# Welcome to FenixPyre

## Overview

\
FenixPyre is a comprehensive Post-Authentication Data Security (PADS) Platform, enhancing data security through advanced file encryption and dynamic access controls in a platform that is easy to setup and manage:

* **Military-Grade Encryption**: Utilizes FIPS 140-2 validated modules and AES-256 encryption, securing any file type, from standard office documents to specialized formats like CAD files.
* **Access Files Through Native Applications**: Any file can be encrypted but with FenixPyre, no matter what the file type, encrypted files are accessed from their native application making the experience seamless to users.
* **Milliseconds of Latency**: Every file is encrypted with a distinct encryption key. Encryption and decryption are optimized at a kernel-level implementation, with no noticeable impact to the client.
* **Strong and Performant Key Management:** Every file key is encrypted and stored in a high-performance database. File keys can only be decrypted in a Hardware Security Module, where the master key is hosted. Customers can manage their own HSM. File contents are zero-knowledge to anyone outside of the client’s access list, including the possible external data management or cloud hosting solution.
* **Seamless User Experience**: Offers frictionless integration into user workflows, ensuring files remain secure without impacting productivity.
* **Patented Dynamic and Context-Aware Access Controls**: Implements robust role-based and location-based access restrictions and revocation capability, effectively reducing risk by controlling who can access files and under what conditions. Files remain protected even when stolen.
* **Comprehensive Compatibility**: Supports encryption across various environments, including network shares, cloud storage platforms (SharePoint, AWS S3, Azure), and local file systems.
* **Real-Time Monitoring and Analytics**: Integrates seamlessly with SIEM tools to provide real-time logs, behavioral analytics, anomaly detection, and proactive threat response capabilities, further enhancing organizational security posture.
* **Revocation and Tracking:** Administrators can revoke access, set expiration times, and track who tries to open any file. This creates a **feedback loop of visibility and control**, even post-delivery.
* **Secure Sharing**: Share encrypted files outside your organization but never lose control and security.

By encrypting sensitive files and enforcing access at the source, FenixPyre ensures your data stays protected even when someone is inside your network using valid credentials. Security is baked into the file itself, so data stays secure and in compliance no matter the person, place or device.

## Quick links

{% content-ref url="/pages/1LjoHG1LlT2olZ7CkJpO" %}
[What we do](/overview/what-we-do)
{% endcontent-ref %}

## Get Started

We've put together some helpful guides for you to get setup with our product quickly and easily.

#### FenixPyre for Admins

{% content-ref url="/pages/g0mywMhkL3yfxhABpUJq" %}
[Getting Started](/fenixpyre-for-admins/getting-started)
{% endcontent-ref %}

{% content-ref url="/pages/6L2mICKdszudRV0SIEAG" %}
[Admin Dashboard](/fenixpyre-for-admins/admin-dashboard)
{% endcontent-ref %}

{% content-ref url="/pages/Y9bDBt8CBXLrr72sttVY" %}
[Integrations](/fenixpyre-for-admins/admin-dashboard/integrations)
{% endcontent-ref %}

{% content-ref url="/pages/4d9puP96wobKV2sH8F0a" %}
[Identity & Provisioning](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning)
{% endcontent-ref %}

{% content-ref url="/pages/1iQPnPqsLrwzFtURIDpS" %}
[Key management](/fenixpyre-for-admins/admin-dashboard/key-management)
{% endcontent-ref %}

{% content-ref url="/pages/HMYd9joVo5nny14Tdmf2" %}
[User Policies](/fenixpyre-for-admins/admin-dashboard/user-policies)
{% endcontent-ref %}

#### FenixPyre for Users

{% content-ref url="/pages/xGNfXNexX7eTLNDyKefO" %}
[Windows Agent](/fenixpyre-for-users/windows-agent)
{% endcontent-ref %}

{% content-ref url="/pages/mcMrfK6QMns4bIjUbPhH" %}
[FenixPyre Sharing](/fenixpyre-for-users/fenixpyre-sharing)
{% endcontent-ref %}

#### FenixPyre for Recipients

{% content-ref url="/pages/wHPpaDUCPcwZo8lTsZrN" %}
[FenixPyre for Recipients](/fenixpyre-for-recipients/fenixpyre-sharing-guide)
{% endcontent-ref %}


# What we do

#### **FenixPyre: Simplifying Post-Authentication Data Security**

FenixPyre takes the complexity out of Post-Authentication Data Security management, providing continuous protection for your sensitive data while ensuring seamless collaboration. With FenixPyre, you can trust that your data remains secure, whether it’s at rest, in transit, or in use.

{% embed url="<https://www.loom.com/share/bc8ff08511d94cf093df4ac820702ba2?sid=52cba0d0-122a-4011-bfeb-3634c74ec2d1>" %}

**Key Features:**

* **File-Level Encryption**: FenixPyre applies encryption directly to your files, creating a self-protecting perimeter that travels with the data, ensuring it remains secure wherever it goes.
* **Post-Authentication Data Security**: The platform embeds data-centric security into every file, leveraging a combination of military-grade FIPS-validated encryption and multi-factor access controls to protect your information.
* **Effortless Integration**: FenixPyre integrates seamlessly into your existing workflows, ensuring minimal disruption and eliminating friction for users while simplifying compliance efforts.
* **Comprehensive Protection**: Whether your data resides on-premises, in the cloud, or across multi-cloud environments, FenixPyre provides robust protection that supports regulatory mandates like CMMC, mitigates risks from insider threats and ransomware, and helps enforce data governance.

FenixPyre ensures that your organization can collaborate securely without compromise, meeting compliance requirements and enhancing data security with minimal effort.\ <br>


# Our Features

## Secure File Sharing

FenixPyre enhances the security of Enterprise File Synchronization and Sharing (EFSS) by providing a dedicated data security layer that bridges the gap for secure collaboration.

Organizations can retain control over their data and ensure its protection as it moves between cloud storage environments and desktop systems. FenixPyre enables secure file synchronization and sharing across the enterprise, reducing the risks of data breaches, compliance violations, and unauthorized access.\ <br>

<figure><img src="/files/pSc7FutvvWYKnwaHjlth" alt=""><figcaption><p>Secure Data During Transit</p></figcaption></figure>

##


# Getting Started

Integrating FenixPyre is straightforward and designed to limit disruptions to your current workflows. Follow our easy, step-by-step guide to seamlessly incorporate FenixPyre into your organization and start utilizing its robust security features quickly.

{% stepper %}
{% step %}

### **Prerequisites**

Before beginning the setup process, ensure the following [prerequisites](/fenixpyre-for-admins/getting-started/prerequisites-checklist) are met. These steps will confirm that your firewalls, systems, and network configurations comply with FenixPyre requirements.
{% endstep %}

{% step %}

### **Creating a tenant for your organization**

Raise a support ticket with FenixPyre team and provide the details mentioned [here](/fenixpyre-for-admins/getting-started/creating-a-tenant-for-your-organization). After that, we will set up a tenant for you and an admin will get an invitation to proceed.
{% endstep %}

{% step %}

### **Invite your team members**

[Inviting team members](/fenixpyre-for-admins/getting-started/invite-your-team-members) and assigning roles is simple, enabling immediate collaboration and secure data sharing. Promote users to admins for access to the admin dashboard.
{% endstep %}

{% step %}

### Create your first Master Encryption Key (MEK)

To activate FenixPyre encryption capabilities within your organization, [create your first master encryption key](/fenixpyre-for-admins/getting-started/create-your-master-encryption-key). You can store the Master Encryption Key using either FenixPyre HSM or a BYO-HSM (Bring Your Own HSM).
{% endstep %}

{% step %}

### Define your user policies

User policies are essential guidelines for managing permissions, applications and access controls within an organization, making it easier to manage specific users or groups. Follow [this](/fenixpyre-for-admins/getting-started/setup-user-policies) guide to define your policy.
{% endstep %}

{% step %}

### **Setup SSO and automatic user provisioning**

Set up [Single Sign-On (SSO)](/fenixpyre-for-admins/getting-started/setup-sso-and-automatic-user-provisioning) and automate user provisioning in a few clicks to manage users and groups through your Identity Provider.
{% endstep %}

{% step %}

### Install FenixPyre Windows Agent

[Download the Windows Agent](/fenixpyre-for-admins/getting-started/install-fenixpyre-windows-client-in-a-machine) from the admin dashboard to access FenixPyre's powerful features.
{% endstep %}

{% step %}

### **Integrate your cloud file storage**

Easily [connect your first cloud storage](/fenixpyre-for-admins/getting-started/create-your-first-cloud-integration) service or app for instant, secure file management throughout.
{% endstep %}
{% endstepper %}

### Other Guides

* Setup User Groups
* Setup SharePoint/OneDrive Integration
* Install FenixPyre Chrome Extension


# Prerequisites Checklist

Before the FenixPyre onboarding process can begin admin should make sure the following criterias and requirements are met

* [Firewall Settings](#firewall-settings)
* [Spam Filter Settings](#spam-filter-settings)
* [Whitelist FenixPyre's Client Software in your Antivirus/EDR/XDR \[Needed for Windows agent deployments\]](#whitelist-fenixpyres-client-software-in-your-antivirus-edr-xdr)
* [Complete Minimum system requirements \[Needed for Windows agent deployments\]](#minimum-system-requirements)

Once complete please contact [FenixPyre support](mailto:support@fenixpyre.com) so we can schedule a call to begin the FenixPyre onboarding.

## Firewall Settings

To ensure smooth communication between the FenixPyre Desktop Client and our SaaS servers, please make sure your firewall settings are updated with the below requirements.

### Domain Whitelisting

Please ensure these domains are whitelisted in your Firewall to guarantee proper operation of the FenixPyre service on user client devices.

{% hint style="info" %}
We are still in the process of changing our domains from datanchor.io and anchormydata.com to fenixpyre.com. We'll notify you if there any changes in the domain entries
{% endhint %}

<table><thead><tr><th width="172.86328125">Domain</th><th width="179">Protocol</th><th width="64">Port</th><th align="center">Description</th></tr></thead><tbody><tr><td>apis.anchormydata.com<br>apis.fenixpyre.com</td><td>HTTPS (http over TLS 1.2/1.3)</td><td>443</td><td align="center">FenixPyre Configuration</td></tr><tr><td>fenixshare.anchormydata.com<br>share.fenixpyre.com</td><td>HTTPS (http over TLS 1.2/1.3)</td><td>443</td><td align="center">FenixPyre sharing portal</td></tr><tr><td>mtls.apis.anchormydata.com<br>mtls.apis.fenixpyre.com</td><td>HTTPS (http over TLS 1.2/1.3)</td><td>443</td><td align="center">FenixPyre mutual TLS</td></tr><tr><td>admin.anchormydata.com<br>admin.fenixpyre.com</td><td>HTTPS (http over TLS 1.2/1.3)</td><td>443</td><td align="center">FenixPyre admin dashboard</td></tr><tr><td><p>oauth.anchormydata.com</p><p>oauth.fenixpyre.com</p></td><td>HTTPS (http over TLS 1.2/1.3)</td><td>443</td><td align="center">FenixPyre authentication</td></tr><tr><td>office.datanchor.io</td><td>HTTPS (http over TLS 1.2/1.3)</td><td>443</td><td align="center">FenixPyre Document Editors</td></tr><tr><td>wopi.anchormydata.com<br>wopi.fenixpyre.com</td><td>HTTPS (http over TLS 1.2/1.3)</td><td>443</td><td align="center">FenixPyre Document Editors</td></tr><tr><td>anchormydata-com.us.auth0.com</td><td>HTTPS (http over TLS 1.2/1.3)</td><td>443</td><td align="center">FenixPyre authentication</td></tr><tr><td>agent-logs-stream.anchormydata.com<br>agent-logs-stream.fenixpyre.com</td><td>HTTPS (http over TLS 1.2/1.3)</td><td>443</td><td align="center">FenixPyre Install Logs</td></tr></tbody></table>

### IP Whitelisting

{% hint style="info" %}
**Note:** We recommend whitelisting the domains because IP addresses used by cloud providers can change over time. While we provide the known IPs based on current information (as of April 3, 2025), [whitelisting by domains](#domain-whitelisting) is often more resilient if your firewall supports it. We recommend checking the official documentation from Auth0, and Cloudflare for their most current IP ranges if you encounter issues.
{% endhint %}

It is essential to configure your firewall to allow outbound connections to the following IP addresses used by our underlying service providers: Auth0 (for authentication), Cloudflare (for CDN and security), and Google Cloud Platform (for various APIs and services).

{% hint style="info" %}
Admins who have whitelisted FenixPyre servers using [domain entries](#domain-whitelisting) on their firewall can skip whitelisting individual IPs to firewall.
{% endhint %}

### 1. Auth0 (Authentication Service)

Auth0 handles user authentication processes.

* **IP Addresses to Whitelist (Grouped by Region):**
  * **United States (US) (For US Customers):**

    ```
    174.129.105.183, 18.116.79.126, 18.117.64.128, 18.191.46.63, 18.218.158.118, 
    18.218.26.94, 18.232.225.224, 18.233.90.226, 3.131.238.180, 3.131.55.63, 
    3.132.201.78, 3.133.18.220, 3.134.176.17, 3.19.44.88, 3.20.16.23, 
    3.20.244.231, 3.21.254.195, 3.211.189.167, 34.211.191.214, 34.233.19.82, 
    34.233.190.223, 35.160.3.103, 35.162.47.8, 35.166.202.113, 35.167.74.121, 
    35.171.156.124, 35.82.131.220, 44.205.93.104, 44.218.235.21, 44.219.52.110, 
    44.224.190.45, 44.246.144.93, 52.12.243.90, 52.14.149.14, 52.2.61.131, 
    52.204.128.250, 52.206.34.127, 52.33.36.223, 52.43.255.209, 52.88.192.232, 
    52.89.116.72, 54.145.227.59, 54.157.101.160, 54.200.12.78, 54.209.32.202, 
    54.245.16.146, 54.245.93.221, 54.68.157.8, 54.69.107.228 
    ```
  * **Europe (EU):**

    ```
    18.197.9.11, 18.198.229.148, 3.125.185.137, 3.65.249.224, 3.67.233.131, 
    3.68.125.137, 3.72.27.152, 3.74.90.247, 34.246.118.27, 35.157.198.116, 
    35.157.221.52, 52.17.111.199, 52.19.3.147, 52.208.95.174, 52.210.121.45, 
    52.210.122.50, 52.28.184.187, 52.30.153.34, 52.57.230.214, 54.228.204.106, 
    54.228.86.224, 54.73.137.216, 54.75.208.179, 54.76.184.103
    ```
  * **Australia (AU):**

    ```
    13.210.52.131, 13.238.180.132, 13.55.232.24, 16.50.37.252, 16.51.137.244, 
    16.51.49.47, 54.153.131.0, 54.252.2.143, 54.79.31.78
    ```
  * **Canada (CA):**

    ```
    15.222.97.193, 3.97.144.31, 40.176.144.225, 40.176.166.165, 40.177.34.170, 
    99.79.94.44
    ```
  * **Japan (JP):**

    ```
    13.208.85.227, 15.152.185.222, 15.152.2.46, 15.152.28.221, 15.152.56.146, 
    15.152.95.63, 176.34.22.106, 35.74.30.168, 43.206.201.6, 46.51.243.250, 
    54.150.87.80, 54.248.192.141
    ```
  * **United Kingdom (UK):**

    ```
    18.135.40.36, 3.10.89.10, 3.8.59.62
    ```

### 2. Cloudflare (CDN & Security)

Cloudflare is used for content delivery, performance optimization, and security for several endpoints.

* **IP Ranges to Whitelist (CIDR Notation):**\
  Cloudflare utilizes a large range of IPs. It is recommended to whitelist these entire ranges:

  ```
  173.245.48.0/20
  103.21.244.0/22
  103.22.200.0/22
  103.31.4.0/22
  141.101.64.0/18
  108.162.192.0/18
  190.93.240.0/20
  188.114.96.0/20
  197.234.240.0/22
  198.41.128.0/17
  162.158.0.0/15
  104.16.0.0/13
  104.24.0.0/14
  172.64.0.0/13
  131.0.72.0/22
  ```

  *(For the most current list, refer to Cloudflare's official IP ranges page: <https://www.cloudflare.com/ips/>)*

### 3. Google Cloud Platform (APIs & Services)

Various Google Cloud services are used for APIs and application hosting.

* **IP Addresses to Whitelist:**\
  The following specific Google IP addresses are currently known to be used:

  ```
  34.168.41.125
  34.49.147.218
  34.58.168.108
  34.49.85.80
  34.49.231.16
  34.120.34.82
  34.49.2.34      
  34.102.184.168
  34.120.207.202
  35.227.235.21
  34.36.159.126
  34.95.74.209
  34.172.254.182
  34.120.144.215
  34.49.5.35
  34.49.28.53
  35.244.198.68
  35.241.21.239
  34.149.5.18
  ```

## Spam Filter Settings (Email Settings)

To ensure FenixPyre's emails are delivered during device registration and user authentication for secure sharing, adjust spam filters to allow these messages. Access permission may be necessary.

Confirm users can receive mail from [support@fenixpyre.com,](mailto:support@fenixpyre.com) [support@anchormydata.com,](mailto:support@anchormydata.com) <help@anchormydata.com> (sent from SendGrid by Twilio - em8537.anchormydata.com)

## Whitelist FenixPyre's Client Software in your Antivirus/EDR/XDR

The FenixPyre Windows Agent installs various components such as filesystem drivers, background daemons, and local services. These components might be mistakenly flagged or blocked by your AV/EDR/XDR systems. To ensure seamless operation, consider adding FenixPyre services to the whitelist or trusted applications list in your security software.

[Follow this guide](/references/how-to-guides/how-to-whitelist-fenixpyres-windows-agent-in-your-antivirus-edr-xdr) to whitelist FenixPyre Client Software in your AV/EDR/XDR systems

### Minimum System requirements

The FenixPyre Windows Agent is compatible only with 64-bit (X64) architecture processors. Support for ARM architecture processors is currently not available

Apart from that we also require the following requirements to be met.

* [Microsoft Visual C++ Redistributable (x64) 2019 or higher is required](/references/how-to-guides/how-to-install-microsoft-visual-c++-redistributable-x64-2019-or-higher)
* [TLS 1.2 and above enabled](/references/how-to-guides/how-to-enable-tls-1.2-on-windows-for-agent-installation)
* [Install WebView2 if it is not already installed](https://docs.anchormydata.com/docs/pre-requisites-for-installing-server-agent)
* The **AppData** folder, which stores important application data, must be located on local storage rather than network storage. This is critical for performance and reliability during the operation of FenixPyre.

### FenixPyre Root Certificate Authority

FenixPyre uses a Private Certificate Authority which issues client certificates for each device using the FenixPyre Windows Agent. Since this Certificate Authority isn't trusted by default, TLS communications between the FenixPyre client on Windows and FenixPyre Cloud APIs may be blocked. To prevent issues, please whitelist the Root CA certificate or add it to the Trusted Root Certification Authorities.

{% hint style="info" %}
Contact [FenixPyre support](mailto:support@fenixpyre.com) for more information.
{% endhint %}


# Creating a tenant for your Organization

After you have selected a purchase or trial option for FenixPyre, we will begin the process of creating a tenant for your organization. To proceed, please provide the following details. Be sure to complete all [onboarding prerequisites](/fenixpyre-for-admins/getting-started/prerequisites-checklist), before submitting this information.

### **Creating a New Tenant in FenixPyre**

To create a new tenant for a customer, the following details are required:

| Information     | Description                                                                               | Example               |
| --------------- | ----------------------------------------------------------------------------------------- | --------------------- |
| Org ID          | A unique identifier of the organization                                                   | org-fp-demo           |
| Admin Email     | Provide the admin user's email address. This email will receive the login credentials for | <admin@fenixpyre.com> |
| Number of Seats | The number of user seats to be allocated in the trial version.                            | 20                    |

Submit this information to your FenixPyre point of contact or through [FenixPyre Support](mailto:support@fenixpyre.com), and we will set up your organization's tenant. The administrator will then receive an invitation to the FenixPyre dashboard.

### **Admin Invitation to FenixPyre**

Once the FenixPyre team has processed your request to join the platform as an admin, you will receive an email inviting you to access the FenixPyre admin dashboard. The email will contain the following details:

* **Organization ID**: The unique identifier for your organization (e.g., `fp-demo`).
* **Admin Dashboard URL**: The URL where you can log in and manage your organization’s FenixPyre settings (e.g., `admin.anchormydata.com`).

<figure><img src="/files/VZ0v7O2ltmEvypPGqVrM" alt="" width="375"><figcaption></figcaption></figure>

You will need to click on the **Accept Invite** button within the email to confirm your role as an admin. This link will expire within a few days, so make sure to accept it promptly.

Once the admin has logged in, the admin can invite other admin users as needed. Please read the next document for the next steps

{% hint style="info" %}
You will receive a Slack invitation to join our channel. We recommend joining for quicker support and guidance from the FenixPyre team. You'll also get regular FenixPyre product updates through this channel.
{% endhint %}


# Invite your team members

Inviting users to your FenixPyre organization is simple and quick. You can either manually add users or use [Single Sign-On (SSO)](/fenixpyre-for-admins/getting-started/setup-sso-and-automatic-user-provisioning) for streamlined user management.

### **Add Users Manually**

{% stepper %}
{% step %}

#### **Navigate to Users section**

Login into [admin dashboard](https://admin.anchormydata.com). Navigate to the **Users** section and then **Members**
{% endstep %}

{% step %}

#### **Click** the **Add New Users** button.

<figure><img src="/files/R5BPf793peX8n2XICJox" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Enter the emails

Enter one or more email addresses, separated by commas, to add users.
{% endstep %}

{% step %}

#### Click the Add button

After entering the email, click **Add** to add the users to your organization.
{% endstep %}
{% endstepper %}

### Add Users Via SSO

Alternatively, you can add users via Single Sign-On (SSO) for a more seamless user experience. To learn how to set up and manage users with SSO, click here for the detailed guide.

### Promote a user as admin

{% stepper %}
{% step %}

#### **Navigate to Users section**

Login into [admin dashboard](https://admin.anchormydata.com). Navigate to the **Users** section and then **Members**
{% endstep %}

{% step %}

#### Click on Actions menu (three dots)

Next to the user's name, click on the three dots.

<figure><img src="/files/4A7qZyzCOiSCb3kAXyJB" alt="" width="375"><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Select "Promote to admin"

Click on the button and you'll find these options

<figure><img src="/files/7ydbv8v1OOxEzHGxl9FN" alt="" width="375"><figcaption></figcaption></figure>

1. **Email-Password Login**: Selecting this option sends an invitation email to the user to join the admin dashboard. Upon accepting the invite, the user must set
2. **SSO Login:** Choose this option to send an invitation email prompting the user to join the admin dashboard. The user must log in using SSO to access the admin dashboard.

{% hint style="info" %}
The SSO login method will only be shown if you have SSO configured
{% endhint %}
{% endstep %}
{% endstepper %}

### **Video Tutorial**

For a step-by-step visual guide on how to add users, watch our video tutorial on Loom here.

{% embed url="<https://www.loom.com/share/51eb46252a034a598aa5471ba1075ae0?sid=727efb51-8796-42ba-ab9b-ef28cf5abdcc>" %}


# Create your Master Encryption Key

A Master Encryption Key (MEK) is a crucial key generated by an organization and stored within a Hardware Security Module (HSM). These keys are used to encrypt File Encryption Keys before they are stored in the database. MEKs are essential in key management systems, significantly enhancing data security and controlling access.<br>

<figure><img src="/files/qmBDaFN7Yj16rtY8eclP" alt="" width="188"><figcaption><p>Master Encryption Key Architecture</p></figcaption></figure>

{% hint style="warning" %}
Admins must ensure that a Master Encryption Key is created for your organization as FenixPyre's file encryption and decryption require an active key before proceeding to installing Windows Agent or using Fenix Share.
{% endhint %}

FenixPyre provides three distinct methods to generate your Master Key, allowing for flexibility tailored to your security needs and preferences. Select the option that aligns best with your organization’s requirements:

1. [Create Your Own Master Key with FenixPyre](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/create-master-encryption-key-with-fenixpyre)
2. [Bring Your Own Google HSM (Hardware Security Module)](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-google-hsm/create-a-master-encryption-key-and-store-in-google-hsm)
3. [Bring Your Own Azure HSM (Hardware Security Module)](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-azure/configure-azure-key-vault-as-bring-your-own-key-provider)


# Setup SSO and automatic user provisioning

### SAML Single Sign-On Setup

FenixPyre offers two flexible options for setting up SAML-based Single Sign-On (SSO), allowing you to integrate with your organization’s existing identity provider:

1. **Azure Active Directory (Entra ID) SSO Integration**

Admin can set up SAML SSO using **Azure Active Directory (Entra ID)**. This method integrates FenixPyre with your Azure AD instance, enabling secure and centralized access management for your organization’s users.

Follow through this guide to [setup Azure Active Directory](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/saml-single-sign-on-sso-setup/set-up-saml-sso-with-azure).

2. **Okta SSO Integration**

FenixPyre seamlessly integrates with **Okta** for SAML-based authentication. With Okta, you can manage user access across all your applications with ease, while leveraging Okta’s robust security and user management features.

Follow through this guide to [setup Okta SSO Integration](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/saml-single-sign-on-sso-setup/set-up-saml-sso-with-okta).

### Automatic User Provisioning Setup (SCIM Provisioning)

Using SCIM, you can automatically provision and de-provision users in your identity provider (IdP).

Follow through this guide to [setup SCIM provisioning](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/scim).


# Create your first cloud integration

FenixPyre makes it easy to integrate with major cloud storage services, enabling secure access and management of your files. Whether you're using Box, SharePoint, or Egnyte, FenixPyre ensures that your sensitive data remains protected while making it accessible across platforms.

## **Supported Cloud Integrations:**

### **SharePoint**

SharePoint integration with FenixPyre enables you to securely store and share files within your organization's SharePoint environment. With the added security features of FenixPyre, you can ensure that sensitive documents are encrypted while maintaining compliance with security regulations.

#### Get Started

{% content-ref url="/pages/oVw1EVvJVtkNyPtoA8ZC" %}
[SharePoint/OneDrive](/fenixpyre-for-admins/admin-dashboard/integrations/sharepoint-onedrive)
{% endcontent-ref %}

### Box

FenixPyre integrates seamlessly with Box, allowing you to manage your Box files securely and access them with confidence. With FenixPyre, you can ensure that files stored on Box are protected through encryption, while allowing authorized users to collaborate effectively.

#### Get Started

{% content-ref url="/pages/S7o4dyMLWAL7h1rOB9FR" %}
[Box](/fenixpyre-for-admins/admin-dashboard/integrations/box)
{% endcontent-ref %}

### Egnyte

Egnyte is another supported platform that works seamlessly with FenixPyre. This integration provides a secure way to access, manage, and share files across Egnyte, ensuring that data is encrypted both in transit and at rest.

#### Get Started

{% content-ref url="/pages/mBp49XTZdqcnDEf5prs6" %}
[Egnyte](/fenixpyre-for-admins/admin-dashboard/integrations/egnyte)
{% endcontent-ref %}


# Setup User Policies

{% content-ref url="/pages/HMYd9joVo5nny14Tdmf2" %}
[User Policies](/fenixpyre-for-admins/admin-dashboard/user-policies)
{% endcontent-ref %}

{% content-ref url="/pages/jwkTtKkj2lymqahw2BIp" %}
[Policy Rules Guide](/fenixpyre-for-admins/admin-dashboard/user-policies/policy-rules-guide)
{% endcontent-ref %}


# Install FenixPyre Windows Client in a machine

### Prerequisites Checklist

{% content-ref url="/pages/QzLFlmmYVoJgEz0JHaIQ" %}
[Prerequisites Checklist](/fenixpyre-for-admins/getting-started/prerequisites-checklist)
{% endcontent-ref %}

{% content-ref url="/pages/fNI4DDHIjhV23KyAgn6y" %}
[How to download FenixPyre Windows Agent from Installers Page](/fenixpyre-for-admins/admin-dashboard/installers/fenixpyre-windows-client/how-to-download-fenixpyre-windows-agent-from-installers-page)
{% endcontent-ref %}

{% content-ref url="/pages/KNMPqyjcu4HZ1F9ZwRUl" %}
[Auto Update and Upgrade Management of FenixPyre Windows Client](/fenixpyre-for-admins/admin-dashboard/installers/fenixpyre-windows-client/auto-update-and-upgrade-management-of-fenixpyre-windows-client)
{% endcontent-ref %}

###


# Firewall Whitelisting Requirements for FenixPyre Services

### Introduction

To ensure seamless operation and communication for services associated with `fenixpyre.com`, `anchormydata.com` and `datanchor.io`, it is essential to configure your firewall to allow outbound connections to specific DNS hostnames and IP addresses used by our underlying service providers: Auth0 (for authentication), Cloudflare (for CDN and security), and Google Cloud Platform (for various APIs and services).

Please whitelist the following DNS names and IP addresses/ranges in your firewall for outbound traffic, typically over HTTPS (port 443).

**Note:** IP addresses used by cloud providers can change over time. While we provide the known IPs based on current information (as of April 3, 2025), whitelisting by DNS hostname is often more resilient if your firewall supports it. We recommend checking the official documentation from Auth0, Cloudflare, and Google for their most current IP ranges if you encounter issues.

