heroui logo

Anthropic Magic Link Second Factor Disabled

Elastic Detection Rules

View Source
Summary
Detects when an administrator disables the magic-link second factor for Anthropic passwordless sign-in by inspecting audit logs for a configuration-change event: org_magic_link_second_factor_toggled with anthropic.audit.enabled set to false. This enables magic-link logins to bypass the second factor, creating a fallback path that can be exploited if SSO is weakened. The rule maps to MITRE ATT&CK: T1556 Modify Authentication Process, with subtechnique T1556.006 MFA, under the Defense Evasion tactic. Investigations should correlate the actor type, user/email, source IP, and user_agent with the organization, and look for concurrent SSO changes within the same time window. False positives include legitimate maintenance or policy changes; confirm tickets and restoration evidence. Remediation includes re-enabling the second factor, reviewing subsequent magic-link sign-ins, and auditing related IAM/SAML and IdP events.
Categories
  • Identity Management
  • Endpoint
  • Application
Data Sources
  • Logon Session
ATT&CK Techniques
  • T1556
  • T1556.006
Created: 2026-09-12