Vertexgraph monitors users’ access patterns and alerts admins of possible ransomware attacks when there is an unusual level of file changes detected. In this article, we will show how to enable this for the organization.
Turn on ransomware protection in settings
1. Click on the admin avatar on the top right, then click on “Settings”
2. Click on “Configure” under “Native Client Settings”
3. Go to the “Ransomware protection” tab and turn on the toggle for “Ransomware protection”. By default, this is enabled for newly registered organizations.
Ransomware protection in action
When VertexGraph detects an unusual level of file changes on a device, the user will see the alert on the desktop notifications.
After a few seconds, an alert shows that the session is expired.
You will also see the alert in the admin dashboard
You can go to the alerts page by clicking on the avatar on the top right, and clicking on “Alerts” in the dropdown
You can see the alert again in this list
At this point, the user’s device is disabled, and the user gets automatically logged out.
Suppose the user tries to login again after entering the email and password.
The user won’t be able to sign in and will instead get a “DEVICE_DISABLED” error message
Re-enabling the device
1. If you would like to re-enable the device for the user, you can go to the list of devices by clicking on the top-right avatar, and then selecting “Devices”
2. Find the user's device and click on “Manage”
3. The device will show that the State is “Disabled”
4. Change the State back to “Allowed” and click “Save”
5. Now the user should be able to login into the Windows client successfully
Comments
0 comments
Please sign in to leave a comment.