Alerts related to data source "Okta".
A disabled user attempted to authenticate via SSO
A successful SSO sign-in from TOR
A user accessed multiple unusual resources via SSO
A user connected from a new country
A user logged in at an unusual time via SSO
A user rejected an SSO request from an unusual country
Authentication attempt by a honey user
Azure Privilege Escalation Using an Application
First connection from a country in organization
First SSO access from ASN for user
First SSO access from ASN in organization
First SSO Resource Access in the Organization
Impossible traveler - SSO
Intense SSO failures
Invalid SAML Detected
IP Rotation Pattern in SSO Spray
Multiple Okta MFA requests sent to a user
Possible Impossible Travel Pattern - SSO
Possible Insider Threat Activity
Possible phishing attack via Microsoft Teams
Potential extraction of NAA Account Credentials in Microsoft Configuration Manager
SSO authentication attempt by a honey user
SSO authentication by a machine account
SSO authentication by a service account
SSO Brute Force
SSO Password Spray
SSO with abnormal operating system
SSO with abnormal user agent
SSO with new operating system
Suspicious SSO access from ASN
Suspicious SSO authentication
User attempted to connect from a suspicious country
Was this helpful?