ISPM does not like Avanan
under review
M
Mark Mullarky
We use Avanan for spam/phishing filtering. Avanan creates rules that Huntress does not like and triggers the following two alerts.
Transport Rules Should Not Bypass Security Controls
Connection Filter Should Not Bypass Spam Filtering
For the connection filter, I can accept the risk. I cannot do that for transport rules.
I'm not sure that "accept risk" is the best solution to this anyway. If we could review and approve the current config, but monitor for changes, maybe? Or Huntress might recognize the tenant is configured for Avanan (and other popular plug-in filters)?
B
Ben Wildman
updated the status to
under review
B
Ben Wildman
Hi Mark, thanks for the feedback, We will look at this.
I want to point out that if you accept risk on any control, if we then detect a change, we will re-raise the escalation for you so you're aware this is different from your original risk exception.