# Week 48, 2023

### 💌 Bring your own mail provider!

One popular way to make identity insights actionable is to create workflows that improve employee awareness. This includes emailing employees that are not adhering to policies. For example, they may be using a personal VPN against company policy. In order to inform the relevant employees (and, optionally, their managers) it’s helpful to send them an email.&#x20;

So far, this email will come from the Oort domain. For a more seamless process, we’re introducing the ability to bring your own mail provider. In the integrations tab, there is a new section for “Email”, which includes options to set up integrations for your own SendGrid or Mailgun service.&#x20;

Configuring your own mail provider will enable you to define specific check failures that are delivered to failing users from your own email domain.<br>

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FAUuTj3Irzvq4jymrbPL1%2FPYpuOsca2Y4PuwX5dOu7EJdAcmeDvoYPVTzmPKkKFOac5XJ2R5ni7yO5zqzcxvKTfuWqZnnAaAOac9mTuVEpGt08SCDSijSRjBmmxkoyRBns8iUX8xewKRwwd7aRes8ZeF0WKfM2f9Vs.png?alt=media&#x26;token=5c91eccb-9b0a-422d-b4a8-546a7963122b" alt=""><figcaption></figcaption></figure>

<br>

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FgMHne5xlh14qMFsmjAiA%2FPoz2mifrReRONGFVgo1UYnZf8vAiDtz9QRMVgqgVcMesvdrXE9EM4MEoMaszGdEzyoUqtVhWZ35kzeTn956RsDP77CGiFTggzKpIgL6LAZ5pYcNeVpDmFDeVn9Y8CA9VvMw2Id1dmwDR.png?alt=media&#x26;token=e3f5fb1b-2b97-4149-a221-16f9e1e9f8a7" alt=""><figcaption></figcaption></figure>

<br>

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FWd6ud3SJwUDgr22a4bPE%2FSr8A3yTXpDSLtUMjCjZD4FOyMUe2mJVd7bsldhRDO0BUSZi6QZD9sus6bDjRSeMXbw9Zl11LlE-9DZDEfRVsDFvyGcyjDSNqk5M6pZsrfLYYMHfnELsT2aUMvntNaRAKQtd5wI4hHd1i.png?alt=media&#x26;token=2686c18d-bba3-4ed2-b7ab-51de8cff9493" alt=""><figcaption></figcaption></figure>

<br>

### 🔢 Track Usage of Bypass Codes in Microsoft Entra ID

The working world is starting to adopt strong, phishing-resistant forms of MFA. This makes it considerably harder for attackers. However, there are always exceptions; always times where employees lose tokens, forget passwords, and need to get access. In rare cases, companies may provide bypass codes for employees to login in. This is OK as an exception, but you want to ensure you are closely monitoring the use of these codes. If an attacker gets hold of these codes, they can gain access and register their own MFA.

In this release, we have extended the coverage for the “A Bypass Code Was Used to Successfully Sign In” check from Cisco Duo to Microsoft Entra ID. This, unsurprisingly, will notify you any time a user successfully logins in with a bypass code.<br>

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FgDFmrPKKsMiNDfXQfgBY%2Fr5iJ-LCzo5TIEBI_648NLVkgv_61GI1c-uXxB10tCCtEJjNXUaWXw_Txa3IXfN-cupjOST63sD867L2qA_3bbp8wf2F7zbLCjxPtW6fTHh6ad2dLGzmu-nyHJ1eCd7LowBfSPJIcxAyf.png?alt=media&#x26;token=4b04149b-2c44-48f8-bddb-d57f012d34e8" alt=""><figcaption></figcaption></figure>

<br>

### ✅ Easily track check actions taken

Last week, we added the ability to [view check actions within System Logs](https://oort.io/blog/release-notes-week-47-2023). In this release, we’ve extended that visibility with a new dashboard widget that shows you the feedback that checks have received in the past 30 days. This includes those marked as interesting, marked as normal behavior, and excluded or included in checks. This widget will enable you to focus on the most interesting checks, and tune your check settings if appropriate.

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FPRp4eGvQgVQSuSAiXQa0%2F2ncBJU2K8cwDiNfa9LSK2H7Mz_uSIgqNTPYWulDy7LNbbEoOxX3RK348EL_Pgt61lYYE9d4iz_DH7hh7y_C4NnMrph7OCJsD3QK3I5Y340v5RXa0XrXGpDywo60xGZsi55ykfYcd_Yfy.png?alt=media&#x26;token=ed360ebc-d9ad-4d7b-b286-3cb200a5d502" alt=""><figcaption></figcaption></figure>

<br>

### ⛔ View user status for each provider

When investigating a user, it’s important to understand their status across the various identity providers that account exists in. For example, that user may be active in Salesforce, but suspended in Entra ID. Identifying these discrepancies is vital context for assessing the impact of a failing check.<br>

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2F0LX2FShJQJWEYeTeE5m3%2FrFPaBtw1asWdZ2BqCohz6oNqUXKnnOQhs2-SrdwjyCv20K5gF9oFn8EuxjYrQSDTAfg2CTg-UgxLbYc7JeK99IG6DURf3BrL0I0dZQd2LYzdZTekdgC5jUWVeSPWcgYcRW8KM9nMHi81.png?alt=media&#x26;token=f7f845c4-d9b9-4cd0-a684-0a5612dd60cc" alt=""><figcaption></figcaption></figure>

### Bug Fixes and Minor Improvements

* Salesforce login results. Oort now parses Salesforce login results in more detail, and displays those values in activity logs and the User 360 profile.
* Disabled integrations. Oort will now notify when an integration is disabled for more than 7 days. Stale data can harm the reliability and data integrity of checks and reports, so it is important to either re-enable the connection, or delete it.&#x20;
* Registered location. We have simplified the logic of the Registered Location tag. When you select this tag in the Networks tab, you will now just see one chip in the search bar.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.oort.io/release-notes/2023/week-48-2023.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
