How Are You Restricting ScreenConnect to Approved Vendors?

0
0
Asked By MapleRidge42 On

We have several clients who need approved vendors to connect through ScreenConnect, but we don't want the agent reaching unauthorized ScreenConnect instances or sites. What are you using to manage and restrict incoming connections besides blocking the software entirely? We currently have DNSFilter available, but I'm interested in how others are handling this securely.

3 Answers

Answered By SilverKite19 On

Be careful with relying only on DNS filtering. Attackers can create temporary cloud-hosted ScreenConnect tenants, and traffic from unrelated tenants may occasionally share infrastructure with legitimate hosted tenants. An EDR rule based on your exact instance ID, combined with network filtering, provides stronger control.

Answered By CedarFox88 On

An EDR can usually handle this more reliably than DNS filtering alone. ScreenConnect tenants have unique instance IDs, and many EDR products—including Huntress—can treat other instances as suspicious while allowing your approved ID. The instance ID may appear in the executable details, process information, or the service name if you’re using Control rather than Support.

MapleRidge42 -

That sounds promising. I wasn’t able to find where to configure the tenant or instance allowlist in Huntress—do you manage it through a policy or submit it for review?

Answered By QuietOrbit7 On

A practical approach is to allowlist your specific ScreenConnect host or tenant in DNSFilter, then block the other ConnectWise endpoints. That should still let approved vendors connect without allowing the agent to communicate with unrelated instances.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.