Analytics BIOC
Informational
✕
MFA was disabled for a Google Workspace user
Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Google Workspace Audit Logs
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Modify Authentication Process: Multi-Factor Authentication (T1556.006)
Detector tags: Google Workspace
Attacker's goals:
Adversaries may impair defenses by disabling Multi-Factor Authentication (MFA) to maintain persistence and evade detection.
Investigative actions:
Verify if the MFA disablement was authorized. Investigate the source IP and User Agent for previous malicious activity or anomalies. Follow further actions done by the user and IP address.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- MFA was disabled for a Google Workspace administrative user Medium (parent: Informational)
- MFA was disabled for a Google Workspace user by a different account for the first time Low (parent: Informational)