For the complete documentation index, see llms.txt. This page is also available as Markdown.

Suspicious Activity Reported by End User

Detects users who reported suspicious or unrecognized activity to the organization’s admin.

In Microsoft, users can report suspicious activity through the Microsoft Authenticator or via their phone. In Duo, users will report via a Duo Push notification. In Okta, this can be done from an email notification.

Please note that this check requires the "Suspicious Activity Reporting" feature to be configured in Okta, and "Report Suspicious Activity" to be configured in Microsoft.

Recommended Actions

Identity Intelligence recommends you notify the user and admin channel. Identity Intelligence allows the user to say the user made a mistake to reduce false positives. Please review the highlighted activity in the log to see the highlighted session.

Compatibility

Okta

Duo

Microsoft Entra ID

Last updated