Okta: Unauthorized App Access Attempt Based on System Log Message

Alerts when Okta logs show a user attempted unauthorized access to an app.

FreeReviewedSigma · Medium · v4
Product
okta
Service
okta
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-09-12
Updated
2026-07-31

What it detects

This rule flags events where Okta records that a user attempted unauthorized access to an application. Attackers often probe app authorization boundaries to gain access to protected resources or validate misconfigurations. Detection relies on Okta System Log telemetry, specifically the event's display message indicating an unauthorized app access attempt.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.