### 1. Auth0 (Authentication Service)

Auth0 handles user authentication processes.

* **DNS Hostnames to Whitelist:**
  * `anchormydata-com.us.auth0.com`
  * `oauth.anchormydata.com`
* **IP Addresses to Whitelist (Grouped by Region):**
  * **United States (US):**

    ```
    174.129.105.183, 18.116.79.126, 18.117.64.128, 18.191.46.63, 18.218.158.118, 
    18.218.26.94, 18.232.225.224, 18.233.90.226, 3.131.238.180, 3.131.55.63, 
    3.132.201.78, 3.133.18.220, 3.134.176.17, 3.19.44.88, 3.20.16.23, 
    3.20.244.231, 3.21.254.195, 3.211.189.167, 34.211.191.214, 34.233.19.82, 
    34.233.190.223, 35.160.3.103, 35.162.47.8, 35.166.202.113, 35.167.74.121, 
    35.171.156.124, 35.82.131.220, 44.205.93.104, 44.218.235.21, 44.219.52.110, 
    44.224.190.45, 44.246.144.93, 52.12.243.90, 52.14.149.14, 52.2.61.131, 
    52.204.128.250, 52.206.34.127, 52.33.36.223, 52.43.255.209, 52.88.192.232, 
    52.89.116.72, 54.145.227.59, 54.157.101.160, 54.200.12.78, 54.209.32.202, 
    54.245.16.146, 54.245.93.221, 54.68.157.8, 54.69.107.228 
    ```
  * **Europe (EU):**

    ```
    18.197.9.11, 18.198.229.148, 3.125.185.137, 3.65.249.224, 3.67.233.131, 
    3.68.125.137, 3.72.27.152, 3.74.90.247, 34.246.118.27, 35.157.198.116, 
    35.157.221.52, 52.17.111.199, 52.19.3.147, 52.208.95.174, 52.210.121.45, 
    52.210.122.50, 52.28.184.187, 52.30.153.34, 52.57.230.214, 54.228.204.106, 
    54.228.86.224, 54.73.137.216, 54.75.208.179, 54.76.184.103
    ```
  * **Australia (AU):**

    ```
    13.210.52.131, 13.238.180.132, 13.55.232.24, 16.50.37.252, 16.51.137.244, 
    16.51.49.47, 54.153.131.0, 54.252.2.143, 54.79.31.78
    ```
  * **Canada (CA):**

    ```
    15.222.97.193, 3.97.144.31, 40.176.144.225, 40.176.166.165, 40.177.34.170, 
    99.79.94.44
    ```
  * **Japan (JP):**

    ```
    13.208.85.227, 15.152.185.222, 15.152.2.46, 15.152.28.221, 15.152.56.146, 
    15.152.95.63, 176.34.22.106, 35.74.30.168, 43.206.201.6, 46.51.243.250, 
    54.150.87.80, 54.248.192.141
    ```
  * **United Kingdom (UK):**

    ```
    18.135.40.36, 3.10.89.10, 3.8.59.62
    ```

### 2. Cloudflare (CDN & Security)

Cloudflare is used for content delivery, performance optimization, and security for several endpoints.

* **DNS Hostnames to Whitelist:**
  * `apis.anchormydata.com`
  * `fenixshare.anchormydata.com`
  * `admin.anchormydata.com`
  * `wopi.anchormydata.com`
  * `apis.fenixpyre.com`
  * `share.fenixpyre.com`
  * `admin.fenixpyre.com`
  * `wopi.fenixpyre.com`
* **IP Ranges to Whitelist (CIDR Notation):**\
  Cloudflare utilizes a large range of IPs. It is recommended to whitelist these entire ranges:

  ```
  173.245.48.0/20
  103.21.244.0/22
  103.22.200.0/22
  103.31.4.0/22
  141.101.64.0/18
  108.162.192.0/18
  190.93.240.0/20
  188.114.96.0/20
  197.234.240.0/22
  198.41.128.0/17
  162.158.0.0/15
  104.16.0.0/13
  104.24.0.0/14
  172.64.0.0/13
  131.0.72.0/22
  ```

  *(For the most current list, refer to Cloudflare's official IP ranges page: <https://www.cloudflare.com/ips/>)*

### 3. Google Cloud Platform (APIs & Services)

Various Google Cloud services are used for APIs and application hosting.

* **DNS Hostnames to Whitelist:**
  * `apis.anchormydata.com` *(Also listed under Cloudflare)*
  * `fenixshare.anchormydata.com` *(Also listed under Cloudflare)*
  * `mtls.apis.anchormydata.com`
  * `admin.anchormydata.com` *(Also listed under Cloudflare)*
  * `wopi.anchormydata.com` *(Also listed under Cloudflare)*
  * `apis.fenixpyre.com` *(Also listed under Cloudflare)*
  * `share.fenixpyre.com` *(Also listed under Cloudflare)*
  * `mtls.apis.fenixpyre.com`
  * `admin.fenixpyre.com` *(Also listed under Cloudflare)*
  * `wopi.fenixpyre.com` *(Also listed under Cloudflare)*
* **IP Addresses to Whitelist:**\
  The following specific Google IP addresses are currently known to be used:

  ```
  34.168.41.125
  34.49.147.218
  34.58.168.108
  34.49.85.80
  34.49.231.16
  34.120.34.82
  34.49.2.34      
  34.102.184.168
  34.120.207.202
  35.227.235.21
  34.36.159.126
  34.95.74.209
  34.172.254.182
  34.120.144.215
  34.49.5.35
  34.49.28.53
  35.244.198.68
  35.241.21.239
  34.149.5.18
  ```

***

By ensuring these endpoints are accessible through your firewall, you facilitate the proper functioning of AnchorMyData services. Please consult your firewall documentation for instructions on adding DNS and IP-based rules.


# Admin Dashboard

### Dashboard

{% content-ref url="/pages/c26dGTUhwGbqtOny7miz" %}
[Home](/fenixpyre-for-admins/admin-dashboard/home)
{% endcontent-ref %}

### Directory

{% content-ref url="/pages/ftDBElILRhjG7P2NxuI7" %}
[User Management](/fenixpyre-for-admins/admin-dashboard/user-management)
{% endcontent-ref %}

{% content-ref url="/pages/Owrt4f5hZIcrIJH47O5l" %}
[Groups Management](/fenixpyre-for-admins/admin-dashboard/groups-management)
{% endcontent-ref %}

### Platform

{% content-ref url="/pages/rxyGGKtqC0su1pUPKgKY" %}
[Installers](/fenixpyre-for-admins/admin-dashboard/installers)
{% endcontent-ref %}

{% content-ref url="/pages/GX9n3zOo5U9xa1MXxZxs" %}
[Reports](/fenixpyre-for-admins/admin-dashboard/reports)
{% endcontent-ref %}

### FenixPyre Sharing

{% content-ref url="/pages/Y9bDBt8CBXLrr72sttVY" %}
[Integrations](/fenixpyre-for-admins/admin-dashboard/integrations)
{% endcontent-ref %}

{% content-ref url="/pages/GQZXHRkdeerOVQQKhii5" %}
[Sharing Settings](/fenixpyre-for-admins/admin-dashboard/sharing-settings)
{% endcontent-ref %}

### Security

{% content-ref url="/pages/4d9puP96wobKV2sH8F0a" %}
[Identity & Provisioning](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning)
{% endcontent-ref %}

{% content-ref url="/pages/1iQPnPqsLrwzFtURIDpS" %}
[Key management](/fenixpyre-for-admins/admin-dashboard/key-management)
{% endcontent-ref %}

{% content-ref url="/pages/HMYd9joVo5nny14Tdmf2" %}
[User Policies](/fenixpyre-for-admins/admin-dashboard/user-policies)
{% endcontent-ref %}

{% content-ref url="/pages/PmYs1mxEUd5JfYUcDpuK" %}
[User Applications](/fenixpyre-for-admins/admin-dashboard/user-applications)
{% endcontent-ref %}


# Home

The **Admin Dashboard** in FenixPyre provides administrators with a comprehensive view of user activity, file interactions, and platform performance. This centralized panel is designed to make monitoring and managing your organization’s data security and user behavior easier.

<figure><img src="/files/y6uxzPYOVRoXyHSjbtJb" alt=""><figcaption></figcaption></figure>

### **Key Sections of the Admin Dashboard:**

1. **Overview**:
   * Displays key metrics such as the total number of active files and users.
   * **Active Files**: Shows the number of files being actively managed, including changes over time.
   * **Active Users**: Displays the number of active users, allowing administrators to track user engagement with the platform.
2. **Recent Activity**:
   * A feed that highlights the latest actions taken by users, such as modifying files.
   * Each activity entry includes information on the user and the file they interacted with, as well as the action performed (e.g., **ANCHOR**, **UNANCHOR,** etc.).
3. **Active File Actions**:
   * Provides insights into specific file interactions (e.g., co-editing) performed by users.
   * The section displays the number of file actions (e.g., co-editing, file modifications) .
4. **Active Applications**:
   * Displays a breakdown of the active applications used within your organization, visualizing how different apps are being utilized for file access and management.


# User Management


# Invite your team members

Inviting users to your FenixPyre organization is simple and quick. You can either manually add users or use [Single Sign-On (SSO)](/fenixpyre-for-admins/getting-started/setup-sso-and-automatic-user-provisioning) for streamlined user management.

### **Add Users Manually**

{% stepper %}
{% step %}

#### **Navigate to Users section**

Login into [admin dashboard](https://admin.anchormydata.com). Navigate to the **Users** section and then **Members**
{% endstep %}

{% step %}

#### **Click** the **Add New Users** button.

<figure><img src="/files/R5BPf793peX8n2XICJox" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Enter the emails

Enter one or more email addresses, separated by commas, to add users.
{% endstep %}

{% step %}

#### Click the Add button

After entering the email, click **Add** to add the users to your organization.
{% endstep %}
{% endstepper %}

### Add Users Via SSO

Alternatively, you can add users via Single Sign-On (SSO) for a more seamless user experience. To learn how to set up and manage users with SSO, [click here for the detailed guide.](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/scim)

### Promote a user as admin

{% stepper %}
{% step %}

#### **Navigate to Users section**

Login into [admin dashboard](https://admin.anchormydata.com). Navigate to the **Users** section and then **Members**
{% endstep %}

{% step %}

#### Click on Actions menu (three dots)

Next to the user's name, click on the three dots.

<figure><img src="/files/4A7qZyzCOiSCb3kAXyJB" alt="" width="375"><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Select "Promote to admin"

Click on the button and you'll find these options

<figure><img src="/files/7ydbv8v1OOxEzHGxl9FN" alt="" width="375"><figcaption></figcaption></figure>

1. **Email-Password Login**: Selecting this option sends an invitation email to the user to join the admin dashboard. Upon accepting the invite, the user must set
2. **SSO Login:** Choose this option to send an invitation email prompting the user to join the admin dashboard. The user must log in using SSO to access the admin dashboard.

{% hint style="info" %}
The SSO login method will only be shown if you have SSO configured
{% endhint %}
{% endstep %}
{% endstepper %}

### **Video Tutorial**

For a step-by-step visual guide on how to add users, watch our video tutorial on Loom here.

{% embed url="<https://www.loom.com/share/51eb46252a034a598aa5471ba1075ae0?sid=727efb51-8796-42ba-ab9b-ef28cf5abdcc>" %}


# Manage Guests

While FenixPyre does not allow the creation of guest users, the platform provides functionality to manage external users who access shared links.

**External User Access to FenixPyre Shared Links:**

* **Automatic User Creation**:\
  When an external user accesses a FenixPyre shared link, a user account will be automatically created for them in the system. This ensures that the external user can securely access the shared content.
* **Deactivate External Users**:\
  If necessary, administrators have the ability to deactivate these external users after they have been created. This gives the organization full control over external user access, ensuring that only authorized individuals can continue to interact with shared resources.


# Groups Management

## How to create a FenixPyre managed group

Creating groups in FenixPyre helps you organize users and manage access permissions more efficiently.

Follow these simple steps to create a group

{% stepper %}
{% step %}

### Navigate to groups

Go to the **Groups** section in the FenixPyre admin dashboard.

<figure><img src="/files/yntjeiFeEJHflikJVUcO" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### **Click on "Create Group"**

Once you're in the Groups section, click on the **Create Group** button.

<figure><img src="/files/iqUZfv0bXkqdIm3HbUUV" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### **Enter a Group Name**

Provide a name for the group. This name will help you identify the group and assign appropriate permissions.
{% endstep %}

{% step %}

### Click on Create

After entering the group name, click the **Create** button to finalize the group creation process.
{% endstep %}
{% endstepper %}

## How to import groups from Identity Provider

To import a group into FenixPyre, you must have **SCIM (System for Cross-domain Identity Management)** configured. This allows FenixPyre to sync with your SAML SSO provider (Okta or Azure).

**Steps to Import a Group:**

1. **Ensure SCIM is Configured**:\
   Before importing a group, make sure that SCIM is properly configured with your SAML SSO provider (either Okta or Azure). SCIM enables FenixPyre to automatically sync with your identity provider.
2. **Click on "Import Group"**:\
   Navigate to the **Groups** section in the FenixPyre admin dashboard. Click on the **Import Group** button to begin the process

.![](/files/YHcbvf2PyjS3zHa6uENP)

1. **View the Linked Groups**:\
   After clicking "Import Group," you will see a list of groups that are linked with your FenixPyre app in your SAML SSO provider (Okta or Azure).![](/files/M6NpUj3vMCuAtxUHWCJN)
2. **Select the Groups to Import**:\
   From the list of available groups, select the groups you wish to import into FenixPyre.
3. **Click on "Import"**:\
   After selecting the groups, click on the **Import** button to import the chosen groups into FenixPyre.

Once imported, the groups will be available within the FenixPyre platform, and you can assign permissions and manage access as needed


# Installers

{% content-ref url="/pages/fNI4DDHIjhV23KyAgn6y" %}
[How to download FenixPyre Windows Agent from Installers Page](/fenixpyre-for-admins/admin-dashboard/installers/fenixpyre-windows-client/how-to-download-fenixpyre-windows-agent-from-installers-page)
{% endcontent-ref %}

{% content-ref url="/pages/KNMPqyjcu4HZ1F9ZwRUl" %}
[Auto Update and Upgrade Management of FenixPyre Windows Client](/fenixpyre-for-admins/admin-dashboard/installers/fenixpyre-windows-client/auto-update-and-upgrade-management-of-fenixpyre-windows-client)
{% endcontent-ref %}


# FenixPyre Windows Client

{% content-ref url="/pages/KNMPqyjcu4HZ1F9ZwRUl" %}
[Auto Update and Upgrade Management of FenixPyre Windows Client](/fenixpyre-for-admins/admin-dashboard/installers/fenixpyre-windows-client/auto-update-and-upgrade-management-of-fenixpyre-windows-client)
{% endcontent-ref %}

{% content-ref url="/pages/fNI4DDHIjhV23KyAgn6y" %}
[How to download FenixPyre Windows Agent from Installers Page](/fenixpyre-for-admins/admin-dashboard/installers/fenixpyre-windows-client/how-to-download-fenixpyre-windows-agent-from-installers-page)
{% endcontent-ref %}

{% content-ref url="/spaces/OuMyGdeUQs2m5OYPFuwT/pages/Sp795akbbTTA2hlAc1mp" %}
[Broken mention](broken://spaces/OuMyGdeUQs2m5OYPFuwT/pages/Sp795akbbTTA2hlAc1mp)
{% endcontent-ref %}

{% content-ref url="/pages/1L7uyyDhgTw7sQbtcmrd" %}
[How to install FenixPyre Windows Desktop Client](/fenixpyre-for-admins/fenixpyre-windows-agent/how-to-install-fenixpyre-windows-desktop-client)
{% endcontent-ref %}

{% content-ref url="/pages/WgZSmjRxjGYQFCbcmpPI" %}
[How to un-install FenixPyre Windows Client](/fenixpyre-for-users/windows-agent/how-to-un-install-fenixpyre-windows-client)
{% endcontent-ref %}


# How to download FenixPyre Windows Agent from Installers Page

### Download FenixPyre Windows Agent

Follow these steps to successfully install FenixPyre on your system:

{% stepper %}
{% step %}
**Ensure Minimum System Requirements Are Met**

Before beginning the installation, ensure that your system meets all the **prerequisites**. [Check this document for prerequisites](/fenixpyre-for-admins/fenixpyre-windows-agent/prerequisites-for-fenixpyre-windows-client-installation). Verify that the necessary configurations, such as supported operating systems, disk space, and other required settings, are in place.
{% endstep %}

{% step %}
**Download the FenixPyre Installer zip file**

* **Go to the Admin Dashboard**: Log in to the FenixPyre admin dashboard.
* **Navigate to Installers**: On the dashboard, click on the **Installers** section to view available installer versions.
* **Download the Desired Version**: Find and click the **download icon** next to FenixPyre version **6.3.0+** to download the installer zip file to your machine.

<figure><img src="/files/rQn8kAeSqoGXedexVadk" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Unzip the Downloaded File**

* Once the zip file is downloaded, **right-click** on the file and select **Extract All** to unzip the contents.
* This will extract the **FPInstaller.exe** executable that you’ll use to install FenixPyre.
  {% endstep %}
  {% endstepper %}

### Install FenixPyre Windows Desktop Client

{% content-ref url="/pages/1L7uyyDhgTw7sQbtcmrd" %}
[How to install FenixPyre Windows Desktop Client](/fenixpyre-for-admins/fenixpyre-windows-agent/how-to-install-fenixpyre-windows-desktop-client)
{% endcontent-ref %}


# Auto Update and Upgrade Management of FenixPyre Windows Client

### **Concept of Default Installer and its properties:**

Please note the following:

1. Once a new installer is released by FenixPyre and made available on the *Installers* page, it is the responsibility of the FenixPyre administrator to mark that installer as default, at which time the installer will be made available for updates.
2. The ability to specify a default xinstaller allows FenixPyre administrators the opportunity to test a newly released version first, before rolling it out to their user population at large.
3. Once an installer is marked as default, any automatic update checks by already installed agent software will result in the default installer being selected for downloading and updating.
4. Support for a default installer version allows administrators full control over the automatic update process, while still providing necessary flexibility for manual downloads of non-default versions by administrators.
5. *It is critical to note again that once a new installer version is released by FenixPyre and is listed in the Installers page, end user agent installations will not be aware of the availability of the new installer version until it is marked as the default installer by the FenixPure administrator.*

Consider the following Installers page of the FenixPyre dashboard, with a total of five versions for download (shown for illustrative purposes only), listed from newest to oldest, with the most recent version listed at the top of the page:

<figure><img src="/files/sv0IbBCrtbrySiQ4JvgA" alt=""><figcaption><p>Installers page</p></figcaption></figure>

Note that *FenixPyre\_v6.3.0* is marked as the default installer. Note also that an installer version more recent than the default installer has since been released and made available on the page (i.e. version *FenixPyre\_v6.4.0*).

In the above example:

1. When an agent running an older installation (e.g. version *Anchor\_v5.3.3*) automatically checks for an available update, the system will provide installer version *FenixPyre\_v6.3.0* as the suitable installer for an update (because it is marked as default), although a more recent installer version (*FenixPyre\_v6.4.0*) is available.
2. This behavior is by design, and as mentioned earlier, allows administrators precise control over installer deployments.
3. When the administrator is satisfied that the new installer *FenixPyre\_v6.4.0* can be rolled out to end users, the administrator can mark that installer as default.

Please note:

1. Agent software does not have the capability to downgrade to earlier versions.
2. Unintentional marking of an older installer version will be ignored by any installed agent software that is at a more recent version.
3. As an example, if all of the end users are running a version that is more recent than installer version *FenixPyre\_v6.3.0*, and *FenixPyre\_v6.3.0* is inadvertently marked as default, the default marking will be ignored by the agents, and will be interpreted as no update being available, because agents will already be at a more recent installer version than the default marked installer version.

**Minor and major types of installers:**

FenixPyre installer releases may be one of two types, minor or major, with the following properties:

1. During an update, a minor type release does not require a Windows reboot during installation.
2. If a minor type release is installed on a Windows system that currently does not have a previous FenixPyre installation (i.e. a fresh install from scratch), reboots will be required.
3. A major type release includes updates to the driver components and will require reboots during installation, whether as part of an update or as a fresh install from scratch.

(Note: In rare instances, a minor type release will involve Windows reboot during an update operation. FenixPyre will advise administrators of such cases and point out the need for reboots.)

### **Downloading non-default installers:**

Note that in the above example, despite the default installer version being specified as *FenixPyre\_v6.3.0*, the more recent version *FenixPyre\_v6.4.0* (or any other installer on the page) may still be downloaded seperately by the FenixPyre administrator. An installer downloaded in this manner will require manual installation on an endpoint.

To access additional details about any installer, either:

* Click the down arrowhead symbol at the far right, or
* Click anywhere on the body of the installer description.

The entry for the corresponding installer version will expand down and reveal a button to initiate downloads as well as other information, as shown below:

![expand installer entry.gif](/files/IccmuS6haQqB5LHzgi9W)

**Changing the default installer:**

To mark another installer as default:

1. Click the 'more information' icon (with three vertical dots **⋮**, located in the upper right corner of the installer entry).
2. Click the 'Set as default' option.
3. Click the 'Yes' button in the confirmation dialog.

Observe the message 'Default installer set successfully' at the top of the page. The example below sets installer *FenixPyre\_v6.4.0* as the default installer, removing the default setting from installer *FenixPyre\_v6.3.0*:

![change default installer.gif](/files/q6xbm2dZJcYt6WuUJmjg)

Please note the following:

1. At any time, only one installer version can be marked as default.
2. When an installer is marked as default, the default marking will be removed from the currently marked installer.
3. The only way to remove a default marking from an installer is to mark another installer as default.

**Checking file signatures:**

The file signatures of the contents comprising an installer zip file are available for all installers. To access this information

1. Click the 'more information' icon (with three vertical dots **⋮** located in the upper right corner of any installer entry).
2. Click the 'Show installer signatures' option displayed.

The SHA-256 hash values for all three component files of the installer zip file will be displayed.

To copy the signatures to the Windows clipboard, click the 'Copy to clipboard' button, as illustrated below:

![show signatures.gif](/files/mtybXTmBkKukafZRl8E5)


# FenixPyre Standalone Encryption Utility

The FenixPyre Standalone Encryption Utility is a powerful, high-performance application designed to secure encrypt sensitive files at rest using FIPS 140-2 validated AES-256 cryptographic libraries.

{% content-ref url="/pages/IN6NyzbDjBApCxsH8tqF" %}
[Overview](/fenixpyre-for-admins/admin-dashboard/fenixpyre-standalone-encryption-utility/overview)
{% endcontent-ref %}

{% content-ref url="/pages/sSP88oSKWInp3lzK3xAJ" %}
[How to encrypt and decrypt files using FenixPyre Standalone Encryption Utility?](/fenixpyre-for-admins/admin-dashboard/fenixpyre-standalone-encryption-utility/how-to-encrypt-and-decrypt-files-using-fenixpyre-standalone-encryption-utility)
{% endcontent-ref %}

{% content-ref url="/pages/OyHTnfWQBGxDirc6SEHe" %}
[Registry Values Guide](/fenixpyre-for-admins/admin-dashboard/fenixpyre-standalone-encryption-utility/registry-values-guide)
{% endcontent-ref %}

{% content-ref url="/pages/xw4e2yDWmCAgegAobRYs" %}
[Limitations, FAQ and Best Practices](/fenixpyre-for-admins/admin-dashboard/fenixpyre-standalone-encryption-utility/limitations-faq-and-best-practices)
{% endcontent-ref %}


# Overview

The FenixPyre Standalone Encryption Tool is a powerful, high-performance application designed to securely encrypt sensitive files at rest using FIPS 140-2 validated AES-256 cryptographic libraries.

FenixPyre Windows suite has 2 components:

* **FenixPyre Windows Client**: Primary use is for end-user Windows devices (Windows 10 and 11) who needs to access encrypted files using native desktop applications. The Windows Client can encrypt and decrypt files but not as fast and efficiently as the Standalone Encryption Tool.
* **FenixPyre Standalone Encryption Tool**: Primary use is to install on Windows Servers (Windows 2019 and above) to encrypt and decrypt files at scale. We recommend not to install this tool and the Windows client simultaneously as it impacts the performance of the tool.

### What Can the Standalone Encryption Tool Do?

* **Efficient Data Handling:** Designed for managing datasets over multiple TBs seamlessly.
* **Storage Optimization:** Optimized for both local and network storage environments.
* **Multi-threaded Processing:** Enhances large-scale encryption tasks.
* **Performance and Scalability:** Built for robust performance and scale.
* **Customizable Settings:** Modify encryption options via registry settings.
* **Recursive Encryption/Decryption:** Capable of encrypting and decrypting directories recursively.
* **Strong Encryption Standards:** Utilizes FIPS 140-2 validated AES-256 cryptographic libraries for strong, military-grade data protection.

### Prerequisites Checklist

* Make sure **FenixPyre Windows Client** is not running on the system.
* By default, Windows services run under the Local System account. When using this tool to encrypt or decrypt files on a network share, ensure that the Local System account has the required permissions on the network share folder. If the necessary permissions are not granted, consider changing the service's logon user to an account that has the appropriate access rights to the network share.
* Minimum System requirements
  * Supported OS: Windows 10, 11 and Windows Server 2016 and above
  * Apart from that we also require the following requirements to be met.
    * [Microsoft Visual C++ Redistributable (x64) 2019 or higher is required](/references/how-to-guides/how-to-install-microsoft-visual-c++-redistributable-x64-2019-or-higher)
    * [TLS 1.2 and above enabled](/references/how-to-guides/how-to-enable-tls-1.2-on-windows-for-agent-installation)
* To get access to the **Prerequisite Checker Utility** and **Standlone Encryption Tool** contact [FenixPyre Support](mailto:support@fenixpyre.com)
* Certificate Installation - Contact [FenixPyre support](mailto:support@fenixpyre.com) for getting the secret certificate file. We will make this process easier in the future iterations for the encryption tool.

{% content-ref url="/pages/sSP88oSKWInp3lzK3xAJ" %}
[How to encrypt and decrypt files using FenixPyre Standalone Encryption Utility?](/fenixpyre-for-admins/admin-dashboard/fenixpyre-standalone-encryption-utility/how-to-encrypt-and-decrypt-files-using-fenixpyre-standalone-encryption-utility)
{% endcontent-ref %}

{% content-ref url="/pages/OPhKdHZrO7WfWcUaJIxe" %}
[How to decrypt files using FenixPyre Standalone Encryption Utility ?](/fenixpyre-for-admins/admin-dashboard/fenixpyre-standalone-encryption-utility/how-to-decrypt-files-using-fenixpyre-standalone-encryption-utility)
{% endcontent-ref %}

{% content-ref url="/pages/OyHTnfWQBGxDirc6SEHe" %}
[Registry Values Guide](/fenixpyre-for-admins/admin-dashboard/fenixpyre-standalone-encryption-utility/registry-values-guide)
{% endcontent-ref %}

{% content-ref url="/pages/aAtI6jnchb1UWOnysQ6U" %}
[FenixPyre Prerequisites Checker Documentation](/fenixpyre-for-admins/admin-dashboard/fenixpyre-standalone-encryption-utility/fenixpyre-prerequisites-checker-documentation)
{% endcontent-ref %}

{% content-ref url="/pages/xw4e2yDWmCAgegAobRYs" %}
[Limitations, FAQ and Best Practices](/fenixpyre-for-admins/admin-dashboard/fenixpyre-standalone-encryption-utility/limitations-faq-and-best-practices)
{% endcontent-ref %}


# FenixPyre Prerequisites Checker Documentation

### Overview

The FenixPyre Prerequisites Checker is a tool that checks if your system and network environment meet the requirements for running FenixPyre. It performs several automatic checks to identify potential issues before you begin the installation process.

{% hint style="info" %}
Follow [this link](/fenixpyre-for-admins/getting-started/prerequisites-checklist) to understand the complete prerequisites for running FenixPyre. This tool focuses on checking if your environment meets running FenixPyre Standalone Encryption Utility
{% endhint %}

### How to Use

1. Contact [FenixPyre support](mailto:support@fenixpyre.com) and download the FenixPyre Prerequisites Checker application.
2. Open a powershell windows in administrator mode (optional).
3. Navigate to the folder containing the checker.
4. Run the application with your organization information:

   ```
   ./fenixpyre-checker --org-id yourOrgID --user-id your@email.com
   ```

#### Optional Parameters

* `--skip-ip-check`: Makes the check run faster by skipping IP connectivity tests.
* `--use-tcp`: Uses an alternative method to check network connectivity if standard methods are blocked in your environment.

### What It Checks

#### 1. Network Connectivity

Verifies your system can reach all required FenixPyre services.

#### 2. Security Protocols

Checks if your system supports modern security standards (TLS 1.2 or 1.3) required for secure communications.

#### 3. Firewall Settings

Tests if your network allows connections to all necessary IP addresses used by FenixPyre services.

