Analytics
Informational
✕
Multiple Okta MFA requests sent to a user
Multiple SSO MFA attempts were sent to the user. This may indicate an MFA fatigue attack.
- Module:
- Identity Analytics
- Data source:
- Okta
ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)
ATT&CK techniques: Compromise Accounts (T1586) Multi-Factor Authentication Request Generation (T1621)
Attacker's goals:
An attacker is attempting to gain access to an account secured with MFA.
Investigative actions:
Verify the reasoning behind the MFA request rejections. Follow further actions performed by the user.
- Test period:
- 30 Minutes
- Deduplication:
- 1 Day
1 variation:
- Multiple Okta MFA requests sent to a user with unusual characteristics Low (parent: Informational)