Multiple Okta MFA requests sent to a user
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
30 Minutes
Deduplication Period
1 Day
Required Data
Okta
Detection Modules
Identity Analytics
ATT&CK Tactic
Credential Access (TA0006), Resource Development (TA0042)
ATT&CK Technique
Compromise Accounts (T1586), Multi-Factor Authentication Request Generation (T1621)
Severity
Informational
Description
Multiple SSO MFA attempts were sent to the user. This may indicate an MFA fatigue attack.
Attacker's Goals
An attacker is attempting to gain access to an account secured with MFA.
Investigative actions
Verify the reasoning behind the MFA request rejections.
Follow further actions performed by the user.
Variations
PreviousMultiple network-related alerts produced by different detectors on the same host
NextMultiple Rare LOLBIN Process Executions by User
Was this helpful?
