MSP first 7 days: Dual-Strike XISEM quickstart
From tenant creation to first meaningful detection — a public field checklist.
Onboarding a new MSP practice or client org on Dual-Strike XISEM follows a predictable arc. This 7-day quickstart is the public version of what successful partners run internally — no internal codenames, no infra details.
Day 1 — Foundation
Create MSP org and first client org
Invite analyst seats (role-based access)
Download XISEM Agent MSI and Anti-Venom from dual-strike.com/downloads
Deploy agent to 3–5 pilot endpoints (mix of desktop + laptop)
Day 2 — Browser coverage
Confirm Anti-Venom from Chrome Web Store / Edge Add-ons / Firefox AMO (8.7.x GA line)
Publish browser policy in Settings → Browser Extension
Open Browsing Insights — verify sessions within 24h
Check Extension Health — aim for Healthy, not Not Detected on active machines
Day 3 — Identity
Establish Microsoft GDAP (or client-specific identity infeed)
Validate Entra sign-ins on Asset timelines
Skim Conditional Access intelligence panel — no enforcement, just context
Day 4 — EDR and PSA
Connect primary EDR (SentinelOne, CrowdStrike, Huntress, etc.)
Connect PSA (ConnectWise, Autotask, Halo, SuperOps, …)
Fire test detection → confirm ticket creates with evidence body
Day 5 — Detection tuning
Enable COBRA² rules in learning mode: shadow AI, posture regression, identity drift
Review Threat Center volume — disable noisy rules
Map severities to PSA boards
Day 6 — Compliance and reporting
Select target framework (SOC 2, NIST, CMMC, …)
Review initial control gaps
Schedule first monthly executive report
Day 7 — Client readout
Walk client through Asset modal on one device (live demo)
Show Browsing Insights top domains + AI usage
Agree remediation priorities from POA&M top items
Success metrics at day 7
MetricGood sign Agent coverage>80% of managed endpoints in pilot Extension healthActive users reporting Healthy/Idle Identity eventsSign-ins visible for M365 clients PSA loopAt least one ticket round-trip Detections<5 false-positive Criticals after tuning
Deep dives: Evidence doctrine · COBRA² guide · GDAP onboarding
Adjust pacing for client size — enterprise may need 14 days for change windows.

