Set "Entra Usage Location" in Huntress
in progress
Dru DuBay
It seems that Huntress just wants this Entra Usage Location set so they can use it as a datapoint, setting it per user it tedious. MSP and IT also use JIT accounts which can create accounts on the fly. As an MSP, we are getting these alerts for every JIT account being created.
For all our clients, we could simply just tell you (in settings) that USA is the only Usage Location, vs setting this on a per user basis. Above that, if there was a single user in say Japan, it would be better for us to set that usage location on their identity in Huntress, not in Entra.
Rich Mozeleski
Merged in a post:
Cross-check usage location for linked identities in both Google and M365
L
Luke Stacy
Some environments may have an identity that is in both a google and M365 environment, their usage location set on the Microsoft identity, but can still generate escalation in the Google side.
Example a user that uses Google for their inbox, but logs in via Microsoft SSO.
Rich Mozeleski
Merged in a post:
"Login without Entra usage location" alert for newly created accounts
d
d _
Escalation notices are being created for brand new accounts because they have no usage location associated. Is it possible to disable this reporting for x-hours/days after an account is first seen?
Rich Mozeleski
updated the status to
in progress
Y
Yidel Steinfeld
I think a partial solution can be utilizing the "office location" attribute in Entra. We, as an MSP, utilize that vs Usage location for any location-based policies, etc.
Would be a huge help for the unexpected location escalations.
ari
it should also link both identities in all aspects.
D
Dru DuBay
How are we doing on this? It's been under review for over a year. We are now working to onboard Evo PAM and running into the same issue. Can you just add an option to disable escalations from "Login without Entra Usage Location" entirely?
Photo Viewer
View photos in a modal
L
Luke Keane
Agree that this is a lot of noise with questionable benefit (most companies with some workers based overseas will still specify the same usage location).
At least allow us to set a default location so we don't get these alerts.
P
Peter Fisher
It would really be great if we had the option for Huntress to just default to the usage location of the tenant and use the per-user usage location as an override. We also run into the issue with accounts generated by Immy or for Entra/Intune bulk enrollment and it's a pain to get a ticket for every one of these. Seems like the current implementation goes against Huntress' stance of limiting noise for partners.
T
Talbot Menear
I have found that when we add a new account - until that account is licensed - the default location is <null>. However, in our case, when a 365 license gets assigned, it sets the user's location accordingly (to the US). It think it would be helpful if Huntress would automatically rescan the null location users with active incidents (or maybe once before creating an incident) to see if a value has been set and then automatically resolve the incident - maybe in 12 hours. This would potentially remove a lot of noise incidents, at least for (365) licensed users.
J
Joe Cimino
Folks, can this get resolved? Default Usage Location should be the tenant DefaultMailboxRegion.
Load More
→