Skip to content
Notifications
Clear all

Anyone else getting false positives on their "security events" for legit logins?

3 Posts
3 Users
0 Reactions
4 Views
(@crm_surfer_99)
Estimable Member
Joined: 2 months ago
Posts: 122
Topic starter   [#7000]

JumpCloud's security event log is starting to feel like the boy who cried wolf. For the last two weeks, I'm seeing a steady stream of "Suspicious Login Activity" flags for my own team members, and every single one has been a legitimate, multi-factor authenticated login from their usual devices and locations.

The pattern seems to be:
* Logins from managed company laptops, on the corporate network, with a recently-used browser.
* Events triggered despite successful MFA completion (TOTP).
* No actual anomalous pattern other than the system deciding it's suspicious.

I've had to whitelist or acknowledge these events manually dozens of times now. It's creating alert fatigue and my team is starting to ignore the notifications, which defeats the whole purpose.

Is this a known issue with a recent policy update or a change in their threat detection backend? I'm not seeing any configuration changes on our end. Compared to the more granular conditional access policies in other platforms, this feels like a blunt instrument.

What's the workflow here? Do we have to dial back the sensitivity globally and risk missing a real threat, or is there a way to fine-tune this without opening a support ticket for every user?

-- CRM Surfer


Your CRM is lying to you.


   
Quote
(@chrisw)
Estimable Member
Joined: 1 week ago
Posts: 94
 

Yep, same here. Thought it was just us. Started maybe three weeks back.

Check your Threat Insights config. Ours had somehow toggled on "Elevated Security Mode" after an update. It basically nukes the trust for known devices after a short period. Turning that off dropped the noise by about 80%.

Still getting a few, but now they're actually weird logins worth looking at. Their detection engine is definitely less tunable than something like Azure AD. You're right, it's a blunt tool.


metrics not myths


   
ReplyQuote
(@eval_rookie_42)
Reputable Member
Joined: 4 months ago
Posts: 158
 

Agreed, it's making the whole log nearly useless. I'm curious about the workflow side of things too.

Do you know if JumpCloud has any sort of learning period or baseline mode? We came from a platform that would chill out after establishing normal patterns for a user, but this feels like it starts from zero suspicion every time. We're stuck just lowering the global sensitivity slider, which doesn't seem right.



   
ReplyQuote