---
title: >-
  BeyondTrust Identity Security Insights suspicious authentication activity
  detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  suspicious authentication activity detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights suspicious authentication activity detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect suspicious authentication activity that may indicate unauthorized access attempts, compromised credentials, or abnormal sign-in behavior.

## Strategy{% #strategy %}

Monitor authentication events across identity platforms to identify sign-ins that deviate from established user behavior patterns or organizational security expectations.

## Triage and Response{% #triage-and-response %}

1. Identify the account `{{@entityName}}` associated with the suspicious authentication activity.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Validate whether the activity aligns with expected user behavior, approved access patterns, and organizational security policies.
1. If the activity is unauthorized, take appropriate response actions in accordance with incident response.