#### 4. Windows-Specific Requirements (Windows only)

* Confirms you have the right system architecture (64-bit)
* Checks for required software components:
  * Microsoft Visual C++ Redistributable
  * Microsoft Edge WebView2
* Verifies your system settings are configured correctly

#### 5. Authentication Setup (Windows only)

Tests if your system has the proper security certificates installed.

#### 6. Organization Configuration

Verifies your organization's FenixPyre configuration is properly set up (when organization ID is provided).

### Understanding the Results

The checker provides a detailed report with check marks (✅) and X marks (❌) to indicate which requirements passed or failed:

* ✅ **Passed**: This requirement is met.
* ❌ **Failed**: This requirement is not met and needs to be addressed.
* ⚠️ **Warning/Skipped**: This check was either skipped or requires manual verification.

### Next Steps

#### If All Checks Pass

* Verify your email spam filter settings to ensure you'll receive communications from FenixPyre.
* Contact FenixPyre support to schedule your onboarding.

#### If Some Checks Fail

Address the issues indicated in the report:

1. **Network Connectivity Issues**
   * Ensure your network firewall allows access to the required endpoints.
   * Contact your IT department to adjust network settings if needed.
2. **Security Protocol Issues**
   * Update your operating system to support modern security standards.
   * Ensure TLS 1.2 or 1.3 is enabled on your system.
3. **Windows Requirements Issues**
   * Install missing components like Visual C++ Redistributable or WebView2.
   * Ensure your system time is correctly set.
   * Verify that AppData is stored on local storage (not a network drive).
4. **Certificate Issues** (Windows)
   * Ensure client certificates are properly installed.
   * Update your system's root certificates if needed.
5. **Organization Configuration Issues**
   * Verify your organization ID is correct.
   * Contact FenixPyre support to verify your organization's setup.

### Support

If you encounter issues that you cannot resolve, please contact FenixPyre support with your checker utility at <support@fenixpyre.com>.


# How to encrypt and decrypt files using FenixPyre Standalone Encryption Utility?

This guide provides step-by-step instructions on how to install, configure, and use the FenixPyre Standalone Encryption Utility.

### Installation

Follow these steps to install the FenixPyre tool service:

1. **Extract the Utility:** Unzip the downloaded `fenixpyre_standalone_enc_dec_tool_v1.x.x.zip` file to a location on your computer (e.g., `C:\Tools\FenixPyre`).
2. **Open PowerShell as Administrator:** Search for PowerShell, right-click it, and select "Run as administrator". This is necessary to install system services.
3. **Navigate to the Tool Directory:** In the PowerShell window, change the current directory to where you extracted the tool. For example:

   ```powershell
   cd C:\Tools\FenixPyre
   ```
4. **Download the certificate:** Get the certificate from FenixPyre support and place it in the extracted zip folder. Rename the certificate to `FenixPyreSACert.pfx` . ***Without the certificate the installation will not succeed.***
5. **Run the Installation Script:** Execute the installation script `FPEncDecServiceInstall.ps1` with the `install` action, providing your specific Organization ID (`orgId`) and registration email (`username`). **Important:** Replace `<your org id>` and `<your org email id e.g. admin@orgid.com>` with your actual details before running the command.

   ```powershell
   .\FPEncDecServiceInstall.ps1 -action install -orgId <your org id> -username <your org email id e.g. admin@orgid.com>
   ```

   This command installs the `FPEncDecService` Windows service and registers the tool.

### Configuration and Operation

Once installed, you configure the tool's actions using Windows Registry settings:

1. **Specify Target Folders:**

   * Open the Windows Registry Editor (regedit.exe).
   * Navigate to: `HKEY_LOCAL_MACHINE\SOFTWARE\FPEncDecTool`

   ![](/files/qXF9Mc6RHEGz3U0RjKqX)

   * Find the `FolderPath` key.
   * Modify this value to include the full path(s) of the folder(s) you want the tool to process (encrypt, decrypt, load file keys or report on). If you need multiple paths, this value supports multi-string input. For example:

   <figure><img src="/files/BhkpvfigPfTt6gxUOy0l" alt="" width="370"><figcaption></figcaption></figure>
2. **Set the Desired Action:**
   * In the same registry location (`HKEY_LOCAL_MACHINE\SOFTWARE\FPEncDecTool`), find the `Action` value.
   * Modify this value to specify what the tool should do:
     * Set it to `ENCRYPT` to encrypt the files in the specified `FolderPath`.
     * Set it to `DECRYPT` to decrypt the files.
     * Set it to `REPORT` to generate a report on the files without modifying them.
     * Set it to `LOADKEYS` to import the file keys you received from FenixPyre Support into the local secure database.
   * Once you set this value, the service will automatically pick up the action and start processing.

### Monitoring Progress

You can monitor the tool's activity and progress:

1. **Check the Log File:** The tool logs its activities dynamically. You can view the log file for real-time updates and troubleshooting information at:
   1. `C:\Users\Public\FPEncDecTool\FPEncDecService.log`
   2. `C:\Users\Public\FPEncDecTool\FPEncDecLib.log`
2. **Monitor Registry Status:**
   * Check the `DetailedStatus` registry value at `HKEY_LOCAL_MACHINE\SOFTWARE\FPEncDecTool` for detailed JSON updates on the ongoing process.
   * Monitor the `Action` registry value. The service will update it to indicate progress (e.g., `ENCRYPT_IN_PROGRESS`).
3. **Wait for Completion:** The operation is finished when the `Action` registry value is updated to show the completed status, such as `ENCRYPT_DONE`, `DECRYPT_DONE`, or `REPORT_DONE`.

### Important Notes

* During encryption, the tool syncs the encryption keys to our SAAS platform. It is important to allow the key syncing to complete before you can access the file or decrypt the file. Do not uninstall or delete any files in `C:\Users\Public\FPEncDecTool` folder before the key syncing is complete.
* To verify that the files are being encrypted, you can download a report from the FenixPyre admin dashboard page, under **Reports**. Select the user and the time range and click on **Download**.
* Perform decryption only after the key syncing is done. The key syncing is fairly fast, but please ensure to provide sufficient time to sync the keys before decrypting.

### Uninstallation

<mark style="color:red;">**Note: Do not uninstall the tool before the encryption keys sync to the FenixPyre Cloud. Please take a backup copy of**</mark><mark style="color:red;">**&#x20;**</mark><mark style="color:red;">**`C:\Users\Public\FPEncDecTool`**</mark><mark style="color:red;">**&#x20;**</mark><mark style="color:red;">**folder before uninstallation.**</mark>

To uninstall the FenixPyre Standalone Encryption Utility:

1. **Important Pre-Check:** Before uninstalling, ensure that all encryption keys and file logs have been fully synchronized with the FenixPyre backend/cloud SAAS service. **Failure to do this may result in permanent data loss**, as you might be unable to decrypt files whose keys were not synced before the local database was removed during uninstallation. (Refer to [Known Issues](/fenixpyre-for-admins/admin-dashboard/fenixpyre-standalone-encryption-utility/limitations-faq-and-best-practices)).
2. **Open PowerShell as Administrator:** As during installation, open an administrative PowerShell window.
3. **Navigate to the Tool Directory:** Use the `cd` command to go to the folder where `FPEncDecServiceInstall.ps1` is located.
4. **Run the Uninstallation Script:** Execute the script with the `uninstall` action:

   ```powershell
   .\FPEncDecServiceInstall.ps1 -action uninstall
   ```

   This will stop and remove the `FPEncDecService` Windows service and perform cleanup operations.


# Registry Values Guide

### What is the Windows Registry?

Think of the Windows Registry as a central database where Windows and many installed applications store their settings and configuration options. It's like a big settings panel, but organized in a hierarchical structure.

The FenixPyre Tool uses the Registry to store its operational settings. Making changes directly in the Registry is generally for advanced users, but understanding what these settings mean can be helpful.

{% hint style="warning" %}
**Important:** Incorrect changes to the Registry can cause problems with your system or applications. Only modify these settings if you are instructed to do so by technical support or documentation.
{% endhint %}

### FenixPyre Standalone Encryption Utility Registry Location

The settings for the FenixPyre Tool are stored in the following location within the Windows Registry:

`Computer\HKEY_LOCAL_MACHINE\SOFTWARE\FPEncDecTool`

### Configuration Settings Explained

Here's a breakdown of the settings you might find in this location and what they do:

***

**1. Action**

* **Purpose:** Tells the utility what job it needs to perform.
* **Possible Values:**
  * `ENCRYPT`: Encrypt files to make them unreadable without a key.
  * `DECRYPT`: Decrypt files back to their original readable state.
  * `REPORT`: Generate a report about the files (without changing them).
  * `LOADKEYS` : Import file keys provided by FenixPyre Support into the local database for offline decryption.s
* **Status Updates:** The utility updates this setting to show its progress, like `ENCRYPT_IN_PROGRESS` (encryption started) or `DECRYPT_DONE` (decryption finished).

***

**2. AgentId**

* **Purpose:** This is a unique identification code assigned to this specific installation of the FenixPyre Standalone Encryption Utility on your computer.
* **How it's set:** It's automatically generated the first time the tool starts and registers itself.

***

**3. AgentKey**

* **Purpose:** This stores a secret code (like a password or key) that the tool uses for secure communication or operations.
* **Security:** The key itself is stored in an encrypted (scrambled) format for security.
* **How it's set:** It's automatically generated when the tool first registers.

***

**5. DetailedStatus**

* **Purpose:** Provides a more detailed, technical status update about the task the tool is currently performing or has just completed.
* **Format:** The information is often stored in JSON format, which is a structured way to represent data.

***

**6. FolderPath**

* **Purpose:** Specifies exactly which folder(s) on your computer or network the tool should work on (encrypt, decrypt, or report).
* **Multiple Folders:** You can list more than one folder here.

***

**7. LogLevel**

* **Purpose:** Controls how much detail the tool records in its activity logs. Logs help troubleshoot problems.
* **Levels (More detail = Higher number):**
  * `0` (Error): Only records errors.
  * `1` (Info): Records basic information about operations.
  * `2` (Debug): Records more detailed information useful for diagnosing issues.
  * `4` (Verbose): Records the most detailed information possible.

***

**8. OrgId**

* **Purpose:** An identification code for the organization that this installation of the FenixPyre tool belongs to.

***

**9. PreserveFileSecurityInfo**

* **Purpose:** Decides whether to keep the original file's security settings (like who has permission to access it) after encrypting or decrypting.
* **Options:**
  * `1`: Keep the original security settings (Enabled).
  * `0`: Do not keep the original security settings (Disabled).
* **Default:** If not specified, the tool defaults to `1` (Enabled), keeping the security information.

***

**10. PreserveFileTimestamps**

* **Purpose:** Decides whether to keep the original file's date and time information (like 'Date Created' and 'Date Modified') after encrypting or decrypting.
* **Options:**
  * `1`: Keep the original timestamps (Enabled).
  * `0`: Do not keep the original timestamps; the file will get new timestamps based on when the encryption/decryption happened (Disabled).
* **Default:** If not specified, the tool defaults to `1` (Enabled), keeping the original timestamps.

***

**12. Status**

* **Purpose:** Provides a brief, simple status update on the current task (e.g., "Encrypting...", "Completed", "Error"). This is less detailed than `DetailedStatus`.

***

**13. ThresholdDays**

* **Purpose:** Defines how "old" a file needs to be (based on its 'Date Modified') to be considered "old data" (which might trigger settings like `ReuseEncryptionKeysForOldData`).
* **Value:** You set a number of days.
* **Default:** If not specified, files older than 365 days are considered old.
* **Maximum:** Can be set up to 1825 days (5 years).

***

**14. Username**

* **Purpose:** Stores the user's email address associated with this FenixPyre tool installation, used during registration.

***

**15. NumThreads**

* **Purpose:** Controls how many simultaneous processes (threads) the tool can use to perform tasks like encryption or decryption. More threads can speed up the process on computers with powerful processors, but using too many can also slow things down.
* **Value:** A number representing the threads.
* **Maximum:** Can be set up to 1024 threads.

***

**16. ChunkSize**

* **Purpose:** When the tool processes files using multiple threads (see `NumThreads`), this setting defines how many files each thread should grab and work on at a time (a "chunk").
* **Value:** A number representing the files per chunk.
* **Maximum:** Can be set up to 10,000 files per chunk.

***

**17. FileKeyDbTtlSecs**

* **Purpose:** Controls how long (in seconds) an individual file's encryption key (`FileKey`) is kept readily available in a temporary cache or database ("time to live" or TTL). This can speed up repeated access to recently processed files.
* **Default:** If not specified, keys are kept for 3600 seconds (1 hour).
* **Maximum:** Can be set up to 86400 seconds (1 day).

***

**18. FileKeySyncBatchSize**

* **Purpose:** When the tool needs to synchronize file key information with a central service, this setting determines how many keys are sent together in one batch.
* **Default:** If not specified, the batch size is 100 keys.
* **Maximum:** Can be set up to 300 keys per batch.

***

**19. MonitoringLogBatchSize**

* **Purpose:** Similar to `FileKeySyncBatchSize`, but this controls the batch size for sending monitoring or activity log information to a central service.
* **Default:** If not specified, the batch size is 100 log entries.
* **Maximum:** Can be set up to 300 log entries per batch.

***

**20. IgnoredExtensions**

* **Purpose:** Allows you to specify types of files that the tool should completely ignore and not encrypt, decrypt, or report on. This is usually used for system files or application files that shouldn't be modified.
* **Format:** You list the file extensions, including the dot (e.g., `.dll`, `.exe`, `.log`, `.tmp`).

***


# Limitations, FAQ and Best Practices

This document provides information on known limitations, answers to frequently asked questions, and tips for getting the best performance from the FenixPyre Tool.

### Known Issues & Limitations

| Issue                                  | Description                                                                                                                                                              | Workaround                                                                                                                                                                                                                                         |
| -------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Slow performance with multiple clients | When multiple computers try to encrypt files on the same network share (SMB) simultaneously, file locking can cause the process to slow down significantly.              | Assign different specific folders to each client machine instead of having them all work on the exact same folder concurrently.                                                                                                                    |
| No UI to monitor encryption status     | The tool does not have a dedicated graphical interface (UI) to show detailed progress while encrypting or decrypting files. Progress tracking is limited.                | You can monitor the `Status` and `DetailedStatus` registry keys (mentioned in the configuration documentation) for updates on the current task.                                                                                                    |
| Key sync not checked on uninstall      | When uninstalling the tool, it doesn't automatically check if all the encryption keys or file logs have been successfully synchronized (synced) with the central server. | **Crucially:** Before uninstalling, manually check or confirm that all keys and logs have been fully synced. Uninstalling before sync is complete can lead to data loss, as you won't be able to decrypt files whose keys weren't saved centrally. |
| Tool Un-registration Display Issue     | After the tool is uninstalled from a computer, the central management dashboard might still show the tool as being registered for a period.                              | This is typically a display delay. The central system should update eventually.                                                                                                                                                                    |

***

### Troubleshooting & FAQs

**Q: The tool is not encrypting files. What should I do?**

* **Check Permissions:** Ensure the account running the FenixPyre service has the necessary read, write, and modify permissions for the folder(s) you are trying to encrypt (`FolderPath` setting).
* **Check Service Account:**
  * By default, the `FPEncDecService` (the tool's Windows service) runs using the 'Local System' account. This works fine for local folders.
  * If encrypting **local folders**, try restarting the `FPEncDecService` with Administrator privileges.
  * If encrypting **network share folders**, the 'Local System' account usually doesn't have network access. You need to change the service's "Log On As" setting:
    1. Open Windows Services (services.msc).
    2. Find `FPEncDecService`.
    3. Go to Properties -> Log On tab.
    4. Select "This account" and enter the credentials of a user account that has full permissions on the target network share.
    5. Restart the service.

**Q: How do I verify if a file is encrypted by this tool?**

* Try opening the file using a simple text editor like Notepad.
* If the file has been successfully encrypted by the FenixPyre tool, the content will usually start with the text `MONADNOCK_SODS` followed by seemingly random characters (garbled text). The original content will not be readable.

**Q: How can I share logs with the FenixPyre team for troubleshooting issues?**

* The utility stores all the logs inside `C:\Users\Public\FenixPyre` folder. Compress and send the archive to FenixPyre team.

***

### Performance Tips & Best Practices

* **Use Fast Storage:** For significantly faster encryption and decryption speeds, run the tool on drives that use Solid State Drive (SSD) technology rather than traditional Hard Disk Drives (HDD).
* **Network Share Strategy:** Avoid having multiple FenixPyre clients encrypting files within the *exact same network folder* at the same time, as this can cause slowdowns (see Known Issues). If multiple clients need to work on network shares, assign them different target folders to process.

***


# How to decrypt files using FenixPyre Standalone Encryption Utility ?

FenixPyre Standalone Encryption Utility now includes support for offline decryption in environments with limited or no internet connectivity.

**📝 Prerequisites**

1. **Request FileKeys Package**\
   To initiate the process, contact FenixPyre Support and request offline decryption assistance. A secure download link will be provided upon verification.
2. **Download and Extract Package**\
   The download will be a `.zip` archive containings files with the necessary file keys. Extract the contents to a known local directory.
3. **Ensure Access to Master Key**\
   The administrator should already have access to the **Master Key** as a `.txt` file generated via the Admin Dashboard.

***

**⚙️ Configure Registry for Offline FileKey Loading**

Update the registry with the following entries to load the file keys into the local secure database:

**Registry Path:**\
`HKEY_LOCAL_MACHINE\Software\FPEncDecTool\`

| Key                 | Type     | Description                                                        |
| ------------------- | -------- | ------------------------------------------------------------------ |
| `folderPath`        | `REG_SZ` | Path to the extracted folder containing the `.parquet` files.      |
| `masterKeyFilePath` | `REG_SZ` | Path to the `.txt` Master Key downloaded from the Admin Dashboard. |
| `action`            | `REG_SZ` | Set to `LOADKEYS` to initiate the key loading process.             |

> ℹ️ Use double backslashes (`\\`) or quotes for paths with spaces.

Once these values are set, the utility will begin loading keys into the local database. You can monitor progress using the `status` and `detailedStatus` keys in the same registry path.

| Key              | Description                                                                      |
| ---------------- | -------------------------------------------------------------------------------- |
| `status`         | Displays the current state (`PENDING`, `IN_PROGRESS`, `COMPLETED`, or `FAILED`). |
| `detailedStatus` | Provides descriptive progress or error information.                              |

***

**🔓 Perform Decryption Using Loaded FileKeys**

Once the key loading process completes successfully:

1. Update the `folderPath` to point to the folder containing the **encrypted files**.
2. Change the `action` registry key to:

```
DECRYPT
```

This will trigger the utility to decrypt the files in the specified folder using the locally available file keys.

***

#### ⏱️ Key Sync Timing (for `LOADKEYS`)

Before using the `LOADKEYS` action, please ensure the file keys have fully synced from the FenixPyre storage system to your local storage.

* 🔄 **Key syncing occurs every 12 hours.**
* 🕒 To ensure a complete set of keys is available for decryption, wait at least **12 hours after the last encryption** operation before downloading the key bundle.
* 📥 Attempting to download and load file keys before this window may result in missing or incomplete decryption capabilities.

> **Recommendation:** Only request or download the offline key bundle once the 12-hour sync window has passed.


# Audit Logs

{% content-ref url="/spaces/OuMyGdeUQs2m5OYPFuwT/pages/sAdPnVf1COEKyUj0E9bX" %}
[Audit Logs](/fenixpyre-for-admins/admin-dashboard/audit-logs/audit-logs)
{% endcontent-ref %}

{% content-ref url="/spaces/OuMyGdeUQs2m5OYPFuwT/pages/THO9R2KA22PR8UveAVOz" %}
[Audit Events Glossary](/fenixpyre-for-admins/admin-dashboard/audit-logs/audit-events-glossary)
{% endcontent-ref %}


# Audit Logs

The Audit Logs feature provides comprehensive visibility into all security events and user activities across your organization.

<figure><img src="/files/OVai5pJ1YwOBxcE3Rp2u" alt=""><figcaption></figcaption></figure>

#### Key Features

* **Pre-configured Filter Sets**: Choose from predefined views tailored to different use cases
* **Flexible Date Range Filtering**: Filter events by specific time periods
* **Advanced Filtering System**: Create complex filter queries with multiple conditions
* **Rich Event Details**: View comprehensive information about each audit event
* **Multi-connector Support**: Track events across different platforms (Fenixpyre, OneDrive, Egnyte, Box, CMMC, and more)

***

### Getting Started

#### Accessing Audit Logs

1. Navigate to the **Audit Logs** section from the main navigation menu
2. You'll see the Audit Logs dashboard with a filter set dropdown at the top

<figure><img src="/files/iRMfqDxEBL0MGTQAGAuQ" alt=""><figcaption></figcaption></figure>

#### First Steps

1. **Select a Filter Set**: Choose a filter set from the dropdown to begin viewing audit logs
2. **Review the Table**: Once a filter set is selected, the table will populate with relevant audit events
3. **Apply Filters**: Use date range and advanced filters to narrow down your search

***

### Filter Sets

Filter sets are pre-configured views that determine which columns and data are displayed in the audit logs table. Each filter set is designed for specific use cases and provides relevant columns for that scenario.

#### Selecting a Filter Set

1. Click on the **Filter Set** dropdown at the top of the page
2. Browse through available filter sets - each shows:
   * **Name**: The filter set's display name
   * **Description**: A brief explanation of what the filter set shows

<figure><img src="/files/V8KiWUHjp5Mre4ALdg2B" alt=""><figcaption></figcaption></figure>

3. Click on a filter set to apply it
4. The table will automatically refresh with data matching that filter set

#### Understanding Filter Sets

* Each filter set shows different columns relevant to its purpose
* You can switch between filter sets at any time

The URL will update when you select a filter set, allowing you to bookmark specific view

***

### Date Range Filtering

The date range picker allows you to filter audit logs by a specific time period. This is one of the most common ways to narrow down your search.

#### Using the Date Range Picker

1. Click on the **Date Range Picker** field (located next to the Filter Set dropdown)
2. Select a start date from the calendar
3. Select an end date from the calendar
4. The table will automatically refresh with events within that date range

<figure><img src="/files/EeIZnngh6I9yYqSemZE6" alt=""><figcaption></figcaption></figure>

#### Date Range Features

* **Quick Selection**: Choose from preset ranges (Today, Last 7 days, Last 30 days, etc.)
* **Custom Range**: Select any custom date range
* **Clear Filter**: Click the X button on the date range tag to remove the filter
* **Visual Indicator**: Applied date ranges are displayed as green tags above the table

#### Best Practices for Date Ranges

* Start with broader date ranges and narrow down as needed
* Use date ranges in combination with other filters for precise results
* Remember that very large date ranges may take longer to load

***

### Advanced Filtering

The Advanced Filter feature provides powerful query-building capabilities to create complex filter conditions. This is ideal for finding specific events or patterns.

#### Opening the Advanced Filter Sidebar

1. Click the **Advanced Filter** button (located next to the Date Range Picker)
2. A sidebar will slide in from the right side of the screen
3. The sidebar contains the filter builder interface

<figure><img src="/files/zz4UfyMohvZtasRotS3g" alt=""><figcaption></figcaption></figure>

#### Understanding Filter Groups

Filter groups allow you to organize multiple filter conditions:

* **Filter Group**: A container for multiple filter conditions
* **Logical Operators**: Each group uses AND or OR to combine conditions
* **Multiple Groups**: You can create up to 10 filter groups
* **Nested Groups**: Groups can contain nested sub-groups for complex queries

#### Creating a Filter Condition

1. In a filter group, click **Add Condition**
2. Select a **Field** from the dropdown (e.g., Action, Status, File Name, etc.)
3. Choose an **Operator**:
   * **Equals (=)**: Exact match
   * **Not Equals (!=)**: Exclude specific values
4. Enter a **Value** in the input field
5. The condition will be added to the current filter group

<figure><img src="/files/v7GSKZmWpjYqKJJzbMPx" alt=""><figcaption></figcaption></figure>

#### Adding Multiple Conditions

* Click **Add Condition** to add more conditions to the same group
* Conditions within a group are combined using the group's logical operator (AND/OR)
* You can add as many conditions as needed within each group

#### Creating Multiple Filter Groups

1. Click **Add Filter Group** at the bottom of the sidebar
2. A new filter group will be created
3. Add conditions to the new group
4. Multiple groups are combined with AND logic (all groups must match)

<figure><img src="/files/EzncTKOAkKAQ9vOymm8U" alt=""><figcaption></figcaption></figure>

#### Nested Groups

For complex queries, you can create nested groups:

1. Within a filter group, click **Add Sub-Group**
2. A nested group will be created inside the parent group
3. Nested groups allow for complex logical combinations

#### Applying Filters

1. After building your filter conditions, click **Apply Filters** at the bottom of the sidebar
2. The sidebar will close and the table will refresh with filtered results
3. Applied filters will be displayed as tags above the table

#### Managing Applied Filters

Applied filters are displayed as colored tags above the table:

* **Blue Tags**: Individual filter conditions
* **Purple Tags**: Filter groups with multiple conditions
* **Green Tags**: Date range filters

<figure><img src="/files/LfR74A3f4pv9PicfhtVL" alt=""><figcaption></figcaption></figure>

**Removing Individual Filters**

* Click the **X** button on any filter tag to remove that specific filter
* The table will automatically refresh

**Clearing All Filters**

* Click **Clear All** button to remove all applied filters (including date range)
* This resets the view to show all data for the selected filter set

***

### Pagination and Loading More Data

The audit logs table uses a "Load More" pagination system to efficiently handle large datasets.

#### Understanding Pagination

* **Initial Load**: The table loads the first 50 events by default
* **Total Count**: The pagination bar shows how many events match your filters
* **Load More Button**: Click to load the next 50 events

<figure><img src="/files/6qBgebtUeZRqLhp11DSS" alt=""><figcaption></figcaption></figure>

***

***


# Audit Events Glossary

FenixPyre continuously records activity across your organization - file interactions, administrative changes, user sessions, and agent connectivity - as structured audit events. These events power the [**Audit Logs**](/fenixpyre-for-admins/admin-dashboard/audit-logs/audit-logs) dashboard and can be exported through [**Log Streaming**](/fenixpyre-for-admins/admin-dashboard/log-streaming) to Splunk, Datadog, or a custom HTTP endpoint.

Every event is classified into one of four categories via its `event_type` field:

| `event_type`   | Category           |
| -------------- | ------------------ |
| `file_access`  | File Access Events |
| `admin_events` | Admin Events       |
| `user_events`  | User Events        |
| `agent`        | Agent Events       |

Within each category, events are further grouped into subtypes. Below is the full list of actions tracked within each subtype, with a one-line explanation of what each one represents.

***

### File Access Events

`event_type: file_access`

Records of file- and folder-level interactions across FenixPyre and connected storage platforms (Desktop, Network Drive, SharePoint, Box, Egnyte, etc.).

#### File Management

| Action                    | Description                                                  |
| ------------------------- | ------------------------------------------------------------ |
| `file.open`               | A file was opened                                            |
| `file.create`             | A new file was created                                       |
| `file.edit`               | A file was edited                                            |
| `file.write`              | A file was written to                                        |
| `file.rename`             | A file was renamed                                           |
| `file.delete`             | A file was deleted                                           |
| `file.download`           | A file was downloaded                                        |
| `file.upload`             | A file was uploaded                                          |
| `file.access`             | A file was accessed                                          |
| `file.deny`               | Access to a file was denied                                  |
| `file.lock`               | A file was locked to prevent concurrent edits                |
| `file.unlock`             | A file was unlocked                                          |
| `file.co-edit`            | A file was opened for collaborative editing                  |
| `file.email-attachment`   | A file was sent as an email attachment                       |
| `file.encrypt`            | A file was encrypted by FenixPyre                            |
| `file.decrypt`            | A file was decrypted                                         |
| `file.auto-encrypt`       | A file was automatically encrypted per policy                |
| `file.offline_open`       | A file was opened while the agent was offline                |
| `file.offline_edit`       | A file was edited while the agent was offline                |
| `file.offline_deny`       | Access to a file was denied while the agent was offline      |
| `file.offline_access`     | A file was accessed while the agent was offline              |
| `file.offline-encrypt`    | A file was encrypted while the agent was offline             |
| `file.encrypted_download` | A file was downloaded in its encrypted form via a share link |
| `file.decrypted_download` | A file was downloaded in its decrypted form via a share link |

#### Folder Management

| Action                           | Description                                      |
| -------------------------------- | ------------------------------------------------ |
| `folder.add-offline`             | A folder was made available offline              |
| `folder.remove-offline`          | A folder was removed from offline availability   |
| `folder.add-protection`          | Encryption protection was applied to a folder    |
| `folder.remove-protection`       | Encryption protection was removed from a folder  |
| `folder.auto-encrypt-enabled`    | Automatic encryption was enabled for a folder    |
| `folder.auto-encrypt-disabled`   | Automatic encryption was disabled for a folder   |
| `folder.auto_encryption_enable`  | Automatic encryption was turned on for a folder  |
| `folder.auto_encryption_disable` | Automatic encryption was turned off for a folder |
| `folder.auto_decryption_enable`  | Automatic decryption was turned on for a folder  |
| `folder.auto_decryption_disable` | Automatic decryption was turned off for a folder |

#### File Collaboration

| Action                | Description                                |
| --------------------- | ------------------------------------------ |
| `collaboration.join`  | A user joined a collaborative file session |
| `collaboration.leave` | A user left a collaborative file session   |

***

### Admin Events

`event_type: admin_events`

Records of actions taken by administrators within the FenixPyre Dashboard — user, policy, group, identity, integration, and configuration management.

