Post on 22-Mar-2018
www.metalogix.com info@metalogix.com 202.609.9100
Sensitive Content Manager
January 05, 2018
Installation Guide
© 2018 Metalogix International GmbHAll rights reserved. No part or section of the contents of this material may be reproduced or transmitted in any form or by any meanswithout the written permission of Metalogix International GmbH.
Sensitive Content Manager™ is a trademark of Metalogix International GmbH
Windows SharePoint Services is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or othercountries. Other product and company names mentioned herein may be the trademarks of their respective owners.
www.metalogix.com info@metalogix.com 202.609.9100
Sensitive Content Manager Installation Guide Metalogix
Technical Support
For information about Metalogix Technical support visit http://metalogix.com/support.
Technical support specialists can be reached by phone at +1-202-609-9100. The level of technical support provided depends upon thesupport package that you have purchased. Contact us to discuss your support requirements.
Copyright
Sensitive Content Manager Installation Guide Metalogix
www.metalogix.com info@metalogix.com 202.609.9100
ContentsPreface ....................................................................................................................................................... 4
System Requirements ................................................................................................................................. 5
Install Instructions ...................................................................................................................................... 9
Sensitive Content Manager Installation Guide Metalogix
4
Preface
Metalogix Sensitive Content Manager provides a highly accurate and flexible out of the box solution for
detecting sensitive information such as PII, PHI and PCI within enterprise content management systems.
With on-demand scanning, administrators can flag specific libraries, sites, or site collections for content
discovery, or enable real-time content shield by analyzing files as they are created, modified, moved, or
destroyed.
By leveraging ControlPoint’s existing security, compliance and administration capabilities, the addition of
Sensitive Content Manager can enforce policies using the full range of SharePoint's permissions
management, auditing and user activity reporting. The combined solution offers a powerful Data Loss
Prevention (DLP) solution that enables clients to identify, track, and secure documents using advanced
neural network powered machine learning, with a more robust level of information governance inside
increasingly complex enterprise environments.
This guide contains instructions for the on-premise installation of Metalogix Sensitive Content Manager.
Sensitive Content Manager Installation Guide Metalogix
5
System RequirementsThe table below lists the components required to install the Metalogix Sensitive Content Manager.
Component Type Component
Operating System Windows Server 2012
Database SQL Server 2012 upto SQL Server 2014
Application Windows Powershell 2.0 or later with unrestricted execution policy.
Windows Server
Roles
Application Server, Web Server (IIS)
Additional
Software
· Microsoft .NET Framework 4.5
· Microsoft SQL Server Transact-SQL ScriptDom
· Microsoft System CLR Types for Microsoft SQL Server 2012
· Microsoft Web Deploy 3.5
NOTE: If these applications have not been pre-installed, they will be automatically
installed by the Sensitive Content Manager installer.
Installation
Account
The account used to install Sensitive Content Manager must be:
· a Domain Administrator
· a Local Administrator on the Server where Sensitive Content Manager will be
installed
· a Sysadmin on the SQL instance where the Sensitive Content Manager Database
will reside
The following system setup instructions are presented in this topic:
1. Steps to change the Windows PowerShell Script Execution Policy
2. Steps to install the following roles and features on Windows Server 2012
· Web Server (IIS) role
· Application Server role
Sensitive Content Manager Installation Guide Metalogix
6
· Active Directory module for Windows PowerShell, which enables the installer to create an Active
Directory group called CloudOperators and (optionally) the Sensitive Content Manager Service
Account.
NOTE: All accounts that interface with Sensitive Content Manager Server must be in the
CloudOperators Active Directory group.
Steps to change the Windows PowerShell Script Execution Policy
By default, Windows PowerShell scripts are restricted. To change the execution policy:
1. Open Windows PowerShell
2. At the command prompt, renter and run the following script
Set-ExecutionPolicy Unrestricted
3. Enter Y at the prompt and press Enter. A confirmation message appears.
Steps to install roles and features on Windows Server 2012
1. Open Server Manager.
2. Under Manage menu, select Add Roles and Features.
3. Select Role-based or Feature-based Installation. Click Next.
Sensitive Content Manager Installation Guide Metalogix
7
4. Select the appropriate server (local is selected by default). Click Next. The Select Server Roles page
appears.
5. Select the Web Server (IIS) checkbox.
6. Customize your installation of IIS, or accept the default settings that have already been selected for
you.
7. Check the Application Server box and expand the node.
8. Select the the following features:
a. .NET Framework 4.5 Feature
b. Web Server (IIS) Support
9. Click Next. The Select Features page appears.
10.Ensure that the following feature check boxes are checked:
a. .NET Framework 4.5 Feature
b. Message Queuing
c. Remote Server Administration Tools
d. User Interfaces and Infrastructure
e. Windows PowerShell
f. Windows Process Activation Service
Sensitive Content Manager Installation Guide Metalogix
8
11.Expand the Role Administration Tools node, then expand AD DS and AD LDS Tools and check the Active
Directory module for Windows PowerShell box.
