---
title: Okta User Access Denied to Sign On
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: Docs > Datadog Security > OOTB Rules > Okta User Access Denied to Sign On
---

# Okta User Access Denied to Sign On
Classification:attackTactic:[TA0001-initial-access](https://attack.mitre.org/tactics/TA0001)Technique:[T1078-valid-accounts](https://attack.mitre.org/techniques/T1078) 
## Goal{% #goal %}

Detect when a user is denied access to sign on to an app based on sign-on policy.

## Strategy{% #strategy %}

This rule lets you monitor the following Okta events to detect when a user is denied access to sign on to an app based on sign-on policy:

- `application.policy.sign_on.deny_access`

## Triage and response{% #triage-and-response %}

1. Inspect the `@target` array to determine why the user was denied access to sign on.
1. Contact the user to determine whether they attempted to access this app or whether their account is compromised.