#### User Management

| Action                           | Description                           |
| -------------------------------- | ------------------------------------- |
| `authentication.password.update` | A user's password was updated         |
| `user.create`                    | A new user account was created        |
| `user.update`                    | A user account's details were updated |
| `user.delete`                    | A user account was deleted            |
| `user.role.add`                  | A role was assigned to a user         |
| `user.role.remove`               | A role was removed from a user        |
| `user.status.activate`           | A user account was activated          |
| `user.status.deactivate`         | A user account was deactivated        |

#### Policy Management

Attaching or detaching groups and rules to/from a policy.

| Action           | Description                                |
| ---------------- | ------------------------------------------ |
| `group.add`      | A group was attached to a policy           |
| `group.remove`   | A group was detached from a policy         |
| `members.add`    | Members were added to a policy's group     |
| `members.remove` | Members were removed from a policy's group |
| `policy.create`  | A policy was created                       |
| `policy.update`  | A policy was updated                       |
| `policy.delete`  | A policy was deleted                       |
| `rules.add`      | A rule was added to a policy               |
| `rules.update`   | A rule was updated                         |
| `rules.delete`   | A rule was deleted                         |

#### Group Management

Management of the group entity itself (distinct from attaching a group to a policy above).

| Action                 | Description                       |
| ---------------------- | --------------------------------- |
| `group.create`         | A new group was created           |
| `group.delete`         | A group was deleted               |
| `group.update`         | A group's details were updated    |
| `group.members.add`    | Members were added to a group     |
| `group.members.remove` | Members were removed from a group |

#### Identity Provisioning (SSO/SCIM)

| Action                             | Description                                                |
| ---------------------------------- | ---------------------------------------------------------- |
| `automatic_account_creation.allow` | Automatic account creation for new identities was enabled  |
| `automatic_account_creation.deny`  | Automatic account creation for new identities was disabled |
| `scim.add`                         | A SCIM provisioning configuration was added                |
| `scim.remove`                      | A SCIM provisioning configuration was removed              |
| `scim.update`                      | A SCIM provisioning configuration was updated              |
| `signin_method.update`             | The organization's sign-in method was changed              |
| `sso.add`                          | An SSO configuration was added                             |
| `sso.remove`                       | An SSO configuration was removed                           |
| `sso.update`                       | An SSO configuration was updated                           |

#### Integration Management

| Action               | Description                           |
| -------------------- | ------------------------------------- |
| `integration.create` | A third-party integration was added   |
| `integration.update` | A third-party integration was updated |
| `integration.delete` | A third-party integration was removed |

#### Share Link Management

Admin-initiated management of a user's share link.

| Action                   | Description                                 |
| ------------------------ | ------------------------------------------- |
| `share_link.create`      | A share link was created                    |
| `share_link.update`      | A share link's settings were updated        |
| `share_link.enable`      | A share link was enabled                    |
| `share_link.disable`     | A share link was disabled                   |
| `share_link.user.add`    | A user was granted access to a share link   |
| `share_link.user.remove` | A user's access to a share link was removed |

#### Sharing Policy Management

Organization-wide default sharing settings and permission toggles.

| Action                                        | Description                                              |
| --------------------------------------------- | -------------------------------------------------------- |
| `access_levels.default_sharing_method.update` | The default sharing method for access levels was changed |
| `allowed_sharing_methods.update`              | The set of allowed sharing methods was updated           |
| `default_editor.update`                       | The default editor for shared files was changed          |
| `default_expiry.update`                       | The default share link expiry period was changed         |
| `maximum_expiry.update`                       | The maximum allowed share link expiry period was changed |
| `permissions.can_create.update`               | The create-permission default for shares was updated     |
| `permissions.can_delete.update`               | The delete-permission default for shares was updated     |
| `permissions.can_download.update`             | The download-permission default for shares was updated   |
| `permissions.can_edit.update`                 | The edit-permission default for shares was updated       |
| `permissions.can_rename.update`               | The rename-permission default for shares was updated     |
| `permissions.can_share.update`                | The re-share-permission default for shares was updated   |
| `permissions.can_upload.update`               | The upload-permission default for shares was updated     |
| `permissions.can_move.update`                 | The move-permission default for shares was updated       |
| `permissions.can_copy.update`                 | The copy-permission default for shares was updated       |

#### Installer Management

| Action               | Description                               |
| -------------------- | ----------------------------------------- |
| `installer.download` | An agent installer package was downloaded |
| `installer.update`   | An installer configuration was updated    |

#### Application Management

| Action                    | Description                              |
| ------------------------- | ---------------------------------------- |
| `user_application.create` | An application was registered for a user |
| `user_application.delete` | An application registration was removed  |
| `user_application.update` | An application registration was updated  |

#### Domain Management

| Action          | Description                                |
| --------------- | ------------------------------------------ |
| `domain.add`    | A domain was added to the organization     |
| `domain.remove` | A domain was removed from the organization |

#### Auto Encryption Management

| Action                            | Description                            |
| --------------------------------- | -------------------------------------- |
| `auto_encryption_settings.create` | An auto-encryption setting was created |
| `auto_encryption_settings.update` | An auto-encryption setting was updated |
| `auto_encryption_settings.delete` | An auto-encryption setting was deleted |

#### Key Management

| Action             | Description                   |
| ------------------ | ----------------------------- |
| `key.create`       | An encryption key was created |
| `key.update`       | An encryption key was updated |
| `key_vault.create` | A key vault was created       |
| `key_vault.update` | A key vault was updated       |

#### Reports

| Action                      | Description                               |
| --------------------------- | ----------------------------------------- |
| `user_logs.download`        | A user activity log report was downloaded |
| `application_logs.download` | An application log report was downloaded  |

***

### User Events

`event_type: user_events`

Captures authentication and user-initiated activity such as logins, sharing, favourites, and file downloads.

#### Authentication

| Action        | Description                              |
| ------------- | ---------------------------------------- |
| `user.login`  | A user logged in to FenixPyre            |
| `agent.login` | A user logged in via the FenixPyre agent |

#### Share Link Management

| Action                      | Description                                 |
| --------------------------- | ------------------------------------------- |
| `share_link.create`         | A share link was created                    |
| `share_link.update`         | A share link's settings were updated        |
| `share_link.enable`         | A share link was enabled                    |
| `share_link.disable`        | A share link was disabled                   |
| `share_link.user.add`       | A user was granted access to a share link   |
| `share_link.user.remove`    | A user's access to a share link was removed |
| `share_link.access`         | A share link was accessed                   |
| `share_link.request_access` | A user requested access to a share link     |

#### Favourites Management

| Action             | Description                                  |
| ------------------ | -------------------------------------------- |
| `favourite.create` | A file or folder was marked as a favourite   |
| `favourite.delete` | A file or folder was removed from favourites |

#### File Management

| Action                | Description                                       |
| --------------------- | ------------------------------------------------- |
| `user.zip_download`   | A user downloaded multiple files as a zip archive |
| `user.quick_download` | A user downloaded a file via quick download       |

***

### Agent Events

`event_type: agent`

Events emitted by the FenixPyre Windows Agent about its own connectivity and session state.

| Action             | Description                    |
| ------------------ | ------------------------------ |
| `agent.go-online`  | The agent came online          |
| `agent.go-offline` | The agent went offline         |
| `agent.revoke`     | The agent's access was revoked |

***

### Cross-Cutting Concepts

* **Severity** (`severity`): `info`, `warn`, `error`, `fatal` — indicates how significant the event is.
* **Status** (`status`): `info` or `alert` — flags events that warrant attention.
* **Result status** (`event_result_info.status`): `allow` or `deny` — a `deny` result means the action was blocked (e.g. an unauthorized access attempt), and these events surface in the Audit Logs "Unauthorized Access" views.

***

These four categories back both the [Audit Logs](https://docs.fenixpyre.com/fenixpyre-for-admins/admin-dashboard/audit-logs) dashboard and the [Log Streaming](https://docs.fenixpyre.com/fenixpyre-for-admins/admin-dashboard/log-streaming) export feature.


# Reports

This guide explains how to export FenixPyre logs from the Admin Dashboard

### User Logs

This report provides a detailed log of user activity within the FenixPyre platform, showcasing interactions across various accounts. Each entry includes the user’s email ID, login timestamps, and associated session metadata, enabling administrators to track platform access and usage patterns effectively. These reports support compliance, internal reviews, and proactive user management. Admins can download reports for multiple users within a selected date range, making it easy to audit platform usage over specific periods.<br>

<figure><img src="/files/QEuO7zkREq3FcQcmQeoi" alt=""><figcaption></figcaption></figure>

### Application Logs

This application log report provides granular visibility into file-level activities performed within the FenixPyre platform by each application. Each log entry captures detailed metadata such as File ID, file name, action type (e.g., OPEN, ACCESS, EDIT), user identity, timestamp, and agent ID. In addition, contextual data like geolocation (latitude/longitude), Wi-Fi SSID, geohash, organization ID, and IP addresses are recorded to support security and compliance auditing. Admins can use this report to trace specific user actions on sensitive files and identify potential anomalies. The ability to filter this data by user and timeframe ensures targeted investigations and regulatory reporting. This log report benefits environments that require strong data governance, such as CMMC-compliant organizations.

<figure><img src="/files/MNI3PXhIo1eke81KC1ns" alt=""><figcaption></figcaption></figure>

### How to download User/Application Logs

<figure><img src="/files/zmR6NRZTChSvicmwwoPn" alt=""><figcaption><p>Reports</p></figcaption></figure>

#### Step 1: Access the Reports Tab

* Log in to the Admin Dashboard.
* Navigate to the **"Reports"** section.

#### Step 2: Select Log Type

* Choose one of the following log categories:
  * **User Logs**-These logs capture actions performed by individual users within the system and provide insights into user activities.
  * **Application Logs** - These logs track events and actions related to applications integrated with FenixPyre

#### Step 3: Apply Filters and Download

* Use the drop-down menus to enter the desired details.
* Select the **"Download"** button to export the logs.

### CSV Export Options

Users can export a **CSV file** of logs based on **Users and Applications**.

**Example: Exporting User Logs**

1. Select **"Users"** from the dropdown.
2. Choose a specific user from the list.
3. Set a **custom time range** or select a predefined range.
4. Click **"Download"** – the CSV file will be downloaded.

The exact process applies when exporting **Application** logs.


# Integrations

{% content-ref url="/pages/oVw1EVvJVtkNyPtoA8ZC" %}
[SharePoint/OneDrive](/fenixpyre-for-admins/admin-dashboard/integrations/sharepoint-onedrive)
{% endcontent-ref %}

{% content-ref url="/pages/S7o4dyMLWAL7h1rOB9FR" %}
[Box](/fenixpyre-for-admins/admin-dashboard/integrations/box)
{% endcontent-ref %}

{% content-ref url="/pages/mBp49XTZdqcnDEf5prs6" %}
[Egnyte](/fenixpyre-for-admins/admin-dashboard/integrations/egnyte)
{% endcontent-ref %}


# SharePoint/OneDrive

{% content-ref url="/pages/36kyzcipeZ2z2DL2FbQM" %}
[Overview](/fenixpyre-for-admins/admin-dashboard/integrations/sharepoint-onedrive/overview)
{% endcontent-ref %}

{% content-ref url="/pages/c2WpHBs0lMP0lvgsQBeQ" %}
[How to enable FenixPyre integration in SharePoint](/fenixpyre-for-admins/admin-dashboard/integrations/sharepoint-onedrive/how-to-enable-fenixpyre-integration-in-sharepoint)
{% endcontent-ref %}

{% content-ref url="/pages/GOQZyOhNV2xlxUXjccSp" %}
[How to configure SharePoint Integration in Admin Dashboard](/fenixpyre-for-admins/admin-dashboard/integrations/sharepoint-onedrive/how-to-configure-sharepoint-integration-in-admin-dashboard)
{% endcontent-ref %}

{% content-ref url="/pages/QK6D6pTG7spvPNdJ2Sfr" %}
[How to configure Auto Encrypted folders](/fenixpyre-for-admins/admin-dashboard/integrations/sharepoint-onedrive/how-to-configure-auto-encrypted-folders)
{% endcontent-ref %}


# Overview

Integrating the SharePoint app with the FenixPyre platform streamlines secure file management by enabling seamless encryption, decryption, and editing directly within SharePoint. With the FenixPyre menu options-**Encrypt, Decrypt, Share, and Open**-users can efficiently protect sensitive documents while maintaining easy accessibility. Encryption ensures that only authorized users can access files, while decryption allows for secure retrieval when needed. The integration eliminates the need for external tools, providing a user-friendly experience within SharePoint’s familiar interface. This simplifies compliance with security policies while enhancing collaboration and data protection within organizations.

After correctly configuring the integration, the "FenixPyre" menu option will appear on your SharePoint site.

FenixPyre offers a variety of menu options.

For Files:

* Open: Allows multiple users to collaborate on a file simultaneously without a need of decryption.
* Share: Easily share files securely with users both inside and outside your organization.
* Encrypt: Encrypt any file that requires protection.
* Decrypt: Decrypt any file that has been encrypted and restore its original content.
* Access Logs: Monitor file usage logs for any file.

<figure><img src="/files/VIIG08iMo57fv6sujIiU" alt=""><figcaption></figcaption></figure>

For Folder

* Share: Easily share folders securely with users both inside and outside your organization.
* Add to Auto Encryption: Quickly add folders to Auto Encryption to ensure they are automatically protected.

<figure><img src="/files/U9oYQ0w92qqAvTt0UrK6" alt=""><figcaption></figcaption></figure>


# How to enable FenixPyre integration in SharePoint

### Create an Azure app (requires Admin access) <a href="#this-article-will-discuss-how-to-enable-the-fenixpyre-integration-on-sharepointonedriveteams-create" id="this-article-will-discuss-how-to-enable-the-fenixpyre-integration-on-sharepointonedriveteams-create"></a>

**Step 1:** Go to <https://portal.azure.com/>

**Step 2:** Click on Azure Active Directory

<figure><img src="/files/m40DVHEdC6pjqam96aUs" alt=""><figcaption></figcaption></figure>

**Step 3:** Click on `App Registrations` from the menu items on the left.

<figure><img src="/files/lDuBAGeEjNHVtqGCMba5" alt=""><figcaption></figcaption></figure>

**Step 4:** Click on `New registration` on top of the page.

<figure><img src="/files/HZoCUbl5WcaGupRUDrC5" alt=""><figcaption></figcaption></figure>

**Step 5:** Give the app a name.

1. Our recommendation is: `FenixPyre`

**Step 6:** Select the account type and provide a redirect URL, and select app type as web

1. Account Type: Accounts in this organizational directory only (FenixPyre only - Single tenant).
2. App Type: `Web`and add redirect URI as: <https://admin.anchormydata.com/\\><org-id>/integrations/sharepoint and <https://admin.fenixpyre.com/\\><org-id>/integrations/sharepoint
3. Click on Add again and add another redirect URL. App Type: `Web`and add redirect URI as <https://share.anchormydata.com/\\><org id>/callback/onedrive and <https://share.fenixpyre.com/\\><org id>/callback/onedrive
4. Click on Add again and add another redirect URL. App Type: `Web`and add redirect URI ashttps\://fenixshare.anchormydata.com/\<org id>/callback/onedrive.

<figure><img src="/files/V2JulX56ZOIDFVPhDmwp" alt=""><figcaption></figcaption></figure>

**Step 7:** Click on `Register`<br>

<figure><img src="/files/V2JulX56ZOIDFVPhDmwp" alt=""><figcaption></figcaption></figure>

**Step 8:** \[Optional] In the app details page, click on `Branding & Properties` tab to customize your app.

1. Logo: Please use the image below for the logo
   * <https://icon-assets.anchormydata.com/fenixpyre_200x200_b%26w.jpg>
2. Home page URL: `https://fenixpyre.com/`
3. Terms of service URL: [`https://fenixpyre.com/ssa`](https://fenixpyre.com/ssa)
4. Privacy Statement URL: [`https://fenixpyre.com/privacy-policy`](https://fenixpyre.com/privacy-policy)
5. Click on `Save`

<figure><img src="/files/Nfhbsr2t6OFSlovdrXvy" alt=""><figcaption></figcaption></figure>

**Step 9:** Create a secret key

* Click on `Certificates & Secrets` from the app details page
* Click on `Client secrets` and select `New client secret`

<figure><img src="/files/LEWtWWLy0uG0OspwEAqD" alt=""><figcaption></figcaption></figure>

* Give a name to the secret. We recommended the name: `sharepoint_integration`. Select Expiry date as `12 months` and then click on `Add.`

<figure><img src="/files/bf0yXQMTIn2A8Rh73J0f" alt=""><figcaption></figcaption></figure>

* Copy the secret value to add it to the FenixPyre admin portal later. **Note: Please do not share the secret with anyone except FenixPyre.**

<figure><img src="/files/yebvWviuQiJiY2rNO6qW" alt=""><figcaption></figcaption></figure>

**Step 10:** In the app details page, click on `Manifest` from the left menu items.

<figure><img src="/files/zFhf3abPtmpmkf7Lv4Xn" alt=""><figcaption></figcaption></figure>

**Step 11:** Paste the following JSON into the `addIns` section (highlighted in the screenshot) in the manifest. Click on Save.

```
"addIns": [
		{
			"id": "76724c1c-90f2-44d1-af08-37166e0223c0",
			"type": "FileHandler",
			"properties": [
				{
					"key": "version",
					"value": "2"
				},
				{
					"key": "actions",
					"value": "[{\"type\":\"custom\",\"id\":\"custom1\",\"url\":\"https://onedrive.anchormydata.com/handler/v1/file/open\",\"displayName\":\"Open\",\"shortDisplayName\":\"Open\",\"icon\":{\"png1x\":\"https://icon-assets.anchormydata.com/fenixpyre_200x200_trans.png\"},\"availableOn\":{\"file\":{\"extensions\":[\"*\"]},\"web\":{}}},{\"type\":\"custom\",\"id\":\"custom2\",\"url\":\"https://onedrive.anchormydata.com/handler/v1/file/share\",\"displayName\":\"Share\",\"shortDisplayName\":\"Share\",\"icon\":{\"png1x\":\"https://icon-assets.anchormydata.com/fenixpyre_200x200_trans.png\"},\"availableOn\":{\"file\":{\"extensions\":[\"*\"]},\"folder\":{},\"allowMultiSelect\":false,\"web\":{}}},{\"type\":\"custom\",\"id\":\"custom3\",\"url\":\"https://onedrive.anchormydata.com/handler/v1/files/anchor/setup\",\"displayName\":\"Add To Auto Encryption\",\"shortDisplayName\":\"Auto Encryption\",\"icon\":{\"png1x\":\"https://icon-assets.anchormydata.com/fenixpyre_200x200_trans.png\"},\"availableOn\":{\"folder\":{},\"allowMultiSelect\":false,\"web\":{}}},{\"type\":\"custom\",\"id\":\"custom4\",\"url\":\"https://onedrive.anchormydata.com/handler/v1/files/anchor\",\"displayName\":\"Encrypt\",\"shortDisplayName\":\"Anchor\",\"icon\":{\"png1x\":\"https://icon-assets.anchormydata.com/fenixpyre_200x200_trans.png\"},\"availableOn\":{\"file\":{\"extensions\":[\"*\"]},\"allowMultiSelect\":true,\"web\":{}}},{\"type\":\"custom\",\"id\":\"custom5\",\"url\":\"https://onedrive.anchormydata.com/handler/v1/files/unanchor\",\"displayName\":\"Decrypt\",\"shortDisplayName\":\"unAnchor\",\"icon\":{\"png1x\":\"https://icon-assets.anchormydata.com/fenixpyre_200x200_trans.png\"},\"availableOn\":{\"file\":{\"extensions\":[\"*\"]},\"allowMultiSelect\":true,\"web\":{}}},{\"type\":\"custom\",\"id\":\"custom6\",\"url\":\"https://onedrive.anchormydata.com/handler/v1/files/logs\",\"displayName\":\"Access Logs\",\"shortDisplayName\":\"Show Logs\",\"icon\":{\"png1x\":\"https://icon-assets.anchormydata.com/fenixpyre_200x200_trans.png\"},\"availableOn\":{\"file\":{\"extensions\":[\"*\"]},\"allowMultiSelect\":false,\"web\":{}}}]"
				}
			]
		}
	],
```

<figure><img src="/files/zFhf3abPtmpmkf7Lv4Xn" alt=""><figcaption></figcaption></figure>

**Step 12:** In the app details page, click on `API Permissions` from the left menu items.

1. Anchor requires API permissions to access Microsoft Graph APIs and SharePoint files, permissions etc.

Please provide the following API permissions

**Application Level Permissions:**

1.`Sites.Manage.All` (Graph Permission)

**Delegated Level Permissions:**

1.`User.Read.All` (Graph Permission)

2.`AllSites.FullControl`(SharePoint Permission)

<figure><img src="/files/BF2rn2Ah6GYLx93VVOQ8" alt=""><figcaption></figcaption></figure>

**Step 13:** After adding the API permissions please click on `Grant admin consent`

**Step 14:** For the App to be visible in SharePoint/OneDrive/Teams following Steps has to be performed

* Go to Azure Active Directory or Microsoft Entra ID

<figure><img src="/files/QB0bpMLLNHbBx2pXx2m8" alt=""><figcaption></figcaption></figure>

* Click on Enterprise applications

<figure><img src="/files/8gORSVkpt5FkcMWtzUgD" alt=""><figcaption></figcaption></figure>

* Select your App from the list

<figure><img src="/files/MGh6lA4EwtZhWPUwzGhd" alt=""><figcaption></figcaption></figure>

* Click on Properties

<figure><img src="/files/9QO0dhSI0HdML9EhuakN" alt=""><figcaption></figcaption></figure>

* App Visibility
  * To enable app for specific users and groups

    * **Set "Assignment Required" to "Yes"** – This ensures that only specifically assigned users have access.
    * **Set "Visible to Users" to "Yes"** – This hides FenixPyre from general users, making it accessible solely to those who are assigned.

    <figure><img src="/files/yb0DI0dbfPaTIux5odrX" alt=""><figcaption></figcaption></figure>
  * To enable app for all the users across organization

    * **Set "Assignment Required" to "No"**
    * **Set "Visible to Users" to "Yes"**

    <figure><img src="/files/8FCXnqOSCoGvGBop9ES4" alt=""><figcaption></figcaption></figure>


# How to remove FenixPyre integration in SharePoint/OneDrive

If you no longer wish to use the FenixPyre integration with Microsoft 365, or you need to rotate credentials and re-provision the app, you can safely remove the FenixPyre application from your Azure Active Directory (Entra ID) App Registrations.\
This guide walks you through the steps required to delete the app registration, revoke permissions, and confirm the integration is fully removed.

***

### **Prerequisites**

Before removing FenixPyre from Azure App Registrations, ensure:

* You have **Global Administrator**, **Cloud Application Administrator**, or **Application Administrator** permissions in Azure.
* No active workflows, automations, or SharePoint/OneDrive protections are currently relying on the FenixPyre integration.
* You have communicated the change to internal teams relying on the integration (if applicable).

***

### **Step 1: Sign in to the Azure Portal**

1. Go to [**https://portal.azure.com**](https://portal.azure.com/).
2. Sign in using an account with appropriate administrative access.

***

### **Step 2: Navigate to App Registrations**

1. In the left navigation menu, select **Microsoft Entra ID** (formerly Azure Active Directory).
2. Under **Applications**, click **App registrations**.
3. Use the search bar to look for:
   * **FenixPyre**, or
   * The custom name you assigned during installation.

***

### **Step 3: Select the FenixPyre App Registration**

1. Click the application entry to open its overview page.
2. Review the app details to confirm it is the correct registration (e.g., Application ID, Redirect URIs, API permissions).

***

### **Step 4: Delete the App Registration**

1. From the top menu, click **Delete**.
2. Azure will prompt you to confirm removal.
3. Click **Yes** to permanently delete the app registration.

> **Note:** Deleting the app registration immediately revokes all associated client secrets, certificates, API permissions, and access tokens. Any services relying on the FenixPyre integration will stop functioning.

***

### **Step 5: Remove Enterprise Application (Optional but Recommended)**

Deleting an *App Registration* does not automatically delete the associated *Service Principal* (Enterprise Application). To fully remove the integration:

1. In the left menu, go back to **Microsoft Entra ID**.
2. Select **Enterprise applications**.
3. Search again for **FenixPyre**.
4. Open the application's profile.
5. Click **Delete**.

This ensures all tenant-scoped permissions and tokens are revoked.

***

### **Step 6: Verify Permissions Are Revoked**

After deletion:

* Attempting to use FenixPyre-based SharePoint/OneDrive operations should return authentication errors.
* Any scripts, automations, or API calls relying on the deleted app will fail until reconfigured.

You can also check:

1. **API Permissions** → Ensure no lingering delegated or application permissions remain.
2. **Audit Logs** → Confirm the delete event is recorded in Azure.

***

## **Troubleshooting**

#### **I can’t delete the enterprise application**

Ensure:

* You have **Global Administrator** access.
* The application is not assigned to Conditional Access policies.
* No active users or groups are assigned-remove them first.

#### **The app still shows in SharePoint Admin Center**

SharePoint may cache integration metadata for several hours - sometimes upto 24 hours. Clearing browser cache or waiting 24 hours hours usually resolves it.


# How to configure SharePoint Integration in Admin Dashboard

Follow these steps to integrate FenixPyre with SharePoint and enable its functionality:

### Step 1: Configure Integration in the Admin Dashboard

* **Access the Admin Dashboard**:

  * Navigate to **FenixPyre Sharing > Integrations > SharePoint**
  * Click on **Connect Button**

  <figure><img src="/files/fqqnNmYGtdgITkWQ8h4d" alt=""><figcaption></figcaption></figure>
* **Enter the Required Information in the SharePoint settings page**\ <br>

  <figure><img src="/files/JwrQdBDT26gTKr4X48BD" alt=""><figcaption></figcaption></figure>
* **Application (Client) ID**: Locate this on the app’s overview page in Azure.
* **Client Secret Value**: Use the value saved in Step 9 of the [How to enable FenixPyre integration in SharePoint](/fenixpyre-for-admins/admin-dashboard/integrations/sharepoint-onedrive/how-to-enable-fenixpyre-integration-in-sharepoint)
* **Directory (Tenant) ID**: This is also available on the app’s overview page in Azure.

<figure><img src="/files/EeM4jY34OwzH92o5DkDs" alt=""><figcaption></figcaption></figure>

* **Enter Your SharePoint Domain**:
  * In the first field, input your SharePoint domain. Do not forget to add **https\://** at the beginning of the URL. For example:
    * **Correct**: `https://<orgname>.sharepoint.com`
    * **Incorrect**: `https://<orgname>-admin.sharepoint.com`
  * Avoid using the SharePoint admin center URL .

### Step 2: Verify Integration on SharePoint

1. Open a browser in **Incognito/Private Mode**.
2. Log in to your **SharePoint Account**.
3. Access a SharePoint site and navigate to the **Documents** section.
4. Select a file and right click .
   * You should now see **FenixPyre options** in the right-click menu.

<figure><img src="/files/U9oYQ0w92qqAvTt0UrK6" alt=""><figcaption></figcaption></figure>

### Step 3: Configure Protected Folders

1. Go to user policies.
2. Select the policy to configure for SharePoint.
3. Click "Configure" under "Protected Folders."
4. In the modal, choose "OneDrive Web" from the dropdown menu.
5. Enter your SharePoint path as `\\<tenant-name>.sharepoint.com\folder-path`, press Enter, and click "Update."
6. Save the policy to apply changes.

<figure><img src="/files/tI6gBDuIPCrYa3cvXeMr" alt=""><figcaption></figcaption></figure>

Your SharePoint is now secured with FenixPyre.

***

#### Notes:

* Microsoft may take up to **24 hours** to apply changes across your SharePoint environment.
* If the FenixPyre options do not appear, try the following:
  * Log out and log back into SharePoint.
  * Access SharePoint in Incognito/Private Mode.
  * Wait a few hours and try again.

If the issue persists, contact the **FenixPyre Support Team** for assistance.


# How to configure Auto Encrypted folders

**To enable Auto Encryption for a folder in OneDrive:**

**Step 1:** right-click the folder--> **FenixPyre** -->**Add to Auto Encryption**. Folders configured for auto encryption will automatically encrypt files added to them through actions on SharePoint and OneDrive apps.

