Shield Suspicious Location User-Level Exclusion
Allow for user level exclusion for suspicious location alerts. This is helpful in the event that users are traveling across locations and various IP addresses.
Has any progress been made on this request? I have 3 false positives within 3 days all from different IP addresses because we have a user currently working from outside the country.
We would like an expansion of exclusions for Suspicious Location alerts. The addition of an exclusion for specific users in specific countries would be a huge improvement. This is useful if there is a contractor located in another country or if a user/executive is traveling to another country.
The current system only allows for exclusion of an entire country or IP address. With so many people working from home or traveling IP addresses change to frequently to try and constantly maintain that list.
AdminWilliam Higgins (Admin, Box) commented
Customer would like exclude a specific user from alerts on a detection rule. For example, I have an alert setup to monitor usage from Canada, but I have determined that one specific user is OK and needs to be exempt or excluded from the alerts being generated. Today we have an optional filter criteria that allows us to exclude Public Shared Links, IP Address and Apps. I don’t see a way to exclude USERS.