Setting up and using Fortify

This article explains how to enable Fortify in Kaseya SIEM, connect a Microsoft tenant, and use the Fortify interface to review security posture, apply recommended controls, and track configuration changes over time.

Fortify provides centralized visibility into Microsoft tenant security posture and allows you to apply supported security controls directly from Kaseya SIEM. Fortify focuses on configuration posture and control enforcement, not on alerting or threat detection.

Important: When to use Fortify vs Respond. Use Fortify when you want to review and improve Microsoft security posture. Fortify is used to evaluate tenant configuration, review Microsoft Secure Score–driven recommendations, and explicitly apply supported security controls. It focuses on posture, configuration state, and control enforcement, not on detecting or responding to live activity.

Use Respond when you want to automate reactions to detected activity.

Respond is used to define rules that trigger actions based on alerts or correlated activity after investigation confirms meaningful patterns. Respond does not change Microsoft configuration posture directly.

Before you begin

Before setting up Fortify in Kaseya SIEM, ensure that:

  • Fortify is available in your SIEM environment

  • You have Global Administrator credentials for the Microsoft tenant you want to connect

  • You understand that Fortify applies configuration changes directly to the Microsoft tenant when controls are applied

Enabling Fortify

  1. From the side navigation menu, select Fortify.

  2. On the next page, review the listed options and select Turn On Fortify

    You may be prompted to authenticate.

Connecting a Microsoft tenant

  1. When prompted, authenticate using a Global Administrator account for the Microsoft tenant

  2. Grant Kaseya SIEM permission to access the tenant

  3. After authentication completes, confirm that the tenant connection status indicates that the connection is complete

  4. Close the connection window

Once connected, Fortify begins evaluating the tenant’s security posture.

How the Fortify workflow fits together

Fortify follows a clear lifecycle:

  1. Dashboard: Review posture and confirm connectivity

  2. Actions: Review and select recommended changes

  3. Apply Actions: Explicitly deploy changes

  4. Ongoing: Monitor deployment progress

  5. Completed: Confirm applied controls

  6. Snapshots: Track posture over time

  7. Templates: Standardize future configuration

Operational considerations and boundaries

  • Fortify applies configuration changes directly to the Microsoft tenant.

  • All actions require appropriate Microsoft permissions.

  • Secure Score updates may not be immediate.

  • Fortify configuration and enforcement are separate from:

    • Unify correlation and investigation

    • Respond rule execution

  • Fortify should be used deliberately, especially in production environments.

Related articles

Use the following articles to continue working with Fortify or to understand adjacent workflows in Kaseya SIEM:

  • Creating Respond rules: Learn how to define alert‑ and action‑driven automation rules that respond to detected activity after investigation confirms meaningful patterns. Use this when you are ready to automate reactions, not when adjusting Microsoft configuration posture.

  • Using the Respond module: Understand how Respond rules are reviewed, validated, and executed during daily operations, including alert‑only, manual approval, and automated outcomes.

  • Using Kaseya SIEM: Learn how to review alerts, investigate activity with context, and decide when escalation or automation is appropriate during day‑to‑day security operations.