Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Your Identity Provider's Breach Is Your Breach

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2023, written in 2026 with the benefit of hindsight.

The short version: In 2023, attackers broke into Okta's customer support system and stole login sessions from files customers had uploaded for troubleshooting. Some customers detected the attack in their own systems before Okta confirmed it. When your identity provider is breached, every app you sign in to is at risk.

Why your identity provider is the most critical vendor

Your identity provider — Okta, Microsoft Entra ID, Google, Ping — controls access to email, files, finance systems and everything else. A breach there can unlock everything downstream.

The business impact

  • Access to many systems at once.
  • Dependence on the vendor's disclosure, which may be slow or incomplete.
  • Lost trust if the vendor's account of events changes.

Questions to ask your team

  • Do we monitor our identity provider's admin activity ourselves, rather than relying on the vendor?
  • Are admin sessions protected so stolen session tokens can't be reused elsewhere?
  • What do employees share with vendor support — and do they strip out sensitive data first?
  • What's our plan if our identity provider announces a breach?

What good looks like

Independent monitoring of identity provider activity, device-bound and short admin sessions, a policy for sanitizing data shared with support, and an identity provider breach playbook.

The decision

Treat your identity provider as your most critical vendor. Review its security, monitor it independently, and prepare a response plan before you need one.

okta breach 2023 impactOkta support HAR files2023

More on this story