Introduction
More urgent AROs generally have steps to take right away (such as locking accounts or isolating devices) or reacting to Active Response actions taken on your behalf by Field Effect MDR. This section will help you understand how to best respond to these situations:
AROs Involving Isolations
Network isolations are one Active Response technique we use to limit the impact from a security event. If your Active Response policy is set to allow Field Effect to perform isolations, we usually recommend that you perform some remediations prior to unisolating a device.
If you do not already have an exemption in place for your remote management tool, we recommend that you Request Help on these AROs and seek an exemption for your tool so that you can investigate. Once you are confident that the situation is suitably remediated, Request Help on the ARO again to request the removal of the isolation.
For Vision Users: You may be able to perform the unisolation yourself in the Action Center. See Vision documentaton for more information.
It may also be worth looking at setting up a client- or partner-wide exemption for your remote management tool to avoid having to request these each time you get an isolation. Please see [link here] for more information.
AROs Involving Account Locks
Account locks are another Active Response technique we use to limit the impact from security events involving user accounts. If your Active Response policy is set to allow Field Effect to perform account locks, and your integrations have sufficient permissions for us to perform them, you may see these happen for users.
Accounts locks can involve both an account lock and the creation of a conditional access policy to prevent any actions using the account. After you investigate and remediate appropriately, you will need to confirm that you unlock the account and remove any conditional access policies.
AROs That You Would LIke to Tune
The analytics behind most of our AROs are tuned for best performance across our entire fleet; however, there are hidden configuration settings that we can tweak for your particular needs.
Please request help on any AROs that you find prone to false positives and let us know what special tuning you would like to see change if you. Conversely, please reach out to support@fieldeffect.com if you have any security events that you find our analytics are not alerting to you via AROs. Not every customization is possible but we will work with you to better tune our analytics for your environment.
If you would like a listing of all analytic customizations we have in place for your organization, please reach out to support@fieldeffect.com.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article