12.Click Next to confirm the roles and features you want to install, then click Install.
13.When the installation completes, the wizard reflects the installation status.
14.Click Close to exit the wizard.
Sensitive Content Manager Installation Guide Metalogix
9
Install InstructionsThis topic provides instructions for installing the Metalogix Sensitive Content Manager using a Windows
Installer for an on-premise installation. In this topic:
1. Planning your install
2. Before you begin
3. Steps to retrieve a certificate's thumbprint
4. About licensing and registration
5. Downloading the install files
6. Steps to install the Metalogix Sensitive Content Manager Server
7. Steps to install the Analysis Service on a different server
8. Steps to verify the installation
9. Troubleshooting
Planning your install
The scenarios described below are simple estimates to provide some guidance about how to think about
load sizing and analysis server distribution. Since processing efficiencies are heavily dependent on your
server configurations, some research and verification will be necessary necessary to arrive at optimum
server load configurations. It is recommended that you contact your Metalogix representative to assist you
in this process.
SCENARIO 1: You have several hundred kilobytes of files (but less that a gigabyte) on a single Windows
SharePoint server that needs analysis.
The suggested approach for this scenario would be to install the SCM database, portal and analysis
services on a separate physical or virtual machine (the SCM server). You would then install Metalogix
ControlPoint on the SharePoint machine so that the files to be analyzed can be efficiently submitted
through Metalogix ControlPoint.
SCENARIO 2: You have several terabytes of files spread across a Windows SharePoint server farm, and
about a gigabyte of these files need to be analyzed per day.
The suggested approach for this scenario would be to install the SCM database and portal on a separate
physical machine (the SCM server) and install the analysis services on multiple physical or virtual
machines. You would then install Metalogix ControlPoint on a separate server so that the files to be
Sensitive Content Manager Installation Guide Metalogix
10
analyzed can be efficiently submitted and distributed through Metalogix ControlPoint. The distributed
nature of the Analysis servers ensures efficient retrieval and processing of the files required for analysis.
Before you begin
1. The machine on which you are installing Metalogix Sensitive Content Manager must meet the System
Requirements.
2. The machine on which you are installing Metalogix Sensitive Content Manager should have access to
the Internet, which is necessary to download the files needed for a successful install.
3. If an integration with Metalogix ControlPoint or another software is planned, the machine on which
you are installing Metalogix Sensitive Content Manager must be on a domain in a full trust relationship
with the domain on which ControlPoint (or other client application) is installed. Specifically, verify that
the machine on which you are installing Metalogix Sensitive Content Manager is reachable by the
server on which ControlPoint (or other client application) is installed.
4. You have the following information ready (sample values are provided here as a guidance).
Field Description Sample Value
SQL Server Name The SQL server instance name. SCM-CUSTOMER
SQLIntegrated
Authentication
Checkbox that indicates whether SCM will use
Windows or mixed-mode authentication to log
into the SQL server.
When checked, SCM will use Windows
authentication and the fields for SQL Server
Administrative User, SQL Server Administrative
User Password, and Password for SCM SQL User
are disabled.
When unchecked, SQL or mixed-mode
authentication is used, and you must complete
the other fields as well.
For more information, see the Microsoft article
about authentication mode configuration.
Sensitive Content Manager Installation Guide Metalogix
11
SQL Server
Administrative
User
The SQL server user account with sysadmin rights. sa
SQL Server
Administrative
User Password
Password for the SQL Server sysadmin user. Pass@w0rd1
Password for SCM
SQL User
The password for the user registered in the
database who will use the Sensitive Content
Manager functionality.
Pass@w0rd1
Create Service
Account
The Windows user account that will be used by
SCM to execute the Analysis services and
application pools.
By default, the checkbox is checked and the
installer automatically creates its own Service
Account (domain\mx-cloud-svc) during
installation.
You can uncheck this box and enter an alternate
account (in the domain\user_name format).
Password for SCM
Windows Account
The password for the administrator who has
access to the windows machine on which you are
installing Metalogix Sensitive Content Manager.
Pass@w0rd1
Working Storage
Path
Full path of the folder that will contain the files to
be analyzed.
C:\FileStorageSystem. You
could specify a network path
as well such as
\\myserver\mypath.
Protocol Internet protocol to access the portal. http or https
Portal URL Fully qualified domain name and a unique port
number. The port number should not be a
reserved port number
https://scm-
customer.mydomain.com:443
Sensitive Content Manager Installation Guide Metalogix
12
Result Service URL Fully qualified domain name and a unique port
number. The port number should not be a
reserved port number
https://scm-
customer.mydomain.com:443
01
File Upload URL Fully qualified domain name and a unique port
number. The port number should not be a
reserved port number
https://scm-
customer.mydomain.com:443
02
SSL Certificate
Thumbprint
SSL certificate that the service binds with. Can be
specified at time of install or can be setup later
with IIS Manager.
