Managed Detection and Response (MDR) must be configured by a Super Admin before the MDR team can monitor your Nebula console activity. To begin configuring MDR, go to Managed Services > Configurations in Nebula.
MDR Contacts
The MDR team needs Nebula Super Admins to contact when remediation steps are required for a detection or suspicious activity. During emergencies, you may be contacted by phone at any time of the day. Select Super Admins and provide phone numbers for primary, backup, and alternate contacts that the MDR team can communicate with.
Note: The save button is grayed out if the following requirements are not met for selecting a contact or entering a phone number.
- The selected Nebula user must be a Super Admin who has verified their account.
- The phone number cannot include spaces or symbols, except for the + symbol that can be used before an international country code. Examples of valid phone numbers:
- 1234567890
- +447891234500
- The same phone number cannot be used more than once.
Nebula notifications are created for all contacts selected on this page. For more information, see Set up Managed Detection and Response notifications in Nebula.
When deleting a Super Admin who is an MDR contact from the Settings > Users page, you are prompted to select a new MDR contact.
Global Data Protection Regulation requirement
CAUTION - This setting cannot be changed later. Confirm the correct selection is made before clicking Save.
Global Data Protection Regulation (GDPR) is a regulation on data protection and privacy in the European Union (EU) and European Economic Area (EEA). If you have any endpoints protected by Nebula located in the EU or EEA, select Yes. This selection controls where data for MDR is stored.
Remediation authorization
You can choose the level of remediation service provided by the MDR team.
- ThreatDown managed: The MDR team will remove threats to protect your environment. This does not include rebooting, re-imaging, or other onsite tasks.
- Notification only: The MDR team notifies you of detected threats and provides detailed instructions to perform remediation.
Isolation authorization
Select Yes, authorize to allow MDR analysts to perform isolation on endpoints protected by Endpoint Detection and Response on your behalf. Once the devices are investigated and cleaned, isolation can be removed. Endpoints are automatically rebooted when isolation is removed.