<figure><img src="/files/6jMVkkgHzxIQLOmNSfP3" alt=""><figcaption></figcaption></figure>

To enable auto-encryption on a folder, click on "Enable auto-encryption"

<figure><img src="/files/WJ8eP9eUpNTabzFHiycA" alt=""><figcaption></figcaption></figure>

To disable a folder's Auto Encryption settings click on "Disable auto-encryption"

<figure><img src="/files/dkDiPXxGcbJgj0RmNLPb" alt=""><figcaption></figcaption></figure>


# Egnyte

We are in the process of migrating documentation from old site to new one.\
Visit: <https://docs.anchormydata.com/docs/anchor-app-on-egnyte-an-overview>


# Overview

Installing FenixPyre (previously Anchor) app on Egnyte streamlines secure file management by enabling seamless encryption, decryption, and editing directly within Egnyte. With the FenixPyre menu options-**Encrypt, Decrypt, Share, and Open**-users can efficiently protect sensitive documents while maintaining easy accessibility. Encryption ensures that only authorized users can access files, while decryption allows for secure retrieval when needed. The integration eliminates the need for external tools, providing a user-friendly experience within Egnyte's familiar interface. This simplifies compliance with security policies while enhancing collaboration and data protection within organizations.

After correctly configuring the integration, the "FenixPyre" menu option will appear on your SharePoint site.

FenixPyre offers a variety of menu options.

For Files:

* Open: Allows multiple users to collaborate on a file simultaneously without a need of decryption.
* Share: Easily share files securely with users both inside and outside your organization.
* Encrypt: Encrypt any file that requires protection.
* Decrypt: Decrypt any file that has been encrypted and restore its original content.
* Access Logs: Monitor file usage logs for any file.

<figure><img src="/files/dL1j3IGFdk8wloj6ipxw" alt=""><figcaption></figcaption></figure>

For Folder

* Share: Easily share folders securely with users both inside and outside your organization.
* Add to Auto Encryption: Quickly add folders to Auto Encryption to ensure they are automatically protected.

<figure><img src="/files/CDQBO2iXdKcc0QSdEqVm" alt=""><figcaption></figcaption></figure>


# How to enable FenixPyre integration in Egnyte

### Pre-requisites <a href="#prerequisites" id="prerequisites"></a>

Before you begin the installation, we recommend setting up an Egnyte admin account with the name **Anchor (FenixPyre) application**. This ensures a smooth integration process.

### Installation Steps <a href="#installation-steps" id="installation-steps"></a>

1. **Install Anchor app on Egnyte dashboard**\
   Navigate to the Apps and Integrations page on your Egnyte dashboard. Search for the FenixPyre app and install the version that is **not** marked as Legacy.

<figure><img src="/files/DDKzGYVx2kcOwYSLRqbj" alt=""><figcaption><p>Search and Enable App from Egnyte app store</p></figcaption></figure>

2. **Enable Egnyte Integration on Anchor Dashboard**

{% hint style="info" %}
Recommendation

Create a new admin-user account on Egnyte with display name FenixPyre Application” and use the same account to add the integration.\
All changes from the FenixPyre App will be reflected under **updated\_by** field in the name of the user who authorized while adding the integration in the admin dashboard.
{% endhint %}

* Login to the FenixPyre dashboard.
* Navigate to the 'Integrations' tab and select 'Egnyte'.
* Enter your Egnyte domain, e.g., **`abc.egnyte.com`**.
* Click 'OK'. You'll be redirected to the Egnyte authentication page.
* Make sure you provide access to
  * Read and Write all files and folders
  * Manage Egnyte Webhooks
  * Create and manage links
* Log in and approve the FenixPyre app.

And that's it! Your integration is now set up, and you're all set to explore the new features.

{% content-ref url="/pages/uoY641xr7mjG6y2Ubmqv" %}
[How to configure user policy (Protected folder)](/fenixpyre-for-admins/admin-dashboard/integrations/egnyte/how-to-configure-user-policy-protected-folder)
{% endcontent-ref %}


# How to configure user policy (Protected folder)

This guide for adding an Egnyte folder as a protected folder on FenixPyre Dashboard

1. **Log into FenixPyre Dashboard**
   * Open your browser and go to the **FenixPyre Dashboard**.
   * Enter your **Admin credentials** and sign in.
2. **Navigate to User Policy**

   * Click on the **User Policy** section in the left menu.

   <figure><img src="/files/mzssUHsGwjLGfXWPL3pK" alt=""><figcaption><p>User Policy Page</p></figcaption></figure>
3. **Select the User Policy to Modify**
   * Select the respective policy if applying the protected folder to a specific user group.
   * If applying to **all users**, select the **Default Policy**.
4. **Go to the Protected Folder Tab**

   * In the **User Policy settings**, navigate to the **Protected Folder** tab.

   <figure><img src="/files/TgUUPk1GuaYyq0x2ICfv" alt=""><figcaption></figcaption></figure>
5. **Add the Protected Folder Path**

   * Click on **Protected Folders**
   * Select Type as **"Egnyte Web"** from the dropdown.

   <figure><img src="/files/zvbXfQUzEyDYTblJ70H6" alt=""><figcaption></figcaption></figure>

   * Enter the folder path in the required format:

     ```
     \\<egnyte-domain>\<folder path>
     ```
   * Example:

     ```
     \\fenixpyre.egnyte.com\Shared\Documents\Demo
     ```
6. **Save changes**
   * and the above folder will be added as a protected folder


# How to configure Auto Encryption folders

## What is Auto Encryption Folder on Egnyte?

Auto-Encryption is a feature that enables administrators to ensure all files remain encrypted without manual intervention. Once an admin designates a folder as an auto-encryption folder, any new files added will be encrypted periodically by FenixPyre.

{% hint style="info" %}
Auto-encryption for a folder can only be enabled by an administrator on FenixPyre.
{% endhint %}

### How to add a folder as Auto Encryption Folder?

{% stepper %}
{% step %}

### Right-click a folder on Egnyte

Right-click the folder--> **Add to Auto Encryption**. Folders configured for auto encryption will automatically encrypt files added to them.
{% endstep %}

{% step %}

### Enable Auto Encryption

To enable auto-encryption on a folder, click on "Enable auto-encryption"
{% endstep %}
{% endstepper %}

### Manage Auto Encryption Folders on Dashboard

Log in to the FenixPyre Admin Dashboard and navigate to Integrations and then Egnyte tab. You will find a list of folders designated for auto-encryption. Administrators possess the authority to delete any folder from this list of automatically encrypted folders.

### How to disable auto-encryption setting?

{% stepper %}
{% step %}

### Right-click a folder on Egnyte

Right-click the folder--> **Add to Auto Encryption**. Folders configured for auto encryption will automatically encrypt files added to them.
{% endstep %}

{% step %}

### Disable Auto Encryption

To disable a folder's Auto Encryption settings click on "Disable auto-encryption"
{% endstep %}
{% endstepper %}

<figure><img src="/files/dkDiPXxGcbJgj0RmNLPb" alt=""><figcaption></figcaption></figure>


# Box

{% content-ref url="/pages/SagydzShGl3UZiFrsjs6" %}
[Overview](/fenixpyre-for-admins/admin-dashboard/integrations/box/overview)
{% endcontent-ref %}

{% content-ref url="/pages/KFYw7oyAfYQN8KWULkVp" %}
[How to enable FenixPyre integration in Box](/fenixpyre-for-admins/admin-dashboard/integrations/box/how-to-enable-fenixpyre-integration-in-box)
{% endcontent-ref %}

{% content-ref url="/pages/Vabdh945EsqBXIcrw0Ey" %}
[How to configure Box Integration in the Admin Dashboard](/fenixpyre-for-admins/admin-dashboard/integrations/box/how-to-configure-box-integration-in-the-admin-dashboard)
{% endcontent-ref %}

{% content-ref url="/pages/jWS4XEaFpdhsH2A31Ily" %}
[How to configure user policy (Protected folder)](/fenixpyre-for-admins/admin-dashboard/integrations/box/how-to-configure-user-policy-protected-folder)
{% endcontent-ref %}


# Overview


# How to enable FenixPyre integration in Box

### Pre-requisites

Before you begin the installation, we recommend setting up a Box admin account with the name FenixPyre application. This ensures a smooth integration process.

### Adding FenixPyre to Your Box Account

1. **Log in to Box:**
   * Access your Box account by logging in with your credentials.
2. **Search for FenixPyre**
   * Go to the `Apps` section in the Box interface.
   * Use the search bar to find the FenixPyre app.
3. **Add the FenixPyre App:**

   * Click on `Add` to install the FenixPyre app.
   * Review and grant the necessary permissions required by the FenixPyre app to ensure proper functionality.

   <figure><img src="/files/jn76S1oKssiDwKxO9iPK" alt=""><figcaption></figcaption></figure>

### Configuring FenixPyre for All Users in Box

1. **Log in as an Admin:**
   * Access your Box Admin console using your administrative credentials.
   * Go to the `Admin Console`.
2. **Access Individual Application Controls:**

   * In the Admin Console, navigate to `Apps` and click on `Individual Application Controls` tab.
   * Select the `FenixPyre` app from the list.
   * Click on `Configure` button.

   <figure><img src="/files/z2kgfks7tJAgniQCyADy" alt=""><figcaption></figcaption></figure>
3. **Set FenixPyre as default app for all users:**

   * A pop-up will appear.
   * Choose the option `"Added by default for All users"` to ensure the FenixPyre app is available to all users by default.
   * Save the changes

   <figure><img src="/files/gvmn2OaIwsXgjHcPwAUJ" alt=""><figcaption></figcaption></figure>

By following these steps, you can configure FenixPyre to be automatically available for all users in your Box environment.


# How to configure Box Integration in the Admin Dashboard

**Step 1: Log In to the FenixPyre Admin Dashboard and navigate to Integration Settings**

1. Log in to your dashboard.
2. Go to the `Integrations` section and then click on `Box`

<figure><img src="/files/yWvEpWOogzdBTPVWcUdQ" alt=""><figcaption></figcaption></figure>

**Step 2: Enter Enterprise ID**

1. Enter your `Enterprise ID` in the designated text box.
2. You can locate your Box **Enterprise ID** on the Box website by navigating to the **Admin Console** under the **Accounts & Billing** section.

**Step 3: Save and Authenticate**

1. Click on the `Save` button.
2. A pop-up will appear with the message: "**Do you want to proceed with the update? You will be redirected to Box site for authentication.**"
3. Click `OK` to continue.

**Step 4: Authenticate with Box**

1. You will be redirected to the Box site for authentication.
2. Complete the authentication process to finalize the integration.

By following these steps, you can successfully configure the integration with Box, ensuring secure and seamless connectivity.


# How to configure user policy (Protected folder)

This guide for adding a folder as a protected folder in box

1. **Log into FenixPyre Dashboard**
   * Open your browser and go to the **FenixPyre Dashboard**.
   * Enter your **Admin credentials** and sign in.
2. **Navigate to User Policy**

   * Click on the **User Policy** section in the left menu.

   <figure><img src="/files/mzssUHsGwjLGfXWPL3pK" alt=""><figcaption><p>User Policy Page</p></figcaption></figure>
3. **Select the User Policy to Modify**
   * Select the respective policy if applying the protected folder to a specific user group.
   * If applying to **all users**, select the **Default Policy**.
4. **Go to the Protected Folder Tab**

   * In the **User Policy settings**, navigate to the **Protected Folder** tab.

   <figure><img src="/files/TgUUPk1GuaYyq0x2ICfv" alt=""><figcaption></figcaption></figure>
5. **Add the Protected Folder Path**

   * Click on **Protected Folders**
   * Select Type as **"Box Web"** from the dropdown.

   <figure><img src="/files/zvbXfQUzEyDYTblJ70H6" alt=""><figcaption></figcaption></figure>

   * Enter the folder path in the required format:

     ```
     \\<enterprise ID>@app.box.com<folder path>
     ```
   * Example:

     ```
     \\1174000000@app.box.com\all files\shared\lab folders
     ```
6. **Save changes**
   * and the above folder will be added as a protected folder


# Sharing Settings

The **Sharing Settings** in FenixPyre allow administrators to configure file-sharing permissions, editor preferences, and expiration policies for shared files. This guide explains each setting in detail to help you customize your organization's sharing controls effectively.

### How to edit the settings

1. Under FenixPyre Sharing, Go to Sharing Settings.

### Permissions

These settings control the level of access users have when sharing files in FenixPyre:

* **Can Edit**: Allows users to edit files with edit access (Toggle: ON by default).
* **Can Create**: Allows recipients with edit access to create new files in shared folders (Toggle: ON by default).
* **Can Upload**: Allows recipients with edit access to upload files to shared folders (Toggle: ON by default).
* **Can Download**: Allows users to share files with download access, enabling decryption and downloading (Toggle: ON by default).
* **Can Delete**: Allows recipients with edit access to delete files in shared folders (Toggle: ON by default).
* **Can Rename**: Allows recipients with edit access to rename files in shared folders (Toggle: ON by default).
* **Can Share**: Allows users to share files via FenixPyre. Disabling this removes sharing functionality across all products (Toggle: ON by default).

### Sharing Settings

These settings define expiration rules and access levels for shared files:

* **Default Share Expiry**: The default expiration time for new shares (Set to 7200 hours by default).
* **Maximum Share Expiry**: The maximum allowed expiration time for shared files (Set to 14410 hours by default).
* **Allowed Share Access Levels**: Determines who can access shared files. The options include:
  * **Public**: Anyone with the link.
  * **Restricted Access**: Only specific users.
  * **Organization**: Only members of the organization.
* **Default Share Access Level**: Sets the default access level for new shared files. The current default is **Organization**.

### Additional Notes

* Admins can modify these settings at any time based on organizational requirements.
* Disabling file-sharing permissions such as "Can Share" will restrict users from sharing files externally.
* Expiry settings help maintain security by ensuring shared files are not accessible indefinitely.


# Identity & Provisioning

{% content-ref url="/pages/wQoFEe3NHqhCEFCzyuIM" %}
[Domain Management](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/domain-management)
{% endcontent-ref %}

{% content-ref url="/pages/iKejPLeveZPGDxIHbkQT" %}
[SAML Single Sign-On (SSO) Setup](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/saml-single-sign-on-sso-setup)
{% endcontent-ref %}

{% content-ref url="/pages/HhBxib4wypkxZpIvNOZs" %}
[Automatic Account Creation](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/automatic-account-creation)
{% endcontent-ref %}

{% content-ref url="/pages/SdgMBYWJLaa0JewPbODE" %}
[SCIM](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/scim)
{% endcontent-ref %}


# Domain Management

{% content-ref url="/pages/ZxdAeS9Lj4cvphBqcHAr" %}
[Primary Domain](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/domain-management/primary-domain)
{% endcontent-ref %}

{% content-ref url="/pages/JbkmBhxFx8opB2fnByuO" %}
[Guest Domain](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/domain-management/guest-domain)
{% endcontent-ref %}


# Primary Domain

A primary domain refers to the email domain used for sign-in and access to the FenixPyre admin dashboard (for admin users), FenixPyre Windows agent, and FenixPyre cloud integrations.

When an organization is created, a default primary domain is automatically assigned, typically based on the email domain of the admin user. This primary domain serves as the core identity for the organization within FenixPyre.

Only admin users have the necessary permissions to add, remove, or update the primary domain for an organization.

### Adding a new primary domain

Adding a new primary domain requires admin access to the admin dashboard. Follow the steps below to add a new primary domain.

* Sign in to the administrator dashboard at [https://admin.anchormydata.com](https://admin.anchormydata.com/)
* Click on Settings -> Security -> Identity & Provisioning -> Domains.

<figure><img src="/files/4UBH79cbZ8zEQfLialjj" alt=""><figcaption></figcaption></figure>

* Under **Primary Domains**, click on the **Add Domain** button
* Enter your domain. For example eviz&#x69;*.com*
* If the domain addition is successful, you will receive a success notification on the top right corner of the dashboard

{% embed url="<https://www.loom.com/share/778f7ca74b67400d8c433a306aaa5244>" %}

### Deleting an existing primary domain

1. Sign-in to admin dashboard at [https://admin.anchormydata.com](https://admin.anchormydata.com/).
2. Click on Settings -> Security -> Identity & Provisioning -> Domains.
3. To remove a primary domain, click on the delete icon next to the associated primary domain.

<figure><img src="/files/FrXHqh5PCjHN75GXj16J" alt=""><figcaption></figcaption></figure>

4. A dialog box appears to confirm the deletion, enter the word **DELETE** (all in uppercase) in the text box field and then click on the **Delete** button. To cancel the deletion, click on the **Cancel** button.

<figure><img src="/files/TsibIrrLw5OklzAZEpNw" alt=""><figcaption></figcaption></figure>

4. If the domain deletion is successful, you will receive a notification on the top right corner of the dashboard.

### What happens if I delete a primary domain?

Deleting a primary domain will instantly deactivate all the users with emails associated with that primary domain. Deactivation means the user will be blocked from accessing the platform. This includes sign-in to the admin dashboard, sign-in user sharing portal, access to all encrypted files, and all links shared by the users of the primary domain.

### Editing an existing primary domain

* Sign in to the admin dashboard at [https://admin.anchormydata.com](https://admin.anchormydata.com/).
* Click on Settings -> Security -> Identity & Provisioning -> Domains.
* Click the edit icon next to the associated primary domain to edit a primary domain.
* When you click on the edit icon, the primary domain becomes an editable text box.
* Make your changes and click on the done icon on the right. If you want to cancel the editing, click on the cancel icon on the right.
* When you click on the done icon, a confirmation dialog appears to confirm that changes. Click on the **Change** button to confirm and the **Cancel** button to cancel the changes.
* If the domain change is successful, you will receive a success notification on the top right corner of the dashboard.

### What happens if I edit a primary domain?

Editing a primary domain will instantly deactivate all the users with emails associated with that primary domain. Deactivation means the user will be blocked from accessing the platform. This includes sign-in to the admin dashboard, sign-in to the user sharing portal, and access to all encrypted files, and all links shared by the users of the primary domain.

For example: if you change the primary domain from contoso.com to contoso.xyz, then all users in contoso.com will get deactivated<br>

\ <br>


# Guest Domain

### What are guest domains? <a href="#what-are-guest-domains" id="what-are-guest-domains"></a>

Guest domains are email domains that internal users (primary domain users) can share files with. Only domains that are added to the guest domains are allowed access to links shared by internal users (primary domain users).

By default, there are no guest domains added to an organization, which means internal users can share files/folders with any email domain. Only admins can add/remove/update a guest domain.

### Adding a new guest domain

Adding a new guest domain requires admin access to the admin dashboard. Follow the steps below to add a new guest domain.

1. Sign in to the admin dashboard at [https://admin.anchormydata.com](https://admin.anchormydata.com/).
2. Click on Settings -> Security -> Identity & Provisioning -> Domains.
3. Under **Guest Domains**, click on the **Add New Domain** button
4. Enter your domain. For example contoso.com and click on **Add new domain**

<figure><img src="/files/T0j2O6BMh9mxNxaNI24L" alt=""><figcaption><p>Guest Domain</p></figcaption></figure>

### Deleting an existing guest domain

1. Sign in to the admin dashboard at [https://admin.anchormydata.com](https://admin.anchormydata.com/).
2. Click on Settings -> Security -> Identity & Provisioning -> Domains.
3. To remove a guest domain, click on the delete icon next to the associated guest domain.
4. A dialog box appears to confirm the deletion, click on the **Delete** button. To cancel the deletion, click on **Cancel** button
5. If the domain deletion is successful, you will receive a notification on the top right corner of the dashboard.

### What happens if I delete a guest domain?

Deleting a guest domain will instantly deactivate all the users with emails assocaited to that guest domain. Deactivation means, the guest users will be blocked from accessing all the links shared with them.

#### Editing an exisiting guest domain

1. Sign-in to admin dashboard at [https://admin.anchormydata.com](https://admin.anchormydata.com/).
2. Click on Settings -> Security -> Identity & Provisioning -> Domains.
3. To edit a guest domain, click on the edit icon next to the associated guest domain.
4. When you click on the edit icon, the guest domain becomes a editable text box.
5. Make your changes and click on the done icon on the right. If you want to cancel the editing, click on the cancel icon on the right.
6. When you click on done icon, a confirmation dialog appears to confirm that changes. Click on **Change** button to confirm and **Cancel** button to cancel the changes.
7. If the domain change is successful, you will receive a success notification on the top right corner of the dashboard.

### What happens if I edit a guest domain?

Editing a guest domain will instantly deactivate all the users with emails assocaited to that guest domain. Deactivation means, the guest users will be blocked from accessing all the file/folder links shared with them.

For example: if you change the guest domain from contoso.com to contoso.xyz, then all users in contoso.com will get deactivated.

\ <br>


# SAML Single Sign-On (SSO) Setup

### Authentication

You can use your company's identity management system to let employees sign in to Fenixpyre with their corporate credentials. This simplifies user provisioning for Fenixpyre. Fenixpyre supports integration with any SAML-based Single Sign-On (SSO) system. You can use your Enterprise Identity Provider, such as Azure Active Directory or Okta, for SSO.

### User authentication and provisioning for SSO

When Single Sign-On (SSO) is set up, users are automatically given a new Fenixpyre account the first time they log in through SSO.

The sign-in process works as follows:

1. Users select SSO to log in and are redirected to their identity provider for authentication.
2. The identity provider confirms authentication and sends the required data to Fenixpyre servers to create the user.
3. Fenixpyre checks its directory for the user.
4. If the user already exists, Fenixpyre grants the appropriate access. For new users, Fenixpyre adds them to the directory and redirects them to the Fenixpyre app with the correct access.

### Pre-requisites to setup SAML Single Sign-On (SSO)

Security Assertion Markup Language (SAML) is a login standard that allows users to access applications using sessions from another context. It provides a secure and user-friendly Single Sign-On (SSO) authentication method, improving security and user experience compared to traditional username and password logins.

Before setting up SAML Single Sign-On (SSO), ensure you meet the following prerequisites:

* Access to the Fenixpyre admin dashboard
* Administrator access to the Azure Active Directory portal or the Okta admin portal


# Set-up SAML SSO with Azure

Setup Single Sign-on with Azure enterprise application

1. Sign-in to your Azure admin portal
2. In the left menu bar, click on Microsoft Entra ID

<figure><img src="/files/ysOjZ53LxGTRbpQyRszL" alt=""><figcaption></figcaption></figure>

3. Click on **Enterprise applications** in the left menu bar
4. In the Enterprise applications page, click on **New application**
5. In the **Browse Microsoft Entra Gallery** page, click on **Create your own application**

<figure><img src="/files/khEdKEyxN4UM3bfNEpAs" alt=""><figcaption></figcaption></figure>

6. In the **Create your own application**,
   1. Enter a name for the application. For example **fp-saml-sso-application**
   2. Select **Integrate any other application you don't find in the gallery (Non-gallery)**

<figure><img src="/files/26aqZnRvdGzAjYhX5EAK" alt=""><figcaption></figcaption></figure>

7. Click on the **Create** button
8. In the newly created application page, select **Single sign-on** in the left menu bar

<figure><img src="/files/w2JhYCTUBuaMHKtTUkUF" alt=""><figcaption></figcaption></figure>

9. Select SAML in the **Select a single sign-on method**

<figure><img src="/files/L888kJWso6IEpRu32eUn" alt=""><figcaption></figcaption></figure>

10. In the **Set up Single Sign-On with SAML** page, click on the Edit icon under **Basic SAML configuration**

<figure><img src="/files/L9JVIJ3GLlaklkUapRpU" alt=""><figcaption></figcaption></figure>

11. On the configuration page, click on the **Add Identifier** button

<figure><img src="/files/fEcdgBaZXW1elEFi3Sl2" alt=""><figcaption></figcaption></figure>

12. Now you will need to get the following values from the Fenixpyre admin dashboard.
    1. Identifier (Entity ID)
    2. Reply URL (Assertion Consumer Service URL)
    3. Sign on URL
13. Sign in to the Fenixpyre admin dashboard
14. Click on Identity & Provisioning under Security in Settings (Left Navigation Menu)

<figure><img src="/files/dJJGeagGveCdqrgne1rz" alt=""><figcaption></figcaption></figure>

15. Switch to SAML SSO Tab

<figure><img src="/files/rygBTljTKNlO92qyHp8L" alt=""><figcaption></figcaption></figure>

16. Click on **Add new SAML SSO** and select **Setup Azure AD SAML SSO**

<figure><img src="/files/QyKXJFNzXtthKxZ47Fht" alt=""><figcaption></figcaption></figure>

17. You will be presented with a dialogue which contains the following values:
    1. Identifier (Entity ID)
    2. Reply URL (Assertion Consumer Service URL)
    3. Sign on URL

<figure><img src="/files/ccUnR3EH16opY5AKZODN" alt=""><figcaption></figcaption></figure>

18. Copy the **Identifier (Entity ID)**, **Reply URL (Assertion Consumer Service URL)**, and **Sign on URL** and paste it in the **Azure Basic SAML configuration** page like shown below.

<figure><img src="/files/neFXZ893SysmSCJCCUPa" alt=""><figcaption></figcaption></figure>

19. Click on the **Save** button, You will navigated back to the SSO landing page.

<figure><img src="/files/mhqnIl0Lh9KjAsejMUHF" alt=""><figcaption></figcaption></figure>

20. Click on the **Permissions** in the left menu bar and then click on **app registration**.
21. In the API permissions page, click on **Add a permission**
22. Add the following API permissions
    1. Microsoft Graph -> Delegated permissions -> User.Read
    2. Microsoft Graph -> Delegated permissions -> Directory.Read.All

{% embed url="<https://www.loom.com/share/433646d0cc57458aa1eda49c22f2ece1?sid=02d55527-387d-4d97-9134-acb3a7f1d650>" %}

23. Click on \*\*Grant admin consent \*\*
24. Go back to **Enterprise applications** -> find the **fp-saml-sso-application**, and then click on **Single sign-on**.
25. Download the Base64 certificate, and copy the **Login URL**

{% embed url="<https://www.loom.com/share/2af2d979ada7482d97a112567a858a0f?sid=41abea10-4dc7-48c6-9c80-bd5e3797a92a>" %}

26. Paste the **Login URL** in the **Sign-in URL** field on the Fenixpyre dashboard, and upload the Base64 certificate you downloaded to the Fenixpyre dashboard.

{% embed url="<https://www.loom.com/share/deccce5e2d8d4b1d9fac3b96dbf9c68d?sid=f7130a23-b3c6-4bbe-8d93-27a518017a5c>" %}

27. You will see a success dialogue box if the setup is successful.
28. Click on **Close** or **Logout and verify the connection** to verify the newly added SAML SSO.


# Verify the SAML SSO

How to verify the newly added SAML SSO?

1. Create/Add users to the Azure Application, who need to login to dashboard using SSO

{% embed url="<https://www.loom.com/share/3f10633b7d884b76a3050b4b180b2442?sid=a1401cda-9ad5-4bed-b427-fb03e36784e2>" %}

2. Make sure that your Azure Microsoft Entra ID primary domain is part of Fenixpyre's primary domains
3. Now sign out and sign back into the Fenixpyre admin dashboard
4. You can configure the Sign-in method to SAML-SSO or Any
5. According to the configured Sign-in method, When you sign in, you will be provided with 2 options:
   1. Continue with Email
   2. Continue with SSO

{% embed url="<https://www.loom.com/share/435efd184bb74d6497a2facd8f1400b6?sid=8a0054ca-9185-44d8-931c-8816d269f39b>" %}

6. Choose **Continue with SSO** to sign in with your newly added Azure SAML SSO
7. If sign-in is successful you will be see the home page of admin dashboard.


# Sign-in to Admin Dashboard with Azure AD

1. Open the Login page of Fenixpyre Admin Dashboard
2. Enter your organization ID. You can find this in the invite email that was sent to you or on the admin dashboard.
3. Enter your email address.
4. When you enter your email address during sign-in, we automatically detect if SSO is enabled for your organization. Depending on the **sign-in method** you choose in the settings you will be provided with 2 sign-in options:
   1. Continue with Email
   2. Continue with SSO

{% embed url="<https://www.loom.com/share/435efd184bb74d6497a2facd8f1400b6?sid=7bcd9d3b-8616-4729-8612-97949453ee0c>" %}

1. Choose **Continue with SSO** to sign-in with your newly added Azure SAML SSO
2. If sign-in is successful you will be see the home page of admin dashboard.


# Sign-in to SharePoint integration with Azure AD

1. Sign-in to your SharePoint site.
2. Right-click on a file in your SharePoint site.
3. You will be presented with FenixPyre options in the context menu.
4. Click on **FenixPyre** -> Encrypt.
5. ![](/files/NcHQaUVz9hcVfoI7POUW)
6. You will redirected to a sign-in page, where you will be asked to sign-in with SSO, if SSO is already enabled for your organization.
7. Sign in with your Microsoft O365 account to complete the operation.


