> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/accounts-with-unusually-high-activity.md).

# Accounts With Unusually High Activity

Detects accounts with unusually high daily sign-in events, which can indicate unauthorized or malicious activity or the presence of a service account. An account will fail this check if Identity Intelligence detects more than 1,000 sign-in events per day.

**Recommended Actions**

Tag known service accounts and machine identities appropriately within your Identity Provider so that Identity Intelligence can correctly classify accounts. Investigate the spike to determine what application is generating the activity and if that behavior is legitimate and expected or problematic - such as if a human account is being used to run automated actions or scripts that should only be done by machine identities.&#x20;

**Default Check Settings**

Events per day: 1,000

**Compatibility**

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)

[Okta](/integrations/okta-data-integration.md)

[Duo](/integrations/duo-security-integration.md)

[Google Workspace](/integrations/google-workspace-integration.md)

[Snowflake](/integrations/snowflake.md)

<br>
