Okta MFA Bypass Attempted

Set up the okta integration.

Goal

Detect when a user attempts to bypass multi-factor authentication (MFA).

Strategy

This rule lets you monitor the following Okta events to detect when a user attempts to bypass MFA:

  • user.mfa.attempt_bypass

Triage and response

Contact the user who attempted to bypass MFA and ensure the request was legitimate.

PREVIEWING: esther/docs-7422-add-rsyslog-note