# Set-up SAML SSO with Okta

Setup Single Sign-on with Okta SAML application

1. Sign in to your Okta admin portal
2. In the left menu bar, click on Applications tab

<figure><img src="/files/BqK70OGSNgWiZ8bvjRkH" alt=""><figcaption></figcaption></figure>

3. Click on **Create App Integration**

<figure><img src="/files/bnbHWE435l0tci4d9jl2" alt=""><figcaption></figcaption></figure>

4. In the pop-up select **SAML 2.0** and click on **Next**

<figure><img src="/files/2c6SZtprT6Me9AvsYePo" alt=""><figcaption></figcaption></figure>

5. In the **Create SAML Integration** page, provide a name to the application and click **Next**

<figure><img src="/files/PWNOz0Aind2ZBHGJH3Lb" alt=""><figcaption></figcaption></figure>

6. At this point you will need the following details from the Anchor admin dashboard
   1. Single sign-on URL
   2. Audience Restriction
7. Login to Fenixpyre admin dashboard
8. Click on Identity & Provisioning under Security option in Settings

<figure><img src="/files/8spelagXHMijPkRfMgc2" alt=""><figcaption></figcaption></figure>

9. Click on **SAML SSO** tab
10. Click on **Add new SAML SSO** -> **Setup Okta SAML SSO**
11. A pop-up window will appear with the following details. Copy **Single Sign On URL** and **Audience Restriction** and click **Next**

<figure><img src="/files/t7ReFv9b8HcHxNNZ5IaG" alt=""><figcaption></figcaption></figure>

12. Paste the copied **Single Sign On URL** and **Audience Restriction** into Okta SAML settings page.

<figure><img src="/files/umXuD7HF4NpUmFAfp5QB" alt=""><figcaption></figcaption></figure>

13. In the **Attribute Statements (optional)** add the following values. Avoid spelling mistakes.

<figure><img src="/files/istKNyjsAxZMkHnaPIMd" alt=""><figcaption></figcaption></figure>

14. In the **Group Attribute Statements (optional)** add the following value. Avoid spelling mistakes.

<figure><img src="/files/eNCeowqSvnQfKRyGxbv1" alt=""><figcaption></figcaption></figure>

15. Click on **Next** and select the following options.
16. Click **Finish**.

<figure><img src="/files/aKkbwroMzqbR3Cp8rNoT" alt=""><figcaption></figcaption></figure>

17. The app is successfully created now. Now click on **Sign On** tab.

<figure><img src="/files/EegRTdonhKoqcxbZFgpZ" alt=""><figcaption></figcaption></figure>

18. You need the **Sign on URL**, **Sign out URL** and the **X509 certificate** from the Okta portal to finish the setup on Anchor admin dashboard. Follow the video below to finish the setup.

{% embed url="<https://www.loom.com/share/2c6675f0aa7544808f65b87c3d79425d?sid=94a9ea47-5390-44aa-ab04-f2628381daa3>" %}

19. If the setup is successful then you will see the following pop-up.

<figure><img src="/files/iJDkDajOeOKeSJDFqpp7" alt=""><figcaption></figcaption></figure>


# Adding users to Okta Application

Adding users to newly created Okta SAML SSO app

1. Login to Okta admin portal.
2. Go to **Applications** tab and click on the newly created app **fp-saml-sso-application**
3. Click on **Assignments** tab.
4. Click on **Assign** and in the dropdown select **Assign to People**.
5. Click on **Assign** beside the name of the user. This will add the user to the newly created SAML app.

{% embed url="<https://www.loom.com/share/05a9bf4ef7e4488ab58ddca6268d3de4?sid=79c2e964-9261-4c57-b752-f9d6ac921052>" %}


# How to verify SSO sign-in

How to verify SSO sign-in with the newly added SAML SSO?

1. Make sure that your email domain is part of the [FenixPyre primary domains.](/fenixpyre-for-admins/admin-dashboard/identity-and-provisioning/domain-management/primary-domain)
2. Make sure your email is added to the Okta SAML SSO app.
3. Add/promote the user as an Admin in the Fenixpyre admin dashboard.
4. Now sign-out and sign back in to the Fenixpyre admin dashboard with SSO.
5. Go to Admin Dashboard, Enter your organization ID. Enter the email, you will be presented with 2 options:
   1. Continue with Email
   2. Continue with SSO

<figure><img src="/files/QgLaXB3L5qJTEfwsgRDP" alt=""><figcaption></figcaption></figure>

6. Choose **Continue with SSO** to sign-in with your newly added Okta SAML SSO

<figure><img src="/files/YwFkcVVoCRNM2hpmZB6T" alt=""><figcaption></figcaption></figure>

6. If sign-in is successful you will be see the home page of admin dashboard.


# Sign-in to SharePoint integration with Okta

1. Sign-in to your SharePoint site.
2. Right-click on a file in your SharePoint site.
3. You will be presented with FenixPyre options in the context menu.
4. Click on **FenixPyre** -> Encrypt.\
   ![](/files/NcHQaUVz9hcVfoI7POUW)
5. You will redirected to a sign-in page, where you will be asked to sign-in with SSO, if SSO is already enabled for your organization.
6. Sign-in with your Okta account to complete the operation.

{% embed url="<https://www.loom.com/share/2e8cf06a20cd47d3b0d01226b506f9dc?t=0>" %}


# Automatic Account Creation

FenixPyre provides an option to automatically create user accounts when users first log in via Single Sign-On (SSO).

You can find this option under Security > Identity & Provisioning > SAML SSO

<figure><img src="/files/DMxxg3RimHuutzcDz8mF" alt=""><figcaption></figcaption></figure>

This feature helps streamline user management by eliminating the need for manual user account creation.

### **When Automatic User Account Creation is Enabled:**

* **User Account Creation**:\
  When a user logs in for the first time using SSO, FenixPyre will automatically create a user account for them. The system assigns the **default user policy** to the newly created account, ensuring that the user has the necessary access rights and permissions to use the platform.

### **When Automatic User Account Creation is Disabled:**

* **Access Denied**:\
  If Automatic User Account Creation is disabled, the system will not create a user account when they log in for the first time using SSO. Instead, the user will receive an **access denied error**, and they will be unable to proceed with accessing the platform.

This feature gives administrators control over whether users are automatically provisioned when they log in through SSO, ensuring that account creation aligns with your organization’s policies and workflows.


# SCIM

**SCIM (System for Cross-Domain Identity Management)** is an industry-standard framework designed to streamline and automate the management of user identities across different systems and applications. SCIM provisioning enables seamless and secure user lifecycle management by automating the processes of creating, updating, and deactivating user accounts across various services, reducing the administrative burden and the potential for errors.

FenixPyre integrates with leading identity providers like **Azure Active Directory** and **Okta**, allowing for efficient and automated user provisioning and de-provisioning. With this integration, your organization can ensure that user data remains consistent, accurate, and up-to-date across all systems, while also maintaining strict access control and security compliance.


# User Management with SCIM(SCIM events)

FenixPyre supports a variety of SCIM provisioning actions to streamline user and group management. Changes made in your Single Sign-On (SSO) system will automatically reflect in FenixPyre, ensuring seamless synchronization.

### FenixPyre listens to the following SCIM Events:

* **User Creation:** Easily create new user accounts within your SSO and add them to FenixPyre SAML app in your SSO. These users will then be added to FenixPyre.
* **User Update:** Modify existing user details and attributes as needed is your SSO provider and changes will be reflected in FenixPyre
* **User Deletion:** Remove user accounts from FenixPyre SAML app in your SSO and corresponding user accounts will be deactivated from FenixPyre
* **Group Creation:** Add a new group to the FenixPyre SAML app in your SSO, and all users within that group will be automatically added to FenixPyre.
* **Group Update:** Add or delete users in a group within your SSO, and these changes will be automatically reflected in FenixPyre.
* **Group Deletion:** Delete groups that are no longer needed within your SSO, and these changes will be automatically reflected in FenixPyre.
* **Adding a User to a Group:** Add users in a group within your SSO, and these changes will be automatically reflected in FenixPyre.
* **Removing a User from a Group:** Delete users in a group within your SSO, and these changes will be automatically reflected in FenixPyre.


# Set-up SCIM for Azure

**Pre-requisites**

* Admin access to FenixPyre admin dashboard
* SAML SSO is already setup on FenixPyre dashboard
* Admin access to Azure active directory portal or Okta portal

**Note**- During set up, your identity provider will ask for an API token created through the OAuth 2.0 flow.

#### How to Set Up SCIM with Azure AD

* **Navigate to SCIM Settings:**
  * Go to `Settings` -> `Security` -> `Identity and Provisioning`.
  * Select `SCIM`.
* **Set Up SCIM:**
  * Click on "Set-up SCIM".
* **Select Directory Provider:**
  * From the "Select your directory provider" menu, choose `Azure AD`.

![scim\_ad.png](/files/FKJUgyY6RApmj8mgYEF0)

* **Give Your Application a Descriptive Name:**
  * Ensure your application has a clear and descriptive name for easy identification.

![scim\_10.png](/files/vdbNEkhYeF64gtDO8m9K)

* **Continue Setup in FenixPyre:**
  * On the FenixPyre dashboard, click “Continue to Next Step”.
  * Copy the provided Endpoint and Bearer Token.<br>

<figure><img src="/files/uKUAA3m0ARODrpU14Hey" alt=""><figcaption></figcaption></figure>

* **Paste Endpoint and Token in Azure:**
  * In the Azure Admin portal, navigate to the provisioning screen where you previously enabled provisioning(Check Prerequisite's document).
  * Paste the Endpoint and Bearer Token into the respective fields.<br>

<figure><img src="/files/MP2C1ThRdc3wwKUBPXIp" alt=""><figcaption></figcaption></figure>

* **Test Connection:**
  * Click on `Test Connection` to ensure the details are correct and the connection is successful.<br>

<figure><img src="/files/GNmE6YOtADUzlb2cVm5y" alt=""><figcaption></figcaption></figure>

* **Save Configuration:**
  * Click `Save` to save the provisioning configuration in the Azure Admin portal.

<figure><img src="/files/QwvvW64SaJGBox6NYDQv" alt=""><figcaption></figcaption></figure>

* **Configure User Attributes:**
  * On the same page, scroll down to find “Provision Azure Active Directory Users”.
  * Click on the attribute with `externalId`.
  * Change the value from `mailNickname` to `objectId`.
  * Ensure the attributes are mapped correctly
  * Save the attributes

<figure><img src="/files/8JrrSSUoOAurBKARzd98" alt=""><figcaption></figcaption></figure>

* **Return to FenixPyre Portal:**
  * Go back to the FenixPyre portal and click on “Continue to Next Step”.
* **Verify and Continue:**
  * Verify the details on the page and click on “Continue to Next Step” again.
* **Start Sync:**
  * Click on “Start Sync” to begin the synchronization process.<br>

<figure><img src="/files/a8BUfgT4ORRbLCti5NYz" alt=""><figcaption></figcaption></figure>

* **Add Users in Azure:**
  * In the Azure portal, go to the "Users and Groups" tab.
  * Click on `Add User`.
  * Select `None Selected`.

<figure><img src="/files/VBTWE2BL9I5tOGyhkvnL" alt=""><figcaption></figcaption></figure>

* Choose the users/groups to be added to the application.

<figure><img src="/files/smwOksN4x2D9LOA855wL" alt=""><figcaption></figcaption></figure>

* Click on the "Provision on Demand" tab.
* Select your user/group and click `Provision`.

<figure><img src="/files/AwzyDmg5l7Pcboe6KjSf" alt=""><figcaption></figcaption></figure>

* **Verify Success:**
  * The success screen should be visible on the FenixPyre dashboard.
  * You will also see SCIM marked as active in the SCIM tab.

<figure><img src="/files/VMRrpwm89LMtwOZaVyIo" alt=""><figcaption></figcaption></figure>


# Getting started

**Pre-requisites**

* Admin access to FenixPyre admin dashboard
* SAML SSO is already setup on FenixPyre dashboard
* Admin access to Azure active directory portal or Okta portal

**Note**- During set up, your identity provider will ask for an API token created through the OAuth 2.0 flow.

#### How to Set Up SCIM with Azure AD

* **Navigate to SCIM Settings:**
  * Go to `Settings` -> `Security` -> `Identity and Provisioning`.
  * Select `SCIM`.
* **Set Up SCIM:**
  * Click on "Set-up SCIM".
* **Select Directory Provider:**
  * From the "Select your directory provider" menu, choose `Azure AD`.

![scim\_ad.png](/files/FKJUgyY6RApmj8mgYEF0)

* **Give Your Application a Descriptive Name:**
  * Ensure your application has a clear and descriptive name for easy identification.

![scim\_10.png](/files/vdbNEkhYeF64gtDO8m9K)

* **Continue Setup in FenixPyre:**
  * On the FenixPyre dashboard, click “Continue to Next Step”.
  * Copy the provided Endpoint and Bearer Token.<br>

<figure><img src="/files/uKUAA3m0ARODrpU14Hey" alt=""><figcaption></figcaption></figure>

* **Paste Endpoint and Token in Azure:**
  * In the Azure Admin portal, navigate to the provisioning screen where you previously enabled provisioning(Check Prerequisite's document).
  * Paste the Endpoint and Bearer Token into the respective fields.<br>

<figure><img src="/files/MP2C1ThRdc3wwKUBPXIp" alt=""><figcaption></figcaption></figure>

* **Test Connection:**
  * Click on `Test Connection` to ensure the details are correct and the connection is successful.<br>

<figure><img src="/files/GNmE6YOtADUzlb2cVm5y" alt=""><figcaption></figcaption></figure>

* **Save Configuration:**
  * Click `Save` to save the provisioning configuration in the Azure Admin portal.

<figure><img src="/files/QwvvW64SaJGBox6NYDQv" alt=""><figcaption></figcaption></figure>

* **Configure User Attributes:**
  * On the same page, scroll down to find “Provision Azure Active Directory Users”.
  * Click on the attribute with `externalId`.
  * Change the value from `mailNickname` to `objectId`.
  * Ensure the attributes are mapped correctly
  * Save the attributes

<figure><img src="/files/8JrrSSUoOAurBKARzd98" alt=""><figcaption></figcaption></figure>

* **Return to FenixPyre Portal:**
  * Go back to the FenixPyre portal and click on “Continue to Next Step”.
* **Verify and Continue:**
  * Verify the details on the page and click on “Continue to Next Step” again.
* **Start Sync:**
  * Click on “Start Sync” to begin the synchronization process.<br>

<figure><img src="/files/a8BUfgT4ORRbLCti5NYz" alt=""><figcaption></figcaption></figure>

* **Add Users in Azure:**
  * In the Azure portal, go to the "Users and Groups" tab.
  * Click on `Add User`.
  * Select `None Selected`.

<figure><img src="/files/VBTWE2BL9I5tOGyhkvnL" alt=""><figcaption></figcaption></figure>

* Choose the users/groups to be added to the application.

<figure><img src="/files/smwOksN4x2D9LOA855wL" alt=""><figcaption></figcaption></figure>

* Click on the "Provision on Demand" tab.
* Select your user/group and click `Provision`.

<figure><img src="/files/AwzyDmg5l7Pcboe6KjSf" alt=""><figcaption></figcaption></figure>

* **Verify Success:**
  * The success screen should be visible on the FenixPyre dashboard.
  * You will also see SCIM marked as active in the SCIM tab.

<figure><img src="/files/VMRrpwm89LMtwOZaVyIo" alt=""><figcaption></figcaption></figure>


# How to provision a user

#### Assigning Users and Groups in Azure for SSO

1. **Log in to Azure Portal:**
   * Access the Azure portal and log in with your credentials.
2. **Navigate to Enterprise Applications:**
   * Go to the `Enterprise Applications` section.
3. **Select the SSO Application:**
   * Navigate to the application you have configured for Single Sign-On (SSO).
4. **Assign Users and Groups:**
   * Click on `Assign users and groups`.

![Screenshot 2024-07-22 at 6.26.02 PM.png](/files/6xBYKMv8a07zdRpAEJnv)

5. **Add Users or Groups:**
   * Click on the `+` sign at the top of the page to add users or groups.

![Screenshot 2024-07-22 at 6.27.04 PM.png](/files/H0RXauHVkZ0K0uAQIyMO)

**Note**: Even if you assign a group to the SAML application, all users in that group will be added to FenixPyre.

By following these steps, you can efficiently provision users to FenixPyre through your Azure portal.


# How to de-provision a user?

#### Methods for De-Provisioning a User

There are three ways to de-provision a user in FenixPyre:

1. **Remove the User from the Application:**
   * Directly remove the user from the FenixPyre application.
2. **Remove or Deactivate the User in SSO:**
   * Remove or deactivate the user in your Single Sign-On (SSO) system.
3. **Remove the User from the Group:**
   * Remove the user from the group that is assigned to the FenixPyre SAML app.


# Known limitations

**Microsoft Event Delay:** There may be a 40-minute delay for Microsoft events to reflect change


# Set-up SCIM for OKTA

### **Pre-requisites**

* Admin access to FenixPyre admin dashboard
* SAML SSO is already setup on FenixPyre dashboard
* Admin access to Okta portal

**Note**- During set up, your identity provider will ask for an API token created through the OAuth 2.0 flow.

### Configuration

Follow these steps to configure SCIM in your FenixPyre dashboard and ensure seamless user management:

* Sign-in to FenixPyre dashboard: [https://admin.anchormydata.com](https://admin.anchormydata.com/)
* Open **Settings** -> **Security** -> **Identity & Provisioning** -> **SCIM** tab.
* FenixPyre's SCIM is powered by [WorkOS](https://workos.com/). Click on **Setup SCIM** button to redirect to WorkOS setup page.

<figure><img src="/files/1bFjZvhWb8JNbjWcKO3m" alt=""><figcaption></figcaption></figure>

* On the WorkOS setup page, select **Okta**.

<figure><img src="/files/IHvLHcDqWydiSPXMZNEk" alt=""><figcaption></figcaption></figure>

Note

Do not follow the steps in **Configure Directory Sync** page as it is a outdated. Please follow the steps in this page.

* Sign-in to your Okta admin portal and open the SAML SSO application you created as part of [Okta SAML SSO setup](https://docs.anchormydata.com/fenixpyre/docs/getting-started-okta-sso).

<figure><img src="/files/suYT8GxcR9SGdhjePOhY" alt=""><figcaption></figcaption></figure>

* In the **General** tab **Edit** the App Settings
* In the **Provisioning** section select **SCIM** and click on **Save**.

<figure><img src="/files/4XwXjbxlZfI2ViLOho8Z" alt=""><figcaption></figcaption></figure>

* A new Tab should be visible by the name of “Provisioning”

<figure><img src="/files/qqda86dsMS93WLNMnQgt" alt=""><figcaption></figcaption></figure>

* Navigate back to **FenixPyre Dashboard**
* Copy the Endpoint and bearer token value from the FenixPyre dashboard.

<figure><img src="/files/3XIkjTiq9VbkW3RGesyW" alt=""><figcaption></figcaption></figure>

* In the Okta Admin portal, navigate to Provisioning -> Integrations.
* Paste the copied endpoint value into the **SCIM Connector Base URL** textbox

<figure><img src="/files/jQtufbUILTyfyd6PsmPW" alt=""><figcaption></figcaption></figure>

* Paste the copied bearer token value into the **Authorization** textbox.
* Select the below checkboxes in Supported provisining actions column
* Import New Users and Profile Updates
* Push New Users
* Push Profile Updates
* Push Groups

<figure><img src="/files/iQWprRlzBzgEU7XfdelB" alt=""><figcaption></figcaption></figure>

### Test the connector configurations

* Click on Test Connector Configuration.
* If everything is working properly, you should see a success screen confirming the configuration is correct.
* Save the changes

<figure><img src="/files/enuSpbY9WgKLNimARs1X" alt=""><figcaption></figcaption></figure>

* Edit the app and enable below options in the Provisionining tab and save the changes again

<figure><img src="/files/rRfdtEQSy9O2T6rF1QHd" alt=""><figcaption></figcaption></figure>

* Return to the FenixPyre Dashboard and click on "**Continue to Next Step**".

<figure><img src="/files/TCPYmMfzSVXliNryXuoX" alt=""><figcaption></figcaption></figure>

* In the "**Assign People and Groups to Okta Application**" tab, click on "Continue to Next Step" again.

<figure><img src="/files/8pt4sbwQo3PgpTJRfxcs" alt=""><figcaption></figcaption></figure>

* In the "**Push Groups**" tab, click on "Continue to Next Step" again.

<figure><img src="/files/7ilA8GQqruNGKJSo2NK1" alt=""><figcaption></figcaption></figure>

* In the "**Test directory connection"** tab , test the connection and make sure you get a success message
* Navigate back to FenixPyre Dashboard and verify that you have Okta configured successfully with **Active** status as below

<figure><img src="/files/mSCAbN0mEBsDbMT7UhT3" alt=""><figcaption></figcaption></figure>


# How to provision a user?

Below are are the steps to provision a user

1. **Log in to Okta Portal:**
   * Access your organization's Okta portal and log in with your credentials.
2. **Navigate to Applications:**
   * Go to the `Applications` section.
   * Select the `Applications` submenu.
3. **Assign Users:**
   * Click on the down arrow icon next to the FenixPyre SAML app.
   * Select "Assign to Users."
4. **Assign Users to FenixPyre:**
   * Assign the desired users to the FenixPyre SAML app.
   * The same users will be automatically added to FenixPyre.

<figure><img src="/files/wP2TpLKZJxiDqQVaiuUi" alt=""><figcaption></figcaption></figure>

**Note**: Even if you assign a group to the SAML application, all users in that group will be added to FenixPyre.

By following these steps, you can efficiently provision users to FenixPyre through your Okta portal.


# How to de-provision a user?

There are three ways to de-provision a user in FenixPyre:

**Remove the User from the Application:**

1. **Log in to Okta Portal:**
   * Access your organization's Okta portal and log in with your credentials.
2. **Navigate to Applications:**
   * Go to the `Applications` section.
   * Select the `Applications` submenu.
3. **Select the FenixPyre SAML Application:**
   * Click on the SAML application for FenixPyre.
4. **Remove User Assignment:**

   * Navigate to the `Assignments` tab.
   * Remove the user from the assignments by click on `x` icon.

   <figure><img src="/files/dtT1xk5jzkFTZQFh5JbO" alt=""><figcaption></figcaption></figure>

   The same user will be deactivated in FenixPyre.

**Remove or Deactivate the User in SSO**

* If you deactivate the user in your Okta user directory, the same user will be deactivated in FenixPyre.

**Remove the User from the Group**

* Remove the user from the group that is assigned to the FenixPyre SAML app.

By following these steps, you can effectively de-provision users from FenixPyre through your Okta portal.


# Known limitations

* **Re-provisioning Users:** After initial setup and user provisioning, if the admin changes the SCIM configuration to set up provisioning again, the option to provision old users will not be displayed. The admin must remove and re-add all users to provision them again.

<figure><img src="/files/pwS4acpMjql8o53hhMMB" alt=""><figcaption></figcaption></figure>

* **Event Limitations:** When a user is suspended or deleted, no event is sent. Only the deactivate action triggers an event.
* **SCIM Settings Changes in Okta:** If the admin or a user makes any changes to the SCIM settings in Okta and events stop being received, there is no way for us to detect this issue.


# What happens when a user is de-provisioned?

When a user is de-provisioned:

* **Access to FenixShare:** The user will no longer be able to log in to FenixShare.
* **Access to FenixPyre Dashboard:** The user will be unable to access the FenixPyre Dashboard.
* **User Status:** The user's status will be updated to `Deactivated` in FenixPyre.


# Known Limitations

Below are the common mistakes and limitations of configuring SCIM with FenixPyre

* **Provisioning Requirement:** While setting up SCIM, if the admin does not provision a user, they will be unable to change the SCIM provider until a user is provisioned.
* **User Redirection:** Users will be redirected to the WorkOS URLs for authentication and setup.
* **Microsoft Event Delay:** There may be a 40-minute delay for Microsoft events to reflect changes.
* **User Visibility:** Users will not appear in the list of provisioned users in the dashboard unless the admin clicks "Edit" in the dashboard.


# Key management

Effective **Key Management** is essential for ensuring the security and integrity of your data within FenixPyre. FenixPyre utilizes a hierarchical encryption approach where files are encrypted using unique **Encryption Keys**, and these encryption keys are subsequently encrypted with **Master Encryption Keys**. The encrypted encryption keys are securely stored in the database, adding an extra layer of protection and simplifying key lifecycle management.

#### How It Works

1. **File Encryption:**
   * When you upload a file to FenixPyre, it is encrypted using a unique **Encryption Key**. This ensures that each file has its own distinct layer of security.
2. **Encryption Key Protection:**
   * Each **Encryption Key** is encrypted using a **Master Encryption Key**. This means that even if an encryption key is compromised, the master key adds an additional layer of security, safeguarding your data against unauthorized access.
3. **Secure Storage:**
   * The encrypted encryption keys are stored in the database, ensuring they are protected and accessible only through authorized processes and personnel.

#### Key Components

1. **Master Encryption Keys**
   * **Function:** Serve as the primary keys that encrypt and protect subordinate encryption keys.
   * **Storage:** Stored securely using Hardware Security Modules (HSMs) or integrated with cloud-based key management services such as Azure HSM and Google Cloud HSM.
2. **Encryption Keys**
   * **Function:** Used to encrypt and decrypt individual files within FenixPyre.
   * **Protection:** Each encryption key is encrypted with a master encryption key before being stored in the database.
3. **Hardware Security Modules (HSMs)**
   * **Function:** Provide a tamper-resistant environment for storing and managing cryptographic keys.
   * **Integration:** FenixPyre integrates with leading HSM providers like Azure HSM and Google Cloud HSM to ensure keys are stored securely and operations are performed within a protected hardware environment.

#### Importance of Key Management

* **Data Security:** Ensures that both your files and the keys that encrypt them are protected against unauthorized access and breaches.
* **Compliance:** Helps your organization adhere to regulatory requirements and industry standards (e.g., GDPR, HIPAA, PCI-DSS) by maintaining robust key management practices.
* **Operational Efficiency:** Streamlines the encryption process, reducing the complexity and overhead associated with managing multiple keys.

#### Key Management in FenixPyre

FenixPyre offers a comprehensive key management solution that integrates seamlessly with leading Key Management Services (KMS) and Hardware Security Modules (HSMs).


# Encryption Key Providers

Encryption Key Providers facilitate importing keys from your Hardware Security Module. Once added, they allow easy key imports.


# Setup Your Own Encryption Key Provider with Azure


# Setup Your Own Encryption Key Provider with Google


# Master Encryption Keys

**In encryption**, a master key is a key that can decrypt multiple sets of encrypted data or manage other keys. It is a critical component in key management systems and plays a significant role in ensuring data security and access control.\
\
FenixPyre offers three different methods to create your Master Key, giving you flexibility based on your security requirements and preferences. Choose the option that best fits your organization’s needs:

{% content-ref url="/pages/Wx72m9SDEBnJMwNReODP" %}
[Create Master Encryption Key with FenixPyre](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/create-master-encryption-key-with-fenixpyre)
{% endcontent-ref %}

{% content-ref url="/pages/kplPBzuWXHTPNvarzeLk" %}
[Setup Bring Your Own Master Encryption Key (BYOMEK) with Azure](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-azure)
{% endcontent-ref %}

{% content-ref url="/pages/8pce5OQj1bNfuqrvu0vW" %}
[Setup Bring Your Own Master Encryption Key (BYOMEK) with Google HSM](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-google-hsm)
{% endcontent-ref %}

#### Master Key Creation Options and Prerequisites

FenixPyre offers three methods to create your master key:

**Create Your Own Master Key with FenixPyre:**

* Generate your master key and store it in the FenixPyre-managed HSM (Encryption Key Provider).
* To create your master key with FenixPyre, you only need to have access to the FenixPyre dashboard. This is the most convenient option and is recommended for small enterprises.

**Google HSM:**

* Import your existing master key from Google’s Hardware Security Module (HSM).
* To create a master key from Google's Hardware Security Module, you need to have a vault (key ring) created with FenixPyre and a key created in the same vault.

**Azure HSM:**

* Import your existing master key from Azure’s Hardware Security Module (HSM).
* To create a master key from Azure's Hardware Security Module, you need to have a vault created with FenixPyre and a key created in the same vault.


# Create Master Encryption Key with FenixPyre

### Setting up Master Encryption Key with FenixPyre

{% hint style="info" %}
Watch video tutorial [here](#video-tutorial)
{% endhint %}

{% stepper %}
{% step %}

#### **Log in to the FenixPyre Dashboard**

Access the FenixPyre Dashboard using your credentials.
{% endstep %}

{% step %}

#### **Navigate to Key Management**

Go to `Security` → `Key Management`.
{% endstep %}

{% step %}
**Create a Master Encryption Key**

To add a new master encryption key, first click on `Master Encryption Keys`, then click on \`Add new master encryption key

<figure><img src="/files/4JjYQ06PM5i8r7Q2Dbrz" alt="" width="375"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Select `FenixPyre` from the options**

<figure><img src="/files/3SWcOVqHNB6sNGDMYlG3" alt="" width="375"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Enter Key Details and Create the Key:**

To proceed, click on `Create Key` and assign a name to your key

<figure><img src="/files/rIt4neLCOYC2RM6WwqBE" alt="" width="375"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Success Confirmation**

You will receive a success message confirming the key import.

<figure><img src="/files/qOBaBA2uDbDgKPGcCExr" alt="" width="375"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Copy and Download the Master Key**

Make sure to copy the master key and securely download it for safekeeping. Please provide the key on the next page for verification.

{% hint style="info" %}
**Important:** FenixPyre does not store the decrypted version of the master key. Please ensure you securely store the key, as it is essential for decrypting your data in the future.
{% endhint %}
{% endstep %}

{% step %}

#### Key Verification

Enter the key in the final step for verification to complete the master key creation process.

