Anthropic SSO Disabled or Connection Removed
editAnthropic SSO Disabled or Connection Removed
editSSO routes Anthropic authentication through the corporate identity provider. Disabling SSO, or deactivating or deleting an SSO connection, moves users onto alternate sign-in paths where IdP-enforced MFA, conditional access, and session policies no longer apply. That opens the door to password or magic-link accounts the attacker controls.
Rule type: esql
Rule indices: None
Severity: high
Risk score: 73
Runs every: 5m
Searches indices from: now-9m (Date Math format, see also Additional look-back time)
Maximum alerts per execution: 100
References:
Tags:
- Domain: GenAI
- Domain: Identity
- Platform: Anthropic
- Data Source: Anthropic Audit Logs
- Use Case: Identity and Access Audit
- Use Case: Threat Detection
- Resources: Investigation Guide
- Rule Type: ES|QL
- Tactic: Defense Evasion
Version: 1
Rule authors:
- Elastic
Rule license: Elastic License v2
Investigation guide
editTriage and analysis
Investigating Anthropic SSO Disabled or Connection Removed
SSO is the primary path that enforces corporate IdP MFA and session policy. Turning SSO off, or deactivating/deleting a connection, pushes users onto alternate sign-in (password / magic link) the attacker may control.
Severity by action: org_sso_connection_deleted (must re-bind IdP) > org_sso_connection_deactivated >
org_sso_toggled with anthropic.audit.enabled: false.
Unauthorized = no IdP change ticket / maintenance window for this anthropic.audit.connection_id, or a user_actor
change outside known admins, especially with sibling magic-link second-factor disablement or admin role grants.
SCIM-driven events during a documented connector sync are usually FP.
Possible investigation steps
-
Branch on
anthropic.audit.actor.type: -
scim_directory_sync_actor: checkanthropic.audit.directory_id/workos_event_id/idp_connection_typeagainst IdP sync or certificate rotation windows before escalating. -
user_actor: compareuser.email,source.ip, anduser_agent.originalto expected admins; scripting UA or new IP is higher priority. -
Note
event.action,anthropic.audit.connection_id, andorganization.id. Check whether SSO was restored afterward. - Correlate ±hours for magic link second factor changes, admin role grants, invites, or admin API key creation.
False positive analysis
- IdP migrations often deactivate or delete a connection before the replacement is live — match ticket and restore.
Response and remediation
- On unauthorized change: restore or reconfigure SSO immediately, then review accounts that authenticated while SSO was unavailable and rotate credentials for any suspicious successful logins in that window.
Rule query
editfrom logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "iam") and
(
event.action in ("org_sso_connection_deactivated", "org_sso_connection_deleted") or
(event.action == "org_sso_toggled" and anthropic.audit.enabled == false)
)
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Defense Evasion
- ID: TA0005
- Reference URL: https://attack.mitre.org/tactics/TA0005/
-
Technique:
- Name: Modify Authentication Process
- ID: T1556
- Reference URL: https://attack.mitre.org/techniques/T1556/