> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/okta-sign-in-threat-detected.md).

# Okta Sign In Threat Detected

Detects users with recent Okta threat-detection sign-in events that may indicate suspicious access.

**Recommended Actions**

Investigate these suspicious sign-in events to verify whether the account has been compromised. If compromise is confirmed, consider killing all sessions and add the user to a quarantine group.

**Compatibility**

[Okta](/integrations/okta-data-integration.md)
