> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/accounts-with-unusually-high-activity.md).

# Accounts With Unusually High Activity

Detects accounts with unusually high daily sign-in events, which can indicate unauthorized or malicious activity or the presence of a service account. An account will fail this check if Identity Intelligence detects more than 1,000 sign-in events per day.

**Recommended Actions**

Tag known service accounts and machine identities as "MACHINE" in Identity Intelligence. Investigate the spike to determine what application is generating the activity.<br>

**Default Check Settings**

Events per day: 1,000

**Compatibility**

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)

[Okta](/integrations/okta-data-integration.md)

[Duo](/integrations/duo-security-integration.md)

[Google Workspace](/integrations/google-workspace-integration.md)

[Snowflake](/integrations/snowflake.md)

<br>
