A user rejected an SSO request from an unusual country

Cortex XDR Analytics Alert Reference by data source

Product
Cortex XDR
Last date published
2024-12-03
Category
Analytics Alert Reference
Order
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

  • Requires:
    • Okta

Detection Modules

Identity Analytics

Detector Tags

ATT&CK Tactic

ATT&CK Technique

Severity

Low

Description

A user rejected an SSO authentication request from an abnormal country.

Attacker's Goals

An attacker is attempting to gain access to an account secured with MFA.

Investigative actions

  • Verify the reject cause of the MFA attempts.
  • Check to see if the user has successfully authenticated around the time of the alert, and confirm it's a legitimate login.
  • Verify the authentication attempt from the rare country is benign.