<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Blocking Suspicious Sign-In Attempts Accessing the Okta Tenant
Administration
Okta Classic Engine
Okta Identity Engine
Overview

This article details strategies Okta admins can take to help block suspicious sign-in attempts against malicious authentication attempts by bad actors using password spraying.

Applies To
  • Credential-based attack
  • User account lockout
Solution

The collection of references below highlights Okta's best practices and how to secure against unwanted authentications:

 

  • In October 2025, Okta added a significant enhancement to its Breached Credentials Protection, designed to provide greater control and stronger defense against account takeover attacks. This protection is enabled by default for all Okta organizations using Okta-mastered or AD-mastered password policies, aligning with Okta's "secure by default" philosophy.

 

Related References

 

Loading
Blocking Suspicious Sign-In Attempts Accessing the Okta Tenant