Team: Huntress Platform
Product: PSA Ticket Integration, Email Integration
Environment: Platform
Summary: Learn about notification categories, email subject parsing formats, and integration options in the Huntress Platform.
In This Article
Overview
Huntress released significant improvements to notifications on January 28, 2026. These changes enable greater flexibility in configuring and routing notifications from the Huntress Platform. The new categories align with automated and manual workflows.
Notification Categories
| Category Name | Description | State |
|---|---|---|
| Incident Report | Malicious activity is confirmed or imminent. | No changes |
| Escalation | Security events where Huntress does not have enough context to make a high-confidence decision. | Updated (some notifications moved) |
| Platform Action | Important notifications that impact Huntress service delivery and generally require an account administrator to take action. | New |
| Account Notice | Events that are not directly actionable and are not reviewed by the Security Operations Center (SOC). | New |
The table below lists specific notifications and their assigned category, including updated notifications from Escalation to Platform Action.
| Notification Name | Category |
|---|---|
| Active Directory Sync Identity Disablement Failure - #{username} | Platform Action |
| Active Directory Sync Identity Enablement Failure - #{username} | Platform Action |
| Defender Disabled | Platform Action |
| Endpoints with Low Disk Space | Platform Action |
| Endpoints with Network Connectivity Issues | Platform Action |
| Log sources not reporting | Platform Action |
| Login without Entra Usage Location | Platform Action |
| macOS EDR Health Escalation | Platform Action |
| Microsoft 365 Integration - Error | Platform Action |
| Microsoft 365 Integration - Identity Error | Platform Action |
| Microsoft 365 Integration - MFA Required | Platform Action |
| Microsoft 365 Integration - Permission Error | Platform Action |
| Multiple Endpoints Isolated | Escalation |
| Platform Integration | Platform Action |
| Managed SIEM data not being audited properly | Platform Action |
| Unexpected Country - #{country_display_name} | Escalation |
| Unexpected VPN - #{vpn_name} | Escalation |
Integrations
PSA Tickets
All ticket integrations allow control over which notification categories deliver to the integration, as well as mapping ticket values to each notification category. This enables users to send notifications to ticketing systems that were previously available only via email.
Email integrations allow routing on a per-category basis. Updated email subjects provide more details designed for common email automation tools.
Email Subjects
Email subjects contain additional information for easier parsing with automation tools. Emails sent from email integrations follow this format:
Huntress [Severity] [Category] | [Details of the notification]
Where:
- Severity: Critical, High, or Low
- Category: Incident Report, Escalation, Platform Action, or Account Notice
- Details: Description of the notification, which may include the host or organization name
Examples:
Huntress High Escalation | Hosts not being properly protectedHuntress Critical Escalation | Multiple Endpoints Isolated
Frequently Asked Questions (FAQ)
What happens to existing notification configurations?
Existing configurations were automatically migrated. However, you should review your settings to take advantage of new delivery options.
When did the notification changes take effect?
The updated notification features went live on January 28, 2026.
Can notification destinations be configured at the organization level?
No. Notification settings are configured only at the account level.
However, many partners route alerts using email rules based on the organization name in the subject line.
The links provided in notifications can only be accessed by account administrators. Recipients without administrative roles cannot fully interact with these links.
For more information on parsing Huntress alerts, review Parse Incident Reports to Integrations (RMM, PSA, Email).
If alerting and remediation must be managed separately for an organization, that organization must be converted to a Huntress Account Contract under the parent account. For details, see Reselling Huntress (for resellers).