Zetect Usage Guide Admin PortalSwitch portal ⇄

Behaviour Detection

Profiles normal sign-in behaviour — devices, locations and timing — and flags anomalies so they can raise the risk level of an attempt.

Behaviour Detection screen
Behaviour Detection — captured from the h-technova tenant.

How to use it

  1. Open Authentication → Behaviour Detection.
  2. Enable detection and choose the signals to evaluate, such as new device or impossible travel.
  3. Set sensitivity for each signal.
  4. Save. Anomalies now contribute to the risk score consumed by the Risk Engine and Authentication Rules.

Field reference

FieldDescription
New deviceSign-in from an unrecognised device fingerprint.
Impossible travelTwo sign-ins too far apart geographically to be plausible. Requires the GeoIP database to be mounted.