AKY DEVA

Impossible Travel Is Noisy. Watch Tokens and MFA Fatigue

AKY DEVA2 min read

VPN hops look like travel. Stream token reuse, refresh anomalies, and MFA push-spam into your SIEM so analysts can actually act.

Impossible Travel Is Noisy. Watch Tokens and MFA Fatigue

Why “impossible travel” burns out the SOC

A laptop on VPN, then LTE, then a coffee-shop proxy can look like two countries in ten minutes. Coarse IP geolocation floods the queue. Real account takeovers hide in the noise.

You still want location as a hint. You cannot run identity threat detection on that signal alone. You need what happened to the session: tokens, device, MFA prompts.

Stolen tokens look like a normal user

Adversary-in-the-middle kits proxy the login and walk away with cookies or OAuth refresh tokens. After that, MFA does not help. The IdP sees a valid bearer token.

Watch the token, not just the password. User-agent flips, odd refresh patterns, and sudden scope jumps are the tells. AuthOne can stream those events so you revoke the family before the attacker moves laterally.

MFA fatigue is a velocity problem, not a one-off prompt

Push-spam works because platforms treat each tap as an isolated yes/no. Twenty prompts in two minutes is an attack, even if the user eventually approves.

Cap prompt rate. Fall back to a hardware key or number matching. Emit a structured event so the SIEM can page someone — not just log “MFA success.”

Ship identity events in seconds, then auto-revoke

Nightly log dumps are too slow once a session is stolen. Stream issuance, refresh, step-up, and failures into OpenTelemetry or your SIEM as they happen.

When detections fire, call AuthOne to kill refresh tokens and force re-auth across apps. Mean time to respond should be a playbook, not a ticket to find the right admin console.

Need help with identity or security architecture?

Talk to us