LoFP LoFP / administrators disable magic link second factor during authentication policy changes or troubleshooting. verify the actor and whether the setting was re-enabled or replaced with an equivalent control.

Techniques

Sample rules

Description

Magic link second factor adds an extra authentication step to passwordless sign-in for Anthropic. An attacker with administrative access can turn it off so magic link logins no longer require the second factor, which makes stolen or attacker-controlled mailboxes usable for interactive access. This often shows up alongside SSO weakening when the attacker wants a fallback authentication path outside the corporate IdP.

Detection logic

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "configuration") and
    event.action == "org_magic_link_second_factor_toggled" and
    anthropic.audit.enabled == false
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*