Team: Huntress Managed Identity Threat Detection and Response (ITDR)
Product: Microsoft 365, Google Workspace
Environment: Cloud
Summary: Learn how Huntress is updating Managed ITDR escalations to reduce alert noise, eliminate false positives, and transition to a precise per-identity escalation model.
In this Article
Overview of Escalation Quality
IP-Based Expected Rules
Onboarding Escalation Throttle
Trusted Device Suppression
Microsoft 365 Usage Location Inference
Per-Identity Escalations Default
How to Access Configuration Rules
Overview of Escalation Quality
To improve your experience with Huntress Managed Identity Threat Detection and Response (ITDR), we are introducing a series of updates designed to reduce alert noise and maximize detection accuracy. These changes address common sources of false positives—such as geographic shifts, VPN usage, and initial customer onboarding bursts—while ensuring critical security events are never missed.
We are rolling out these updates in sequence, starting with new volume-control features to eliminate systemic noise at the source, followed by a total transition to a per-identity escalation model.
IP-Based Expected Rules
You can now mark specific IP addresses or Classless Inter-Domain Routing (CIDR) ranges as expected at the identity, organization, or account scope. This feature allows you to explicitly define trusted corporate network spaces, such as known office egress points, cloud network address translations (NATs), or static wide area network (WAN) boundaries.
When a login matches an expected IP rule, Huntress suppresses Unexpected Country and Unexpected VPN escalations, and bypasses malicious datacenter detectors. This feature supports both Microsoft 365 and Google Workspace environments. You can create these rules directly from the Respond menu within an existing escalation.
Onboarding Escalation Throttle
New organization onboarding can generate high initial alert volumes before you have time to configure expected settings. To mitigate this noise, Huntress automatically applies an onboarding safeguard.
If an organization generates five escalations for the same subtype (such as a specific country or VPN operator) within 24 hours of its first login event, escalation generation pauses for that specific organization and subtype. You will receive one pause notification through your configured email or professional services automation (PSA) workflows. The pause automatically lifts after 24 hours. This safeguard applies separately to Microsoft 365 and Google Workspace environments and requires no manual configuration. Established organizations are not affected.
Trusted Device Suppression
Logins originating from verified corporate devices, such as Microsoft Intune-compliant laptops or Microsoft Entra-joined workstations, are highly unlikely to be malicious. Huntress allows you to suppress Unexpected Country and Unexpected VPN alerts based on device trust levels.
You can manage three independent suppression toggles at the account and organization levels:
- Compliant devices (Default: ON)
- Entra Joined / Hybrid Joined devices (Default: ON)
- Entra Registered devices (BYOD tier) (Default: OFF)
If device data is missing or incomplete, the system fails open and generates an escalation normally. Every suppressed event is saved in an internal audit log to maintain full visibility. In this first version, this feature is exclusively available for Microsoft 365 environments.
Note: For all existing accounts, these suppressions default to OFF to match current operational patterns.
Microsoft 365 Usage Location Inference
When a Microsoft 365 identity lacks a designated Microsoft Entra usage location, every login outside its inferred home environment can trigger inaccurate alerts. Huntress addresses this by automatically inferring the missing value using the tenant's default country code (defaultCountryCode).
The inferred value serves as the identity's expected country. This process is fully automatic and requires no customer configuration. A valid usage location explicitly defined in Microsoft Entra always overrides the value inferred by Huntress.
Per-Identity Escalations Default (coming soon)
Historically, Huntress rolled up alerts at the organization level, grouping multiple affected identities into a single tenant-wide escalation. While this controlled volume, it occasionally caused security teams to overlook new compromises when additional identities were silently added to a previously resolved escalation.
Following the deployment of our noise-reduction features, Huntress is transitioning to a per-identity escalation model. Every identity receives a dedicated Huntress Escalation, notification, and corresponding PSA ticket. This ensures complete visibility into distinct account compromises without letting new activity fold into closed events.
How to Access Configuration Rules
You can access and manage your configuration rules directly within the Huntress platform.
- Log in to Huntress and go to the Unwanted Access dashboard using the left-hand navigation bar.
- Select either Manage VPN Rules or Manage Country Rules to adjust your settings.