Certain Okta rules unexpectedly changed to passing

Incident Report for Obsidian Security

Resolved

The incident has been resolved.
Thank you for your cooperation.
If you experience any further issues, please don't hesitate to reach out to our support team
Posted Aug 15, 2024 - 17:05 PDT

Update

The root cause has been identified, and a fix is currently under review.
Posted Aug 15, 2024 - 14:53 PDT

Identified

The issue has been identified and a fix is being implemented.
Posted Aug 15, 2024 - 14:48 PDT

Investigating

We are currently investigating an issue impacting a subset of Okta posture rules.
Impacted customers may find that the rules noted below will have unexpectedly moved from a failing to passing state.
In the course of addressing the underlying cause, and rules being reverted to their proper state, posture drift alerts may be received.
#Global session policies with long max session lifetime
#Global session policies without MFA required
#Policies in Okta with zero assigned rules
#Global session policies with long session timeout
#Users only covered by the default global session sign-on rule
# Sign-on policies with MFA required on new devices only
Posted Aug 15, 2024 - 14:48 PDT
This incident affected: Posture Management.