Breached credentials protection

This feature helps you detect breached credentials in your Okta environment and customize their remediation.

Okta monitors third-party lists of public data breaches for username-password combinations in your org. When a user signs in, Okta checks if their credentials appear in a list. If so, Okta expires the password according to the password policy configuration, and the results can include user logout, password expiry, and custom workflows. Okta records the security.breached_credential.detected event in the System Log, and the user is required to reset their password the next time they attempt to sign in.

How it works

Breached credentials protection is a security setting in your password policy.

The password authenticator is active by default for Okta users, and its policy controls password requirements like complexity, age, minimum length, and lock out settings. The breached credential protection feature adds Password Security options to this policy, so that you can expire the password early or perform custom actions through Okta Workflows if breached credentials are detected. Okta provides sample credentials that you can use to test your Password Security settings.

After you configure the feature, Okta begins detection and remediation whenever the credentials are used to sign in. Because the check happens during sign-in requests and self-service password resets, this feature doesn't retroactively check for breached credentials.

Enhanced breached credentials protection is an additional service that's available through Identity Threat Protection for Okta Customer Identity (ITP for OCI). Where breached credentials protection relies on publicly available breach data, enhanced breached credentials protection proactively screens for breaches to allow faster notification of compromised credentials.

Enhanced breached credentials protection is on by default for ITP customers. You can switch to standard breached credentials protection on the Identity Threat Protection page.

Topics

Configure breached credentials protection

Test your breached credentials protection configuration

User experience with breached credentials protection