Techniques
Sample rules
Anthropic SSO Disabled or Connection Removed
- source: elastic
- technicques:
- T1556
Description
SSO routes Anthropic authentication through the corporate identity provider. Disabling SSO, or deactivating or deleting an SSO connection, moves users onto alternate sign-in paths where IdP-enforced MFA, conditional access, and session policies no longer apply. That opens the door to password or magic-link accounts the attacker controls.
Detection logic
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "iam") and
(
event.action in ("org_sso_connection_deactivated", "org_sso_connection_deleted") or
(event.action == "org_sso_toggled" and anthropic.audit.enabled == false)
)
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*