Google Workspace user has unenrolled from Advanced Protection
Set up the gsuite integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when a Google Workspace user unenrolls from Google’s Advanced Protection.
Strategy
Monitor Google Workspace logs to detect when a user unenrolls from Google’s Advanced Protection. An attacker who has already gained initial access may unenroll from Advanced Protection to degrade security controls.
Triage and response
- Check for other signals and logs generated by the impacted user
{{@usr.email}}
, and look for deviations in the following properties:- Application
- Device
- Geolocation
- IP address
- Reach out to the user
{{@usr.email}}
to confirm if they recognize the activity. - If the activity is not legitimate, block the user from signing in and begin your Incident Response process.