LoFP LoFP / t1621

t1621

TitleTags
a user may have accidentally entered the wrong credentials during the mfa challenge. if the user is new to mfa, they may have trouble authenticating. ensure that the user is aware of the mfa process and has the correct credentials.
although not recommended, certain users may be exempt from multi-factor authentication. adjust the filter as necessary.
aws administrators may disable mfa but it is highly unlikely for this event to occur without prior notice to the company
false positives may be generated by normal provisioning workflows for user device registration.
false positives may be generated by normal provisioning workflows that generate a password reset followed by a device registration.
false positives may be generated by users working out the geographic region where the organizations services or technology is hosted.
false positives may be present based on organization size and configuration of okta. monitor, tune and filter as needed.
legitimate users may miss to reply the mfa challenge within the time window or deny it by mistake.
multiple denifed mfa requests in a short period of span may also be a sign of authentication errors. investigate and filter as needed.
multiple failed mfa requests may also be a sign of authentication or application issues. filter as needed.
users actually login but miss-click into the deny button when mfa prompt.