A user modified an Okta policy rule
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
2 Days
Required Data
Okta Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Okta Audit Analytics
ATT&CK Tactic
Persistence (TA0003), Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685), Domain or Tenant Policy Modification (T1484), Modify Authentication Process (T1556)
Severity
Informational
Description
An Okta policy rule was modified by a user, suggesting a potential compromise of the account.
Attacker's Goals
An attacker may attempt to modify an Okta policy rule to weaken an organization's security controls.
Investigative actions
Follow further actions done by the account.
Verify that the configuration change was expected.
Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Investigate if any other security policies have been changed or removed.
Variations
Was this helpful?
