<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Get the Most Out of Okta ThreatInsight

Administration
Okta Classic Engine
Okta Identity Engine

Overview

Okta ThreatInsight detects and blocks high-volume credential-based attacks, such as password spraying and credential stuffing, directed at Okta endpoints. Administrators can optimize ThreatInsight by reviewing the technical brief for basic and advanced configuration scenarios.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta ThreatInsight

Solution

What are the optimal configuration methods for Okta ThreatInsight?

The degree to which ThreatInsight requires configuration depends largely on organizational requirements. ThreatInsight is a baseline security capability available to every Okta organization. It detects and mitigates large-scale attacks on an Okta organization.

If all users in an organization authenticate directly to the Okta tenant, administrators can confidently toggle ThreatInsight on by reviewing the Basic Configuration documentation.

The technical brief provides additional advice for organizations with more complex authentication flows, such as those using the following configurations.

  • Third-party security network providers that intercept access requests between an originating client and Okta.
  • Externally-hosted resources, such as Content Delivery Networks or self-hosted sign-in widgets.
  • Trusted applications that process authentication requests en route to Okta.

Review the Advanced Configuration documentation for detailed advice regarding these scenarios.

 

When a request originates from a globally blocked IP address, ThreatInsight immediately drops the connection. ThreatInsight detects malicious activity before authentication, causing the block details in the System Log to resemble a network zone block. Because Okta terminates the transaction before reading the username, Okta records no username, preventing correlation to specific user accounts for these blocked events.

 

Related References

Loading
Okta Support - Get the Most Out of Okta ThreatInsight