Locking sessions to a single ASN is probably a good idea. I always worry about the "insider threats" where your coworker sitting next to you grabs your cookie out of the Chrome inspector while you're in the bathroom, and this doesn't really help with that situation. But, it does help a lot with the attack that compromised Okta here, so I think it's a good idea in general.
(Obviously you should always lock your screen when you step away from your workstation... but people seem pretty bad about that. At my last in-person job, I don't think anyone ever locked their screen when stepping away. So that's what makes this something I would worry about.)
(Obviously you should always lock your screen when you step away from your workstation... but people seem pretty bad about that. At my last in-person job, I don't think anyone ever locked their screen when stepping away. So that's what makes this something I would worry about.)