Okta App

eventTypeDescriptionSampleRule
app.access_request.approver.approveRequest to access an app was approved by an administrator-defined approver.NN
app.access_request.approver.denyRequest to access an app was denied by an administrator-defined approver.NN
app.access_request.deleteRequest to access an app was deleted by an administrator.NN
app.access_request.denyRequest to access an app was denied after at least one approver denied the request.NN
app.access_request.expireRequest to access an app expired by the system due to lack of approver action.NN
app.access_request.grantRequest to access an app was granted after all approvers approved the request.NN
app.access_request.requestRequest to access an app was performed by a user.NN
app.ad.api.user_import.account_lockedActive Directory user account set to locked following profile update: user is locked in active directory.NN
app.ad.api.user_import.warn.skipped_contact.attribute_invalid_valueSkipping import of contact due to invalid attribute.NN
app.ad.api.user_import.warn.skipped_user.attribute_invalid_valueSkipping import of user due to an invalid AD attribute.NN
app.ad.api.user_import.warn.skipped_user.missing_required_attributeSkipping import of user due to a required AD attribute being null.NN
app.ad.password_migration_campaign.cancel.endComplete cancellation of migration campaign.NN
app.ad.password_migration_campaign.cancel.startStart cancellation of a password migration campaign.NN
app.ad.password_migration_campaign.createCreate Active Directory password migration campaign.NN
app.ad.password_migration_campaign.finish.endComplete password migration campaign.NN
app.ad.password_migration_campaign.finish.startStart password migration campaign completion.NN
app.ad.password_migration_campaign.group.addAdd group to Active Directory password migration campaign.NN
app.ad.password_migration_campaign.user.capture_passwordCapture user password from Active Directory.NN
app.ad.password_migration_campaign.user.migrate.endComplete individual user password migration.NN
app.ad.password_migration_campaign.user.migrate.startStart individual user password migration.NN
app.ai_agent_provider.activateActivate an AI agent provider.NN
app.ai_agent_provider.createCreate an AI agent provider.NN
app.ai_agent_provider.credential.validateValidate credentials for an AI agent import provider.NN
app.ai_agent_provider.deactivateDeactivate an AI agent provider.NN
app.ai_agent_provider.deleteDelete an AI agent provider.NN
app.ai_agent_provider.import.completeComplete a bulk import of AI agents from an external provider.NN
app.ai_agent_provider.import.startStart a bulk import of AI agents from an external provider.NN
app.ai_agent_provider.updateUpdate an AI agent provider.NN
app.app_instance.csr.generateCertificate signing request (CSR) generated.NN
app.app_instance.csr.publishCertificate signing request (CSR) published.NN
app.app_instance.csr.revokeCertificate signing request (CSR) revoked.NN
app.app_instance.provision_sync_job.completedFired when a provision sync job has successfully completed.NN
app.app_instance.provision_sync_job.failedFired when a provision sync job has failed.NN
app.app_instance.provision_sync_job.startedFired when a provision sync job has successfully started.NN
app.cross_app_access.connection.createCreate Cross App Access connection.NN
app.cross_app_access.connection.deleteDelete Cross App Access connection.NN
app.cross_app_access.connection.updateUpdate Cross App Access connection.NN
app.generic.unauth_app_access_attemptUser attempted unauthorized access to app.YY
app.inbound_del_auth.login_successSuccessful inbound delegated authentication request for user.NN
app.interclient_mapping.createCreate interclient trust mapping.NN
app.interclient_mapping.deleteDelete interclient trust mapping.NN
app.interclient_mapping.delete_allDelete all interclient trust mappings for app.NN
app.kerberos_rich_client.account_not_foundKerberos based rich client authentication failed: Could not find Office 365 app user for the AD user with principal id.NN
app.kerberos_rich_client.instance_not_foundKerberos based rich client authentication failed: Unknown app instance id.NN
app.kerberos_rich_client.multiple_accounts_foundKerberos based rich client authentication failed: Multiple users with username found.NN
app.kerberos_rich_client.user_authentication_successfulKerberos based rich client authentication successful for Office 365 user.NN
app.keys.cloneApplication signing key cloned.NN
app.keys.generateNew signing key generated.NN
app.keys.rotateApplication signing key rotated.NN
app.ldap.password.change.failedPassword change failed.NN
app.oauth2.admin.consent.grantAdministrator consent granted for scope.YN
app.oauth2.admin.consent.revokeAdministrator consent revoked for scope.NN
app.oauth2.as.authorizeOAuth2 authorization request.YN
app.oauth2.as.authorize.codeOAuth2 authorization code request.YN
app.oauth2.as.authorize.implicit.access_tokenOAuth2 authorization implicit access token request.NN
app.oauth2.as.authorize.implicit.id_tokenOAuth2 authorization implicit ID token request.NN
app.oauth2.as.authorize.scope_deniedSome of the requested scopes were denied by the policy.NN
app.oauth2.as.consent.grantUser granted consent to app.NN
app.oauth2.as.consent.revokeConsent revoked.NN
app.oauth2.as.consent.revoke.implicit.asAll consent revoked for authorization server.NN
app.oauth2.as.consent.revoke.implicit.clientAll consent revoked for client.YN
app.oauth2.as.consent.revoke.implicit.scopeAll consent revoked for scope.NN
app.oauth2.as.consent.revoke.implicit.userConsent for all scopes revoked for user.NN
app.oauth2.as.consent.revoke.userAll consent revoked for user.NN
app.oauth2.as.consent.revoke.user.clientUser consent revoked for client.NN
app.oauth2.as.evaluate.claimClaim evaluation for OAuth 2.0 token.NN
app.oauth2.as.interact.interaction_codeInteraction code is generated by OIE.NN
app.oauth2.as.interact.interaction_handleInteraction handle is generated by OIE.NN
app.oauth2.as.key.rolloverCustom Authorization Server token signing key rolled over.YN
app.oauth2.as.resource_server.credentials.lifecycle.activateAuthorization server access token encryption key is activated.NN
app.oauth2.as.resource_server.credentials.lifecycle.createAuthorization server access token encryption key is created.NN
app.oauth2.as.resource_server.credentials.lifecycle.deactivateAuthorization server access token encryption key is deactivated.NN
app.oauth2.as.resource_server.credentials.lifecycle.deleteAuthorization server access token encryption key is deleted.NN
app.oauth2.as.token.detect_reuseDetect one-time refresh token attempted reuse. This event can be used by administrators to detect and audit attempted reuse of one-time refresh tokens.NY
app.oauth2.as.token.grantOAuth2 token request.YY
app.oauth2.as.token.grant.access_tokenOAuth 2.0 access token is granted.YN
app.oauth2.as.token.grant.device_secretGrant an OAuth2 device_secret for the Native SSO flow.NN
app.oauth2.as.token.grant.id_tokenOAuth 2.0 ID token is granted.YN
app.oauth2.as.token.grant.interclient_tokenGrant interclient token. Track the successful issuance of an Interclient token via OAuth token exchange.NN
app.oauth2.as.token.grant.refresh_tokenOAuth2 refresh token is granted.YN
app.oauth2.as.token.revokeOAuth2 token revocation request.NN
app.oauth2.authorizeOIDC authorization request.YN
app.oauth2.authorize.codeOIDC authorization code request.YN
app.oauth2.authorize.implicit.access_tokenOIDC authorization implicit access token request.NN
app.oauth2.authorize.implicit.id_tokenOIDC authorization implicit ID token request.NN
app.oauth2.client.lifecycle.activateActivate OAuth client.YN
app.oauth2.client.lifecycle.createCreate OAuth client.YN
app.oauth2.client.lifecycle.deactivateDeactivate OAuth client.YN
app.oauth2.client.lifecycle.deleteDelete OAuth client.YN
app.oauth2.client.lifecycle.updateUpdate OAuth client.YN
app.oauth2.client.privilege.grantAn OAuth 2.0 client app's admin privileges changed.YN
app.oauth2.client.privilege.revokeAll privileges for OAuth 2.0 client app were revoked.YN
app.oauth2.client.read_client_secretRead OAuth client's secret(s).YN
app.oauth2.client_id_rate_limit_warningRequests from a single client ID consumed the majority of an organization's OAuth2 endpoint rate limit.NN
app.oauth2.consent.grantUser granted consent to app. This event can be used to identify the org AS consent grant.NN
app.oauth2.credentials.lifecycle.activateOAuth client credentials (either client secret or JWK) is added for an application.YN
app.oauth2.credentials.lifecycle.createOAuth client credentials (either client secret or JWK) is activated for an application.YN
app.oauth2.credentials.lifecycle.deactivateOAuth client credentials (either client secret or JWK) is deactivated for an application.YN
app.oauth2.credentials.lifecycle.deleteOAuth client credentials (either client secret or JWK) is deleted for an application.YN
app.oauth2.interact.interaction_codeInteraction code generated by OIE.NN
app.oauth2.interact.interaction_handleInteraction handle generated by OIE.NN
app.oauth2.invalid_client_credentialsMultiple requests with invalid client credentials for client id.NN
app.oauth2.key.rolloverOrg Authorization Server token signing key rolled over.NN
app.oauth2.signonUser performed OIDC single sign on to app.NN
app.oauth2.token.detect_reuseDetect one-time refresh token attempted reuse. This event can be used by administrators to detect and audit attempted reuse of one-time refresh tokens.NY
app.oauth2.token.grantOIDC token request.YN
app.oauth2.token.grant.access_tokenOIDC access token is granted.YN
app.oauth2.token.grant.id_jagOAuth 2.0 Identity Assertion JWT Authorization Grant (ID-JAG) granted.NN
app.oauth2.token.grant.id_tokenOIDC id token is granted.YN
app.oauth2.token.grant.interclient_tokenGrant interclient token. Track the successful issuance of an Interclient token via OAuth token exchange.NN
app.oauth2.token.grant.oauth_stsGrant OAuth Security Token Service (STS) access token.NN
app.oauth2.token.grant.refresh_tokenOIDC refresh token is granted.YN
app.oauth2.token.grant.service_accountGrant Okta Privileged Access service account credentials.NN
app.oauth2.token.grant.vaulted_secretGrant Okta Privileged Access vaulted secret.NN
app.oauth2.token.oauth_sts.request_tokenRequest OAuth tokens from a third-party authorization server.NN
app.oauth2.token.revokeOIDC token revocation request.YN
app.oauth2.token.revoke.implicit.asTokens revoked for authorization server.NN
app.oauth2.token.revoke.implicit.clientTokens revoked for client.NN
app.oauth2.token.revoke.implicit.userTokens revoked for user.YN
app.oauth2.trusted_server.addTrusted authorization server is added.NN
app.oauth2.trusted_server.deleteTrusted authorization server is removed.NN
app.office365.api.change.domain.federation.successSuccessfully updated the domain federation from old settings to new settings.NN
app.office365.api.error.ad.userUser is assigned to more than one instance of Active Directory, could not set Immutable ID.NN
app.office365.api.error.check.user.existsCould not determine status of Office 365 user, received error.NN
app.office365.api.error.create.userCould not create user in Office 365, received error.NN
app.office365.api.error.deactivate.userCould not deactivate Office 365 user, received error.NN
