Explanation of Suspicious Activity Events in Okta
Last Updated:
Overview
Okta logs various suspicious activity events to help administrators identify and troubleshoot access issues, security threats, and rate limits. Reviewing the specific event details provides the necessary context to understand and resolve the underlying trigger.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- System Log Events
- Suspicious Activity
Solution
What do the different suspicious activity events indicate?
Review the following table to understand the different suspicious activity events logged in Okta:
| Events | Explanation |
| Sign-in failed |
|
| Account Locked - Max sign-in attempts exceeded |
|
| Self-service password reset attempted for suspended user |
|
| The user answered the recovery question incorrectly for self-service password reset |
|
| Multiple requests with a client ID are about to be rate-limited |
|
