Okta New Admin Console Behaviours

 Original Source: [Sigma source]
Title: Okta New Admin Console Behaviours
Status: test
Description:Detects when Okta identifies new activity in the Admin Console.
References:
  -https://developer.okta.com/docs/reference/api/system-log/
  -https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection
Author: kelnage
Date: 2023-09-07
modified:2026-04-27
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.initial-access'
  • -'attack.stealth'
  • -'attack.t1078.004'
Logsource:
  • product: okta
  • service: okta
Detection:
  selection_event:
    eventType: 'policy.evaluate_sign_on'
    target.displayName: 'Okta Admin Console'
  selection_positive:
debugContext.debugData.behaviors|contains:'POSITIVE' debugContext.debugData.logOnlySecurityData|contains:'POSITIVE'   condition:all of selection_*
Falsepositives:
  -When an admin begins using the Admin Console and one of Okta's heuristics incorrectly identifies the behavior as being unusual.
Level: high