> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/active-account-under-heavy-attack.md).

# Active Account Under Heavy Attack

Detects login attempts from an IP address associated with probing attempts against other accounts in the organization. A user will fail this check if Identity Intelligence detects more than 5 probing attempts.<br>

**Recommended Actions**

Contact the end user to verify the origin of the actions. If you cannot verify the login, log the user out.<br>

**Default Check Settings**

Minimum Number of Probing IP Addresses: 5

Evaluation Period (Days): 7

**Compatibility**

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)

[Okta](/integrations/okta-data-integration.md)

[Duo](/integrations/duo-security-integration.md)

[Google Workspace](/integrations/google-workspace-integration.md)

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2Fb3AqNIv8U11f388Rikd4%2FActive%20Account%20Under%20Heavy%20Attack.png?alt=media&amp;token=081d3346-0af2-42ec-b714-156fb84f58b2" alt=""><figcaption></figcaption></figure>

<br>
