Glossary
Cross-tenant impersonation
Okta Security's name for attacks that use a second, attacker-controlled identity provider to sign in to a victim org as its real users.
Cross-tenant impersonation is the term Okta Security used in 2023 for a campaign in which attackers, after taking over Super Administrator accounts through helpdesk social engineering, configured a second identity provider they controlled as a "source" IdP in an inbound federation relationship, then manipulated usernames to match real users in the target org (Okta Security). The result is sign-in as any mapped user. MITRE ATT&CK classes such trust changes as T1484.002. Detection and cleanup are covered in Okta cross-tenant impersonation.