Push Unwanted Access Exclusions to Conditional Access Policies
A
Arthur Ebbinger
I realize this would be tricky to implement because of the numberous different ways organizations can implement conditional access policies to block unwanted countries. However, with the introduction of the feature to track unwanted access by countries in Huntress ITDR we've now been doing double duty having to track and enter scheduled exlusions in both Huntress and Entra ID (we utilize the open source CIPP to schedule these exclusions).
It would be great if Huntress would integrate with Entra ID so that the scheduled/timed exclusion that we're creating in Huntress to mark that country as allowed would have the ability to link to a conditional access policy that it can update on the start/end dates of the scheduled travel as well.
Due to everyone potentially having different conditional access policies - the easiest way I can invision this being implemented is simply pulling a list of the Conditional Access policies from the tenant when scheduling the exclusion and requesting which policy should be used for this particular exclusion. Then Huntress can add the user to that conditional access policy for the exclusion when the scheduled travel starts and then remove them when the scheduled travel ends. This is coincidentally the same way CIPP handles these exclusions.
This allows this functionality to work for anyone who has individual conditional access policies for each country, one single conditional access policy for all countries, or anywhere inbetween.
C
Chad Kirchner
I would love this integration. Today out T1 techs have to make the exclusion in CIPP then go make an exception in Huntress or it will send me an alert which I have to track down to make an exclusion.
Working on a standardized process to make sure both happen, but a simple integration that would allow a tech to make the exclusion in CIPP which adds them to a temporary CA policy then creates the same exception in Huntress automatically would be really great.
H
Hacene Djelid
This would be a deal breaker for some of our customers who already asked about this functionality/integration! Thank you!
R
Ryan Sipes
This would be too cool. For policies that arent time-based, it would be nice if it could alert us if for some reason that user is no longer targeted by the associated CA policy in 365, etc.