
GregH.00578 (Customer) asked a question.
A user reported multiple unsolicited Okta Verify request to her mobile device, well after work hours, so she denied them.
We enforce MFA on specific applications by signon policy.
I can see the denies in the log, but is there a way to see what prompted the request?

You should be able to see the authentication events in the log and then events specific to your sign-on policy being triggered.
Joe
Greg - check to see where the auth requests are originating from. It could be indicative of an unauthorized person logging into an account. I like to go to Directories --> People --> PERSONSNAME--> View Logs. helps to narrow the focus
More specifically, in the logs you can see information about the client originating the request like IP address, geo-location, etc...
OK, perhaps I didn't explain this correctly:
User was at home, not trying to log in to anything.
Okta Verify prompt appears on her phone.
She denies the verification request.
I can see the deny in the logs, where she is located, what OS she is using.
I am trying to correlate back to the event that triggered the OV push to see if someone else was attempting to use her credentials to hack into one of our webapps, etc.
Searching for the username yields nothing in the logs within hours of the Denied OV Push event.
So my question is: How do I track down the event that caused the Okta Verify push?