LoFP LoFP / t1539

t1539

TitleTags
applications will tag the operating system as null when the device is not recognized as a managed device. in environments where users frequently switch between managed and unmanaged devices, this may lead to false positives.
automated integrations or scripts using service accounts with session cookies may trigger user-agent based detection. consider excluding known automation accounts by okta.actor.alternate_id.
developers performing browsers plugin or extension debugging.
false positives may occur, depending on the organization's size and the configuration of okta.
legitimate node.js or undici-based automation, health checks, or internal services that use the microsoft authentication broker or the same first-party application ids against graph or exchange may match. developers using axios or undici with delegated flows can also resemble this pattern.
legitimate webproxy settings modification
mobile users switching between wifi and cellular may show ip address changes. correlate with device type and typical user behavior patterns.
unknown
users legitimately switching networks (e.g., vpn connect/disconnect, office to home) may trigger ip-based detection. review the geographic distance and time between ip changes to assess legitimacy.