Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.15.0

Restore User Access

Procedure

  1. Navigate to the event on the Threat Detections page (or open it from the Investigate & Recover page).
  2. Open the event's details panel and select Take an Action.
  3. From the action options, select Restore User Access.
  4. Confirm the action. The system starts a background job that removes the lockout applied to the affected user, including the DENY permissions on any locked SMB shares (or, for NFS or ECS lockouts, the equivalent restore steps for that lockout type).
  5. Monitor the job status in the Jobs section of the left sidebar.
  6. Once the job completes, verify that the event's state has changed to Restored Access.
info

These steps unlock a user and remove the lockout on the shares (or ECS buckets) that were locked out. You can review which shares were processed by consulting the event's Activity Log tab.

See also