> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/sign-in-from-recently-created-idp.md).

# Sign-in from Recently Created IdP

Detects when an administrator successfully signs in into a newly created identity provider.

While this may be a legitimate action (such as logging in to a test IDP), if an attacker were able to perform this action it would enable them to access applications on behalf of others users.

**Recommended Actions**

Please confirm this is a known and expected event. If not, escalate immediately.

**Compatibility**

[Okta](/integrations/okta-data-integration.md)

**Default Detection Settings**

Number of days since idp created: 90
