the right.
Workspace Center with Add workspace rail open
Fill in the customer details:
Field
Description
Workspace name
Friendly label you’ll use to refer to this customer
Tenant ID
The customer’s Microsoft Entra tenant ID
Primary point-of-contact email
The customer admin who will complete onboarding on their side
Detection modules
Pre-select the security tools the customer is bringing
Response modules
Pre-select the response capabilities the customer will use
Detection and response module pre-selection in the rail
Click Send Invite. ContraForce sends an invite email to the POC, and the new workspace appears as a card in the Onboarding tab with a Pending customer setup badge.
New customer workspace card on the Onboarding tab
Repeat this step for every customer you want to manage.
When the customer admin finishes onboarding their workspace, you’ll receive a real-time notification in the portal so you know their workspace is live.
Customer Workspace Onboarding
What your customer sees on their side after they receive the invite email