IP "Expected" for escalations
D
Daniel Evans
Hi team, for escalations when marking as expected we'd like to mark the specific IP rather than allowing the entire country. For example, one of our team members access our clients from Romania, I'd like to create an expected rule for that IPv4 without allowing Romania in it's entirety.
Thanks,
Canny AI
Merged in a post:
allow list a specific IP for unwanted access
S
Sahaj Arora
We have a client who has host data center in Germany and they have a server to access there LOB in Germany and user's are accessing there email's from that server and we are getting escalation from Huntress for there login which are legitimate, Now we don't want to put exception in system for entire Germany to be whitelisted for everyone as if there are any phishing attack or brute force login from Germany due this exception that will not alert us, We have static Public IP for that data center and instead of allowing the whole Geo location Germany, We would like to only put in exception only for that client with those static Public IP and if any login is from that IP are marked as excepted and we are not alerted. Please let us know how we can do this or if we have any other alternative from Huntress on this ?
Only suggestion here is to, Exclude the Germany for entire Organisation But that will be for entire Germany and lets say that client got an attacker from Germany trying to login because of this exception is applied for entire Germany we won't be alerted which is why i want to apply the exception on IP level not on country level
There should be option to add Public static IP as well
J
Justin Talbert
We would love this option as well! We are getting false positive UA alerts/lockouts for a client's Static/Public IP at this HQ with geolocation claiming it is outside of country when it is not.
IP whitelisting is such a common feature in security tools, I was actually surprised this feature did not exist with the launch of UA.
D
Daniel Evans
Or even if just allow the choice for marking country or IPv4 as safe