Lumen Defender Plus
management — inside your IoD scheduler
Apptifi is the only Lumen IoD bandwidth scheduler that also lets you manage Lumen Defender Plus. View threat events, update blocking rules, edit custom allow and deny lists, and configure notifications from the same interface you use to schedule IoD bandwidth. No extra portal. No extra login. No extra cost.
What is Lumen Defender Plus?
Lumen Defender Plus is a network threat detection and blocking service that runs on your Lumen Internet on Demand (IoD) circuit. It is powered by Black Lotus Labs threat intelligence and operates at the network edge, inspecting inbound traffic before it reaches your perimeter. Customers activate it as an add-on to an existing IoD service and manage it through the Lumen Defender tab in Lumen Connect.
Lumen offers two tiers — Defender Essentials and Defender Plus. Defender Plus adds configurable blocking by severity level (Severe, Very High, High), end-user alerts over email and text, custom allow/deny/monitor/block lists, and a rolling 12-month window of exportable reporting.
Lumen Connect is the system of record for Defender Plus. Apptifi does not replace it — Apptifi uses the Defender Plus API to bring the same operational data and controls into the dashboard your network team already uses for IoD bandwidth scheduling.
Defender Plus Management in Apptifi
Event Logs
View threat events detected on your protected IoD services in a paginated log, filtered by severity and time range. Export full event reports as CSV for incident reviews or compliance audits.
Activity Logs
Audit every configuration change made in Defender Plus — including blocking-rule edits, custom list updates, and notification changes. Download full activity reports as CSV for security governance.
Custom Lists
Maintain allow, deny, monitor, and block lists from Apptifi. Add or remove individual IPs, bulk-update entries, or download the full list. When your security team identifies an IP to permit or block, they update it without switching tools.
Blocking Rules
Review and adjust how Defender Plus handles inbound traffic at each severity level. Change your blocking posture as your risk tolerance shifts — all from the same screen where you manage bandwidth events.
Notifications
Configure email or text alerts triggered by severity thresholds or percentage increases in threat volume. Update thresholds as baselines change, or disable alerts that have become noise.
Filters
Apply the full set of Defender Plus filter options when querying event logs — severity, time period, threat category, direction — to isolate the exact traffic you need to review without exporting everything.
Why Defender Plus belongs next to your bandwidth schedule
Bandwidth events and security events happen on the same circuit. A nightly backup window at 5 Gbps exposes more surface area to scanning traffic than a daytime 100 Mbps tier. A holiday shutdown where you scale to 1 Mbps is also when ransomware operators like to probe. Keeping the two workflows in separate consoles means your network team is correlating timelines by hand.
Apptifi puts both on the same timeline. When Defender Plus flags a spike in high-severity events, you can see what bandwidth tier the circuit was at, what event caused the tier change, and who scheduled it — without opening a second tool. When you build a scheduled bandwidth event for a known workload, you can pre-adjust Defender Plus notifications for the same window so your on-call rotation is not paged for expected activity.
For MSPs managing IoD circuits across multiple tenants, this consolidation removes an entire operational surface. One dashboard, tenant-scoped, for bandwidth and Defender Plus on every client circuit.
How Apptifi compares for Defender Plus management
| Capability | Lumen Connect | Apptifi | Flux |
|---|---|---|---|
| View Defender Plus event logs | ✓ | ✓ | — |
| Edit blocking rules & custom lists | ✓ | ✓ | — |
| IoD bandwidth scheduling in the same UI | — | ✓ | ✓ |
| Correlate bandwidth events with threat events | — | ✓ | — |
| CSV export of event & activity logs | ✓ | ✓ | — |
| MSP multi-tenant Defender Plus view | — | ✓ | — |
Defender Plus integration is a capability claim, not a marketing claim — it works by calling the Lumen Defender Plus API that is also available to you directly from Lumen Connect. Apptifi does not modify or proxy that API; it invokes it on your behalf using the credentials you provide.
Getting started
- 1Activate Defender Plus on Lumen. If Defender Plus is not already enabled on your IoD circuit, add it from Lumen Connect. Essentials and Plus both work with the API; the Plus tier unlocks custom lists, severity-based blocking, and 12-month reporting.
- 2Connect Apptifi. In Apptifi Settings, enter the same Lumen Connect client ID and client secret you use for IoD API calls. Apptifi will request the Defender Plus scope automatically and confirm the connection.
- 3Review event logs. Open the Defender Plus tab. Your recent event logs will appear immediately, with severity filters and CSV export. Audit what Defender Plus has been blocking before you change anything.
- 4Correlate with your bandwidth schedule. Switch to the Schedule view and overlay event data on the same timeline as your IoD bandwidth tier changes. Note which bandwidth windows coincide with elevated event counts — this is where threat-model tuning pays off.
One interface for IoD bandwidth and Defender Plus.
Included in the Apptifi Core plan at $50/month. If your circuit has Defender Plus enabled on the Lumen side, you can be managing threats from Apptifi in under 15 minutes.