Okta MFA Bypass Attempted
Incident Management is now generally available! Incident Management is now generally available!
<  Back to rules search

Okta MFA Bypass Attempted

okta

Set up the okta integration.

Overview

Goal

Detect when a user attempts to bypass multi-factor authentication (MFA).

Strategy

This rule lets you monitor the following Okta events to detect when a user attempts to bypass MFA:

  • user.mfa.attempt_bypass

Triage & Response

  1. Contact the user who attempted to bypass MFA and ensure the request was legitimate.