app.office365.api.error.download.custom.objectsCould not download group/role/license data for your Office 365 instance, received error.NN
app.office365.api.error.download.groupsCould not download all groups from your Office 365 instance, received error.NN
app.office365.api.error.download.usersCould not download all users from your Office 365 instance, received error.NN
app.office365.api.error.endpoint.unavailableUnable to reach the Office 365 endpoint.NN
app.office365.api.error.get.company.dirsync.failureUnable to read Office 365 directory sync for the company, received error.NN
app.office365.api.error.get.company.dirsync.status.failureUnable to provision user to Office 365, because 'Directory Sync' value in Azure Active Directory is unsupported.NN
app.office365.api.error.get.company.dirsync.status.pendingUnable to provision user to Office 365, because 'Directory Sync' value in Azure Active Directory not yet in Activated state.NN
app.office365.api.error.get.object.ids.by.group.idCould not get users by group id from your Office 365 instance, received error.NN
app.office365.api.error.group.create.failureCould not create Office 365 group, received error.NN
app.office365.api.error.group.create.failure.name.in.useCould not create Office 365 group because the name is already in use, received error.NN
app.office365.api.error.group.delete.failureCould not delete Office 365 group, received error.NN
app.office365.api.error.group.membership.update.failureCould not update the Office 365 group membership, received error.NN
app.office365.api.error.group.membership.update.group.not.found.failureCould not update the Office 365 group membership because the group could not be found, received error.NN
app.office365.api.error.group.update.failureCould not update Office 365 group, received error.NN
app.office365.api.error.group.update.failure.not.foundCould not update Office 365 group because it was not found, received error.NN
app.office365.api.error.import.profileCould not import profile for Office 365 user, received error.NN
app.office365.api.error.push.passwordCould not push password for Office 365 user, received error.NN
app.office365.api.error.push.profileCould not push profile for Office 365 user, received error.NN
app.office365.api.error.reactivate.userCould not reactivate Office 365 user, received error.NN
app.office365.api.error.remove.domain.federation.failureUnable to remove the domain federation, received error.NN
app.office365.api.error.remove.domain.federation.failure.access.deniedUnable to remove the domain federation because the admin user is not authorized to perform the task.NN
app.office365.api.error.remove.domain.federation.failure.domain.not.foundUnable to remove the domain federation because the specified domain was not found.NN
app.office365.api.error.revoke.refresh.tokenFailed to revoke refresh tokens for user.NN
app.office365.api.error.set.company.dirsync.failureUnable to enable Office 365 directory sync for the company, received error.NN
app.office365.api.error.set.company.dirsync.status.failureUnable to enable Office 365 directory sync for the company, because 'Directory Sync' value in Azure Active Directory is unsupported.NN
app.office365.api.error.set.domain.federation.failureUnable to setup the domain federation, received error.NN
app.office365.api.error.set.domain.federation.failure.access.deniedUnable to setup the domain federation because the admin user is not authorized to perform the task.NN
app.office365.api.error.set.domain.federation.failure.domain.defaultUnable to setup the domain federation because the specified domain is the default domain.NN
app.office365.api.error.set.domain.federation.failure.domain.not.foundUnable to setup the domain federation because the specified domain was not found.NN
app.office365.api.error.sync.contactFailed to sync contact, received error.NN
app.office365.api.error.sync.finalizeFailed to finalize export to Office 365, received error.NN
app.office365.api.error.sync.groupFailed to sync group, received error.NN
app.office365.api.error.sync.not.activatedSync could not execute because Office 365 directory sync for the company not yet Activated.NN
app.office365.api.error.sync.set.attributeFailed to set attribute, received error.NN
app.office365.api.error.sync.userFailed to sync user, received error.NN
app.office365.api.error.unable.to.create.graph.clientAn error occurred while creating the Azure Active Directory Graph API client.NN
app.office365.api.error.validate.admin.credsUser does not have the Company Administrator role.NN
app.office365.api.error.validate.credsCould not validate your Office 365 credentials, received error.NN
app.office365.api.error.x-ms-forwarded-client-ip-header.absentX-MS-Forwarded-Client-IP header either empty or not found in the request.NN
app.office365.api.remove.domain.federation.successSuccessfully removed the domain federation.NN
app.office365.api.set.domain.federation.successSuccessfully set up the domain federation with new settings.NN
app.office365.api.sync.completeUser sync completed.NN
app.office365.api.sync.heartbeat.sentHeartbeat sent to Microsoft Azure Active Directory.NN
app.office365.api.sync.job.completeSync job completed.NN
app.office365.api.sync.job.complete.contactSync job completed.NN
app.office365.api.sync.job.complete.groupSync job completed.NN
app.office365.api.sync.job.complete.userSync job completed.NN
app.office365.clientplatform.conversion.job.processing.app.instanceBegin processing client access conversion for app instance.NN
app.office365.clientplatform.conversion.job.skipping.migrationSkipping migration of client access rules for app instance.NN
app.office365.dirsync.skipping.conflict-objectSkipping sync of conflict object.NN
app.office365.dirsync.skipping.critical-system-objectSkipping sync of critical system object.NN
app.office365.dirsync.skipping.non-security-group-invalid-mailSkipping sync of non security object with invalid mail.NN
app.office365.dirsync.skipping.reserved-attribute-valueSkipping sync of object with reserved attribute value.NN
app.office365.dirsync.skipping.systemmailboxSkipping sync of system mailbox object.NN
app.office365.dirsync.skipping.without-name-and-displaynameSkipping sync of non security object without name and display name.NN
app.office365.error.importing.userAn error occurred while importing user.NN
app.office365.graph.api.error.no.mailbox.foundNo MailBox found for Office 365 user.NN
app.office365.graph.api.error.rate-limit.exceededRate limit exceeded for Microsoft Graph.NN
app.office365.graph.api.error.service.principal.creation.failedFailure while trying to create service principal.NN
app.office365.graph.api.error.service.principal.msgraph.authentication.failureFailure while trying to create service principal due to a Mircrosoft Graph authentication issue.NN
app.office365.service.principal.cleanup.job.completeEnd processing Office 365 service principal cleanup.NN
app.office365.service.principal.cleanup.job.invalid.credentialsThe admin username or password is invalid.NN
app.office365.service.principal.cleanup.job.processingBegin performing Office 365 service principal cleanup.NN
app.office365.service.principal.cleanup.job.skipping.missing.credsSkipping app instance during Office 365 service principal cleanup as it does not contain Office 365 admin user credentials.NN
app.office365.service.principal.cleanup.job.skipping.no.service.principalSkipping app instance during Office 365 service principal cleanup as it does not have a service principal.NN
app.office365.service.principal.cleanup.job.unable.to.delete.service.principalUnable to automatically delete the Office 365 service principal.NN
app.office365.user.delete.successSuccessfully deleted the Office 365 user.NN
app.office365.user.lifecycle.action.failedUnable to complete app user lifecycle action for AppUser.NN
app.office365.user.remove.licenses.successSuccessfully removed all the licenses for the Office 365 user.NN
app.policy.sign_on.updateUpdate app sign on policy.NN
app.radius.agent.listener.failedRadius agent listener failed.NN
app.radius.agent.listener.succeededRadius agent listener succeeded.NN
app.radius.agent.port_inaccessibleRadius agent failed to listen on port.NN
app.radius.agent.port_reaccessibleRadius agent was able to listen on port again.NN
app.radius.info_access.no_permissionNo permission accessing any Radius app info.NN
app.radius.info_access.partial_permissionNo permission accessing info for part of Radius apps.NN
app.realtimesync.import.details.add_userReal time sync added new User.NN
app.realtimesync.import.details.delete_userReal time sync removed existing User.NN
app.realtimesync.import.details.update_userFired when a real time import includes an update to an existing user.YN
app.request_new.notifyA user sent an application request.NN
app.rum.config.validation.errorError validating instance configuration.NN
app.rum.is.api.account.errorRUM API account is not configured or empty.NN
app.rum.package.thrown.errorErrors during execution.NN
app.rum.validation.errorError during package validation.NN
app.saml.sensitive.attribute.updateFired when a SAML assertion contains a sensitive attribute, and that sensitive attribute has been updated (modified/added/deleted).NN
app.user_managementImported new or deleted existing member of an application group.YN
app.user_management.grouppush.mapping.created.from.ruleA Group Push mapping to the group has been created from the rule.YN
app.user_management.grouppush.mapping.created.from.rule.error.duplicateA Group Push mapping to the group did not get created from rule because an existing mapping already existed.YN
app.user_management.grouppush.mapping.created.from.rule.error.validationA Group Push mapping to the group did not get created from rule because of the validation error.NN
app.user_management.grouppush.mapping.created.from.rule.errorsA Group Push mapping to the group did not get created from rule.NN
app.user_management.grouppush.mapping.okta.users.ignoredOkta users ignored while pushing group to AppInstance.NN
app.user_management.import.csv.line.errorError reading line from CSV.NN
app.user_management.push_new_user_successSuccessfully pushed new user account to app.YN
app.user_management.update_from_master_failedCould not apply import.NN
app.user_management.user_group_import.create_failureFailed to create group from app.NN
app.user_management.user_group_import.delete_successDeleted the group from app.YN
app.user_management.user_group_import.update_failureFailed to update group from app.NN
app.user_management.user_group_import.upsert_failFailed to import the group from app.NN
app.user_management.user_group_import.upsert_successImported the group from app.NN
app.ad.credential.verifyVerify a stored Active Directory credential is valid.NN
app.ai_agent_provider.import_staging.confirmConfirm an AI agent staging item for registration.NN
app.ai_agent_provider.import_staging.ignoreIgnore an AI agent staging item.NN
app.ai_agent_provider.priority.updateUpdate the priority ordering of AI agent import providers.NN
app.office365.provisioning_app.createCreates a dedicated Microsoft Entra ID app that's registered and used for Office 365 provisioning.NN
app.office365.provisioning_app_credential.rotateRotates the client secret of the registered Microsoft Entra ID app that's used for Office 365 provisioning.NN

