Skip to main content

Automatic Remediation - Logins

Automatic actions on logins.

Updated over 6 months ago

This guide will walk you through the process of enabling a location based access policy, that will automatically remediate logins from unapproved countries.

Microsoft 365 License Requirement: P1/P2 or higher(e.g. A3)

NOTE: Before setting up make sure you Approve Or Unapprove a Location or IP.


STEP ONE:

Sign into your Cloud Access Monitor Instance.


STEP TWO:

Select the "x Enabled" policies button to the right of the desired Cloud Environment.

Microsoft 365 License Requirement: P1/P2 or higher(e.g. A3)

NOTE: User policies are only effective if your license level contains login monitoring access.


STEP THREE:

Select the User Policies tab.


STEP FOUR:

Under the Unapproved Login Policy, look at Remediation.

  • None: When a user account is logged in from a unapproved location no action will be taken

  • Suspend User: When a user account is logged in from a unapproved country the account will be suspended.

  • Reset Password: The User's password will be reset to a new, randomized password. From this point, the user can reach out to the admin to set a new password for them, or the admin can preemptively set a new password on the user's account page once the policy violation email is received.

  • Send Warning: The User will be notified of the login, and they can verify if activity is normal or not.

mceclip0.png

STEP FIVE:

Now choose when you want the remediation to occur, above the Unapproved IP addresses Logins dropdown you will see the When Dropdown.

Select the time frame you wish to use.


STEP SIX:

Finally choose the On Remediation options.

  • Notify User: When the remediation action takes place to user will be notified via email.

  • Notify Admin: The cloud administrator will be emailed of the policy violation.


STEP SEVEN:

Select the Save button at the bottom of the page.

Setup is now Complete


Office-365 Only

Black listed logins can be filtered by login event type even further. Create a new Policy by selecting the Add Policy Button at the bottom of the page.


Select the Suspicious Logins checkbox and click inside the Activity Types box.

  • Here you are able to select the specific types of suspicious logins you would like to remediate. For more information about the specific types of logins please see the Suspicious Login Details page.


Did this answer your question?