Analytics
Informational
✕
Okta device assignment
A device was assigned as an Okta MFA device to a user.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Okta Audit Log
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003)
ATT&CK techniques: Valid Accounts (T1078)
Detector tags: Okta Audit Analytics
Attacker's goals:
For purposes of maintaining persistence, an attacker could potentially register his device with various accounts that have been compromised.
Investigative actions:
Confirm that the device assignments were intentionally made by the users and are legitimate. Examine the IP address and assess its reputation. Continue monitoring the accounts for any subsequent actions that may indicate suspicious behavior.
- Test period:
- 6 Hours
- Deduplication:
- 1 Day
1 variation:
- A suspicious assignment of a mobile device to multiple users Low (parent: Informational)