Team: Huntress Managed Identity Threat Detection and Response (ITDR)
Product: Microsoft 365
Environment: ITDR
Summary: Set up configuration rules to suppress unexpected country and VPN escalations for trusted device tiers.
Logins from known, verified devices—such as Intune-compliant laptops and Entra-joined workstations—are unlikely to be malicious, yet they can create significant alert noise. You can configure trusted device suppression toggles to filter out these safe events while maintaining visibility over personal or untrusted devices.
Access ITDR Configuration Rules
Before modifying device trust toggles, navigate to the rules configuration area in the Huntress Platform.
Log in to Huntress and select Unwanted Access from the left-hand navigation menu.
From the Unwanted Access dashboard, click either Manage VPN Rules or Manage Country Rules.
Configure Device Trust Toggles
After opening your rules manager, adjust the suppression toggles based on your organization's security preferences.
Locate the three independent suppression toggles at the account or organization level.
-
Turn the toggles On or Off to manage suppressions for each device trust tier:
Compliant devices: Suppresses unexpected country and VPN escalations (Default: ON).
Entra Joined / Hybrid Joined: Suppresses unexpected country and VPN escalations (Default: ON).
Entra Registered (BYOD tier): Suppresses unexpected country and VPN escalations (Default: OFF).
Save your changes.
Note: For existing accounts, all suppressions default to Off to preserve your current alert patterns. If device data is missing entirely, the suppression fails open and escalates normally. Every suppressed event writes an internal audit record to preserve the trail. This feature currently supports Microsoft 365 environments only.