Skip to content
FirstSIDocs

First settings (administrator)

What an administrator sets up in the first week, in an order that avoids going back over things.

The order below saves you from undoing what you have just done. Each step points to its detailed page.

Day one: access

  1. Start by turning on your own two-factor authentication.
  2. Set up customer security: second-factor methods, sign-out after inactivity, SSO if you have one. See Customer security and SSO.
  3. Create your team's accounts with the right role (viewer, operator, administrator) and, if needed, restrict each person's modules. See Users and roles.
  4. Configure email sending in the SMTP tab and send yourself a test. Without SMTP, no alert goes out by email. See Customer settings.

Day one: the first agents

Install the agent on a few pilot computers with NetDiag, NetFlow and AssetMonitor (Install the agent). Check that they show as Online in FSI Agents, then open Network diagnostics: the first measurements arrive within a few minutes. Finally, decide on the fleet's update policy.

First week: widen the scope

StepWhat you getPage
Agent with SI-Tracer on the domain controllersAuthentication, accounts at riskSI-Tracer
Agent with FileMonitor on the file serversWho changed or deleted whatFileMonitor
Declare firewalls and gatewaysLogs, VPN, threatsFirewalls and gateways
UniFi or Peplink providers, SNMPSites, Wi-Fi, tunnelsNetworkMonitor
Monitors for critical servicesAvailability, status pageHostMonitor
Default SIEM rules, then switch them on one by oneSecurity correlationSIEM

First week: data and compliance

Automatic purging is off by default, and as long as it is off, nothing is ever deleted. Set the retention period, then turn purging on; see Data, GDPR and audit.

Keep NetDiag's sensitive options (open files, window titles) turned off unless you have a specific, documented need. See NetDiag.

Later, as needed

Source: · FirstSI Docs · updated 2026-10-10