<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR0000142diX0AQOkta Classic EngineThreatInsightAnswered2025-12-31T17:09:40.000Z2025-12-12T07:24:56.000Z2025-12-31T17:09:40.000Z

YuiT.38950 (Customer) asked a question.

Question about removing an IP from Network Zone after resolving a ThreatInsight block

Hi,

I have a question regarding how ThreatInsight behaves after resolving a block.

A user in our organization was blocked by Okta ThreatInsight with the category "Request from suspicious actor". The root cause was multiple failed login attempts due to the user entering an incorrect password repeatedly. I have already confirmed that the activity was performed by the legitimate user.

To allow the user to log in, I temporarily added the user's IP address to a Network Zone. After doing so, the user was able to authenticate successfully.

My question is:

  • Is it safe to remove the IP address from the Network Zone after the user has logged in successfully?

Or

  • Will ThreatInsight immediately block the same IP again once it is removed from the zone?

 

I would appreciate any guidance or best practices for handling this situation.

Thank you!


Loading
Question about removing an IP from Network Zone after resolving a ThreatInsight block