<figure><img src="/files/jwLUOtKfX9wNqPqVE7wt" alt="" width="375"><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

### Video Tutorial

{% embed url="<https://www.loom.com/embed/d83ce32b2dad4b08b99cb67bfeccec60?sid=de6e754a-51a7-4393-a72f-85768fe063d6>" %}


# Setup Bring Your Own Master Encryption Key (BYOMEK) with Azure

{% content-ref url="/pages/F4Jhf65J19IldWtnLxw9" %}
[Configure Azure Key Vault as Bring Your Own Key Provider](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-azure/configure-azure-key-vault-as-bring-your-own-key-provider)
{% endcontent-ref %}

{% content-ref url="/pages/53vdc7pHvRZ8nfmkKMk6" %}
[Create a Master Encryption Key and Store in Azure Key Vault](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-azure/create-a-master-encryption-key-and-store-in-azure-key-vault)
{% endcontent-ref %}


# Configure Azure Key Vault as Bring Your Own Key Provider

{% hint style="info" %}
Watch the video tutorial [here](#video-tutorial)
{% endhint %}

### Prerequisites

* **Azure Administrative Access:**\
  Confirm that you have administrative access to Microsoft Azure and that the Azure CLI is installed on your system.
* **FenixPyre Portal Administrative Access:**\
  Verify that you have administrative access to the FenixPyre portal to configure encryption key provider settings.

***

### Steps to Set Up Azure Key Vault Managed HSM for FenixPyre

{% stepper %}
{% step %}

#### **Create an Azure Key Vault Managed HSM**

Azure Key Vault Managed HSM (Hardware Security Module) is a fully managed, single-tenant, highly available, and standards-compliant cloud service that safeguards cryptographic keys using FIPS 140-2 Level 3 validated HSMs.

1. Navigate to the Home page on the Azure portal.
2. Select **Azure Key Vault Managed HSMs** from the menu.
3. Click on **Create** to start setting up your HSM.

<figure><img src="/files/E6QQOhyX10WgNfHWIK3a" alt=""><figcaption></figcaption></figure>

4. Choose the ideal region for your organization, such as **East US**.\
   Assign a descriptive name to your HSM. Under **Subscription**, select **Pay As You Go**.

<figure><img src="/files/PuCE5S61rP1IyGPJ8CDz" alt=""><figcaption></figcaption></figure>

5. Assign an administrator to manage the HSM.
6. Click **Create** to complete the setup process.
7. Verify that the provisioning status shows **Succeeded**, indicating the HSM was created successfully.

{% hint style="info" %}
**Important Note:** Consider selecting **Disable purge protection** for flexibility during the retention period.
{% endhint %}
{% endstep %}

{% step %}
**Activate Azure Key Vault Managed HSM**

Before using the HSM, activation is required. During activation, data plane commands (e.g., creating keys or assigning roles) are disabled. Only administrators assigned during HSM creation can perform activation.

**Generate RSA Key-Pairs:**

* You need to generate at least three (up to ten) RSA key-pairs. The minimum number required to decrypt the security domain is known as a quorum.

**Generate RSA Key-Pairs Using OpenSSL:** Run the following commands to create three self-signed certificates:

```bash
openssl req -newkey rsa:2048 -nodes -keyout cert_0.key -x509 -days 365 -out cert_0.cer
openssl req -newkey rsa:2048 -nodes -keyout cert_1.key -x509 -days 365 -out cert_1.cer
openssl req -newkey rsa:2048 -nodes -keyout cert_2.key -x509 -days 365 -out cert_2.cer
```

**Download the Security Domain:** Use the RSA public keys to download the security domain:

```bash
az keyvault security-domain download --hsm-name ContosoMHSM --sd-wrapping-keys ./certs/cert_0.cer ./certs/cert_1.cer ./certs/cert_2.cer --sd-quorum 2 --security-domain-file ContosoMHSM-SD.json
```

**Complete Activation:**

* Once the command executes successfully, your HSM will activate.
* Allow a few minutes for activation to complete.

**Important:** Store the RSA key pairs and the security domain file securely for future use, such as disaster recovery or setting up another HSM sharing the same security domain.
{% endstep %}

{% step %}
**Register an Application in Azure for FenixPyre**

1. **Log in to the Azure Portal:** Access the Azure portal and sign in.
2. **Navigate to Microsoft Entra ID:** Select **Microsoft Entra ID** from the menu.
3. **Open App Registrations:** Click **+ Add** and then select **App Registration.**

<figure><img src="/files/5Mxvz6AIoqt7aDQ041F2" alt=""><figcaption></figcaption></figure>

4. **Register a New App:** Provide a name for your app and click **Create** to register it.

<figure><img src="/files/S5FL5v6rl96CG2nieEvB" alt=""><figcaption></figcaption></figure>

5. **Create a client secret**
   * In the app settings, navigate to **Certificates & Secrets**.
   * Click **+ New Client Secret**, provide a description, and click **Add**.
   * Copy and store the client secret securely as it will only be shown once.

<figure><img src="/files/oomVTITUSkghUyzAmelQ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Configure Role-Based Access Control (RBAC) for Azure Key Vault Managed HSM**

1. **Access Managed HSM:** In the Azure portal, open the HSM you created.
2. **Open the RBAC Tab:** Select the **RBAC** tab.

<figure><img src="/files/pvWwJXpdExNANXAxDXsU" alt=""><figcaption></figcaption></figure>

3. **Create Local RBAC:** Click the **+** icon to create a new role assignment. Select **Managed HSM Crypto User** under **Roles** and **All keys** under **Scope**.

<figure><img src="/files/fngOOov5AphKYfDjkE4J" alt=""><figcaption></figcaption></figure>

4. **Select Security Principal:** Click **Select Security Principal** and choose **Enterprise Applications**. Then, select your previously registered app.
5. **Finalize RBAC Setup:** Complete the role assignment process to grant the appropriate permissions to the app.
   {% endstep %}

{% step %}
**Finalize the Encryption Key Provider Setup in FenixPyre**

1. **Assign a Vault Name:** In the FenixPyre portal, provide a unique and descriptive name for your vault.

<figure><img src="/files/bpPJBVaAz6IE5y01deb3" alt=""><figcaption></figcaption></figure>

2. **Copy HSM URI:** Copy the HSM URI from the Azure HSM overview page.

<figure><img src="/files/9ku24ehLDrX1Y8mbPlvl" alt=""><figcaption></figcaption></figure>

3. **Copy Client ID and Tenant ID:** Retrieve the **Client ID** and **Tenant ID** from your registered app.

<figure><img src="/files/B9NxsdO4gzywWeOSAXyD" alt=""><figcaption></figcaption></figure>

4. **Use Client Secret:** Use the client secret you copied earlier.
5. **Verify and Finalize Setup in FenixPyre:** In the FenixPyre dashboard, paste the HSM URI, Client ID, Tenant ID, and Client Secret. Click **Verify**, then **Create** to finalize the setup.
   {% endstep %}
   {% endstepper %}

By following these steps, you will have successfully set up and integrated Azure Key Vault Managed HSM with FenixPyre.

## Video Tutorial

{% embed url="<https://www.loom.com/embed/06fd5035a2fd444eb67f73491d0df7ae?sid=77c2139f-67b9-4757-8c40-f1428bc97ef7>" %}


# Create a Master Encryption Key and Store in Azure Key Vault

Prerequisites

Before continuing, make sure you've completed the steps in the guide to set up an Azure Managed HSM:\
[Step-by-Step Guide for Setting Up an Encryption Key Provider with Azure](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-azure/configure-azure-key-vault-as-bring-your-own-key-provider)

### Setting up Master Encryption Key with Azure

{% hint style="info" %}
Watch video tutorial [here](#video-tutorial)
{% endhint %}

{% stepper %}
{% step %}
**Log in to the FenixPyre Dashboard**

Use your credentials to access the FenixPyre Dashboard.
{% endstep %}

{% step %}

#### Navigate to Key Management

Go to `Security` → `Key Management`.
{% endstep %}

{% step %}

#### Create a Master Encryption Key

Select `Master Encryption Keys` tab and click on `Add New Master Encryption Key.`
{% endstep %}

{% step %}

#### Select Microsoft Azure from the Key Provider options

<figure><img src="/files/3SWcOVqHNB6sNGDMYlG3" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Select the key provider

From the dropdown, select the Azure Key Provider you have setup.

{% hint style="info" %}
Make sure you have a Azure Key Vault setup as a Key Provider on FenixPyre. [Read more](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-azure/configure-azure-key-vault-as-bring-your-own-key-provider)
{% endhint %}
{% endstep %}

{% step %}

#### Enter the key details and create the key

* Provide a name for your key.
* Click `Create Key` to proceed.
  {% endstep %}

{% step %}
**Success Confirmation**

A confirmation message will appear indicating successful key creation.

<figure><img src="/files/qOBaBA2uDbDgKPGcCExr" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Copy and Download the Master Key**

* Copy the master key and download it for safekeeping.
* Enter the key on the next page for verification.

{% hint style="warning" %}
**Important:** FenixPyre does not store the decrypted version of the master key. Please ensure you securely store the key, as it is essential for decrypting your data in the future.
{% endhint %}
{% endstep %}

{% step %}

#### Key Verification

Enter the key in the final step for verification to complete the master key creation process.

<figure><img src="/files/jwLUOtKfX9wNqPqVE7wt" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

### Video Tutorial

{% embed url="<https://www.loom.com/embed/b7edcb1bc29847c69871b752be6b593a?sid=cbe546dd-ee0a-49e4-82d3-3d0e9ea2d427>" %}


# Setup Bring Your Own Master Encryption Key (BYOMEK) with Google HSM

{% content-ref url="/pages/JEv0246W1YETIS39TrdR" %}
[Configure Google HSM as Bring Your Own Key Provider](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-google-hsm/configure-google-hsm-as-bring-your-own-key-provider)
{% endcontent-ref %}

{% content-ref url="/pages/d3rJOrALSzLXSN4DIkUI" %}
[Create a Master Encryption Key and Store in Google HSM](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-google-hsm/create-a-master-encryption-key-and-store-in-google-hsm)
{% endcontent-ref %}

{% content-ref url="/pages/NAi6p1C4PfgFYBil7dej" %}
[Import a master encryption key from Google HSM to FenixPyre](/fenixpyre-for-admins/admin-dashboard/key-management/master-encryption-keys/setup-bring-your-own-master-encryption-key-byomek-with-google-hsm/import-a-master-encryption-key-from-google-hsm-to-fenixpyre)
{% endcontent-ref %}


# Configure Google HSM as Bring Your Own Key Provider

### Setting Up Encryption Key Provider in FenixPyre

> Watch video tutorial [here](#video-tutorial)

***

#### Prerequisites

* **Admin Access in GCP:**\
  Ensure you have administrative access to Google Cloud Platform (GCP).
* **Admin Access to FenixPyre Portal:**\
  Ensure you have administrative access to the FenixPyre portal to configure the encryption key provider settings.

***

#### Setup Process

**1. Create or Access a Key Ring**

* Follow [Google’s documentation](https://cloud.google.com/kms/docs/create-key-ring?hl=en) to create a key ring or navigate to an existing one.

**2. Copy Resource Name**

* Click on the vertical ellipsis (⋮) next to the key ring and select **Copy Resource Name**.\ <br>

  <figure><img src="/files/dqc7YTwdYzOWjLJ5D7aW" alt=""><figcaption></figcaption></figure>

**3. Update Resource Name in FenixPyre Dashboard**

* Log in to the FenixPyre Dashboard.
* Navigate to **Settings → Security → Key Management → Encryption Key Provider**.
* Paste the resource name into the **KeyRing Resource Name** field.
* Add a vault name for identification in the **Vault Name** text box.

**4. Create a Role in GCP Console**

* Navigate back to the GCP console.
* Go to **IAM → Roles**.
* Follow [Google's documentation](https://cloud.google.com/iam/docs/creating-custom-roles) to create a new role.
* Create a new role with the following permissions:
  * `cloudkms.cryptoKeyVersions.create`
  * `cloudkms.cryptoKeyVersions.get`
  * `cloudkms.cryptoKeyVersions.useToDecrypt`
  * `cloudkms.cryptoKeyVersions.useToEncrypt`
  * `cloudkms.cryptoKeyVersions.useToSign`
  * `cloudkms.cryptoKeyVersions.useToVerify`
  * `cloudkms.cryptoKeyVersions.viewPublicKey`
  * `cloudkms.cryptoKeys.create`
  * `cloudkms.cryptoKeys.get`
  * `cloudkms.cryptoKeys.update`
  * `cloudkms.importJobs.create`
  * `cloudkms.importJobs.get`
  * `cloudkms.importJobs.useToImport`
  * `cloudkms.keyRings.create`
  * `cloudkms.keyRings.get`
  * `cloudkms.keyRings.list`
  * `cloudkms.locations.get`

**5. Create a Service Account**

* Navigate to the **Service Accounts** tab.
* Give your service account a name and click **Create and Continue**.
* In the roles field, select the role you just created.
* Click **Done**.
* A new service account will be created.\ <br>

  <figure><img src="/files/YMGCW5kz11C9mXQD6TyH" alt=""><figcaption></figcaption></figure>

**6. Generate and Download the Encryption Key**

* Select the service account you created in the previous step.
* Go to the **Keys** tab and click on **Add Key**.
* Choose **Create a Key**.
* Select **JSON** and click **Create**.
* A JSON file will be downloaded containing your encryption key.

**7. Create Encryption Key Provider in FenixPyre**

* Navigate back to the FenixPyre Dashboard.
* Use the downloaded JSON file to create your own encryption key provider with GCP in FenixPyre by following the on-screen instructions for uploading or configuring the key.

***

## Video Tutorial

{% embed url="<https://www.loom.com/embed/ef6ba67407f947f2aa38294d23801189?sid=7639055d-78cd-4b51-b4a3-4a2362ffb6bd>" %}


# Create a Master Encryption Key and Store in Google HSM

### Prerequisites

Follow the steps in this document to create a vault in Google Cloud Platform (GCP).

### Setting up Master Encryption Key with Google

> Watch video tutorial [here](#video-tutorial)

#### There are two ways to create a master key for FenixPyre encryption with GCP:

* Create a master key in the FenixPyre Dashboard
* Import the master key

**Creating and Managing a Master Key in FenixPyre Using Google Cloud**

1. **Log in to the FenixPyre Dashboard:**
   * Access the FenixPyre Dashboard with your credentials.
2. **Navigate to Key Management:**
   * Go to `Settings` → `Security` → `Key Management`.
3. **Create a Master Encryption Key:**
   * Click on `Master Encryption Keys`.
   * Click on `Add new master encryption key`.\ <br>

     <figure><img src="/files/4JjYQ06PM5i8r7Q2Dbrz" alt=""><figcaption></figcaption></figure>
4. **Select Google Cloud from the options:**<br>

   <figure><img src="/files/3SWcOVqHNB6sNGDMYlG3" alt=""><figcaption></figcaption></figure>
5. **Enter Key Details and Create the Key:**
   * Provide a name for your key.
   * Click `Create Key` to proceed.<br>

     <figure><img src="/files/rIt4neLCOYC2RM6WwqBE" alt=""><figcaption></figcaption></figure>
6. **Success Confirmation:**
   * A confirmation message will appear indicating successful key creation.\
     ![](/files/qOBaBA2uDbDgKPGcCExr)
7. **Copy and Download the Master Key:**

   * Copy the master key and download it for safekeeping.
   * Enter the key on the next page for verification.

   **Important:** FenixPyre does not store the decrypted version of the master key. Please ensure you securely store the key, as it is essential for decrypting your data in the future.
8. **Key Verification:**
   * Enter the key in the final step for verification to complete the master key creation process.\ <br>

     <figure><img src="/files/jwLUOtKfX9wNqPqVE7wt" alt=""><figcaption></figcaption></figure>

***

## Video Tutorial

{% embed url="<https://www.loom.com/embed/ef6ba67407f947f2aa38294d23801189?sid=75c99dad-1bd0-4aec-8c59-2c6345d41847>" %}


# Import a master encryption key from Google HSM to FenixPyre

Creating a Key in GCP for FenixPyre

**Navigate to Key Ring in GCP Console:**

* Access the Google Cloud Platform console and navigate to your key ring.

**Create a New Key:**

* Click on **Create Key**.<br>

  <figure><img src="/files/hLcQE9uRTZVS2UgeYHBi" alt=""><figcaption></figcaption></figure>

**Configure Key Details:**

* In the **Name** field, enter a name for your new key.
* For the protection level, select the **HSM** radio button.
* Click on **Continue**.\ <br>

  <figure><img src="/files/tKCk0Wgeji3UmQPXUrdA" alt=""><figcaption></figcaption></figure>

**Select Key Type and Purpose:**

* Choose **HSM-Generated-Key**.
* For Purpose and Algorithm, select **Symmetric encrypt decrypt**.

**Complete Key Creation:**

* Click on **Continue**, then click on **Create**.
* You will now see the new key created in HSM.

#### Importing a Master Key in FenixPyre Using Google Cloud

1. **Access the FenixPyre Dashboard:**
   * Log in to your FenixPyre Dashboard with your administrative credentials.
2. **Add a New Master Encryption Key:**
   * Navigate to **Key Management**.
   * Click on **Add New Master Encryption Key**.
3. **Select the Appropriate Vault:**
   * Choose the vault where your encryption key was created from the dropdown menu.
4. **Specify the Key Name:**
   * Enter the name of the key you wish to use.
5. **Import the Key:**
   * Click on **Import a Key**.
   * Enter the same key name that you specified when creating the key in the key ring.
   * Ensure that the key was created in the same vault selected in step 3.
   * Click on **Import** to finalize the key import process.

**Note:** It is crucial to ensure that the key name and vault match the details from the creation process to successfully import the key.

***


# User Policies

Manage user permissions, applications and other FenixPyre settings you want to enforce within your organization.

## What is a User Policy?

User policies are essential guidelines for managing permissions and access controls within an organization, making it easier to manage specific users or groups. They are crucial for defining access rules, permissions, and specifying applications that can access encrypted files through FenixPyre. A user policy generally includes two main components:

{% stepper %}
{% step %}

### Policy Rules

A policy may include multiple rules, such as user permissions, application controls, and endpoint settings.

{% hint style="info" %}
Read more about [Policy Rules](/fenixpyre-for-admins/admin-dashboard/user-policies/policy-rules-guide)
{% endhint %}
{% endstep %}

{% step %}

### Users and Groups

A policy can be assigned to one or more users or groups. Without any users, the policy remains in a **DRAFT** state. Once a user is added, the policy moves to a **PUBLISHED** state.
{% endstep %}
{% endstepper %}

## Default Policy

Upon onboarding to FenixPyre, a default policy is automatically generated. This policy is applied to all users within your organization. It includes default values for all rules and settings. If you wish to streamline permission settings for your entire organization, you can modify the default policy, which will subsequently apply to all users.

## **Custom Policies**

Organizations can create numerous custom policies to tailor permissions by team. For instance, an "HR Policy" can restrict file-sharing capabilities for the HR team, while an "IT Policy" might offer extensive permissions aligned with their responsibilities. Custom policies are specifically designed to override default settings to meet organizational needs more effectively.

This structured approach aids in managing permissions systematically, ensuring each group only has access to the resources necessary for their functions.

#### Policy Ranking and Conflict Resolution

When a user is subject to multiple policies, a ranking system is employed to determine which rules take precedence. Policies are prioritized based on their rank; in the event of conflicting rules, the setting from the highest-ranking policy is used.

**Protected Folders**

For protected folders, all folders specified across policies are combined and incorporated into the final user policy. This ensures comprehensive protection without losing individual policy settings.

## Configure a User Policy

{% tabs %}
{% tab title="Default Policy" %}

<figure><img src="/files/wyaS41SaiuAh9zs5bpAX" alt=""><figcaption><p>Modifying a Default Policy</p></figcaption></figure>

1. Visit User Policies tab
2. Click on Default Policy
3. Scroll through the rule on left sidebar
4. Modify the rule and click on Save
   {% endtab %}

{% tab title="Custom Policy" %}

<figure><img src="/files/XAHTGfBBA7x4xIwB4VHi" alt=""><figcaption><p>Configure Custom Policy</p></figcaption></figure>

1. Visit User Policy tab on dashboard.
2. Click on add a Custom Policy.
3. Search or scroll through the rule on left sidebar
4. Modify the rules required
5. Visit Users tab and select Users and Groups required
6. Save the User Policy
   {% endtab %}

{% tab title="Change Order" %}

<figure><img src="/files/aXZ4jWMZu5O89qPZjLxg" alt=""><figcaption><p>Changing Policy Rule</p></figcaption></figure>

1. Click on the selector next to a custom policy
2. Drag to the new position for the policy
3. Confirm the dialog box.
   {% endtab %}
   {% endtabs %}

## Policy Rules Guide

<table data-view="cards"><thead><tr><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td>Learn how to configure Protected Folders</td><td><a href="/files/CreCxTFBCEjK1Q8YfPP3">/files/CreCxTFBCEjK1Q8YfPP3</a></td><td><a href="/pages/jwkTtKkj2lymqahw2BIp#protected-folders">/pages/jwkTtKkj2lymqahw2BIp#protected-folders</a></td></tr><tr><td>Learn how to configure User Permissions</td><td><a href="/files/ki5FSLg0hdGnNa05z9A1">/files/ki5FSLg0hdGnNa05z9A1</a></td><td><a href="/pages/jwkTtKkj2lymqahw2BIp#user-permissions">/pages/jwkTtKkj2lymqahw2BIp#user-permissions</a></td></tr><tr><td>Learn how to manage User Applications</td><td><a href="/files/CzVFWENyXEao3ecUCpN3">/files/CzVFWENyXEao3ecUCpN3</a></td><td><a href="/pages/jwkTtKkj2lymqahw2BIp#user-applications">/pages/jwkTtKkj2lymqahw2BIp#user-applications</a></td></tr><tr><td>Learn how to manage Endpoint Settings</td><td><a href="/files/48tlLUBigA4Z5cThCUDl">/files/48tlLUBigA4Z5cThCUDl</a></td><td><a href="/pages/jwkTtKkj2lymqahw2BIp#endpoint-settings">/pages/jwkTtKkj2lymqahw2BIp#endpoint-settings</a></td></tr><tr><td>Learn about File Settings</td><td><a href="/files/fmKNXn3jCwbnoANUEUOo">/files/fmKNXn3jCwbnoANUEUOo</a></td><td><a href="/pages/jwkTtKkj2lymqahw2BIp#file-settings">/pages/jwkTtKkj2lymqahw2BIp#file-settings</a></td></tr><tr><td>Learn about Advanced Settings</td><td><a href="/files/EELYfPfB7lelvgDgBSMX">/files/EELYfPfB7lelvgDgBSMX</a></td><td><a href="/pages/jwkTtKkj2lymqahw2BIp#advanced-settings">/pages/jwkTtKkj2lymqahw2BIp#advanced-settings</a></td></tr></tbody></table>


# Policy Rules Guide

Explore this glossary to discover various rules that may be incorporated into a policy.

## Protected folders

<figure><img src="/files/Vtm5UKpGCt719D9CPVLv" alt=""><figcaption><p>Concept of Protected Folders</p></figcaption></figure>

Protected folders are fundamental in FenixPyre, defining specific folder locations accessible to designated users and groups. These folders allow users and groups within your organization to access and consume encrypted content using FenixPyre. Notably, encrypted files can only be accessed within these protected folders, whether via FenixPyre's Windows agent or cloud integrations. Examples of protected folder paths include common user directories, on-premises network drives, and cloud-based document sharing services.

### Supported Path Types

#### 1. Windows Local Paths

Local paths are used for protecting folders on users' Windows machines.

<figure><img src="/files/xXOqEemRNooIAFqZae9v" alt=""><figcaption></figcaption></figure>

**Syntax**

```
C:\Users\%username%\path\to\folder
```

**Key Features**

* Supports `%username%` variable for dynamic user paths
* Case-insensitive
* Backslashes (`\`) required as separators
* Drive letter (e.g., `C:`) must be specified

**Examples**

```
C:\Users\%username%\Desktop\Confidential
C:\Users\%username%\Documents\HR_Files
C:\Program Files\Company\Secure
```

**Best Practices**

* Use `%username%` for paths that should work across different user profiles
* Avoid spaces in folder names when possible
* Use consistent casing for better readability
* Verify the path exists before adding

#### 2. Network Paths

Network paths allow protection of shared folders on network drives. Supports UNC, DFS, and mapped drive paths.

<figure><img src="/files/0HULJhKpclv8zDP8iFyx" alt=""><figcaption></figcaption></figure>

**UNC Path Syntax**

```
\\server_name\share_name\folder_path
```

**DFS Path Syntax**

```
\\domain\dfs_root\folder_path
```

**Key Features**

* Double backslashes (`\\`) required at start
* Server/domain name must be specified
* Supports both IP addresses and hostnames

**Examples**

```
\\fileserver\shared\Finance
\\192.168.1.100\documents\Legal
\\domain.local\dfs\Department\HR
```

**Best Practices**

* Use UNC paths instead of mapped drives for reliability
* Verify network connectivity before adding
* Ensure proper network share permissions
* Consider using DFS for location independence

#### 3. SharePoint/OneDrive Paths

Cloud paths for protecting content in Microsoft 365 environments.

<figure><img src="/files/Gu1QcFcKXCFc1tZhnrhO" alt=""><figcaption></figcaption></figure>

**Syntax**

```
\\<sharepoint_domain>\sites\<site_name>\<folder_path>
```

**Features**

* Automatic conversion from web URLs
* Supports both SharePoint and OneDrive locations

**Examples**

```
\\company.sharepoint.com\sites\HR\Confidential
\\company-my.sharepoint.com\personal\user_company_com\Documents
```

**Automatic URL to Path Conversion**

Web URLs are automatically converted to the correct format. You can just paste any sharepoint/onedrive link and it will automatically be converted to the desired format:

```
https://company.sharepoint.com/sites/HR/Confidential
→ \\company.sharepoint.com\sites\HR\Confidential
```

#### 4. Egnyte Paths

For organizations using Egnyte cloud storage.

<figure><img src="/files/I3GTKQr6P0Zu3HmkoxyF" alt=""><figcaption></figcaption></figure>

**Syntax**

```
\\<domain>.egnyte.com\<folder_path>
```

**Examples**

```
\\company.egnyte.com\Shared\Finance
\\company.egnyte.com\Private\HR
```

#### 5. Box Paths

For organizations using Box cloud storage.

<figure><img src="/files/JdC3nrgFRrkraqmE5UCj" alt=""><figcaption></figcaption></figure>

**Syntax**

```
\\<enterprise ID>@app.box.com\<folder path>
```

**Examples**

```
\\1174000000@app.box.com\New Folder\test
\\1174000000@app.box.com\All Files\Shared\Lab Folders
```

## User Permissions

The following permission decide what type of actions can be performed by the user or group on FenixPyre.

<table><thead><tr><th width="128">Permission</th><th width="230">FenixPyre Windows Agent</th><th>FenixShare (SharePoint, OneDrive and other cloud integrations)</th></tr></thead><tbody><tr><td>Can Encrypt</td><td>This permission determines whether a user can encrypt files</td><td>This permission determines whether a user can encrypt files</td></tr><tr><td>Can Decrypt</td><td>This permission determines whether a user can decrypt files and remove protection.</td><td>This permission determines whether a user can decrypt files</td></tr><tr><td>Can Share</td><td>This permission determines whether you can share a file via outlook or right-click option via FenixShare.</td><td>The permission determines whether you can share a file from SharePoint, OneDrive, Egnyte or Box Drive using FenixShare.</td></tr><tr><td>Can View Audit Logs</td><td>This permission determines whether a user can view audit logs form the right-click option</td><td>Thiis permission determines whether a user can view audit logs .</td></tr><tr><td>Can Open</td><td>Rolling out soon</td><td>Rolling out soon</td></tr><tr><td>Can Edit</td><td>Rolling out soon</td><td>Rolling out soon</td></tr><tr><td>Can Add Protection</td><td>Rolling out soon</td><td>Rolling out soon</td></tr><tr><td>Can Delete</td><td>Rolling out soon</td><td>Rolling out soon</td></tr></tbody></table>

## User Applications

{% hint style="info" %}
All admin approved and FenixPyre approved applications are displayed on the policy page. [Learn how to add a new application](/fenixpyre-for-admins/admin-dashboard/user-applications)
{% endhint %}

With FenixPyre installed on Windows Desktops, you can control which applications can access encrypted files and how they do so.

<figure><img src="/files/ra7W3SpWXb2DKDjDIRk1" alt=""><figcaption><p>Enabling an application for a policy</p></figcaption></figure>

There are a number of configurations that you can manage for an application while adding them to a policy.

<figure><img src="/files/bv1RqX4fufOVQYi3FErZ" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}

#### Allow opening multiple protected files from different protected folders

This option is crucial for managing access to multiple protected files, offering users the flexibility to work with them concurrently across various protected folders. When enabled, it empowers the application to simultaneously open and save several protected files originating from distinct protected directories.
{% endstep %}

{% step %}

#### Enable opening files from non-protected folders

This option determines whether the application can open encrypted files stored outside of [protected folders](#protected-folders).
{% endstep %}

{% step %}

#### Enable application tot encrypt files outside protected folders

This option determines the application encrypts all the files saved irrespective of the folder it's saved to. This setting will be useful to enforce a stricter encryption policy and not worry about defining protected folders.
{% endstep %}

{% step %}

#### Enable compliance mode

Read this [article](/fenixpyre-features/compliance-mode) for more details
{% endstep %}

{% step %}

#### Enable real-time file block

Enable this option to have FenixPyre automatically close the application and files when access rules are violated or a user
{% endstep %}

{% step %}

#### Enable returning original file size

Enable this option to have FenixPyre return decrypted (original) file size or encrypted file size when applications request file information using the windows directory listing api call. Recommended value: Enabled
{% endstep %}

{% step %}

#### Prevent opening protected and unprotected files together

When this option is enabled, the users will not be able to open encrypted and non-encrypted files at the same time. This is to prevent accidental sharing of sensitive data
{% endstep %}
{% endstepper %}

## Endpoint Settings

### Automatic Encryption Service

Automatic encryption service is a windows endpoint feature that FenixPyre offers in which it encrypts any file that has been newly added to or created within an a protected folder.

