Getting Started for MSSP
use this guide to complete first time ai soc for mssp deployment and verify data flow between one client tenant and one central tenant prerequisites you have administrative access to both client and central tenants ai soc core solution (26 2 0 or later) is available to install in each client tenant hero ai and base ai soc capabilities are available in the client tenant you can edit assets, webhooks, and playbook related settings in both tenants you have network access between client and central endpoints you have a valid admin privatetoken (personal access token) for central swimlane api operations used by ai soc mssp central sync you can create or copy a swimlane pat for the client ai soc tenant configuration asset ( private token ) this is not the same token as privatetoken on ai soc mssp central sync after you install ai soc mssp client extension , disable enrich tia record (create) flow in the client ai soc main playbook do not disable the playbook itself see disable enrich tia record in ai soc main in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw install in the required order install ai soc core solution (26 2 0 or later) in the client tenant install ai soc mssp client extension in the client tenant install ai soc mssp central solution in the central tenant confirm installation completion in each tenant before configuration accept get application fields schema overwrite when you install ai soc mssp client extension in a tenant that already has ai soc core solution , the installer may prompt to overwrite the get application fields schema component accept that overwrite do not skip or deselect this component ai soc core does not use this component for client workflows a later core package will remove it configure ai soc for mssp after installation, complete all configuration steps in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw configure the client tenant ( ai soc tenant configuration pat, include tia central sync fields , disable enrich tia record (create) flow in ai soc main , then mssp sync assets) configure the central tenant ( ingest record from client webhook credentials) the webhook is required for case management and reporting sync validate first data flow in the client tenant, ingest a test record through normal ai soc ingestion confirm the enrich tia record (create) flow is disabled in ai soc main for an observable already present in central threat intelligence artifact cache , confirm client tia enrichment does not run again in the central tenant, open central case management and verify the client record appears confirm client name from ai soc mssp client configuration is populated on the central case record open threat intelligence artifact cache and verify the related tiac record appears or updates (full tiac record, not metadata only) open central soc reporting or central soc reporting workspace and verify a reporting aggregate appears after the reporting job runs if validation fails, see validate and troubleshoot mssp sync docid\ qyesknwk rnsc1w1uax d validation sign off checklist configuration in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw is complete for client and central tenants, including tia central sync fields and the enrich tia record (create) flow disabled in ai soc main client record is visible in central within your expected sync window client name from ai soc mssp client configuration is populated on the central case record tiac updates are visible for at least one observable from the test record a second update to the same client record propagates to central a reporting aggregate is visible in central soc reporting after the scheduled reporting sync expected results area expected outcome client workflow record is created and updated normally in client case management central visibility related record is created or updated in central case management ti cache full tiac record appears or updates in central threat intelligence artifact cache client tia enrichment enrich tia record (create) flow in ai soc main is disabled; cache hits do not re enrich on the client reporting aggregate records appear in central soc reporting after the reporting job client identity client name matches the client configuration asset