app.access_request.approver.approve

#

Description

Request to access an app was approved by an administrator-defined approver.

References #

app.access_request.approver.deny

#

Description

Request to access an app was denied by an administrator-defined approver.

References #

app.access_request.delete

#

Description

Request to access an app was deleted by an administrator.

References #

app.access_request.deny

#

Description

Request to access an app was denied after at least one approver denied the request.

References #

app.access_request.expire

#

Description

Request to access an app expired by the system due to lack of approver action.

References #

app.access_request.grant

#

Description

Request to access an app was granted after all approvers approved the request.

References #

app.access_request.request

#

Description

Request to access an app was performed by a user.

References #

app.ad.api.user_import.account_locked

#

Description

Active Directory user account set to locked following profile update: user is locked in active directory.

References #

app.ad.api.user_import.warn.skipped_contact.attribute_invalid_value

#

Description

Skipping import of contact due to invalid attribute. Please consult with your Active Directory admin if you believe this contact should be imported.

References #

app.ad.api.user_import.warn.skipped_user.attribute_invalid_value

#

Description

Skipping import of user due to an invalid AD attribute.

References #

app.ad.api.user_import.warn.skipped_user.missing_required_attribute

#

Description

Skipping import of user due to a required AD attribute being null.

References #

app.ad.password_migration_campaign.cancel.end

#

Description

Complete cancellation of migration campaign. This can be used to confirm that the process to cancel a password migration campaign intentionally is complete. This event marks the end of the cancellation process that began with an app.ad.password_migration_campaign.cancel.start event.

References #

app.ad.password_migration_campaign.cancel.start

#

Description

Start cancellation of a password migration campaign. This can be used to track when the process to intentionally cancel a password migration campaign begins. This begins an asynchronous process. Its conclusion is marked by the app.ad.password_migration_campaign.cancel.end event.

References #

app.ad.password_migration_campaign.create

#

Description

Create Active Directory password migration campaign. This can be used to identify when a migration is created to monitor its duration and impact on users. Marks the beginning of a password migration campaign.

References #

app.ad.password_migration_campaign.finish.end

#

Description

Complete password migration campaign. This can be used to confirm that a Finish password migration campaign process has fully completed. This event marks the successful end of the entire campaign lifecycle. This is an asynchronous process and is preceded by an app.ad.password_migration_campaign.finish.start event.

References #

app.ad.password_migration_campaign.finish.start

#

Description

Start password migration campaign completion. This can be used to track the start of the Finish Campaign process. This begins an asynchronous process. Its conclusion is marked by the app.ad.password_migration_campaign.finish.end event.

References #

app.ad.password_migration_campaign.group.add

#

Description

Add group to Active Directory password migration campaign. This can be used to identify groups that have been included in a password migration campaign. This action expands the set of users eligible for password capture by the campaign.

References #

app.ad.password_migration_campaign.user.capture_password

#

Description

Capture user password from Active Directory. This can be used to track progress for individual users and confirm password collection. This event does not signify the full migration of the user, only the successful capture of their password.

References #

app.ad.password_migration_campaign.user.migrate.end

#

Description

Complete individual user password migration. This can be used as a record that a user's credential is fully migrated to Okta. The user's password is now fully migrated and active in Okta.

References #

app.ad.password_migration_campaign.user.migrate.start

#

Description

Start individual user password migration. This can be used to confirm that a specific user's migration process has begun. The conclusion of this asynchronous process is marked by a corresponding app.ad.password_migration_campaign.user.migrate.end event.

References #

app.ai_agent_provider.activate

#

Description

Activate an AI agent provider. Track when an AI agent import provider is enabled for scheduled imports.

References #

app.ai_agent_provider.create

#

Description

Create an AI agent provider. Track when a new connection to an external AI agent provider is established for importing agents.

References #

app.ai_agent_provider.credential.validate

#

Description

Validate credentials for an AI agent import provider. Verify that credentials for an AI agent import provider are valid before activating the provider. Typically follows provider.credential.update and precedes provider.activate.

References #

app.ai_agent_provider.deactivate

#

Description

Deactivate an AI agent provider. Track when an AI agent import provider is disabled.

References #

app.ai_agent_provider.delete

#

Description

Delete an AI agent provider. Track when a connection to an external AI agent provider is removed.

References #

app.ai_agent_provider.import.complete

#

Description

Complete a bulk import of AI agents from an external provider. Audit the outcome of AI agent imports, including the number of agents found, imported, and errored. Paired with app.ai_agent_provider.import.start. Import outcome details are in the targets.

References #

app.ai_agent_provider.import.start

#

Description

Start a bulk import of AI agents from an external provider. Audit when bulk imports of AI agents from external providers begin. A corresponding app.ai_agent_provider.import.complete event is fired when the import completes.

References #

app.ai_agent_provider.update

#

Description

Update an AI agent provider. Track AI agent import provider changes, such as credential configuration, owner info, and schedule updates. This event refers to the OAuth2 credentials used to connect to an external AI agent provider. For AI agent workload identity credentials (JWK signing keys), see workload_principal.ai_agent.credential.* events.

References #

app.app_instance.csr.generate

#

Description

Certificate signing request (CSR) generated.

References #

app.app_instance.csr.publish

#

Description

Certificate signing request (CSR) published.

References #

app.app_instance.csr.revoke

#

Description

Certificate signing request (CSR) revoked.

References #

app.app_instance.provision_sync_job.completed

#

Description

Fired when a provision sync job has successfully completed. This can be used to confirm that a provision sync job has finished running and is no longer processing users. When fired, this event contains details about number of users processed in the job. Related events include app.app_instance.provision_sync_job.started and app.app_instance.provision_sync_job.failed.

