LoFP LoFP / t1539

t1539

TitleTags
applications will tag the operating system as null when the device is not recognized as a managed device. in environments where users frequently switch between managed and unmanaged devices, this may lead to false positives.
automated integrations or scripts using service accounts with session cookies may trigger user-agent based detection. consider excluding known automation accounts by okta.actor.alternate_id.
developers performing browsers plugin or extension debugging.
false positives may occur, depending on the organization's size and the configuration of okta.
legitimate webproxy settings modification
mobile users switching between wifi and cellular may show ip address changes. correlate with device type and typical user behavior patterns.
unknown
users legitimately switching networks (e.g., vpn connect/disconnect, office to home) may trigger ip-based detection. review the geographic distance and time between ip changes to assess legitimacy.