Okta MFA Deactivation or Full Factor Reset Event Detection

Flags Okta events indicating MFA deactivation or reset_all actions by a user or actor.

FreeReviewedSigma · Medium · v4
Product
okta
Service
okta
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-09-21
Updated
2026-07-31

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule identifies Okta system log events where a user’s MFA factor is deactivated or where all MFA factors are reset. Attackers may use MFA changes to reduce authentication strength and impair account defenses, making these events important to review for unauthorized or unexpected activity. It relies on Okta event telemetry matching the specific MFA deactivation and full MFA reset event types.

Related detections3 linkedT1556.006 — drag to rearrange
Uncommon Security Info Registration Following AiTM Session Theft (via azure)
Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Azure AD Sign-in Success Without MFA (Single-Factor Authentication)
Okta MFA Deactivation or Full Factor Reset Event Detection
Pivot detection · T1556.006 · 3 related

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.