References #

app.app_instance.provision_sync_job.failed

#

Description

Fired when a provision sync job has failed. This can be used to identify when a provision sync job has failed. When fired, this event contains information about the reason the provision sync job failed. Related events include app.app_instance.provision_sync_job.started and app.app_instance.provision_sync_job.completed.

References #

app.app_instance.provision_sync_job.started

#

Description

Fired when a provision sync job has successfully started. This can be used to confirm that a provision sync job has successfully started. Related events include app.app_instance.provision_sync_job.completed and app.app_instance.provision_sync_job.failed.

References #

app.cross_app_access.connection.create

#

Description

Create Cross App Access connection. Audit when a requesting application is configured to connect with one or more resource applications. This is useful for security investigations and for compliance reviews of inter-application trust establishment.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

References #

app.cross_app_access.connection.delete

#

Description

Delete Cross App Access connection. Audit when existing Cross App Access connections are removed. This is useful for tracking application lifecycle management and for security posture cleanup of inter-application trust relationships.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

References #

app.cross_app_access.connection.update

#

Description

Update Cross App Access connection. Audit when existing Cross App Access connection configuration is modified, such as toggling enabled status. The changeDetails field tracks specific modifications. It is useful for generating alerts about unexpected changes to inter-application trusts.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

References #

app.generic.unauth_app_access_attempt

#

Description

User attempted unauthorized access to app.

Example System Log Event #

{
  "actor": {
    "alternateId": "user02@dw-harness.example",
    "detailEntry": null,
    "displayName": "DW Harness 02",
    "id": "00u00000000000000002",
    "type": "User"
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": null,
    "externalSessionId": null,
    "interface": null,
    "issuer": null
  },
  "client": {
    "device": "Computer",
    "geographicalContext": {
      "city": "Anytown",
      "country": "Placeholderland",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      },
      "postalCode": "00000",
      "state": "Anystate"
    },
    "id": null,
    "ipAddress": "198.51.100.2",
    "userAgent": {
      "browser": "CHROME",
      "os": "Mac OS 13.4.0 (Ventura)",
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
    },
    "zone": "null"
  },
  "debugContext": {
    "debugData": {
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestId": "00000000000000000000000000000003",
      "requestUri": "/error/enduser-error-page",
      "url": "/error/enduser-error-page?error_description=The+resource+owner+or+authorization+server+denied+the+request."
    }
  },
  "device": null,
  "displayMessage": "User attempted unauthorized access to app",
  "eventType": "app.generic.unauth_app_access_attempt",
  "legacyEventType": "app.generic.unauth_app_access_attempt",
  "outcome": {
    "reason": null,
    "result": "FAILURE"
  },
  "published": "2024-02-29T22:50:39.032Z",
  "request": {
    "ipChain": [
      {
        "geographicalContext": {
          "city": "Anytown",
          "country": "Placeholderland",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          },
          "postalCode": "00000",
          "state": "Anystate"
        },
        "ip": "198.51.100.3",
        "source": null,
        "version": "V4"
      }
    ]
  },
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "domain": "example.com",
    "isProxy": false,
    "isp": "example-isp"
  },
  "severity": "WARN",
  "target": [
    {
      "alternateId": "Okta Dashboard",
      "detailEntry": null,
      "displayName": "Okta Dashboard",
      "id": "0oa00000000000000003",
      "type": "AppInstance"
    }
  ],
  "transaction": {
    "detail": {},
    "id": "00000000000000000000000000000003",
    "type": "WEB"
  },
  "uuid": "00000000-0000-0000-0000-000000000002",
  "version": "0"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
event_action (splunk rule field)eqfailure1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Splunk #

  • Okta Unauthorized Access to Application source: The following analytic identifies attempts by users to access Okta applications that have not been assigned to them. It leverages Okta Identity Management logs, specifically focusing on failed access attempts to unassigned applications.…T1087, T1087.004

Panther #

References #

app.inbound_del_auth.login_success

#

Description

Successful inbound delegated authentication request for user.

References #

app.interclient_mapping.create

#

Description

Create interclient trust mapping. Audit the creation of a trust mapping between a target app and a requesting app via the interclient access API.

References #

app.interclient_mapping.delete

#

Description

Delete interclient trust mapping. Audit the deletion of a trust mapping between a target app and a requesting app via the interclient access API.

References #

app.interclient_mapping.delete_all

#

Description

Delete all interclient trust mappings for app. Identify the automatic cleanup of all trust mappings associated with a deleted application instance.

References #

app.kerberos_rich_client.account_not_found

#

Description

Kerberos based rich client authentication failed: Could not find Office 365 app user for the AD user with principal id.

References #

app.kerberos_rich_client.instance_not_found

#

Description

Kerberos based rich client authentication failed: Unknown app instance id.

References #

app.kerberos_rich_client.multiple_accounts_found

#

Description

Kerberos based rich client authentication failed: Multiple users with username found.

References #

app.kerberos_rich_client.user_authentication_successful

#

Description

Kerberos based rich client authentication successful for Office 365 user.

References #

app.keys.clone

#

Description

Application signing key cloned.

References #

app.keys.generate

#

Description

New signing key generated.

References #

app.keys.rotate

#

Description

Application signing key rotated.

References #

app.ldap.password.change.failed

#

Description

Password change failed.

References #

app.oauth2.admin.consent.grant

#

app.oauth2.admin.consent.revoke

#

app.oauth2.as.authorize

#

Description

OAuth2 authorization request.

Example System Log Event #

{
  "published": 1780087984977,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000010",
  "actor": {
    "id": "0oa00000000000000040",
    "type": "PublicClientApp",
    "alternateId": "user09@dw-harness.example",
    "displayName": "DW Harness 12",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36",
      "os": "Windows 10",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": "0oa00000000000000040",
    "ipAddress": "192.0.2.11",
    "geographicalContext": {
      "city": null,
      "state": null,
      "country": "Placeholderland",
      "postalCode": null,
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0000002",
      "type": "AuthorizationServer",
      "alternateId": null,
      "displayName": "DW Harness 13",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": "illegal_redirect_uri_enhanced"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.11",
        "geographicalContext": {
          "city": null,
          "state": null,
          "country": "Placeholderland",
          "postalCode": null,
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.as.authorize",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000004",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "redirectUri": "https://app.example.com/oauth2/idpresponse",
      "grantedScopes": "",
      "responseType": "code",
      "authorizationServer": "default",
      "requestId": "00000000000000000000000000000004",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000003",
      "requestUri": "/oauth2/default/v1/authorize",
      "requestedScopes": "openid",
      "state": "Anystate",
      "threatSuspected": "false",
      "defaultAuthorizationServer": "false",
      "url": "/oauth2/default/v1/authorize?client_id=0ln00000000000000041&redirect_uri=00000000000000000000000000000000000000000000000002&response_type=code&scope=openid&state=00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002"
    }
  },
  "displayMessage": "OAuth2 authorization request",
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.as.authorize_failure",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": null,
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

References #

app.oauth2.as.authorize.code

#

Description

OAuth2 authorization code request.

Example System Log Event #

{
  "published": 1785240725562,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000011",
  "actor": {
    "id": "0oa00000000000000042",
    "type": "PublicClientApp",
    "alternateId": "user10@dw-harness.example",
    "displayName": "DW Harness 14",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": "0oa00000000000000042",
    "ipAddress": "192.0.2.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": {
    "id": null,
    "name": null,
    "os_platform": null,
    "os_version": null,
    "managed": null,
    "registered": null,
    "device_integrator": {
      "DEVICE_IDP": {}
    },
    "disk_encryption_type": null,
    "screen_lock_type": null,
    "jailbreak": null,
    "secure_hardware_present": null
  },
  "events": null,
  "target": [
    {
      "id": "00u00000000000000043",
      "type": "User",
      "alternateId": "user11@dw-harness.example",
      "displayName": "DW Harness 15",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "mot00000000000000045",
      "type": "code",
      "alternateId": null,
      "displayName": "DW Harness 16",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.as.authorize.code",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000005",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "redirectUri": "kiro://app.example.com/callback",
      "grantedScopes": "example:scope, offline_access, example:scope",
      "responseMode": "query",
      "authorizationServerName": "Example Auth Server 1",
      "authorizationServer": "aus00000000000000046",
      "behaviors": "{New Geo-Location=NEGATIVE, New Device=NEGATIVE, New ASN=NEGATIVE, New IP=NEGATIVE, New State=NEGATIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}",
      "rule": "0pr00000000000000047",
      "requestUri": "00000000000000000000000000000000000000004",
      "requestedScopes": "example:scope, example:scope, offline_access",
      "userId": "00u00000000000000043",
      "url": "00000000000000000000000000000000000000004?redirect_uri=c1q00000000000000048&scope=000000000000000000000000000000000000000000000000000000000000000000000002&code_challenge=0000000000000000000000000000000000000000003&code_challenge_method=S256&response_mode=query&state=0000000000000000000000000000000000000000002&login_hint=kg700000000000000049&client_id=iik00000000000000050&response_type=code",
      "responseType": "code",
      "authnRequestId": "00000000000000000000000000000005",
      "requestId": "00000000000000000000000000000005",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000004",
      "risk": "{level=LOW}",
      "state": "Anystate",
      "threatSuspected": "false",
      "grantType": "authorization_code",
      "defaultAuthorizationServer": "false",
      "policy": "00p00000000000000051"
    }
  },
  "displayMessage": "OAuth2 authorization code request",
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.as.authorize.code_success",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "LOW"
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "NEGATIVE"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "NEGATIVE"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "NEGATIVE"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "NEGATIVE"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "NEGATIVE"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "NEGATIVE"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000060",
    "externalSessionId": "idx00000000000000060"
  }
}

References #

app.oauth2.as.authorize.implicit.access_token

#

Description

OAuth2 authorization implicit access token request.

