LogoLogo
⌘Ctrlk
BlogSupport
  • Home
AI Assistant

I'm here to help you with the docs.

⌘Ctrli
AI Based on your context
LogoLogo
  • Cortex Analytics Alert Reference
  • Alerts by name
  • Alerts by data source
    • AWS Audit Log
    • Azure Audit Log
    • Azure SignIn Log
    • AzureAD Audit Log
    • AzureAD
    • Box Audit Log
    • DropBox
    • Duo
    • Gcp Audit Log
    • Google Workspace Audit Logs
    • Google Workspace Authentication
    • Health Monitoring Data
    • Idira
    • Kubernetes Audit Logs
    • Microsoft 365 Emails
    • Microsoft Graph Logs
    • Office 365 Audit
    • Okta Audit Log
    • Okta
    • OneLogin
    • Palo Alto Networks Firewall EAL Logs
    • Palo Alto Networks Firewall threat Logs
    • Palo Alto Networks Firewall traffic Logs
    • Palo Alto Networks Global Protect
    • Palo Alto Networks Platform Alerts
    • Palo Alto Networks Url Logs
    • PingOne
    • Third-Party Alerts
    • Third-Party Firewalls
    • Third-Party VPNs
    • Unspecified
    • VMware virtualization servers syslogs
    • Windows Event Collector
    • XDR Agent with eXtended Threat Hunting (XTH)
    • XDR Agent
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. Reference
  2. Alerts & Rules
  3. Analytics Alerts
  4. Alerts by data source

Okta

Alerts related to data source "Okta".

Alert

A disabled user attempted to authenticate via SSO

A successful SSO sign-in from TOR

A user accessed multiple unusual resources via SSO

A user connected from a new country

A user logged in at an unusual time via SSO

A user rejected an SSO request from an unusual country

Authentication attempt by a honey user

Azure Privilege Escalation Using an Application

First connection from a country in organization

First SSO access from ASN for user

First SSO access from ASN in organization

First SSO Resource Access in the Organization

Impossible traveler - SSO

Intense SSO failures

Invalid SAML Detected

IP Rotation Pattern in SSO Spray

Multiple Okta MFA requests sent to a user

Possible Impossible Travel Pattern - SSO

Possible Insider Threat Activity

Possible phishing attack via Microsoft Teams

Potential extraction of NAA Account Credentials in Microsoft Configuration Manager

SSO authentication attempt by a honey user

SSO authentication by a machine account

SSO authentication by a service account

SSO Brute Force

SSO Password Spray

SSO with abnormal operating system

SSO with abnormal user agent

SSO with new operating system

Suspicious SSO access from ASN

Suspicious SSO authentication

User attempted to connect from a suspicious country

PreviousOkta Audit Log
NextOneLogin

Was this helpful?

LogoLogo

‍

  • Trust Center

‍

  • Privacy

‍

  • Terms of Use

‍

  • Legal

© 2026 Palo Alto Networks, Inc. All rights reserved.

Was this helpful?