Okta System Log: New Identity Provider Created via system.idp.lifecycle.create

Alerts on Okta events indicating a new identity provider was created.

FreeReviewedSigma · Medium · v4
Product
okta
Service
okta
Author
kelnage (SigmaHQ), DRL 1.1
Published
2023-09-07
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Okta system events where an identity provider is newly created (eventType system.idp.lifecycle.create). Creating a new IdP can enable attacker-controlled authentication paths and support persistence or privilege escalation by establishing new trust relationships. It relies on Okta system log telemetry capturing identity provider lifecycle events, including the event type indicating creation.

Related detections9 linkedT1098.001 — drag to rearrange
Suspicious MURKY PANDA Credential Addition to Entra ID Service Principal (via azure)
Suspicious IAM Access Key Creation for Persistence (via cloudtrail)
Suspicious AWS Administrator Policy Attachment via CloudTrail (via aws)
Suspicious AWS Inline Policy Granting Full S3 Access
Suspicious GCP Service Account Key Creation for Persistence (via gcp.audit)
Malicious Credential Added to an Azure AD Application (via auditlogs)
Suspicious AWS Long-Term Access Key Creation for Persistence via CloudTrail (via aws)
Suspicious Credential Added to Existing Application for OAuth Persistence in Entra ID (via azure auditlogs)
Suspicious IAM Policy Attachment Granting AdministratorAccess
Okta System Log: New Identity Provider Created via system.idp.lifecycle.create
Pivot detection · T1098.001 · 9 related

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.