References #

app.oauth2.as.authorize.implicit.id_token

#

Description

OAuth2 authorization implicit ID token request.

References #

app.oauth2.as.authorize.scope_denied

#

Description

Some of the requested scopes were denied by the policy.

References #

app.oauth2.as.consent.grant

#

app.oauth2.as.consent.revoke

#

app.oauth2.as.consent.revoke.implicit.as

#

app.oauth2.as.consent.revoke.implicit.client

#

app.oauth2.as.consent.revoke.implicit.scope

#

app.oauth2.as.consent.revoke.implicit.user

#

app.oauth2.as.consent.revoke.user

#

app.oauth2.as.consent.revoke.user.client

#

app.oauth2.as.evaluate.claim

#

Description

Claim evaluation for OAuth 2.0 token. This event is triggered when the OAuth 2.0 authorization server's claim evaluation process can't be completed and fails. This event is useful when detecting misconfigured claims. Recorded details include the requester's ID, the client ID, the user ID, and the claims that couldn't be evaluated. This verification ensures that access tokens are granted only to requests that fully comply with established security policies, thus safeguarding access to protected resources.

References #

app.oauth2.as.interact.interaction_code

#

Description

Interaction code is generated by OIE. This event can be used by administrators to audit interaction_code generation, and troubleshoot why the IdX transaction has failed. When fired, this event contains hashed values of the interaction_code and interaction_handle, as well as information about the client to which they were issued.

References #

app.oauth2.as.interact.interaction_handle

#

Description

Interaction handle is generated by OIE. This event can be used by administrators to detect if additional interaction is required and an interaction handle has been issued. When fired this event contains interaction handle hash and the client to which it was issued.

References #

app.oauth2.as.key.rollover

#

Description

Custom Authorization Server token signing key rolled over.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000074",
    "externalSessionId": "trs00000000000000074"
  },
  "displayMessage": "Custom Authorization Server token signing key rolled over",
  "eventType": "app.oauth2.as.key.rollover",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-24T03:47:55.578Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "authorizationServer": "aus00000000000000075",
      "requestId": "00000000000000000000000000000088",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "kid": "0000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/authorizationServers",
      "defaultAuthorizationServer": "false",
      "url": "/api/v1/authorizationServers?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.as.key.rollover.legacy",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000088",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000101",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "aus00000000000000075",
      "type": "AuthorizationServer",
      "alternateId": null,
      "displayName": "DW Harness 35",
      "detailEntry": null
    }
  ]
}

References #

app.oauth2.as.resource_server.credentials.lifecycle.activate

#

Description

Authorization server access token encryption key is activated. Use this event to find out if a new access token encryption key has been activated for an authorization server. This could be used to audit changes made to authorization server access token encryption keys.

References #

app.oauth2.as.resource_server.credentials.lifecycle.create

#

Description

Authorization server access token encryption key is created. Use this event to find out if a new access token encryption key has been created for an authorization server. This could be used to audit changes made to authorization server access token encryption keys.

References #

app.oauth2.as.resource_server.credentials.lifecycle.deactivate

#

Description

Authorization server access token encryption key is deactivated. Use this event to find out if a new access token encryption key has been deactivated for an authorization server. This could be used to audit changes made to authorization server access token encryption keys.

References #

app.oauth2.as.resource_server.credentials.lifecycle.delete

#

Description

Authorization server access token encryption key is deleted. Use this event to find out if a new access token encryption key has been deleted for an authorization server. This could be used to audit changes made to authorization server access token encryption keys.

References #

app.oauth2.as.token.detect_reuse

#

Description

Detect one-time refresh token attempted reuse. This event can be used by administrators to detect and audit attempted reuse of one-time refresh tokens. When fired this event contains information about the user, client to which the refresh token was minted, and the hash of the refresh tokens.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Okta App Refresh Access Token Reuse source medium: When a client wants to renew an access token, it sends the refresh token with the access token request to the /token Okta endpoint. Okta validates the incoming refresh token, issues a new set of tokens and invalidates the refresh token that was passed with the initial request. This detection alerts when a previously used refresh token is used again with the token request↳ also matches app.oauth2.token.detect_reuse

References #

app.oauth2.as.token.grant

#

Description

OAuth2 token request.

Example System Log Event #

{
  "actor": {
    "id": "0oa00000000000000006",
    "type": "PublicClientApp",
    "alternateId": "user07@dw-harness.example",
    "displayName": "DW Harness 07",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": "0oa00000000000000006",
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000007",
    "externalSessionId": "0000000000000000000000007"
  },
  "displayMessage": "OAuth2 token request",
  "eventType": "app.oauth2.as.token.grant",
  "outcome": {
    "result": "FAILURE",
    "reason": "password_auth_denied_policy"
  },
  "published": "2026-07-26T00:00:36.765Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "WARN",
  "debugContext": {
    "debugData": {
      "clientAuthType": "client_secret_post",
      "grantedScopes": "",
      "authorizationServerName": "dw-harn-090975f0-as-grant",
      "authorizationServer": "aus00000000000000012",
      "responseTime": "425",
      "requestUri": "/oauth2/aus00000000000000012/v1/token",
      "requestedScopes": "openid, offline_access",
      "url": "/oauth2/aus00000000000000012/v1/token?",
      "authnRequestId": "00000000000000000000000000000008",
      "requestId": "00000000000000000000000000000008",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000003",
      "clientSecret": "zBj00000000000000010",
      "threatSuspected": "false",
      "grantType": "password",
      "defaultAuthorizationServer": "false"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.as.token.grant_failure",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000008",
    "detail": {}
  },
  "uuid": "00000000-0000-0000-0000-000000000018",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": null
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::outcome.result (elastic rule field)eqfailure1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Unauthorized Scope for Public App OAuth2 Token Grant with Client Credentials source medium: Identifies a failed OAuth 2.0 token grant attempt for a public client app using client credentials. This event is generated when a public client app attempts to exchange a client credentials grant for an OAuth 2.0 access token, but the request is denied due to the lack of required scopes. This could indicate compromised client credentials in which an adversary is attempting to obtain an access token for unauthorized scopes. This is a New Terms rule where the okta.actor.display_name field value has not been seen in the last 14 days regarding this event.T1078, T1078.004, T1550, T1550.001

References #

app.oauth2.as.token.grant.access_token

#

Description

OAuth 2.0 access token is granted. This event is triggered within OAuth 2.0 frameworks when an app successfully grants an access token to a user or service. The event occurs post-authentication and authorization, marking the final step in accessing protected resources. Use this event as a comprehensive audit trail for issued tokens. The event captures details such as the client ID, subject ID, token attributes (for example: scope, validity period), and the grant type used. This information helps with security audits, ensuring compliance with access policies and troubleshooting authorization flows. Specifically, variations in token attributes and grant type offer insights into the security posture and operational efficiency of OAuth 2.0 implementations. While this event primarily signifies successfully issued tokens, the event details are helpful in many areas. They help flag potential misuse of token grants or anomalies in token attributes. The event details also help facilitate a prompt response to deviations from established security practices.

