Okta Detection Pack
54 detection rules for Okta System Log events — covering MFA fatigue, session hijacking, admin privilege abuse, and policy tampering. Identity is the primary attack surface; detect threats at the authentication layer.
Pack summary
- Detection rules
- 54
- Critical severity
- 14
- Response actions
- 6
- ATT&CK techniques
- 18
What's included
54 rules across 5 threat categories for Okta identity threats.
MFA fatigue, impossible travel, brute force, credential stuffing, ThreatInsight IP matches.
Session cookie theft, API token creation, OAuth scope expansion, client secret rotation.
Admin role assignment, super admin usage, bulk provisioning, admin unlock patterns.
Sign-on policy deletion, MFA downgrade, device trust bypass, log stream disabling.
External IdP addition, delegated authentication modification, authenticator enrollment changes.
Detection rules (20 of 54 shown)
Showing 20 representative rules. All 54 rules activate with one click.
| Rule name | Severity |
|---|---|
| Okta MFA Challenge Denied — Repeated Attempts | Critical |
| Okta Admin Role Assigned to User | Critical |
| Okta Sign-In from Suspicious IP (TI Match) | High |
| Okta Session Token Stolen — Sign-In from New Device with Valid Session | Critical |
| Okta Policy Deleted or Disabled | High |
| Okta Phishing-Resistant MFA Downgraded | Critical |
| Okta Application Assigned to All Users | High |
| Okta API Token Created | High |
| Okta Identity Provider Added | Critical |
| Okta User Account Unlocked by Admin (Unusual Hours) | Medium |
| Okta Impossible Travel Authentication | High |
| Okta Brute Force — High Authentication Failure Rate | High |
| Okta Org-Wide Sign-On Policy Disabled | Critical |
| Okta User Created and Immediately Assigned Admin Role | Critical |
| Okta Delegated Authentication Modified | High |
| Okta Device Trust Policy Bypass | High |
| Okta Log Stream Disabled | Critical |
| Okta Authenticator Enrollment Removed | High |
| Okta User Password Reset by Admin Without User Request | Medium |
| Okta Application Client Secret Rotated to Unknown Value | High |
Prerequisites
- Okta System Log API access via API token or OAuth 2.0 service app with okta.logs.read scope
- Okta ThreatInsight enabled at org level for IP reputation enrichment
- Okta event hooks or log streaming configured if sub-minute latency required
- Okta Workflows (optional) for automated response action execution
Okta Detection Pack: frequently asked questions
What Okta log events does this detection pack use?
The Okta detection pack uses the Okta System Log API, which captures all authentication, policy, admin, and provisioning events. ManySignal connects via the Okta System Log API (token or OAuth 2.0 service app) with configurable polling intervals down to 30 seconds for near-real-time detection.
How does ManySignal detect MFA fatigue attacks against Okta?
MFA fatigue detection tracks the ratio of MFA denials to authentications per user per hour. When a user repeatedly denies Okta push notifications (particularly with multiple denials in quick succession), ManySignal raises a Critical alert and can optionally suspend the user session via the Okta API response action.
Can ManySignal take automated response actions on Okta threats?
Yes. ManySignal integrates with Okta's API for response actions including: suspend user session, clear user sessions (invalidate all active sessions), disable user account, reset MFA factors, and unenroll suspicious authenticators. These actions can be triggered manually or via automated playbooks.
Does this pack cover Okta Workforce and Customer Identity Cloud?
The pack covers Okta Workforce Identity (formerly Okta Identity Cloud). Customer Identity Cloud (formerly Auth0) has a separate detection pack with rules specific to B2C authentication patterns, anomalous sign-up spikes, and credential stuffing detection.
How does ManySignal handle Okta ThreatInsight data?
Okta ThreatInsight provides IP reputation data directly in System Log events. ManySignal reads ThreatInsight risk scores from the event context and combines them with external threat intelligence (Recorded Future, VirusTotal) to produce enriched alerts with full IP attribution.
Detect identity-based attacks at the Okta authentication layer
54 Okta detection rules with automated response actions — suspend sessions, clear tokens, and disable accounts before attackers establish persistence.