Okta device assignment
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
6 Hours
Deduplication Period
1 Day
Required Data
Okta Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Okta Audit Analytics
ATT&CK Tactic
Initial Access (TA0001), Persistence (TA0003)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
A device was assigned as an Okta MFA device to a user.
Attacker's Goals
For purposes of maintaining persistence, an attacker could potentially register his device with various accounts that have been compromised.
Investigative actions
Confirm that the device assignments were intentionally made by the users and are legitimate.
Examine the IP address and assess its reputation.
Continue monitoring the accounts for any subsequent actions that may indicate suspicious behavior.
Variations
Was this helpful?