Example System Log Event #

{
  "actor": {
    "id": "0oa00000000000000004",
    "type": "PublicClientApp",
    "alternateId": "user07@dw-harness.example",
    "displayName": "DW Harness 07",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": "0oa00000000000000004",
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000002",
    "externalSessionId": "0000002"
  },
  "displayMessage": "OAuth2 access token is granted",
  "eventType": "app.oauth2.as.token.grant.access_token",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:38:22.556Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "clientAuthType": "client_secret_post",
      "grantedScopes": "dw.harness.d82abed7.grant",
      "authorizationServerName": "dw-harn-d82abed7-as-grant",
      "authorizationServer": "aus00000000000000011",
      "responseTime": "230",
      "rule": "0pr00000000000000016",
      "requestUri": "/oauth2/aus00000000000000011/v1/token",
      "requestedScopes": "dw.harness.d82abed7.grant",
      "url": "/oauth2/aus00000000000000011/v1/token?",
      "requestId": "00000000000000000000000000000007",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000003",
      "clientSecret": "RhK00000000000000010",
      "threatSuspected": "false",
      "grantType": "client_credentials",
      "defaultAuthorizationServer": "false",
      "policy": "00p00000000000000014"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "0000000000000000000000000000000000000000000002",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000007",
    "detail": {}
  },
  "uuid": "00000000-0000-0000-0000-000000000015",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0000000000000000000000000000000000000000000003",
      "type": "access_token",
      "alternateId": null,
      "displayName": "DW Harness 12",
      "detailEntry": {
        "audience": "api://dw-harn-d82abed7-grant",
        "expires": "2026-07-25T23:43:22.000Z",
        "subject": "0oa00000000000000004",
        "hash": "3xY00000000000000017+RAO2/Pow="
      }
    }
  ]
}

References #

app.oauth2.as.token.grant.device_secret

#

Description

Grant an OAuth2 device_secret for the Native SSO flow. This event adds tracking to let admins know when Native SSO is being used to protect desktop or mobile apps. When fired this event contains the device secret id which administrators can use to correlate with single logout events across native desktop apps.

References #

app.oauth2.as.token.grant.id_token

#

Description

OAuth 2.0 ID token is granted. This event occurs when an OAuth 2.0 authorization server grants an ID token to a client after successful authentication. The ID token, which encapsulates the user's identity information, verifies the user's identity to the client app. Recorded details include the client ID, user ID, token issuance time, and claims associated with the user's identity. You can use this data for security audits, enabling precise tracking of user identity verification across apps. The issuance of an ID token follows established protocols for secure authentication. This ensures that sensitive user information is transmitted securely between the authorization server and the client.

Example System Log Event #

{
  "published": 1783623388112,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000012",
  "actor": {
    "id": "0oa00000000000000067",
    "type": "PublicClientApp",
    "alternateId": "user13@dw-harness.example",
    "displayName": "DW Harness 18",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Amazon/Cognito",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": "0oa00000000000000067",
    "ipAddress": "192.0.2.18",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000068",
      "type": "User",
      "alternateId": "user14@dw-harness.example",
      "displayName": "DW Harness 19",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "0000000000000000000000000000000000000000000003",
      "type": "id_token",
      "alternateId": null,
      "displayName": "DW Harness 20",
      "detailEntry": {
        "audience": "0oa00000000000000067",
        "expires": "2026-07-09T19:56:28.000Z",
        "subject": "00u00000000000000068",
        "hash": "0000000000000000000000000000000000000000004="
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.18",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.as.token.grant.id_token",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000006",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientAuthType": "client_secret_post",
      "redirectUri": "https://app.example.com App app.example.com/oauth2/idpresponse",
      "grantedScopes": "openid, email",
      "authCode": "v3g00000000000000069",
      "authorizationServerName": "default",
      "authorizationServer": "aus00000000000000070",
      "responseTime": "247",
      "requestUri": "/oauth2/default/v1/token",
      "requestedScopes": "",
      "url": "/oauth2/default/v1/token?",
      "authnRequestId": "00000000000000000000000000000007",
      "requestId": "00000000000000000000000000000006",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000005",
      "clientSecret": "ykm00000000000000071",
      "threatSuspected": "false",
      "grantType": "authorization_code",
      "defaultAuthorizationServer": "true"
    }
  },
  "displayMessage": "OAuth2 id token is granted",
  "gatewayContext": null,
  "legacyEventType": "000000000000000000000000000000000000000002",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000072",
    "externalSessionId": "idx00000000000000072"
  }
}

References #

app.oauth2.as.token.grant.interclient_token

#

Description

Grant interclient token. Track the successful issuance of an Interclient token via OAuth token exchange. This event will contain the target audience the interclient token is issued for.

References #

app.oauth2.as.token.grant.refresh_token

#

Description

OAuth2 refresh token is granted.

Example System Log Event #

{
  "published": 1785240727639,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000013",
  "actor": {
    "id": "0oa00000000000000042",
    "type": "PublicClientApp",
    "alternateId": "user10@dw-harness.example",
    "displayName": "DW Harness 14",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "openid-client/v6.8.1",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": "0oa00000000000000042",
    "ipAddress": "192.0.2.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000043",
      "type": "User",
      "alternateId": "user11@dw-harness.example",
      "displayName": "DW Harness 15",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "oar00000000000000073",
      "type": "refresh_token",
      "alternateId": null,
      "displayName": "DW Harness 21",
      "detailEntry": {
        "expires": "2026-10-26T12:12:07.000Z",
        "subject": "00u00000000000000043",
        "refreshtokentype": "persistent",
        "hash": "0000000000000000000000000000000000000000005="
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.as.token.grant.refresh_token",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000008",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientAuthType": "none",
      "redirectUri": "kiro://app.example.com/callback",
      "grantedScopes": "example:scope, offline_access, example:scope",
      "authCode": "mot00000000000000045",
      "authorizationServerName": "Example Auth Server 1",
      "authorizationServer": "aus00000000000000046",
      "responseTime": "251",
      "requestUri": "6vb00000000000000074",
      "requestedScopes": "",
      "url": "6vb00000000000000074?",
      "authnRequestId": "00000000000000000000000000000005",
      "requestId": "00000000000000000000000000000008",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000006",
      "threatSuspected": "false",
      "grantType": "authorization_code",
      "defaultAuthorizationServer": "false"
    }
  },
  "displayMessage": "OAuth2 refresh token is granted",
  "gatewayContext": null,
  "legacyEventType": "00000000000000000000000000000000000000000000002",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000060",
    "externalSessionId": "idx00000000000000060"
  }
}

References #

app.oauth2.as.token.revoke

#

Description

OAuth2 token revocation request.

References #

app.oauth2.authorize

#

Description

OIDC authorization request.

Example System Log Event #

{
  "published": 1785265710206,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000014",
  "actor": {
    "id": "00000000000000000000000000000000000000005",
    "type": "PublicClientApp",
    "alternateId": "user15@dw-harness.example",
    "displayName": "DW Harness 22",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": "00000000000000000000000000000000000000005",
    "ipAddress": "192.0.2.5",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": {
    "id": "guo00000000000000075",
    "name": "Mac17,9",
    "os_platform": "OSX",
    "os_version": "26.4.0",
    "managed": false,
    "registered": true,
    "device_integrator": {
      "DEVICE_IDP": {},
      "ANDROID_ZERO_TRUST": {},
      "WSC": {},
      "CROWDSTRIKE": {}
    },
    "disk_encryption_type": "ALL_INTERNAL_VOLUMES",
    "screen_lock_type": "BIOMETRIC",
    "jailbreak": null,
    "secure_hardware_present": true
  },
  "events": null,
  "target": null,
  "outcome": {
    "result": "FAILURE",
    "reason": "login_required"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.5",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.authorize",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000009",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "redirectUri": "https://app.example.com/enduser/callback",
      "grantedScopes": "",
      "responseMode": "okta_post_message",
      "behaviors": "{New Geo-Location=NEGATIVE, New Device=NEGATIVE, New ASN=NEGATIVE, New IP=NEGATIVE, New State=NEGATIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}",
      "requestUri": "/oauth2/v1/authorize",
      "requestedScopes": "openid, profile, email, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope",
      "userId": "00u00000000000000076",
      "url": "/oauth2/v1/authorize?client_id=00000000000000000000000000000000000000006&code_challenge=0000000000000000000000000000000000000000006&code_challenge_method=S256&nonce=0000000000000000000000000000000000000000000000000000000000000007&prompt=none&redirect_uri=000000000000000000000000000000000000000000000002&response_mode=okta_post_message&response_type=code&state=0000000000000000000000000000000000000000000000000000000000000008&scope=0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002",
      "responseType": "code",
      "authnRequestId": "00000000000000000000000000000009",
      "requestId": "00000000000000000000000000000009",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000009",
      "risk": "{level=LOW}",
      "state": "Anystate",
      "threatSuspected": "false"
    }
  },
  "displayMessage": "OIDC authorization request",
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.authorize_failure",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "LOW"
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "NEGATIVE"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "NEGATIVE"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "NEGATIVE"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "NEGATIVE"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "NEGATIVE"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "NEGATIVE"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000077",
    "externalSessionId": "idx00000000000000077"
  }
}

References #

app.oauth2.authorize.code

#

Description

OIDC authorization code request.

