🧩 Technicians Module – User Guide

Module – User Guide

Overview

The Technicians module allows administrators to connect the platform to Microsoft 365 (O365) and import users who will act as security technicians.
These technicians are responsible for:

  • Receiving security alert notifications generated by the SIEM.
  • Managing and closing incident tickets directly in ConnectWise.

This module ensures that all users handling alerts are synchronized with Microsoft accounts, maintaining consistent access and accountability.


šŸ” Accessing the Module

  1. Log in to the main platform.
  2. From the left menu, select Technicians.
  3. The main page will display the Technicians List, showing all imported or manually added users.

šŸ“‹ Interface Overview

Main Components

  • + New – Create a new technician manually.
  • Refresh – Reload the technician list to show recent changes.
  • Delete – Remove selected technicians.
  • Sync Microsoft Users – Connects to Microsoft 365 and imports available users.

Imported users will show a cloud icon under the Imported column.


šŸ“‘ Technicians List

ColumnDescription
NameTechnician’s full name.
EmailMicrosoft 365 account used for authentication and notifications.
PhoneTechnician’s phone number for SMS or voice alerts.
UsernameInternal system username (can include multiple values).
ImportedDisplays a cloud icon if imported from Microsoft 365.
StatusTechnician’s current state (Active or Inactive).

šŸ”„ Synchronizing with Microsoft 365

  1. Click Sync Microsoft Users.
  2. The system connects to your O365 tenant and retrieves user data.
  3. Select users you want to import as technicians.
  4. Imported users will appear in the list with the blue cloud icon.

šŸ’” Tip: Import only users responsible for handling SIEM alerts and ConnectWise tickets.


šŸ‘¤ Adding or Editing a Technician

Click + New to add a new technician, or click an existing technician’s name to edit their details.

Technician Information Window

This form is used to manually register or update a technician’s information.

FieldDescription
Name*Enter the technician’s full name. This field is required.
Email*The technician’s email address (must be valid, preferably their Microsoft 365 address).
Phone*The phone number used for SMS alerts, MFA, or automated voice calls.
StatusDefines whether the technician is Active (can receive alerts) or Inactive.
Usernames*Add one or more usernames used across systems (for example, ConnectWise or Active Directory). Use commas to separate multiple values.
Optional (SMS Consent)If checked, the user agrees to receive security and verification messages from SkoposGuard. Includes a link to the Privacy Policy and opt-out instructions.

Buttons:

  • Save – Stores the new or updated technician information.
  • List – Returns to the Technicians List.
  • + New – Clears the form to register another technician.

🚨 Integration with SIEM and ConnectWise

  • Imported or manually added technicians are automatically linked to the SIEM.
  • When a new alert is generated, the assigned technician:
    • Receives an email, SMS, or voice alert (based on configuration).
    • Can acknowledge or close the incident directly from the alert interface.
  • When a ticket is closed in SkoposGuard, the system synchronizes the status back to ConnectWise.

🧾 Notes and Best Practices

  • Ensure that the Microsoft 365 credentials used have Directory.Read.All permissions to fetch users.
  • Only assign ā€œActiveā€ status to users currently on the security response team.
  • Review the technician list regularly to remove old or inactive accounts.
  • Keep phone numbers updated to avoid missed SMS or voice alerts.
  • Use the Refresh button after syncing to confirm new entries are displayed.