Wonder if we are ever going to known how this happened.
Curious to know if Okta themselves were using best practices such as only using a hardware token as 2FA (FIDO2) and disabling SMS 2FA and recovery.
Curious to know if Okta themselves were using best practices such as only using a hardware token as 2FA (FIDO2) and disabling SMS 2FA and recovery.
Anyway many legit reasons. Should it set off an alarm? Probably. Can you say before you do it? For sure!