> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/admin-impersonation-in-okta.md).

# Admin Impersonation in Okta

Detects admin impersonation in Okta sessions. Okta allows impersonation for support use cases, but this can be targeted by attackers who can then impersonate other legitimate users.<br>

**Recommended Actions**

Please contact your Okta administrator to ensure the account is authorized to impersonate a user session.

We recommend Okta admins share a Teams/Slack channel and attest that the work was sanctioned, preferably with a ticket.

If the user impersonation session is not legitimate, ensure the target user is returned to a good state and start a security incident.

**Compatibility**

[Okta](/integrations/okta-data-integration.md)

<figure><img src="/files/HErLT6hS6AukoMHPV7VZ" alt=""><figcaption></figcaption></figure>

<br>
