M ManySignal
Detection Pack Okta Identity

Okta Detection Pack

54 detection rules for Okta System Log events — covering MFA fatigue, session hijacking, admin privilege abuse, and policy tampering. Identity is the primary attack surface; detect threats at the authentication layer.

Pack summary

Detection rules
54
Critical severity
14
Response actions
6
ATT&CK techniques
18

What's included

54 rules across 5 threat categories for Okta identity threats.

Authentication Anomalies 18 rules

MFA fatigue, impossible travel, brute force, credential stuffing, ThreatInsight IP matches.

Session & Token Abuse 12 rules

Session cookie theft, API token creation, OAuth scope expansion, client secret rotation.

Admin Privilege Abuse 10 rules

Admin role assignment, super admin usage, bulk provisioning, admin unlock patterns.

Policy & Configuration Tampering 8 rules

Sign-on policy deletion, MFA downgrade, device trust bypass, log stream disabling.

Identity Provider Manipulation 6 rules

External IdP addition, delegated authentication modification, authenticator enrollment changes.

Detection rules (20 of 54 shown)

Showing 20 representative rules. All 54 rules activate with one click.

Rule name Severity
Okta MFA Challenge Denied — Repeated Attempts Critical
Okta Admin Role Assigned to User Critical
Okta Sign-In from Suspicious IP (TI Match) High
Okta Session Token Stolen — Sign-In from New Device with Valid Session Critical
Okta Policy Deleted or Disabled High
Okta Phishing-Resistant MFA Downgraded Critical
Okta Application Assigned to All Users High
Okta API Token Created High
Okta Identity Provider Added Critical
Okta User Account Unlocked by Admin (Unusual Hours) Medium
Okta Impossible Travel Authentication High
Okta Brute Force — High Authentication Failure Rate High
Okta Org-Wide Sign-On Policy Disabled Critical
Okta User Created and Immediately Assigned Admin Role Critical
Okta Delegated Authentication Modified High
Okta Device Trust Policy Bypass High
Okta Log Stream Disabled Critical
Okta Authenticator Enrollment Removed High
Okta User Password Reset by Admin Without User Request Medium
Okta Application Client Secret Rotated to Unknown Value High

Prerequisites

  • Okta System Log API access via API token or OAuth 2.0 service app with okta.logs.read scope
  • Okta ThreatInsight enabled at org level for IP reputation enrichment
  • Okta event hooks or log streaming configured if sub-minute latency required
  • Okta Workflows (optional) for automated response action execution

Okta Detection Pack: frequently asked questions

What Okta log events does this detection pack use?

The Okta detection pack uses the Okta System Log API, which captures all authentication, policy, admin, and provisioning events. ManySignal connects via the Okta System Log API (token or OAuth 2.0 service app) with configurable polling intervals down to 30 seconds for near-real-time detection.

How does ManySignal detect MFA fatigue attacks against Okta?

MFA fatigue detection tracks the ratio of MFA denials to authentications per user per hour. When a user repeatedly denies Okta push notifications (particularly with multiple denials in quick succession), ManySignal raises a Critical alert and can optionally suspend the user session via the Okta API response action.

Can ManySignal take automated response actions on Okta threats?

Yes. ManySignal integrates with Okta's API for response actions including: suspend user session, clear user sessions (invalidate all active sessions), disable user account, reset MFA factors, and unenroll suspicious authenticators. These actions can be triggered manually or via automated playbooks.

Does this pack cover Okta Workforce and Customer Identity Cloud?

The pack covers Okta Workforce Identity (formerly Okta Identity Cloud). Customer Identity Cloud (formerly Auth0) has a separate detection pack with rules specific to B2C authentication patterns, anomalous sign-up spikes, and credential stuffing detection.

How does ManySignal handle Okta ThreatInsight data?

Okta ThreatInsight provides IP reputation data directly in System Log events. ManySignal reads ThreatInsight risk scores from the event context and combines them with external threat intelligence (Recorded Future, VirusTotal) to produce enriched alerts with full IP attribution.

Detect identity-based attacks at the Okta authentication layer

54 Okta detection rules with automated response actions — suspend sessions, clear tokens, and disable accounts before attackers establish persistence.