Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
24 rules
Suspicious Okta Admin Functions Access Through Proxy (via okta)
mediumThis rule detects access to Okta admin functions through proxy.
sigmaIdentity2026-07-22Possible OneLogin User Account Locked (via onelogin.events)
lowThis rule detects when an user account is locked or suspended.
sigmaIdentity2026-07-19Suspicious Okta User Session Start Through An Anonymising Proxy Service (via okta)
highThis rule detects when an Okta user session starts where the user is behind an anonymising proxy service.
sigmaIdentityPaid2026-06-18Possible Creation of New Okta User (via okta)
informationalThis rule detects new user account creation
sigmaIdentity2026-06-14Suspicious Creation of Okta Identity Provider (via okta)
mediumThis rule detects when a new identity provider is created for Okta.
sigmaIdentity2026-05-30Suspicious Okta User Account Locked Out (via okta)
mediumThis rule detects when an user account is locked out.
sigmaIdentity2026-05-20Suspicious Okta Policy Rule Modified or Deleted (via okta)
mediumThis rule detects when an Policy Rule is Modified or Deleted.
sigmaIdentity2026-05-20Suspicious Creation of Okta Admin Role Assignment (via okta)
mediumThis rule detects when a new admin role assignment is created. Which could be a sign of privilege escalation or persistence
sigmaIdentity2026-05-20Suspicious Okta Application Modified or Deleted (via okta)
mediumThis rule detects when an application is modified or deleted.
sigmaIdentity2026-05-17Suspicious Creation of Okta API Token (via okta)
mediumThis rule detects when a API token is created
sigmaIdentity2026-05-15Suspicious Okta Unauthorized Access to App (via okta)
mediumThis rule detects when unauthorized access to app occurs.
sigmaIdentity2026-04-08Suspicious Okta New Admin Console Behaviours (via okta)
highThis rule detects when Okta flags new behavior in the Admin Console.
sigmaIdentityPaid2026-04-05Okta Suspicious Behavior Reported by End-user (via okta)
highThis rule detects when an Okta end-user reports behavior by their account as being potentially suspicious.
sigmaIdentityPaid2026-03-25Suspicious Okta Network Zone Deactivated or Deleted (via okta)
mediumThis rule detects when an Network Zone is Deactivated or Deleted.
sigmaIdentity2026-03-25Possible Okta Policy Modified or Deleted (via okta)
lowThis rule detects when an Okta policy is modified or deleted.
sigmaIdentity2026-03-17Suspicious Okta Admin Role Assigned to an User or Group (via okta)
mediumThis rule detects when the Administrator role is assigned to an user or group.
sigmaIdentity2026-02-11Suspicious Okta FastPass Phishing (via okta)
highThis rule detects when Okta FastPass prevents a known phishing site.
sigmaIdentityPaid2026-02-10Possible OneLogin User Assumed Another User (via onelogin.events)
lowThis rule detects when an user assumed another user account.
sigmaIdentity2026-01-29Suspicious Okta Application Sign-On Policy Modified or Deleted (via okta)
mediumThis rule detects when an application Sign-on Policy is modified or deleted.
sigmaIdentity2026-01-24Suspicious Okta Security Threat Detected (via okta)
mediumThis rule detects when a security threat is detected in Okta.
sigmaIdentity2026-01-20