Coro's Cloud Security module enables admin users to configure user access permissions for connected cloud applications and threat detection policies for specified users or user groups.
To configure cloud security policies:
From the sidebar, select Control Panel:

Select Cloud Security:

Select the Policies tab:

Use this tab to configure:
Coro supports the ability to set access permissions for connected cloud applications. Admin users with sufficient permissions can create the following access policies:
Permitted Locations: Defines a list of locations (countries or IP addresses) from which a named user or user group is permitted to access a connected cloud application. Successful sign-ins by the user from any other location violate the policy and trigger the selected automatic remediation.
Restricted Locations: Defines a list of IP addresses from which a named user or user group is not permitted to access any connected cloud application. Successful sign-ins by the user from a listed IP address violate the policy and trigger the selected automatic remediation.
Coro creates an Access permissions violation ticket for each violation of the configured access policies (unless an exclusion has been defined for that origin).
For Coro to monitor and report security issues, at least one cloud application must be connected.
To see a list of supported cloud applications, see Introducing cloud security.
To view the currently configured permitted or restricted locations, select the relevant dropdown:

For each Permitted Locations policy, Coro shows:
- Users: The users or user groups that this policy affects.
- Cloud app: The cloud application that this policy affects.
- Allowed countries/IPs: The locations (countries and/or US states) or IP addresses that this policy allows. IP addresses can have short descriptions below them.
- Automatic Remediation: The type of automatic remediation Coro applies if a user attempts to access the named cloud application from a location or IP address not listed.
For each Restricted Locations policy, Coro shows:
- Users: The users or user groups that this policy affects.
- Restricted IPs: The IP address or IP address range that this policy restricts, with an optional short description.
- Automatic Remediation: The type of automatic remediation Coro applies if a user attempts to access the named cloud application from an IP address within the restricted list.
To configure a new permitted locations policy:
In Access Permissions, select + ADD POLICY > Add permitted locations:

Coro displays the Create access policy dialog:

Select the cloud application for your policy:

In Allow access based on, select from the following options:
IP Address: Restricts access to a defined range of IP addresses. Enter the allowed IP addresses into the IP Addresses field and provide an optional short description:

Location: Restricts access to named countries or US states. Select either All Countries or USA States:
US state permissions are independent of country permissions. You can select several countries and/or states. If United States is selected as a Country then permissions apply to all US states.

Coro displays a list of countries or US states based on your selection. Select the US states and/or countries to allow access from:

Set the automatic remediation Coro applies when a user does not meet the permission criteria, listed from least to most restrictive:
None: No remediation is applied.
Sign out: The user is signed out.
Suspend: The user account is automatically suspended.

When a user attempts to sign in, Coro evaluates all access permission policies that apply to that user. If multiple policies apply, Coro enforces the most restrictive automatic remediation.
For all options, Coro creates a ticket to alert admin users to the event.
Select the users or groups to assign to this policy:

All Users: The new permission applies to all protected users.
Specific Groups: The new permission applies to a named group within the corresponding cloud application.
When a user belongs to several groups, they inherit the collective permissions of all those groups.
Specific Users: The new permission applies to users within the application, specified by their email addresses.
You can assign access permissions to existing admin users within the corresponding cloud application.
Labels: The new permission applies to all users assigned the specified labels.
Select SAVE PERMISSIONS to save your changes.
When a user belongs to All Users and one or more specific groups, Coro evaluates all applicable access permission policies and applies the most restrictive automatic remediation (Suspend).
For example, if All Users is configured to suspend access outside the US and a user group allows access from Germany with remediation set to None, the user can sign in from the US and Germany but is suspended if they sign in from any other country.
Restricted locations policies apply across all connected cloud applications.
To configure a new restricted locations policy:
In Access Permissions, select + ADD POLICY > Add restricted locations:

Coro displays the Add restriction dialog:

Enter one or more IP addresses or IP address ranges in CIDR notation that you want to restrict, along with an optional short description:

Set the automatic remediation Coro applies when a user successfully signs-in to a connected cloud application from one of the listed IP addresses, from least to most restrictive:
None: No remediation is applied.
Sign out: The user is signed out.
Suspend: The user account is automatically suspended.

Coro evaluates all access permission policies that apply to a specified user. If multiple policies apply, Coro enforces the most restrictive automatic remediation.
For all options, Coro creates a ticket to alert admin users to the event.
Select the users or groups to assign to this policy:

All Users: The new restriction applies to all protected users.
Specific Groups: The new restriction applies to a named group within the connected cloud applications.
When a user belongs to several groups, they inherit the collective restrictions of all those groups.
Specific Users: The new restriction applies to specific users within the application, identified by their email addresses.
Labels: The new restriction applies to all users assigned the specified labels.
Select SAVE RESTRICTION to save your changes.
If a user successfully signs in to a cloud application from a location affected by both a permitted location policy and a restricted location policy, Coro prioritizes the restriction policy.
Admin users with sufficient permissions can edit and delete existing access permissions policies.
To edit or delete existing access permissions policies, select the corresponding action from the three-dot menu:
Select Edit to change an existing policy.
Select Delete to remove an existing policy.

Coro supports creating detection policies for the following threat types:
- Impossible Traveler
- Abnormal Admin Activity
- Mass Data Deletion
- Mass Data Download
- Suspected Bot Attacks
- Suspected Identity Compromise
Coro creates threat detection policies by default for all protected users without automatic remediation when a new workspace is created. Admin users with sufficient permissions can edit or delete these policies as required.
Coro creates a ticket for the named threat if a user violates the policy.
To view the currently configured threat detection policies, select the dropdown header for the policy type:

Coro displays each policy, showing:
- Users: The users or user groups that this policy affects.
- Automatic Remediation: The type of automatic remediation Coro applies if a user violates the policy.
Admin users can create exclusions for known, safe IP addresses such as a company VPN. Connections from these addresses are automatically allowed and do not trigger threat detection policies.
To configure a new threat detection policy:
In Threat types, select + ADD POLICY:

Coro displays the Add new threat detection policy dialog:

Select a threat type for the policy:

Set the type of automatic remediation Coro should apply when a user violates the policy:

None: No remediation steps are required.
Suspend: The user account is automatically suspended.
Sign out: The user is signed out..
In all cases, Coro creates a ticket to alert admin users to the event.
Select the users or groups to assign to this policy:

All Users: The policy applies to all protected users.
Specific Groups: The policy applies to named user groups.
Specific Users: The policy applies to named users, specified by their email addresses.
Labels: The policy applies to users included in the user label. For more information on user labels, see User labels.
Select SAVE to save your changes.
Admin users with sufficient permissions can edit and delete existing threat detection policies.
To edit or delete existing policies, select the corresponding action from the three-dot menu:
Select Edit to change the settings in an existing policy.
Select Delete to remove an existing policy.

If any previously connected cloud applications have connectivity issues, Coro displays a warning banner at the top of the page:

Select Review to see the list of issues, each with a brief description and a link to the console page where you can resolve it.
Detection is disabled for cloud applications in the following connectivity states:
Connected (Additional setup required): For example, Microsoft 365 is connected, but some required permissions may be missing, or audit log recording is disabled.
Incomplete: For example, Microsoft 365 setup was started, but a step in the connection dialog was skipped.
Disconnected: For example, Microsoft 365 permissions were removed after the application was connected.
Coro still allows you to configure policies for these applications, but they only take effect after any issues are resolved.