
SANGFOR IAM v2.1 User Manual
148
[Risk Ident]: Check this item and the options pop up, as shown below:
[Enable], [Disable]: Select it to enable or disable the risky behavior identification function.
[Identification Sensitivity]: Configures the sensitivity level of the rule detecting risky behaviors.
Options are [High], [Medium] and [Low].
[Alarm Level]: Configures the alarm priority of the identified risky behaviors; options are [High],
[Medium], [Low] and [Disable].
[Intercept Level]: Configures the measure (interception) level taken when risky behavior is
identified; options are [High], [Medium], [Low] and [Disable].
[Outgoing Email Identification]: Configures the options to identify and block outgoing email
anomaly. Identification can be based on the number of same-sized emails sent by a single IP
address in certain time period, and frequency of the emails sent by a single IP address in a certain
time period, etc.
[Set administrator email address for this policy]: Configure the email address of the administrator
to which the alarm emails are delivered when risky behavior is detected.
To have the administrator receive the email notice that risky behavior is detected, you have to
configure the corresponding options in [Advanced] > [Alarm] page. For detailed configuration,
please refer to Section 12.1 Alarm.