---
title: >-
  BeyondTrust Identity Security Insights suspicious multi-factor authentication
  activity detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  suspicious multi-factor authentication activity detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights suspicious multi-factor authentication activity detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect suspicious or potentially risky multi-factor authentication (MFA) activity.

## Strategy{% #strategy %}

Monitor MFA-related events across identity platforms to identify abnormal changes, unusual authentication patterns, or deviations from expected MFA usage.

## Triage and Response{% #triage-and-response %}

1. Identify the affected account `{{@entityName}}` associated with the suspicious MFA activity.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Validate whether the activity aligns with approved user behavior, support processes, and organizational security policies.
1. If the activity is suspicious, take appropriate remediation actions in accordance with incident response.
