---
title: Okta rapid application access
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: Docs > Datadog Security > OOTB Rules > Okta rapid application access
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Okta rapid application access
Classification:attackTactic:[TA0007-discovery](https://attack.mitre.org/tactics/TA0007)Technique:[T1526-cloud-service-discovery](https://attack.mitre.org/techniques/T1526) 
## Goal{% #goal %}

Detects rapid access to multiple Okta applications from a new device and geographic location.

## Strategy{% #strategy %}

This rule monitors successful `user.authentication.sso` events to Okta application instances when behavior detection identifies both a new device and a new geographic location. Rapid access across several applications can expose unauthorized use of a compromised Okta account.

## Triage and response{% #triage-and-response %}

- Verify with `{{@usr.email}}` whether the application access was expected from the observed device and location.
- Review the applications accessed by the user and identify sensitive or administrative resources.
- Examine recent authentication, MFA, IP address, user-agent, and session activity associated with the account.
