Reset a User Risk Score
Focus
Focus
SaaS Security

Reset a User Risk Score

Table of Contents

Reset a User Risk Score

Reset a user's risk score to the ML baseline to restore access and remove the user from associated dynamic user groups.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
Reset a user's risk score when you determine that the user no longer poses a threat or there was false positive and you want to restore their scores back to normal. Resetting sets the score back to the baseline and ignores all incidents generated before the reset. After you reset the score, the user's risk drops to 5. If this value no longer meets the CDUG filter condition, the user is automatically removed from the high-risk group—restoring their access in real time without manual changes in Cloud Identity Engine. All score resets are recorded in the audit logs with your justification for compliance tracking.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationSaaS SecurityBehavior ThreatsUsers.
  3. Scroll down to the Users section and select single or multiple users.
    You can also use the Actions menu at the far right of the users table to reset the risk score of individual users.
  4. Click Reset Risk Score.
  5. In the Reset Risk Score page, for Justification, enter a comment explaining the reason for resetting the user's risk score.
    This justification is stored in the audit log entry for the reset action and also appears as an entry in the user's activity timeline.
  6. Click Reset Risk Score.
    After the reset:
    • The user's risk score returns to the baseline.
    • All incidents generated before the reset are excluded from future score calculations.
    • CDUG membership for the user is reassessed in real time.
    • A reset entry is added to the user's activity timeline.