Example System Log Event #

{
  "published": 1785239705087,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000015",
  "actor": {
    "id": "0oa00000000000000078",
    "type": "PublicClientApp",
    "alternateId": "user16@dw-harness.example",
    "displayName": "DW Harness 23",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (X11; Linux x86_64; rv:152.0) Gecko/20100101 Firefox/152.0",
      "os": "Linux",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": "0oa00000000000000078",
    "ipAddress": "192.0.2.17",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": {
    "id": null,
    "name": null,
    "os_platform": null,
    "os_version": null,
    "managed": null,
    "registered": null,
    "device_integrator": {
      "DEVICE_IDP": {}
    },
    "disk_encryption_type": null,
    "screen_lock_type": null,
    "jailbreak": null,
    "secure_hardware_present": null
  },
  "events": null,
  "target": [
    {
      "id": "00u00000000000000079",
      "type": "User",
      "alternateId": "user17@dw-harness.example",
      "displayName": "DW Harness 24",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "9uv00000000000000080",
      "type": "code",
      "alternateId": null,
      "displayName": "DW Harness 16",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.17",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com",
          "ipServiceCategories": [
            {
              "operator": "GLOBAL_PROTECT_CLOUD_VPN",
              "type": "VPN",
              "isAnonymous": false
            }
          ]
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.authorize.code",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000010",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "redirectUri": "https://app.example.com/auth/return",
      "grantedScopes": "openid, email, offline_access",
      "responseMode": "query",
      "behaviors": "{New Geo-Location=NEGATIVE, New Device=NEGATIVE, New ASN=NEGATIVE, New IP=NEGATIVE, New State=NEGATIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}",
      "requestUri": "/login/token/redirect",
      "requestedScopes": "openid, email, offline_access",
      "userId": "00u00000000000000079",
      "url": "/login/token/redirect?stateToken=0000000000000000000000000000000000000000000004",
      "tunnels": [
        {
          "anonymous": false,
          "operator": "GLOBAL_PROTECT_CLOUD_VPN",
          "type": "VPN"
        }
      ],
      "responseType": "code",
      "authnRequestId": "00000000000000000000000000000011",
      "requestId": "00000000000000000000000000000010",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000010",
      "risk": "{level=LOW}",
      "state": "Anystate",
      "threatSuspected": "false",
      "grantType": "authorization_code"
    }
  },
  "displayMessage": "OIDC authorization code request",
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.authorize.code_success",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com",
      "ipServiceCategories": [
        {
          "operator": "GLOBAL_PROTECT_CLOUD_VPN",
          "type": "VPN",
          "isAnonymous": false
        }
      ]
    },
    "risk": {
      "level": "LOW"
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "NEGATIVE"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "NEGATIVE"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "NEGATIVE"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "NEGATIVE"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "NEGATIVE"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "NEGATIVE"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000081",
    "externalSessionId": "idx00000000000000081"
  }
}

References #

app.oauth2.authorize.implicit.access_token

#

Description

OIDC authorization implicit access token request.

References #

app.oauth2.authorize.implicit.id_token

#

Description

OIDC authorization implicit ID token request.

References #

app.oauth2.client.lifecycle.activate

#

Description

Activate OAuth client.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000003",
    "externalSessionId": "trs00000000000000003"
  },
  "displayMessage": null,
  "eventType": "app.oauth2.client.lifecycle.activate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:35:50.283Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000005",
      "clientName": "dw-harn-c1bf671d-oauth-service",
      "requestId": "00000000000000000000000000000002",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/apps",
      "url": "/api/v1/apps?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.client.lifecycle.activate",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000002",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000005",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000005",
      "type": "PublicClientAppEntity",
      "alternateId": "user04@dw-harness.example",
      "displayName": "DW Harness 06",
      "detailEntry": null
    }
  ]
}

References #

app.oauth2.client.lifecycle.create

#

Description

Create OAuth client.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000003",
    "externalSessionId": "trs00000000000000003"
  },
  "displayMessage": null,
  "eventType": "app.oauth2.client.lifecycle.create",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:35:50.238Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000005",
      "clientName": "dw-harn-c1bf671d-oauth-service",
      "requestId": "00000000000000000000000000000002",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/apps",
      "url": "/api/v1/apps?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.client.lifecycle.create",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000002",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000006",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000005",
      "type": "PublicClientAppEntity",
      "alternateId": "user04@dw-harness.example",
      "displayName": "DW Harness 06",
      "detailEntry": {
        "tokenendpointauthmethod": "client_secret_post",
        "clientid": "0oa00000000000000005",
        "responsetypes": "[TOKEN]",
        "clientname": "dw-harn-c1bf671d-oauth-service",
        "clientsecret": "0000000000000000000002",
        "hasexternalclientsecret": "false",
        "applicationtype": "service",
        "granttypes": "[CLIENT_CREDENTIALS]",
        "redirecturis": []
      }
    }
  ]
}

References #

app.oauth2.client.lifecycle.deactivate

#

Description

Deactivate OAuth client.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000007",
    "externalSessionId": "0000000000000000000000007"
  },
  "displayMessage": null,
  "eventType": "app.oauth2.client.lifecycle.deactivate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:35:52.737Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000005",
      "clientName": "dw-harn-c1bf671d-oauth-service",
      "requestId": "00000000000000000000000000000012",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/apps/0oa00000000000000005/lifecycle/deactivate",
      "url": "/api/v1/apps/0oa00000000000000005/lifecycle/deactivate?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.client.lifecycle.deactivate",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000012",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000019",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000005",
      "type": "PublicClientAppEntity",
      "alternateId": "user04@dw-harness.example",
      "displayName": "DW Harness 06",
      "detailEntry": null
    }
  ]
}

References #

app.oauth2.client.lifecycle.delete

#

Description

Delete OAuth client.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000017",
    "externalSessionId": "trs00000000000000017"
  },
  "displayMessage": null,
  "eventType": "app.oauth2.client.lifecycle.delete",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:35:53.028Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000005",
      "clientName": "dw-harn-c1bf671d-oauth-service",
      "requestId": "00000000000000000000000000000013",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/apps/0oa00000000000000005",
      "url": "/api/v1/apps/0oa00000000000000005?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.client.lifecycle.delete",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000013",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000022",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000005",
      "type": "PublicClientAppEntity",
      "alternateId": "user04@dw-harness.example",
      "displayName": "DW Harness 06",
      "detailEntry": null
    }
  ]
}

References #

app.oauth2.client.lifecycle.update

#

Description

Update OAuth client.

Example System Log Event #

{
  "published": 1780091784209,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000016",
  "actor": {
    "id": "00u00000000000000082",
    "type": "User",
    "alternateId": "user18@dw-harness.example",
    "displayName": "DW Harness 25",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0",
      "os": "Linux",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.4",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000083",
      "type": "PublicClientAppEntity",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 26",
      "detailEntry": {
        "tokenendpointauthmethod": "client_secret_basic",
        "clientid": "0oa00000000000000083",
        "responsetypes": "[CODE]",
        "clientname": "Example App 29",
        "clientsecret": "ti400000000000000084",
        "hasexternalclientsecret": "false",
        "applicationtype": "web",
        "granttypes": "[AUTHORIZATION_CODE]",
        "redirecturis": "[http://app.example.com/auth/callback, https://app.example.com/auth/callback]"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.4",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.client.lifecycle.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000012",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000083",
      "clientName": "Example App 29",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000012",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000011",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "kzk00000000000000085",
      "url": "kzk00000000000000085?"
    }
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.client.lifecycle.update",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000086",
    "externalSessionId": "10200000000000000086"
  }
}

References #

app.oauth2.client.privilege.grant

#

Description

An OAuth 2.0 client app's admin privileges changed. This can be used to audit the provisioning of admin privileges for OAuth 2.0 client apps. When fired, this event contains information about the type of admin privileges the OAuth 2.0 client app currently has. Related events include: APP_OAUTH2_CLIENT_PRIVILEGE_REVOKE.

Example System Log Event #

{
  "published": 1781189321136,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000004",
  "actor": {
    "id": "00u00000000000000061",
    "type": "User",
    "alternateId": "user12@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000087",
      "type": "PublicClientAppEntity",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 17",
      "detailEntry": null
    },
    {
      "id": "0000000000002",
      "type": "ROLE_ASSIGNED",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 27",
      "detailEntry": null
    },
    {
      "id": "0000000000003",
      "type": "ROLE",
      "alternateId": "user19@dw-harness.example",
      "displayName": "DW Harness 28",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.client.privilege.grant",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": null,
    "id": "0000003",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "privilegeGranted": "Super administrator"
    }
  },
  "displayMessage": "Grant public client app privilege",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000065",
    "externalSessionId": "trs00000000000000088"
  }
}

References #

app.oauth2.client.privilege.revoke

#

Description

All privileges for OAuth 2.0 client app were revoked. This can be used to audit the deprovisioning of admin privileges from OAuth 2.0 client apps. When fired, this event indicates the OAuth 2.0 client app has no more admin privileges. All of OAuth 2.0 client app's privileges were revoked. Related events include: APP_OAUTH2_CLIENT_PRIVILEGE_GRANT.

