Changelog
Follow up on the latest improvements and updates.
RSS
With this release, Huntress Managed SIEM now supports Okta as an identity and authentication log source, giving teams deeper visibility into the identity layer attackers love to target.
Even better: the Huntress SOC has detections built for Okta, helping identify identity-based attacks across key areas like credential attacks, privilege escalation, MFA bypass and fatigue, account takeover, and federated identity manipulation for organizations using Okta as their IdP or SSO provider.
The support configuration guide can be found here:
This is another big step forward in helping teams protect the full attack surface — from endpoint activity to identity-driven threats.
Searching through SIEM logs just got a whole lot easier. With AI Search, users can now search for logs using plain English instead of relying only on ESQL or the Query Builder.
Even better, AI Search helps users learn as they go. After running a plain-English search, simply click the ESQL button to see how Huntress translated your query into an ESQL query.
That means faster searches, easier investigations, and less time wrestling with query syntax.
Plain English in. Searchable logs out.
AI Search is now generally available in Huntress Managed SIEM.
new
Managed ISPM
Additional Security Controls in Managed ISPM
Managed ISPM features continue to grow as we move towards General Availability on July 1. In this set of updates, new Security Controls and enhancements have been added to the following platforms:
SharePoint Online
- An Idle session timeout for SharePoint and OneDrive is in place
- Anonymous sharing links are blocked in SharePoint and OneDrive
- User creation of SharePoint sites is blocked
- Deleted user OneDrive content is retained for at least 90 days
Microsoft Teams
- Communication with unmanaged Teams should be blocked
- Ensure the Organization cannot communicate with accounts in trial Teams tenants
Continuous Enforcement Improvements
The following policies now support Continuous Enforcement with drift detection and auto-remediation:
- Ensure access to the Azure Management portal is restricted
- Ensure unused device types are blocked
- Ensure Guests are restricted from using Microsoft Office clients
- Require frequent sign-in for Admins
- Require MFA to register or join devices
new
Managed EDR
The redesigned Managed Antivirus Dashboard is now GA
The redesigned Managed Antivirus dashboard brings recent Microsoft Defender activity, your noisiest organizations, and busiest endpoints together in one place, so you can see exactly how Defender is protecting your endpoints faster.
What's new:
- Activity at a glance: a new chart tracks blocked, quarantined, and removed files with deltas, so you can spot what changed. Toggle between 7 and 30 days to catch spikes and trends.
- Dedicated AV Events view: roll up event severities alongside quarantined and removed totals, with details on every event.
- Noisiest organizations, first:"Top organizations with events" shows where Defender is most active, and one click opens that org's AV Events page.
- Busiest endpoints, pinpointed:"Top agents with events" surfaces your most active devices at the account and org level. Click any agent to see its signals pre-filtered to that device.
- Compliance you can confirm: a "Recently installed agents" tab lets you verify that newly deployed endpoints match your Defender configuration, with no fleet-wide hunting required.
- Faster configuration: the most common action, Configure Defender, is now front and center on the dashboard.
Partners can now automate more of their workflows using our expanded Agents API. You can now programmatically uninstall agents, update tags, toggle tamper protection, and isolate or release hosts directly from your automation tools, without needing to log into the Huntress portal.
Managed ISPM now support additional security controls to better protect Microsoft 365 organizations.
Exchange Online
Exchange controls have been expanded to include
- Ensure the Common Attachment types filter is enabled
- Ensure notifications for internal users sending malware is set to Enabled
- Ensure Exchange Online spam policies are set to notify administrators
- Ensure that SPF records are published for all Exchange domains
Microsoft Teams
The foundation for Microsoft Teams controls has been added to Managed ISPM, and today marks the first control in place. With this foundation set, you'll see us add more controls as we move toward GA on July 1.
- Communication with unmanaged Teams should be disabled
SharePoint Online
The foundation for SharePoint Online and OneDrive for Business has also been added to Managed ISPM. Today marks the first two controls in this space, adding protection to business information stored in Microsoft 365.
- Ensure Guest resharing of SharePoint and OneDrive files is set to Disabled
- Ensure Legacy authentication protocols are blocked for SharePoint and OneDrive
new
Managed ISPM
Learning Mode for Conditional Access
Now Live
We're simplifying and automating the entire experience of deploying Conditional Access policies. ISPM Learning Mode monitors the impact analysis each day and clearly identifies individual identities who would be impacted by deploying the policy.
At the end of the 14-day learning period, we'll provide detailed guidance on any remediations. Or, If it's clear, you can go ahead and safely deploy the policy.
NOTE
This feature requires each organization to be on v6 of the application. Please upgrade your app to v6 to benefit from Learning Mode.We now have a new and improved board/auditor/compliance team ready PDF report for SAT Assignments. To access, it simply drill down into the assignment and click the "Export to PDF" button.
Inside you'll get:
* Details on the episodes and settings for the assignment
* The full list of learners who have completed the assignment with details on:
* Score
* Date completed
* Number of sessions
* The full list of learners who did not complete the assignment
This report works on both an individual company and multi-tenant assignments and has been tested with
Admin actions from the Huntress Managed SAT interface can now be reviewed and queried from the Huntress.io portal using the Huntress SIEM.
Customers and partners who wish to consume SAT content in their own Learning Management Software (LMS) can now download the SCORM 1.2 compatible files directly within the portal. This feature is now in GA.
Load More
→