<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007Wi2hICAROkta Classic EngineAdministrationAnswered2024-04-16T10:52:26.000Z2022-03-22T16:54:05.000Z2022-03-24T16:36:52.000Z

ifcrx (ifcrx) asked a question.

Capabilities of Support Engineers

Due to the news of a possible breach with Okta, I'm curious about the capabilites of support engineers. If someone were to gain an admin account, could they assume this type of role? Also what can this type of account perform ,basically i'd like to know a few things about the support engineer capabilities.

  • Can a support engineer change a password/mfa_enabled field in database arbitrarily?
  • Is that event logged?
  • If this event is being logged, does it reflect on customer’s system logs too?

 


  • Hello @ifcrx (ifcrx)​,

     

    Thank you for posting.

     

    Support engineers are able to facilitate the resetting of passwords and MFA factors for users but are unable to choose those passwords, this event is logged.

     

    The event is logged in the customer system, look for events 'reset all factors for user' and 'send user MFA to reset notification email' and the confirm the Actor which will show as an Okta account if an Okta Technical Support Engineer performed this action from SuperUser.

     

    eventType eq "user.mfa.factor.reset_all" and eventType eq "system.email.mfa_reset_notification.sent_message

     

    Regards,

    Natalia

    Okta Inc.

    Expand Post
This question is closed.
Loading
Capabilities of Support Engineers