A user modified an Okta MFA factor
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Okta Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Okta Audit Analytics
ATT&CK Tactic
Credential Access (TA0006), Persistence (TA0003)
ATT&CK Technique
Modify Authentication Process (T1556), Modify Authentication Process: Multi-Factor Authentication (T1556.006)
Severity
Informational
Description
An Okta MFA factor was modified by a user, suggesting a potential compromise of the account.
Attacker's Goals
An attacker is attempting to gain access to an account secured with MFA.
Investigative actions
Contact the user and ensure the operation was legitimate.
Check if the user modifies more factors.
If the user activates a weak factor, check for abnormal successful sign-ins from different countries and times.
If the user deactivates a strong factor, check if he authenticates with unusual factors and checks for abnormal successful sign-ins from different countries and times.
Variations
Was this helpful?