**Managing Automatic Encryption Disruptions**

The suggested delay is 5,000 ms. We recommend keeping the delay value below 60,000 ms (or 1 minute).

Anchor's automatic encryption service may disrupt workflows by encrypting new files in protected folders immediately. This encryption can cause application conflicts, such as interrupting an SFTP file transfer, depending on how files are created in the folder. To address these issues, we have introduced a delay setting to allow more flexible handling of such cases.

{% hint style="info" %}
Limitations

* **Sequential Processing**: When adding multiple files to a protected folder, the encryption service processes each file one at a time. Each file is subject to a delay, regardless of any accumulated delay.
* **Placeholder Files**: The service does not encrypt placeholder files.
* **Active File Usage**: Files may not be encrypted if they are in use by another application or process.
* **Zero-byte Files**: Files with zero bytes are not encrypted.
  {% endhint %}

{% hint style="success" %}
Learn more about [Automatic Encryption Service](/fenixpyre-features/automatic-encryption-service)<br>

If you are looking for a solution for encryption files on cloud - SharePoint/OneDrive, Egnyte or Box we suggest you learn about Auto-Encryption on FenixShare
{% endhint %}

### Periodic Encryption Service

FenixPyre offers a Windows feature called the Periodic Encryption Service, which regularly scans protected folders and encrypts any unencrypted files. You can set the scan frequency between 30 minutes (recommended) and 1440 minutes (every 24 hours).

Recommended value: 30 mins

{% hint style="info" %}
Limitations

* Placeholder files in OneDrive or SharePoint folders will remain unencrypted.
* Network shared folders are excluded from scans, except for Egnyte Connected Folders.
  {% endhint %}

{% hint style="success" %}
Learn more about [Periodic Encryption Service](/fenixpyre-features/periodic-encryption-service)
{% endhint %}

### Automatic Decryption Service

The Automatic Decryption Service is a Windows endpoint feature that monitors a configured source directory for newly copied encrypted files, decrypts them automatically, and moves the decrypted output to a configured destination directory.

| Setting Name           | Default Value                                    | Description                                                                  |
| ---------------------- | ------------------------------------------------ | ---------------------------------------------------------------------------- |
| Enable auto-decryption | FALSE                                            | Whether the auto-decryption feature is currently enabled.                    |
| Expiration window      | 8 hours                                          | Hours after activation before the feature is automatically disabled.         |
| Source directory       | `C:\Users\%username%\OneDrive\Desktop\encrypted` | Absolute path to the folder monitored for new encrypted files.               |
| Destination directory  | `C:\Users\%username%\OneDrive\Desktop\decrypted` | Absolute path where decrypted files are moved.                               |
| Rescan interval        | 60 seconds                                       | Periodic rescan of the source directory as a fallback to folder monitoring.  |
| Destination retention  | 300 seconds                                      | Time-to-live for decrypted files in the destination before they are removed. |
| Max files per window   | 5 files                                          | Maximum number of files processed within the rate-limit window.              |
| Rate limit window      | 5 seconds                                        | Time window over which the rate limit is enforced.                           |

{% hint style="info" %}
The Automatic Decryption Service must be enabled by an administrator before it becomes active.
{% endhint %}

{% hint style="success" %}
Learn more about [Automatic Decryption Service](/fenixpyre-features/automatic-decryption-service)
{% endhint %}

### Offline Mode

Offline mode allows offline access to encrypted files, enabling users to work without an internet connection. Administrators can determine which users have offline access and set a time limit of up to 90 days. While an internet connection is typically needed for accessing Anchored files, offline mode balances offline functionality with maintaining control and protection of Fenixpyre encrypted files

Recommended period: 15 days

{% hint style="success" %}
Learn more about [Offline mode](/fenixpyre-features/offline-mode)
{% endhint %}

### **Allowed Extensions**

By default, any file whose extension is listed under *Allowed Extensions* is encrypted automatically by the Automatic Encryption Service and the Periodic Encryption Service on the FenixPyre Windows agent.

{% hint style="info" %}
If you want to change how applications encrypt files on your system, visit [User Applications.](/fenixpyre-for-admins/admin-dashboard/user-applications)
{% endhint %}

For FenixPyre cloud integrations, encrypting, decrypting, opening, and sharing files on [FenixShare](/fenixpyre-for-users/fenixpyre-sharing) is limited to these *Allowed Extensions*. This serves as a protective measure, ensuring only authorized users can access the encrypted files.

### Clipboard Protection

Clipboard Protection monitors clipboard activity and enforces granular control over cut, copy, paste, and Paste Special actions. It distinguishes between copy and paste operations and prevents content originating from a FenixPyre encrypted file from being pasted into an unencrypted destination. When content does not originate from a FenixPyre encrypted file, users can paste it anywhere. A UI indicator is shown in the bottom-right corner of the screen when Clipboard Protection is enabled.

| Source                   | Destination                      | Result   |
| ------------------------ | -------------------------------- | -------- |
| FenixPyre Encrypted File | Same file                        | Allow    |
| FenixPyre Encrypted File | FenixPyre Encrypted File         | Allow    |
| FenixPyre Encrypted File | Unencrypted File                 | **Deny** |
| Unencrypted File         | Any File (Encrypted/Unencrypted) | Allow    |

{% hint style="info" %}
Enabling the **Clipboard Protection Service** also activates **Screenshot Protection** and **Print Protection**.
{% endhint %}

{% hint style="success" %}
Learn more about [Clipboard Protection](/fenixpyre-features/clipboard-protection)
{% endhint %}

### Print Protection

Print Protection prevents sensitive data from being leaked through physical or digital printing channels. It detects and blocks print, Print to PDF, and virtual printing actions for FenixPyre encrypted files.

{% hint style="success" %}
Learn more about [Print Protection](/fenixpyre-features/print-protection)
{% endhint %}

### Screenshot Protection

Screenshot Protection prevents users from capturing sensitive application data through OS-level or third-party screenshot and screen-recording tools. It blacks out the application window in screen captures, detects standard snipping and screen-recording tools, and extends protection across multi-monitor setups.

{% hint style="success" %}
Learn more about [Screenshot Protection](/fenixpyre-features/screenshot-protection)
{% endhint %}

### Dynamic Watermark Display

Dynamic Watermark Display overlays traceable user information on the screen to help prevent photo-based data leaks. The watermark is transparent and moves with the application window. Administrators configure the content, style, and opacity from the policy.

| Setting Name     | Default Value                | Description                                                         |
| ---------------- | ---------------------------- | ------------------------------------------------------------------- |
| Enable Watermark | FALSE                        | Apply a watermark when documents are encrypted.                     |
| Content          | `%USER_EMAIL% %DEVICE_NAME%` | Watermark text to display on the encrypted file window when opened. |
| Style            | Font Style – Normal          | Font Style – Bold / Italic / Normal. Font Size – 0 to 100 pt.       |
| Opacity          | 40%                          | 0 to 100 %.                                                         |

You can use these values in the watermark text: `%USER_EMAIL%` for the current user's email, `%DEVICE_NAME%` for the current device name, and `%IP_ADDRESS%` for the current device's IP address.

{% hint style="success" %}
Learn more about [Dynamic Watermark Display](/fenixpyre-features/dynamic-watermark-display)
{% endhint %}

## File Settings

### Preserve File Timestamps

By default, FenixPyre preserves original file timestamps when encrypting or decrypting. This means the "last modified date," "last access date," and "last write date" stay the same even after files are processed. If you want these timestamps to reflect the time of encryption or decryption instead, you can change this default behavior.

Recommended Value: Enabled

### Preserve File Security Info

You can keep a file’s security details, like its Discretionary Access Control List (DACL), even after encrypting or decrypting. A DACL controls who can access files and folders in a computer system.

Recommended Value: Enabled

### File Access Rules

Access Rules define the conditions that must be met before encrypted data can be opened. They are automatically applied to new and existing files, which makes managing access controls much easier.

<figure><img src="/files/UQx2HAtQ8bcSSPBHKD0v" alt=""><figcaption><p>Adding File Access Rules with IPs and Geo location</p></figcaption></figure>

* **Default Rule (Organization)**: The device must belong to the data-owning organization. All files are given this global default rule upon encryption.
* **IP Address**: Limit access to selected public IP ranges (supports multiple IPs and [CIDR notation](https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing)).
* **Geo-Fencing**: Currently only supports the US, so files can only be opened if accessed from within the United States. This is verified using geolocation, IP addresses, or both.

## Office Add In Settings

The FenixPyre Office Add-In offers various settings that help Data Loss Prevention (DLP) in Office 365. These settings disable any features that could compromise data security, ensuring your sensitive information remains protected.

| Setting Name                      | Description                                                                                                                                                                                                                       | Recommended Value |
| --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------- |
| Can Lock Files                    | FenixPyre automatically handles file locking for Office files synced from OneDrive or SharePoint. It ensures encrypted files are edited by only one user or device at a time, preventing conflicts and maintaining data security. | enabled           |
| Can Share                         | Enable or Disable Share Options in Microsoft Office                                                                                                                                                                               | disabled          |
| Can View Info                     | Enable or Disable View Info Option in Microsoft Office                                                                                                                                                                            | disabled          |
| Can Transform                     | Enable or Disable Transform Option in Microsoft Office                                                                                                                                                                            | disabled          |
| Can Export                        | Enable or Disable Export Option in Microsoft Office                                                                                                                                                                               | disabled          |
| Can Publish                       | Enable or Disable Publish Option in Microsoft Office                                                                                                                                                                              | disabled          |
| Can Print                         | Enable or Disable Print Option in Microsoft Office                                                                                                                                                                                | disabled          |
| Can Custom Preview                | Enable or Disable Custom Preview Option in Microsoft Office                                                                                                                                                                       | disabled          |
| Can Save to Non-Protected Folders | This setting controls the ability to save files to non-protected folders. It overrides similar setting in [User applications](#user-applications), including Microsoft Word, Excel, and PowerPoint.                               | disabled          |

## Advanced Settings

| Setting Name                      | Description                                                                                                     | Recommended Value |
| --------------------------------- | --------------------------------------------------------------------------------------------------------------- | ----------------- |
| User Policy Update Interval       | The Windows agent updates user policies at regular intervals. By default, these updates occur every 60 seconds. | 60 seconds        |
| Access Control Heartbeat Interval | Frequency at which FenixPyre verifies user status and ensures compliance with file access rules.                | 15 seconds        |


# User Applications

Learn how to manage user applications that need access to encrypted files on FenixPyre for secure data handling.

## User Applications

By default, users with the FenixPyre Windows client installed cannot open encrypted files created with FenixPyre unless the applications are added to user policies. The first step is to identify the applications your organization uses and add them to the policies.

<figure><img src="/files/mFgtHFQr3PVDHWF307rI" alt=""><figcaption><p>User applications</p></figcaption></figure>

## Platform approved applications

FenixPyre keeps a list of certified applications that have been reviewed to ensure they do not leak plain text during normal operations. These applications are automatically added to the default policy, allowing users to open encrypted files with them. You can remove applications from the default policy if desired.

## Admin approved applications

As an admin, you need to specify which applications require access to FenixPyre encrypted files. After identifying them, you can designate applications as admin-approved by providing their paths and specifying the file extensions to encrypt or ignore. These are termed Admin approved applications.

## How to add an application?

<figure><img src="/files/Bh7g7XAODyvBUnPERGoX" alt=""><figcaption><p>Add an application</p></figcaption></figure>

{% stepper %}
{% step %}

### Add new application

Click on User applications tab and click on add new application button
{% endstep %}

{% step %}

### Application Name

Enter the application name. Note: The application name should be unique.
{% endstep %}

{% step %}

### Application Identification Method

You can specify an entire folder path or a single application path to identify the application. For example, you could add the GitHub folder path (e.g., `C:\Program Files\GitHub\`) or just point to a specific application name like Microsoft Word (e.g., `C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE`).
{% endstep %}

{% step %}

### Protection Method

You can choose to encrypt application-created files based on an **Protect Extensions** list you provide, or you can skip them using an **Ignore Extensions** list. By default, FenixPyre does not encrypt certain file types (like `dll`, `exe`, `bat`, `rdp`, `iso`, `atcf`, `lib`, `wbk`, `msi`, `ini`).
{% endstep %}
{% endstepper %}

## Remove an application

Removing an application is only permitted for admin approved applications. Each admin approved application will have a remove action button associated with it.

<figure><img src="/files/cVhU6Jk0cyqEj9kihzeT" alt=""><figcaption><p>Application list with actions</p></figcaption></figure>

To remove an application, click on the trash icon and a confirmation popup will appear. Once you confirm it, it will be removed.

<figure><img src="/files/66rxTcHgPYfwQaRFSTV7" alt=""><figcaption><p>Confirmation popup for app removal</p></figcaption></figure>

**Note**: If the application is already part of any user policy, another confirmation will be asked like below. Once confirmed, the app will be removed from the associated policies first and then removed from the list.

<figure><img src="/files/x5OMIDS1R7tEo0ryrTgB" alt=""><figcaption></figcaption></figure>


# Customizations

This guide walks you through personalizing your workspace with your company’s branding, primary color, and terms & conditions messaging.

### 1. 🔧 Customizing Branding

#### 🖼 Company Logo

You can upload your organization's logo to reflect your brand throughout the FenixPyre experience.

* **Recommended Size**: `100×100px`
* **Supported Formats**: `PNG`, `JPG`

**How to Update the Logo:**

1. Click the **Choose File**
2. Upload your desired logo image.
3. To remove the logo, click **Remove**.

#### 🎨 Brand Color

Customize the accent color used throughout the FenixPyre platform (e.g., buttons, links, highlights).

You can:

* Select from preset colors (shown as circles).
* Or enter a **custom hex code** (e.g., `#22c55e` for green).

💡 **Live Preview**: As you change the color, you will see a real-time preview on the right panel showing how it appears in the interface.

***

### 2. 📄 Customize User-Facing Terms & Conditions

Use this section to define the legal message shown to users when they download encrypted or unencrypted files.

#### ✏️ Editable Fields

* **Heading**: The title of your agreement (e.g., *Access Authorization Terms & Conditions*).
* **Message Body**: Use rich text formatting to describe your terms.

Supported formatting includes:

* Bullet points
* Bold, Italics, Underline
* Alignment options

#### 🧪 Live Preview

To the right, a **live modal preview** shows how the message will appear to your users before they download files.

#### Example Message

```
- This download may contain confidential and privileged information.
- If you are not the intended recipient, please notify the sender immediately and delete this download and destroy any copies.
- Any dissemination or use of this information by a person other than the intended recipient is unauthorized and may be illegal.
```

***

### ✅ Best Practices

* Always use your **official logo** to instill brand trust.
* Choose a **color** that aligns with your corporate theme.
* Ensure your **terms and conditions** comply with legal and compliance requirements.
* Review the **live previews** to confirm everything looks perfect before saving.

Let your brand shine confidently across the FenixPyre platform! ✨


# Log Streaming

{% hint style="info" %}
Log Streaming is an early access feature. Contact [FenixPyre support](mailto:support@fenixpyre.com) to enable this for your organization
{% endhint %}

## Overview

FenixPyre’s **Log Streaming** feature allows you to export your organization’s security audit logs created by FenixPyre to an external log-analysis or SIEM platform such as Splunk, Datadog, or a custom HTTP endpoint.

Log Streaming makes it possible to react to events-such as file encryptions, admin actions, or user access changes - using your own business logic, monitoring tools, or automated workflows.

***

### Data Responsibility and Control

When **Log Streaming** is enabled, **you (the Customer)** become the **data controller** for the exported information.\
This means you are responsible for:

* Deciding **what information** is streamed out of FenixPyre
* Determining **where** and **how** that data is stored, processed, or analyzed in your own environment
* Maintaining compliance with your own security and privacy obligations

FenixPyre acts solely as the processor, transmitting events securely to your chosen destination.

***

### Log Categories Forwarded by FenixPyre

FenixPyre generates several distinct categories of logs that can be forwarded to Splunk. Each category captures a specific type of event within your organization’s FenixPyre environment:

| **Category**         | **Description**                                                                                                                                                                   | **Example Use Cases**                                                                                                         |
| -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- |
| **Admin Logs**       | Records of actions taken by administrators within the FenixPyre Dashboard. Includes configuration changes, integration updates, rule creations, and user-management operations.   | <p>- Tracking changes to encryption policies<br>- Auditing configuration updates<br>- Detecting unauthorized admin access</p> |
| **User Logs**        | Captures authentication, authorization, and user-initiated activities such as login attempts, password resets, and permission changes.                                            | <p>- Monitoring user access behavior<br>- Detecting repeated failed logins<br>- Investigating access control issues</p>       |
| **Agent Logs**       | Logs emitted by FenixPyre Agents deployed on endpoints or servers.                                                                                                                | <p>- Tracking offline event<br>- Tracks other agent critical logs</p>                                                         |
| **File Access Logs** | Detailed records of file-level interactions: open, upload, download, share, delete, or move operations across connected storage platforms (e.g., Desktop, Egnyte, OneDrive, Box). | <p>- Detecting unauthorized file exfiltration<br>- Tracking CUI/PHI/PII access<br>- Analyzing user activity by file type</p>  |

> These logs together provide a full audit trail of all sensitive operations across FenixPyre and its integrated storage connectors.

***

### Supported log streaming services

* [Splunk](/fenixpyre-for-admins/admin-dashboard/log-streaming/setting-up-log-streaming-for-splunk)
* Datadog
* HTTP endpoint


# Setting up Log Streaming for Splunk

### Overview

Splunk is a data platform that allows companies to analyze any structure data, from any source, across any timescale. Splunk not only makes it easy for companies to understand the health of their system in terms of performance and traffic. It also offers robust SIEM and SOAR (Security Orchestration, Automation, and Response) capabilities via Splunk Enterprise Security and Splunk Phantom, covering monitoring, detection, investigation of security threats, and automation of workflows.

### What you’ll prepare

* A **target index** for audit events (e.g., `fenixpyre_audit`)
* A **HEC token** bound to that index
* Your **HEC endpoint URL**
* (Trial stacks only) TLS note if your trial uses port **8088** with a non-public cert (we cover what to tell us)

> HEC is Splunk’s HTTP/HTTPS ingestion method. Steps are identical in Splunk Web across Cloud/Enterprise. [Check splunk docs](https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector)

***

### Identify your HEC endpoint (URL format)

Use the pattern that matches your environment:

* **Splunk Cloud (standard/managed)** `https://http-inputs-<your_stack>.splunkcloud.com/services/collector/event` (port 443)
* **Splunk Cloud (some trials)** `https://<your_stack>.splunkcloud.com:8088/services/collector/event` (port 8088). If `http-inputs-…` is not available on your trial, 8088 is often enabled.
* **Splunk Enterprise (self-hosted)** `https://<your_host>:8088/services/collector/event` (default HEC port is 8088).

> [Check Splunk Docs](https://help.splunk.com/en/splunk-cloud-platform/get-started/get-data-in/9.3.2408/get-data-with-http-event-collector/http-event-collector-rest-api-endpoints)
>
> HEC event ingestion endpoints are `/services/collector/event` (JSON “event” wrapper) or `/services/collector/raw` (raw text). We’ll use `/event` for structured JSON.

***

### Create (or choose) an index

1. In **Splunk Web**, go to **Settings → Indexes → New Index**.
2. Name it (e.g., `fenixpyre_audit`) and **Save**.
3. Note the index name; you’ll bind it to the token.

*(Any index works; dedicated is recommended for access control and retention management.)*

***

### Enable HEC & create a token

1. **Enable HEC (if needed)** **Settings → Data Inputs → HTTP Event Collector → Global Settings → Enabled** (and leave **SSL/TLS** on).<br>

   <figure><img src="/files/6SCpKp8QrbqesAVDssVQ" alt=""><figcaption></figcaption></figure>
2. **Create a HEC token** **Settings → Data Inputs → HTTP Event Collector → New Token**, then:
   * **Name:** `fenixpyre-hec` (or similar)
   * **Source type:** `fenixpyre:audit` (or `json`)
   * **Index:** select your index (e.g., `fenixpyre_audit`)
   * **Allowed Indexes:** ensure your target index is allowed
   * **Indexer acknowledgment:** **OFF** (leave disabled unless you explicitly require ack & channel handling)
3. Click **Save** and copy the **token value** (a long GUID).

> Why keep indexer ack off? If ack is on but no HEC **channel** is used, senders see **“Data channel is missing (code=10)”** and data won’t index.

***

### Confirm your HEC URL + token with `curl`

Replace placeholders and run:

```bash
# For Splunk Cloud (standard, 443)
curl -s https://http-inputs-<your_stack>.splunkcloud.com/services/collector/event \
  -H "Authorization: Splunk <YOUR_HEC_TOKEN>" \
  -d '{"event":{"hello":"fenixpyre-test"},"sourcetype":"fenixpyre:audit","index":"fenixpyre_audit"}'
```

```bash
# For Splunk Cloud trial (if :8088 works for you)
curl -s -k https://<your_stack>.splunkcloud.com:8088/services/collector/event \
  -H "Authorization: Splunk <YOUR_HEC_TOKEN>" \
  -d '{"event":{"hello":"fenixpyre-test"},"sourcetype":"fenixpyre:audit","index":"fenixpyre_audit"}'
```

Expected response:

```
{"text":"Success","code":0}
```

> Splunk Cloud environments enforce a **max HEC request size \~1 MB** by default, so keep payload batches small. (Cribl is pre-tuned for this when we set it up.)

***

### Verify in Splunk Search

In the **Search & Reporting** app, run:

```spl
index=fenixpyre_audit | head 10
```

You should see your test event(s). If nothing appears, check the index, token status, and endpoint you used.

***

### Share these details with FenixPyre Support

Send the following (no screenshots needed for now):

* **HEC endpoint URL** (pick the one that works for your stack):
  * Splunk Cloud standard: `https://http-inputs-<your_stack>.splunkcloud.com/services/collector/event`
  * Splunk Cloud trial (if applicable): `https://<your_stack>.splunkcloud.com:8088/services/collector/event`
* **HEC token** (value from the token you created)
* **Index name** (e.g., `fenixpyre_audit`)
* **Sourcetype** (e.g., `fenixpyre:audit`)

*(FenixPyre Support will configure Cribl with safe defaults, including body size ≤ 1 MB.)*


# FenixPyre Windows Agent

### Prerequisite

{% content-ref url="/pages/QzLFlmmYVoJgEz0JHaIQ" %}
[Prerequisites Checklist](/fenixpyre-for-admins/getting-started/prerequisites-checklist)
{% endcontent-ref %}

### Admin Dashboard

{% content-ref url="/pages/KNMPqyjcu4HZ1F9ZwRUl" %}
[Auto Update and Upgrade Management of FenixPyre Windows Client](/fenixpyre-for-admins/admin-dashboard/installers/fenixpyre-windows-client/auto-update-and-upgrade-management-of-fenixpyre-windows-client)
{% endcontent-ref %}

### How to Guides

{% content-ref url="/pages/fNI4DDHIjhV23KyAgn6y" %}
[How to download FenixPyre Windows Agent from Installers Page](/fenixpyre-for-admins/admin-dashboard/installers/fenixpyre-windows-client/how-to-download-fenixpyre-windows-agent-from-installers-page)
{% endcontent-ref %}

{% content-ref url="/pages/1L7uyyDhgTw7sQbtcmrd" %}
[How to install FenixPyre Windows Desktop Client](/fenixpyre-for-admins/fenixpyre-windows-agent/how-to-install-fenixpyre-windows-desktop-client)
{% endcontent-ref %}

{% content-ref url="/pages/hZ47Gr3YqjErEYbDWer7" %}
[How to login to FenixPyre Windows Agent](/fenixpyre-for-users/windows-agent/how-to-login-to-fenixpyre-windows-agent)
{% endcontent-ref %}


# Prerequisites for FenixPyre Windows Client Installation

### Pre-requisites

{% hint style="warning" %}
If you're the admin of your organization, kindly follow these [prerequisite checklist ](/fenixpyre-for-admins/getting-started/prerequisites-checklist)before proceeding with FenixPyre Windows agent installation
{% endhint %}

{% content-ref url="/pages/QzLFlmmYVoJgEz0JHaIQ" %}
[Prerequisites Checklist](/fenixpyre-for-admins/getting-started/prerequisites-checklist)
{% endcontent-ref %}

Before installing the FenixPyre Windows Client or agent, please ensure that the following prerequisites are met based on the version you are installing.

**For Agent Version 6.2.0 and Above:**

1. **Whitelist FenixPyre**:\
   Ensure that FenixPyre is whitelisted by your network’s firewall and antivirus software to prevent any interference with the installation and operation of the agent. [Read more](/references/how-to-guides/how-to-whitelist-fenixpyres-windows-agent-in-your-antivirus-edr-xdr)
2. **Microsoft Visual C++ Redistributable (x64) 2019 or Higher**:\
   The installation requires the Microsoft Visual C++ Redistributable for Visual Studio 2019 (x64) or a newer version. This is essential for ensuring that the necessary runtime components are available for the agent to function properly. If it is not already installed on the machine, you can download it from the official Microsoft website. [Read more](/references/how-to-guides/how-to-install-microsoft-visual-c++-redistributable-x64-2019-or-higher)
3. **TLS 1.2 or Above Enabled**:\
   FenixPyre requires TLS 1.2 or above to ensure secure communication between the agent and the platform. Verify that TLS 1.2 is enabled in your system settings and network configuration to support secure data transmission. [Read more](/references/how-to-guides/how-to-enable-tls-1.2-on-windows-for-agent-installation)
4. **AppData Folder on Local Storage**:\
   The **AppData** folder, which stores important application data, must be located on local storage rather than network storage. This is critical for performance and reliability during the operation of FenixPyre.
5. **Install WebView2**:\
   FenixPyre uses WebView2 for rendering web content within the application. If WebView2 is not already installed on your system, it must be installed separately. If it's not installed, you will be prompted during the FenixPyre installation process, or you can manually download and install it from the Microsoft website. [Read more](/references/how-to-guides/how-to-install-webview2-on-your-windows-machine)

### Minimum System Requirements

#### **Supported Processors**

FenixPyre is compatible with specific processor architectures:

* **64-bit (x64) Architecture Processors**:\
  FenixPyre supports only 64-bit architecture processors (x64). If your system uses a 32-bit processor, you will need to upgrade to a 64-bit machine to use the FenixPyre agent.
* **ARM Architecture**:\
  Currently, FenixPyre does not support ARM-based processors. If your device is using an ARM processor, it will not be compatible with FenixPyre at this time.

#### Supported Operating System

* Windows 10 (64-bit)
* Windows 11 (64-bit)
* Windows Server 2019 or newer

#### Hardware

* CPU: Dual-core processor
  * 8 core processor recommended for optimal encryption speed
* RAM: 8 GB minimum
  * 16 or 32 GB recommended for optimal encryption speed
* Disk Space: Minimum 2 GB free disk space

#### Network

* Continuous internet or network connectivity for real-time security updates and centralized management
* Outbound HTTPS connectivity (port 443) to FenixPyre cloud or on-premises management server

#### Software

* .NET Framework 4.8 or later
* Latest Windows security patches and updates installed

#### Permissions

* Administrator privileges required for installation
* System-level permissions for operation and updates

### **Supported Identity Providers**

FenixPyre integrates with the following identity providers for Single Sign-On (SSO) to enable seamless authentication for users:

* **Azure Active Directory (Microsoft Entra ID)**:\
  FenixPyre can integrate with Azure AD (now part of Microsoft Entra ID) for centralized user management and SSO authentication, ensuring streamlined user access and security controls.
* **Okta**:\
  FenixPyre also supports Okta for identity management and SSO. With Okta, users can authenticate seamlessly using their existing Okta credentials, simplifying the login process across multiple applications.
* Or any SAML 2.0 based Identity Provider

### **Supported Cloud Providers**

FenixPyre integrates with a variety of cloud storage and collaboration platforms to ensure that your data is securely synced and accessible across all your systems. The following cloud and desktop integrations are supported:

* **Cloud/Web Integrations**:\
  FenixPyre supports integrations with the following cloud storage providers for seamless file access and synchronization:
  * **Egnyte**
  * **OneDrive / SharePoint**
  * **Box**
* **Desktop Integrations**:\
  For local file synchronization and management, FenixPyre supports desktop integration with:
  * **Egnyte**
  * **OneDrive / SharePoint**
  * **Dropbox**

These integrations ensure that FenixPyre can securely manage and protect files across your organization, whether stored on-premises or in the cloud.




---

[Next Page](/llms-full.txt/1)

