#141 · New Prerequisites Before Testing Scan Profile Configuration
To ensure smoother and more efficient scan profile configurations, we’ve introduced new prerequisites that must be met before testing your scan profile (including testing authentication).
These steps will help prevent issues during testing your configuration and ensure a successful scan:

-
Application Accessibility
I confirm that my application is accessible by Escape. This means either:
- I have whitelisted Escape's Public Location IPs
- I have whitelisted
Sec-Escape-User headerin my WAF, or - I am using a Private Location.
Why this is required: Ensuring your application is accessible to Escape is essential for accurate scanning. If the application cannot be accessed due to IP restrictions or incorrect network settings, the scan will not run properly.
-
Authentication Configuration
I have either:
- Disabled CAPTCHA and MFA for test accounts, or
- I am using a supported text-based CAPTCHA or TOTP MFA.
Why this is required: CAPTCHA and MFA can block automated scanning tools. To prevent interruptions during testing, we require these features to be disabled or configured in a supported way for test accounts. This allows the scanning process to proceed without authentication issues.
Important Note: If these prerequisites are not met, the scan configuration will be blocked, preventing the testing from proceeding. By ensuring these conditions are in place, we can offer a smoother and more reliable scanning experience.