Team: Huntress Managed Identity Threat Detection and Response (ITDR)
Product: Google Workspace
Environment: Cloud
Summary: Understand Huntress response actions during a Google Workspace identity incident and the required remediations for partners.
In this Article
| Action | What Happens | Who completes it? |
| Revoke access and active sessions | When Huntress creates an Incident Report, and Containment is available, browser api sessions are revoked, and all active Google Workspace sessions are ended. | Huntress |
| Remove malicious Gmail filters or forwarding rules | Malicious rules can be identified and submitted through the Incident Report. Removing the rule requires manual approval. | Partner approval/Admin |
| Revoke QAuth grants or tokens | This is not an automated Huntress action for Google Workspace. | Google Workspace administrator |
| Revoke app passwords | This is not an automated Huntress action for Google Workspace. | Google Workspace administrator |
| Reset the user's password | This is not an automated Huntress action for Google Workspace. | Google Workspace administrator |
| Suspend the Google Workspace account | Huntress doesn't suspend the Google Workspace account as part of this response. | Google Workspace administrator |
| Review recovery and MFA methods | Session revocation does not remove compromised recovery methods of multi-factor authentication (MFA) changes. Review and correct them as part of the response process. | Google Workspace administrator |
What Happens if Nobody Responds?
If an incident report is created and containment is available, session revocation still occurs even if nobody acknowledges the alert. Approval-based remediation and administrator-led actions do not occur automatically.
Notifications and Escalation
Incident reports are sent by email, with professional services automation (PSA) delivery when configured. Critical incidents also trigger an automated SMS text and phone call to the configured contacts. The automated call directs the contact to the Huntress platform; it is not an analyst call.
Huntress supports one SMS text and/or phone call per unique identity or endpoint within a 24-hour period. The notification process does not guarantee retries, callbacks, overnight escalation, or a morning review. Partners should define their own acknowledgment process, administrator coverage, and escalation procedure.
For configuration details, see Incident Notifications - SMS Texts & Calls.
Notification Routing
Notification settings are configured at the account level. Organization-specific phone and SMS routing is not directly supported. Partners can use email rules based on the organization name in the subject line. If alerting and remediation need to be managed separately for an organization, the documented option is a separate account contract under the parent account.
For configuration details, see Huntress Platform - Notification Categories and Routing.
Testing Before Activation
The supported test is a critical incident simulation. It generates a test incident report and exercises the configured email, SMS, and phone notifications, as well as the remediation approval flow.
Use a test identity that will not disrupt business operations, confirm the intended notification recipients, and review the simulation steps before running it. A simulation is not a passive notification-only test; the selected test resource might be affected as part of the simulated response.
For instructions, see EDR / ITDR Incident Simulation.
Recommended Response Checklist
Open the Huntress incident report and review the affected identity, severity, signals, and remediation status.
Confirm whether Huntress revoked access and signed out active sessions.
Have a Google Workspace administrator complete any required account suspension, password reset, OAuth, app-password, Gmail-rule, recovery-method, or multi-factor authentication (MFA)actions.
Complete any remaining manual remediation steps listed in the incident report and document the actions taken.