Configuring Anomaly Detection Workflows
When Email Security detects a compromised or suspected compromised account, the administrator can configure the Anomaly Detection security engine to take automatic actions. To do that, the administrator must select the required workflow for different scenarios.
To configure Anomaly Detection workflows:
-
To enable login events for Office 365 GCC environment, contact Check Point Support.
-
To create exceptions for anomalies, see Anomaly Exceptions.
-
Compromised accounts refer to anomalies (events) with a Critical severity level, while Suspected compromised accounts refer to anomalies with lower severity levels - High, Medium, and Low.
-
If you are using Microsoft Entra ID (formerly Azure AD) as the SAML/SSOIdentity Provider for your corporate assets, the users get blocked from accessing all the assets including Microsoft 365.
-
Blocking a user account terminates all the active sessions associated with the account.
-
Blocking a Microsoft user account resets the account password and requires the user to set a new password when unblocking their account.
