Okta User Identity Verification failure
이 페이지는 아직 한국어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우
언제든지 연락주시기 바랍니다.Goal
Detects failed Okta user identity verification attempts. Alerts when an identity verification challenge results in DENY.
Strategy
This rule monitors Okta identity verification events, highlighted by the team at Okta. It triggers when @evt.name is user.identity_verification and @evt.outcome is DENY. Identity verification failures during authentication or recovery workflows warrant review to distinguish user error from potential account takeover activity.
Adversaries may try to bypass ID Verification in order to reset a password, enroll a factor for a user with admin permissions, or unlock an account.
This detection has been adopted from rules published by the Okta team.
Triage & Response
- Examine the identity verification context for
{{@usr.email}} to confirm the prompt was expected (authentication challenge, recovery, or risk-based step). - Review recent authentication activity for
{{@usr.email}} around the alert time, including failed logins, MFA challenges, and password reset attempts. - Identify the source IP
{{@network.client.ip}} and geo-location and determine whether they align with normal usage patterns or corporate egress. - Check device and client details to verify whether the attempt originated from a recognized device for the user.
- Analyze subsequent events to see if the identity verification later succeeded or if access attempts continued without resolution.
- If user activity is suspicious, begin your organization’s incident response process and investigate for any account takeovers.