Product: ITDR: Huntress Managed Identity Threat Detection and Response
Environment: Unwanted Access
Summary: The Unwanted Access capability targets adversary tradecraft that attempts to maliciously gain access to partner or customer Microsoft 365 tenants and Google Workspace environments. This access usually occurs through the utilization of stolen credentials (username/password) or stolen session tokens.
The Unwanted Access capability combats malicious tradecraft with the key functionality described below.
- Session Token Theft Detection
- Credential Theft Detection
- Malicious Datacenter / Residential Proxy Detection
- Unwanted Access Dashboard
- Unexpected Country / VPN Escalations
- Unexpected Login Escalation Resolution
- Unwanted Access Rules
Detections
Session Token Theft Detection
Session Token Theft is adversary tradecraft that focuses on stealing and re-using an active Microsoft session token to gain unwanted access to an identity. Session token theft can bypass MFA. Huntress detects session token theft by looking at changes in key attributes between login events within the same session.
Credential Theft Detection
Credential Theft is adversary tradecraft that focuses on stealing the username and password for an identity. Credential theft can be mitigated by MFA, but many businesses still do not enforce MFA. Huntress detects credential theft by looking at all non-MFA logins and detecting login events with new attributes.
Malicious Datacenter / Residential Proxy Detection
Huntress tracks anomalous and abuse-prone datacenter and residential proxy logins and will generate critical incident reports when the SOC detects this activity for an associated identity. Huntress looks for differences in normal login patterns for identities and uses its own threat intelligence to reduce false positives from benign datacenter utilization.
Functionality
Unwanted Access Dashboard
The Unwanted Access dashboard is accessible from the left navigation bar in the Huntress portal. Huntress users can use this dashboard to review login locations and VPN activity at the account level or organization level for all integrated tenants across their Huntress account.
Clicking on the number icon on a country of interest will open a drawer showing all logins from that particular country and whether or not those logins have generated escalations for your review. Logins with pending escalations can be resolved from this view.
Unexpected Country/VPN Escalations
New login events from countries that do not match an existing Unwanted Access Rule and that do not match an identity’s Microsoft Entra License Usage Location will trigger an Unexpected Country escalation within the Huntress portal. Identities without a usage location will pull a usage location from the tenant environments default country. These escalations roll up all unexpected logins for that country and Huntress organization into the same escalation. New unexpected logins for that country will continue to be added to the escalation until the escalation is resolved by creating a rule.
New login events from anonymous VPN providers that do not match an existing Unwanted Access Rule will trigger an Unexpected VPN escalation within the Huntress portal. Huntress DOES NOT generate escalations for enterprise-grade VPNs or SASE providers. These escalations roll up all unexpected logins for that VPN and Huntress organization into the same escalation. New unexpected logins for that VPN will continue to be added to the escalation until the escalation is resolved by creating a rule.
When onboarding a new M365 tenant or GWS environment to Huntress ITDR, Huntress will pause new escalation generation after five escalations have been generated for a particular country or VPN. This pause will remain in effect for 24 hours. Huntress will send a notification when this pause occurs.
Unexpected Login Escalation Resolution
Huntress users can resolve an escalation in several ways. Learn more about how to resolve escalations on the Unwanted Access Escalation Resolution Instructions article.
Escalation resolution has three pathways:
Unauthorized
This activity is NOT authorized for this identity, organization, or the entire account. Huntress will make no further determination on malice against these logins and will automatically revoke sessions and disable identities logging in from this location or VPN.
Unauthorized rules generated from escalations will (by default) cause a Critical incident report to be generated and will revoke sessions and disable the associated identity. This functionality can be disabled at rule creation if desired.
Expected
Activity from this location, VPN, or IP is expected. Huntress will not generate future escalations that match this criteria and will factor in this rule when evaluating logins for malice.
Escalations can be resolved as Expected with an IP rule from the escalation view. Users are able to select a specific IP from the list of all IPs associated with the escalation. The user can create a rule for only one IP from this view, even if multiple IP addresses were involved in the escalation activity. Additional rules can be set and configured from the Unwanted Access rules view.
Dismiss
The Huntress user would not like to classify this activity is Expected or Unauthorized and would simply like to dismiss the escalation. The next login event from this location or VPN for this identity will trigger another escalation.
Unwanted Access Rules
ITDR Unwanted Access Configuration Rules allow Huntress users to set locations and VPNs as explicitly Unauthorized or Expected. These rules also allow users to set specific IPs (IPv4 or IPv6) or IP CIDR ranges as Expected. Expected rules will prevent the generation of new escalations and will serve as a data point for the SOC in determining malice of anomalous activity. Expected rules may have a start and end date to cover identity travel. Unauthorized rules may not have a start or end date.
Rules created at the identity level will override rules set at the organization level, which will override rules set at the account level.
Review the Unwanted Access Configuration Rule Creation Instructions article for more information.
Unwanted Access Policies
The Unwanted Access Policies menu allows for configuration of settings related to ITDR identity logins. Here users can configure Deny All policies for locations and VPNs and Trusted Device Escalation Suppression.
Huntress users can toggle Deny All Locations and Deny All VPNs at the account level, and override account level settings for specific Huntress organizations on the organization-level Unwanted Access rules page. By default, Deny All Locations and Deny All VPNs are toggled off.
The Deny All Locations policy effects all logins from all countries that are not the subject of Expected rules OR are not the default usage location for the tenant(s) or identities. This toggle will generate critical ITDR incident reports for these countries and revoke sessions and disable identities logging in from these countries.
The Deny All VPNs policy effects all logins from all anonymous VPNs that are not the subject of Expected rules. This toggle will generate critical ITDR incident reports for these VPNs and revoke sessions and disable identities logging in from these VPNs.
Trusted Device Escalation Suppression allows Huntress users to suppress escalations for identities logging in from certain types of trusted devices. Logins from these devices for affected identities will not generate any escalations regardless of location or VPN used for login. These categories are described below:
Compliant Devices
Compliant devices are managed devices that are in compliance with tenant policies. Huntress identifies these devices through the Unified Audit Log parameter IsCompliant. ITDR accounts created after July 28th, 2026 have this functionality toggled ON by default.
Joined Devices
Joined devices are managed devices that are added by a tenant administrator. Huntress identifies these devices through the Unified Audit Log parameter TrustType. Devices with a TrustType value of "1" or "2" are considered joined devices. ITDR accounts created after July 28th, 2026 have this functionality toggled ON by default.
Registered Devices
Registered devices are devices recognized by the tenant but that have been added by end users. Huntress identifies thse devices through the Unified Audit Log parameter TrustType. Devices with a TrustType value of "0" are considered registered devices. This functionality is toggled OFF by default for all accounts.
Review the Unwanted Access Policy Creation Instructions article for more information.