Analyzes and blocks suspicious authentication requests across Okta's global network to prevent credential-based attacks like brute force attempts, password spraying, and credential stuffing. Using machine learning and threat intelligence gathered from Okta's ecosystem, it identifies and blocks malicious IP addresses while maintaining audit logs and offering configurable threat levels and proxy IP exemptions. The system integrates with existing security infrastructure and separates threat blocking from account lockout policies to minimize end-user disruption.