We have several clients who need approved vendors to connect through ScreenConnect, but we don't want the agent reaching unauthorized ScreenConnect instances or sites. What are you using to manage and restrict incoming connections besides blocking the software entirely? We currently have DNSFilter available, but I'm interested in how others are handling this securely.
3 Answers
Be careful with relying only on DNS filtering. Attackers can create temporary cloud-hosted ScreenConnect tenants, and traffic from unrelated tenants may occasionally share infrastructure with legitimate hosted tenants. An EDR rule based on your exact instance ID, combined with network filtering, provides stronger control.
An EDR can usually handle this more reliably than DNS filtering alone. ScreenConnect tenants have unique instance IDs, and many EDR products—including Huntress—can treat other instances as suspicious while allowing your approved ID. The instance ID may appear in the executable details, process information, or the service name if you’re using Control rather than Support.
A practical approach is to allowlist your specific ScreenConnect host or tenant in DNSFilter, then block the other ConnectWise endpoints. That should still let approved vendors connect without allowing the agent to communicate with unrelated instances.

That sounds promising. I wasn’t able to find where to configure the tenant or instance allowlist in Huntress—do you manage it through a policy or submit it for review?