LoFP LoFP / identity provider directory sync and scim provisioning can deactivate or delete sso connections during idp migrations, directory attribute changes, or connector maintenance. if `anthropic.audit.actor.type` is `scim_directory_sync_actor`, correlate with workos or okta change windows before escalating.

Techniques

Sample rules

Anthropic SSO Disabled or Connection Removed

Description

SSO routes Anthropic authentication through the corporate identity provider. Disabling SSO, or deactivating or deleting an SSO connection, moves users onto alternate sign-in paths where IdP-enforced MFA, conditional access, and session policies no longer apply. That opens the door to password or magic-link accounts the attacker controls.

Detection logic

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "iam") and
    (
        event.action in ("org_sso_connection_deactivated", "org_sso_connection_deleted") or
        (event.action == "org_sso_toggled" and anthropic.audit.enabled == false)
    )
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*