You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rules: Okta - MFA Denied Followed by Successful Logon
Description
This signal looks for a single user explicitly denying at least two (2) multi factor authentication prompts, followed by a successful Okta login via multi factor authentication within a twenty-five (25) minute window. This logic is designed to catch successful MFA fatigue type attacks. If you find this signal is triggering on legitimate events, consider excluding certain users via tuning expressions. You can also consider tweaking the time window within the "Grouped by" portion of the rule.
Additional Details
Detail
Value
Type
Chain
Category
Credential Access
Apply Risk to Entities
user_username
Signal Name
Okta - MFA Denied Followed by Successful Logon
Summary Expression
Okta - MFA Denied Followed by Successful Logon for: {{user_username}}