A user attempted to bypass Okta MFA
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Okta Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Okta Audit Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Modify Authentication Process (T1556), Multi-Factor Authentication Request Generation (T1621)
Severity
Low
Description
A user may have attempted to bypass Okta MFA.
Attacker's Goals
An attacker is attempting to gain access to an account secured with MFA.
Investigative actions
Contact the user who attempted to bypass MFA and ensure the request was legitimate.
Check if the user successfully authenticated after the event.
Variations
PreviousA user added a Windows firewall rule
NextA user authenticated with weak NTLM to multiple hosts
Was this helpful?
