> Support engineers do have access to limited data - for example, Jira tickets and lists of users - that were seen in the screenshots. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. This means they could have reset anybody’s credentials and logged in. There would a record of it if the audit logs are valid, but saying no act…
Off the top of my head: direct database access, http server - could push compromised pages to all Okta users
The AWS keys really could be the keys to the whole proverbial kingdom.