<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00006uPfwSCASOkta Classic EngineMulti-Factor AuthenticationAnswered2024-04-16T10:25:38.000Z2021-04-06T15:25:37.000Z2021-04-15T17:00:15.000Z

xno3x (xno3x) asked a question.

Okta's Authentication Risk Engine Insight

I am looking for more insight as to how the Risk Engine formulates the Low/Medium/High values assigned during user login. I have reviewed information on what types of information the Risk Engine uses during the evaluation, but I have not seen anything on what determines a user as low vs. medium vs. high risk.

 

It would be helpful to know what internal thresholds are used and if it give any consideration to the admin configurable behavior settings. Does the Risk Engine use all historical context, or a certain amount? Also, when a user behavior context is reset, does this reset what the Risk Engine uses?

 

Thanks in advance for any thoughts and/or guidance regarding the Risk Engine inter-workings.

 


  • Hi Chris,

    Thank you for posting this question to Okta's Community page.

    We have a document that discusses the Behavior Analysis located here.

    https://help.okta.com/en/prod/Content/Topics/Security/behavior-detection/about-behavior-detection.htm

    It contains information on what events are analyzed, how the risk scoring is done, etc. I believe this should provide you with the insight needed regarding this question.

     

    Jim Puder

    Okta, Inc

    Tier 2 Technical Support Engineer

     

    Expand Post
    • xno3x (xno3x)

      Hi Jim, Thank you for the reply. I am more interested in Risk Engine evaluation and how it assigns High, Medium, or Low to the authentication requests. The following shows two users who sign on from the same Cali metro area but get assigned two different Risk Levels.



      USER 1

      {reasons=Anomalous Device, level=MEDIUM}

      {New Geo-Location=NEGATIVE, New Device=POSITIVE, New IP=NEGATIVE, New State=NEGATIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}



      USER 2

      {reasons=Anomalous Device, level=HIGH}

      {New Geo-Location=NEGATIVE, New Device=POSITIVE, New IP=NEGATIVE, New State=NEGATIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}



      It is easy to see the “New Device=POSITIVE” triggers the anomaly for both users, but what would cause the Risk Engine to assign different risk levels for the same anomaly?
      Expand Post
This question is closed.
Loading
Okta's Authentication Risk Engine Insight