Team Sync Tenant
| action | Description | Sample | Rule |
|---|---|---|---|
| team_ | Team synchronization with a tenant was disabled. | N | Y |
| team_ | Team synchronization with a tenant was enabled. | N | Y |
| team_ | The Okta credentials for team synchronization with a tenant were changed. | N | Y |
team_sync_tenant.disabled
#Description
Team synchronization with a tenant was disabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1195↳ also matches team_sync_tenant.enabled, team_sync_tenant.update_okta_credentials
team_sync_tenant.enabled
#Description
Team synchronization with a tenant was enabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1195↳ also matches team_sync_tenant.disabled, team_sync_tenant.update_okta_credentials
team_sync_tenant.update_okta_credentials
#Description
The Okta credentials for team synchronization with a tenant were changed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1195↳ also matches team_sync_tenant.disabled, team_sync_tenant.enabled