Setting up ATR for Barracuda Impersonation Protection
The documentation below outlines the requirements for the Barracuda XDR Automated Threat Response (ATR) for Barracuda Impersonation Protection.
When ATR suspect an account has been taken over, it automatically responds by disabling the affected user.
Requirements
You must have:
Access to the Barracuda XDR Dashboard set up and functioning properly
An XDR Cloud Security license
Access to Barracuda Impersonation Protection set up and functioning properly
A Microsoft 365 ATR integration set up and functioning properly
Configuring the Microsoft 365 integration
To configure the Microsoft 365 Integration to support remediation actions for Automated Threat Response, you must add additional API permissions to the registered application.
See Configuring the Microsoft 365 integration for ATR for procedure.
Enabling ATR in the XDR Dashboard
Once you have configured the Microsoft 365 integration, you must enable ATR in the XDR Dashboard.
Make sure you complete Configuring the Microsoft 365 integration for ATR for the Conditional Access Policy.
To enable ATR in XDR Dashboard
In the Barracuda XDR Dashboard, click Integrations
.
Click the Barracuda Impersonation Protection card.
On the Barracuda Impersonation Protection card, click one of the following
If Barracuda Impersonation Protection is already set up, Update
.
If Barracuda Impersonation Protection is already set up, Setup
.
Select Enable ATR.
In Block List Policy Name, enter the Named Location created in your conditional access policy.
If you followed the procedure in Configuring the Microsoft 365 integration for ATR correctly, the named location isBarracuda_XDR_Email_ATR_Block_IP.Click Save.