Skip to content

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.

Glossary

Cross-tenant impersonation

Okta Security's name for attacks that use a second, attacker-controlled identity provider to sign in to a victim org as its real users.

Cross-tenant impersonation is the term Okta Security used in 2023 for a campaign in which attackers, after taking over Super Administrator accounts through helpdesk social engineering, configured a second identity provider they controlled as a "source" IdP in an inbound federation relationship, then manipulated usernames to match real users in the target org (Okta Security). The result is sign-in as any mapped user. MITRE ATT&CK classes such trust changes as T1484.002. Detection and cleanup are covered in Okta cross-tenant impersonation.

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.