new rules triggering on old alerts
J
Justin KIRK Engard
Every time I want to add a location or VPN disallow to a org or identity the same thing happens. It takes me by surprise every time because it is so unintuitive. I turn on the disallow and the identity instantly locks because there is a log in that matches the disallow in the past. Of course there is. I've already delat with the past. I'm in the present now. Why would I add a rule to act on the past? So if I want a rule I can't make one. I cant make a disallow rule without it locking up accounts from past alerts. It's weird and unexpected. Rules are for the future, not the past in every system I've ever seen.