Changing the notification settings for a user
You can configure which notifications a user will receive by email, if the Cyber Protection service is enabled for the tenant where the user is created.
To configure the notifications for a user
-
Navigate to My Company > Users.
-
Click the user for which you want to configure the notifications, and then, on the Services tab, in the Email notifications section, click the pencil icon.
-
Select the checkboxes for the email notifications that you want to enable.
Notifications Description Maintenance notifications Notifications that inform partner users, child tenants (partners, and customers), and individual users about upcoming maintenance activities on the Cyber Protect data center. These notifications can be enabled by partner users for their child tenants, and by partner users or company administrators for individual users within their organization. Quota overuse notifications Notifications about exceeded quotas. Scheduled usage reports Usage reports that are sent on the first day of each month. URL branding notifications Notifications about the upcoming expiration of the certificate used for the custom URL for the Cyber Protect Cloud services. The notifications are sent to all administrators of the selected tenant - 30 days, 15 days, 7 days, 3 days, and 1 day prior the expiration of the certificate. Countdown to production switch notifications Notifications about the customer trial expiration that will be sent 10 days before the trial expires and 3 days before the trial expires. Production mode activation notification Notifications about the activation of production mode. Failure notifications Notifications about the execution results of protection plans and the results of disaster recovery operations for each device. Warning notifications Notifications about the execution results of protection plans and the results of disaster recovery operations for each device. Success notifications Notifications about the execution results of protection plans and the results of disaster recovery operations for each device. Daily recap about active alerts The daily recap is generated based on the list of active alerts that are present in the Cyber Protect console at the moment when the recap is generated. The recap is generated and sent once a day, between 10:00 and 23:59 UTC. The time when the report is generated and sent depends on the workload in the data center. If there are no active alerts at that time, the recap is not sent. The recap does not include information for past alerts that are no longer active. For example, if a user finds a failed backup and clears the alert, or the backup is retried and succeeds before the recap is generated, the alert will no longer be present and the recap will not include it. Device control notifications Notifications about attempts to use peripheral devices and ports that are restricted by protection plans with the device control module enabled. Notifications about newly discovered devices Notifications about newly discovered devices. These notifications are sent every Monday and Thursday. Recovery notifications Notifications about recovery actions on the following resources: user email messages and entire mailbox, public folders, OneDrive / GoogleDrive: entire OneDrive and files or folders, SharePoint files, Teams: Channels, entire Team, email messages, and Team site.
In the context of these notifications, the following actions are considered recovery actions: send as email, download, or start a recovery operation.
Data loss prevention notifications Notifications about data loss prevention alerts related to the activity of this user on the network. Security incident notifications Notifications about detected malware during on-access, on-execution, and on-demand scans, and about detections from the behavioral engine and the URL filtering engine.
There are two options available: Mitigated and Not mitigated. These options are relevant for Endpoint Detection and Response (EDR) incident alerts, EDR alerts from threat feeds, and individual alerts (for workloads that do not have EDR enabled on them).
When an EDR alert is created, an email is sent to the relevant user. If the threat status of the incident changes, a new email is sent. The emails include action buttons that enable the user to see details of the incident (if it was mitigated), or to investigate and remediate the incident (if it was not mitigated).
Infrastructure notifications Notifications about issues with the Disaster Recovery infrastructure: when the Disaster Recovery infrastructure is unavailable, or the VPN tunnels are unavailable.
Default notification settings enabled by notification type and user role
The notifications that are enabled or disabled by default depend on the notification type and user role.
Notification type\User role | Partner, folder administrators | Customer, unit administrators (Self-service) | Customer, unit administrators (Managed by Service Provider) |
---|---|---|---|
Maintenance notifications |
Yes (enabled by default for users of direct partners, disabled for non-direct partners) |
No | No |
Quota overuse notifications | Yes | Yes | No |
Scheduled usage reports notifications | Yes | Yes | No |
URL branding notifications | No | No | No |
Failure notifications | No | No | No |
Warning notifications | No | No | No |
Success notifications | No | No | No |
Daily recap about active alerts | No | Yes | No |
Device Control notifications | No | No | No |
Recovery notifications | No | No | No |
Data Loss Prevention notifications | No | No | No |
Security incident notifications: Mitigated | No | No | No |
Security incident notifications: Not mitigated | No | No | No |
Infrastructure notifications | No | No | No |
Notifications enabled by default per device type and user role
Device type\User role | User | Customer and unit administrators | Partner and folder administrator |
---|---|---|---|
Notifications for own devices | Yes | Yes | n/a* |
Notifications for all devices of the child tenants | n/a | Yes | Yes |
Notifications for Microsoft 365, Google Workspace, and other cloud-based backups | n/a | Yes | Yes |
* Partner administrators cannot register own devices, but can create their own customer administrator accounts and use those accounts to add own devices. See User accounts and tenants.