I am concerned that excluding enterprise VPNs/SASE from "Unexpected VPN" alerts creates a security gap, as attackers may use these to blend in. Also, what's the purpose of this change, as usually enterprise VPNs and SASEs are added as an expected rule?
Could you clarify how Huntress will maintain detection coverage, and if partners can toggle this exemption on or off?

Photo Viewer

View photos in a modal