<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00008pal4fSAAOkta Classic EngineMulti-Factor AuthenticationAnswered2024-04-16T11:15:24.000Z2020-06-24T12:45:19.000Z2020-07-08T12:23:18.000Z

GregH.00578 (Customer) asked a question.

Unsolicited Okta Verify requests

A user reported multiple unsolicited Okta Verify request to her mobile device, well after work hours, so she denied them.

We enforce MFA on specific applications by signon policy.

I can see the denies in the log, but is there a way to see what prompted the request?


  • feok4 (feok4)

    Greg - check to see where the auth requests are originating from. It could be indicative of an unauthorized person logging into an account. I like to go to Directories --> People --> PERSONSNAME--> View Logs. helps to narrow the focus

  • JohnT.44088 (TWOSENSE.AI)

    More specifically, in the logs you can see information about the client originating the request like IP address, geo-location, etc...

    Screenshot from 2020-07-08 00-55-16

  • GregH.00578 (Customer)

    OK, perhaps I didn't explain this correctly:

     

    User was at home, not trying to log in to anything.

    Okta Verify prompt appears on her phone.

    She denies the verification request.

    I can see the deny in the logs, where she is located, what OS she is using.

     

    I am trying to correlate back to the event that triggered the OV push to see if someone else was attempting to use her credentials to hack into one of our webapps, etc.

     

    Searching for the username yields nothing in the logs within hours of the Denied OV Push event.

     

     

    So my question is: How do I track down the event that caused the Okta Verify push?

     

    Expand Post
This question is closed.
Loading
Unsolicited Okta Verify requests