Analytics BIOC Informational

MFA was disabled for a Google Workspace user

Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Modify Authentication Process: Multi-Factor Authentication (T1556.006)
Detector tags: Google Workspace
Attacker's goals:

Adversaries may impair defenses by disabling Multi-Factor Authentication (MFA) to maintain persistence and evade detection.

Investigative actions:

Verify if the MFA disablement was authorized. Investigate the source IP and User Agent for previous malicious activity or anomalies. Follow further actions done by the user and IP address.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • MFA was disabled for a Google Workspace administrative user Medium (parent: Informational)
  • MFA was disabled for a Google Workspace user by a different account for the first time Low (parent: Informational)