Okta rapid application access

Goal

Detects rapid access to multiple Okta applications from a new device and geographic location.

Strategy

This rule monitors successful user.authentication.sso events to Okta application instances when behavior detection identifies both a new device and a new geographic location. Rapid access across several applications can expose unauthorized use of a compromised Okta account.

Triage and response

  • Verify with {{@usr.email}} whether the application access was expected from the observed device and location.
  • Review the applications accessed by the user and identify sensitive or administrative resources.
  • Examine recent authentication, MFA, IP address, user-agent, and session activity associated with the account.