Steps to retrieve a certificate's thumbprint
1. Open IIS Manager and navigate to the level you want to manage. This would typically be the node with
your machine name.
2. In Features view, double-click Server Certificates.
3. In the Actions pane, click Create Self-Signed Certificate.
4. On the Create Self-Signed Certificate page, type a friendly name for the certificate in the Specify a
friendly name for the certificate box, and then click OK.
5. In the Server Certificates list, double-click the certificate you just created.
6. In the Certificate dialog box, click the Details tab.
7. Scroll through the list of fields and click Thumbprint.
8. Copy the hexadecimal characters from the box to a text editor such as Notepad. Remove the spaces
between the hexadecimal numbers. For example, the thumbprint "4 d 1 9 d 8 9 6 9 c 9 a 4 3 a 9 4 1 1 6
d 6 2 a d 9 4 8 a 2 4 d e f 0 6 3 4 d 3 " should be converted to
4d19d8969c9a43a94116d62ad948a24def0634d3.
9. Enter the thumbprint value in the SSL Certificate Thumbprint field.
Sensitive Content Manager Installation Guide Metalogix
13
About licensing and registration
The first time you install Metalogix Sensitive Content Manager, you will be granted a free 30-day
evaluation license. If you wish to purchase a production license, contact Metalogix. For more information
see Licensing and Registration in the Metalogix Sensitive Content Manager administration guide.
Downloading the install files
1. From your browser, navigate to the http://www.metalogix.com/free-trial-download page
2. Scroll down to the Metalogix Sensitive Content Manager - 30 day free trial section
3. Click the Free Trial button.
4. Fill the Download a Free Trial registration form and click the Submit button. The file download window
appears, or check your default download folder.
5. Ensure that the files are available locally on the machine on which you are planning to install the
Metalogix Sensitive Content Manager.
Sensitive Content Manager Installation Guide Metalogix
14
Steps to install the Metalogix Sensitive Content Manager
1. Unzip the files.
2. Click the windows installer file Metalogix.ContentAnalysis.Installer.msi. The Metalogix SCM installer
window appears.
3. Click Next. The End-User License Agreement (EULA) window appears.
4. Should you wish to proceed, click the checkbox I accept the terms in the LIcense Agreement.
5. [Optional] Click the Print button if you choose to print the EULA.
6. Click the Next button. The SCM Components Selection window appears.
NOTE: If this is a first-time install, the installer will help you setup and configure the database and portal
infrastructure to enable the analysis services. If you have already setup the database and portal
infrastructure, skip to step 10.
7. Click the Database and Portal button. The Database and Portal Configuration window appears.
8. Fill in the values as you have determined in the table of values in the Before you begin section.
9. Click the Next button to proceed to the setup steps for the Analysis Service.
10.Click the Analysis Service button. The Analysis Service setup window appears.
11.Fill in the values as you have determined in the table of values in the Before you begin section.
NOTE: You may click the Test Connection button to verify the values you have entered are valid and
present in the database.
12.Click the Next button. The final Ready to install window appears.
13.Click the Install button to complete the installation.
Steps to install the Analysis Service on a different server
You can choose to install just the Analysis Service on a different server. You should have already installed
all the components on your primary SCM server before you attempt this action.
1. Unzip the downloaded file. NOTE: If your file is blocked, see the section about Troubleshooting .
2. Right-click the windows installer file Metalogix SCM Installer.exe and select Run as administrator. The
Metalogix SCM installer welcome window appears.
3. Click the Install button. The Sensitive Content Manager Server installer dialog appears.
Sensitive Content Manager Installation Guide Metalogix
15
4. Click the Next button. The End-User License Agreement (EULA) window appears.
5. Should you wish to proceed, click the check box I accept the terms in the License Agreement.
6. [Optional] Click the Print button if you choose to print the EULA.
7. Click the Next button. The SCM Components Selection window appears.
8. Click the Analysis Service button. The Analysis Service setup window appears.
9. Fill in the values as you have determined in the table of values in the Before you begin section.
NOTE: You may click the Test Connection button to verify the values you have entered are valid and
present in the database.
10.Click the Install button to complete the installation.
Steps to verify the installation
1. Open a browser such as Chrome, on the local machine.
2. Enter the correct Protocol and Portal URL you had previously specified during install. For example
enter https://scm-customer.mydomain.com:44300
3. Verify that the dashboard appears appears as shown below.
Troubleshooting
Sensitive Content Manager Installation Guide Metalogix
16
Downloaded zip file is blocked
1. The downloaded zip file may be blocked with the message "This file came from another computer and
might be blocked to help protect this computer".
2. Right-click the file and select Properties. The File Properties dialog appears.
3. Open the Security tab.
4. Click the Unblock button.
You can also try using Powershell command Unblock-File at https://technet.microsoft.com/en-
us/library/hh849924.aspx
Install Fails
1. If the installer fails at any step, you will see the error dialog.
2. Click the log file link to see the error logs and take steps to to correct the problem.