Example System Log Event #

{
  "published": 1781189346099,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000007",
  "actor": {
    "id": "00u00000000000000061",
    "type": "User",
    "alternateId": "user12@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000063",
      "type": "PublicClientAppEntity",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 17",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.client.privilege.revoke",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rcr00000000000000089",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "privilegeRevoked": "Super administrator, Organization administrator, Application administrator (all), Application administrator, Read only admin, User administrator (all), User administrator, Help Desk administrator (all), Help Desk administrator, Mobile administrator, API Access Management administrator, Report administrator, Group Membership administrator"
    }
  },
  "displayMessage": "Revoke public client app privilege",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000065",
    "externalSessionId": "trs00000000000000090"
  }
}

References #

app.oauth2.client.read_client_secret

#

Description

Read OAuth client's secret(s). Use this event to verify that an OAuth client's secret(s) have been read when the client is returned in certain API responses. For example, an admin might use this event to audit if a client's secrets were read when using the client credentials management API. When fired, this event indicates that an OAuth client's secrets were read. The targets array may include references to multiple client secrets.

Example System Log Event #

{
  "published": 1780091747879,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000017",
  "actor": {
    "id": "00u00000000000000082",
    "type": "User",
    "alternateId": "user18@dw-harness.example",
    "displayName": "DW Harness 25",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0",
      "os": "Linux",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.4",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000040",
      "type": "PublicClientAppEntity",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 12",
      "detailEntry": null
    },
    {
      "id": "ocs00000000000000091",
      "type": "oau00000000000000092",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 29",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.4",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.client.read_client_secret",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000013",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000013",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000011",
      "requestUri": "00000000000000000000000000000000000000000000000000002",
      "url": "00000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "Read OAuth client's secret(s).",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000086",
    "externalSessionId": "10200000000000000086"
  }
}

References #

app.oauth2.client_id_rate_limit_warning

#

Description

Requests from a single client ID consumed the majority of an organization's OAuth2 endpoint rate limit. This event can be used by admins to discover and deactivate a rogue client. The admin is able to manage the client via the Syslog UI. When fired, this event contains information about the responsible client id. As of release, this event is fired when a single client id consumes 90% of an org's OAuth2 rate limit; this threshold is subject to change.

References #

app.oauth2.consent.grant

#

app.oauth2.credentials.lifecycle.activate

#

Description

OAuth client credentials (either client secret or JWK) is added for an application. Use this event to find out if an application has a new client secret or private/public key that has been added. This could be used to audit changes made to client credentials.

Example System Log Event #

{
  "published": 1781290372590,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000018",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.9",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "ocs00000000000000094",
      "type": "oau00000000000000092",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 31",
      "detailEntry": {
        "clientid": "0oa00000000000000095",
        "clientsecret": "njh00000000000000096",
        "clientcredentialstype": "secret",
        "status": "active"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.9",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "00000000000000000000000000000000000000007",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000014",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000095",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000014",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000012",
      "origin": "https://app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000002",
      "url": "00000000000000000000000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": "00000000000000000000000000000000000000007",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000097",
    "externalSessionId": "10200000000000000097"
  }
}

References #

app.oauth2.credentials.lifecycle.create

#

Description

OAuth client credentials (either client secret or JWK) is activated for an application. Use this event to find out if an application has activated a new client secret or private/public key. This could be used to audit changes made to client credentials.

Example System Log Event #

{
  "published": 1781290372583,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000019",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.9",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "ocs00000000000000094",
      "type": "oau00000000000000092",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 31",
      "detailEntry": {
        "clientid": "0oa00000000000000095",
        "clientsecret": "njh00000000000000096",
        "clientcredentialstype": "secret",
        "status": "active"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.9",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.credentials.lifecycle.create",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000014",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000095",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000014",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000012",
      "origin": "https://app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000002",
      "url": "00000000000000000000000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.credentials.lifecycle.create",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000097",
    "externalSessionId": "10200000000000000097"
  }
}

References #

app.oauth2.credentials.lifecycle.deactivate

#

Description

OAuth client credentials (either client secret or JWK) is deactivated for an application. Use this event to find out if an application has an existing client secret or private/public key that has been deactivated. This could be used to audit changes made to client credentials.

Example System Log Event #

{
  "published": 1780091765668,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000020",
  "actor": {
    "id": "00u00000000000000082",
    "type": "User",
    "alternateId": "user18@dw-harness.example",
    "displayName": "DW Harness 25",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0",
      "os": "Linux",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.4",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "ocs00000000000000098",
      "type": "oau00000000000000092",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 32",
      "detailEntry": {
        "clientid": "0oa00000000000000083",
        "clientcredentialstype": "secret",
        "datecreated": "2026-05-22T19:35:44.000Z",
        "status": "inactive"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.4",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "0000000000000000000000000000000000000000007",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000015",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000083",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000015",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000011",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002",
      "url": "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": "0000000000000000000000000000000000000000007",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000086",
    "externalSessionId": "10200000000000000086"
  }
}

References #

app.oauth2.credentials.lifecycle.delete

#

Description

OAuth client credentials (either client secret or JWK) is deleted for an application. Use this event to find out if an application has an existing client secret or private/public key that has been deleted. This could be used to audit changes made to client credentials.

Example System Log Event #

{
  "published": 1781290504504,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000021",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.9",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "ocs00000000000000099",
      "type": "oau00000000000000092",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 33",
      "detailEntry": {
        "clientid": "0oa00000000000000095",
        "clientsecret": "5q000000000000000100",
        "clientcredentialstype": "secret",
        "datecreated": "2026-04-13T22:42:25.000Z",
        "status": "inactive"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.9",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.credentials.lifecycle.delete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000016",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000095",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000016",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000012",
      "origin": "https://app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000003",
      "url": "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000003?"
    }
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.credentials.lifecycle.delete",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000097",
    "externalSessionId": "10200000000000000097"
  }
}

References #

app.oauth2.interact.interaction_code

#

Description

Interaction code generated by OIE. This event can be used by administrators to audit interaction_code generation, and troubleshoot why the IdX transaction has failed. When fired, this event contains hashed values of the interaction_code and interaction_handle, as well as information about the client to which they were issued.

References #

app.oauth2.interact.interaction_handle

#

Description

Interaction handle generated by OIE. This event can be used by administrators to detect if additional interaction is required and an interaction handle has been issued. When fired this event contains interaction handle hash and the client to which it was issued.

References #

app.oauth2.invalid_client_credentials

#

Description

Multiple requests with invalid client credentials for client id.

References #

app.oauth2.key.rollover

#

Description

Org Authorization Server token signing key rolled over.

References #

app.oauth2.signon

#

Description

User performed OIDC single sign on to app.

References #

app.oauth2.token.detect_reuse

#

Description

Detect one-time refresh token attempted reuse. This event can be used by administrators to detect and audit attempted reuse of one-time refresh tokens. When fired this event contains information about the user, client to which the refresh token was minted, and the hash of the refresh tokens.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Okta App Refresh Access Token Reuse source medium: When a client wants to renew an access token, it sends the refresh token with the access token request to the /token Okta endpoint. Okta validates the incoming refresh token, issues a new set of tokens and invalidates the refresh token that was passed with the initial request. This detection alerts when a previously used refresh token is used again with the token request↳ also matches app.oauth2.as.token.detect_reuse

References #

app.oauth2.token.grant

#

Description

OIDC token request.

Example System Log Event #

{
  "published": 1785260588711,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000022",
  "actor": {
    "id": "0oa00000000000000101",
    "type": "PublicClientApp",
    "alternateId": "user21@dw-harness.example",
    "displayName": "DW Harness 34",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.32.5",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "192.0.2.14",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "",
      "type": "refresh_token",
      "alternateId": null,
      "displayName": "DW Harness 21",
      "detailEntry": {
        "hash": "0000000000000000000000000000000000000000008="
      }
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": "invalid_refresh_token"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.14",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "app.oauth2.token.grant",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000017",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientAuthType": "client_secret_basic",
      "grantedScopes": "",
      "requestId": "00000000000000000000000000000017",
      "responseTime": "42",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000013",
      "clientSecret": "cio00000000000000102",
      "requestUri": "/oauth2/v1/token",
      "requestedScopes": "",
      "threatSuspected": "false",
      "grantType": "refresh_token",
      "url": "/oauth2/v1/token?"
    }
  },
  "displayMessage": "OIDC token request",
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.token.grant_failure",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

References #

app.oauth2.token.grant.access_token

#

Description

OIDC access token is granted.

Example System Log Event #

{
  "published": 1785260615868,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000023",
  "actor": {
    "id": "0oa00000000000000103",
    "type": "PublicClientApp",
    "alternateId": "user22@dw-harness.example",
    "displayName": "DW Harness 35",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "dr000000000000000104",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "192.0.2.15",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0000000000000000000000000000000000000000000005",
      "type": "access_token",
      "alternateId": null,
      "displayName": "DW Harness 36",
      "detailEntry": {
        "audience": "https://app.example.com",
        "expires": "2026-07-28T18:43:35.000Z",
        "subject": "0oa00000000000000103",
        "hash": "0000000000000000000000000000000000000000009="
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.15",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.token.grant.access_token",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000018",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientAuthType": "client_secret_basic",
      "grantedScopes": "okta.users.read, example:scope, example:scope, example:scope, example:scope, okta.groups.read, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope",
      "requestId": "00000000000000000000000000000018",
      "responseTime": "213",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000014",
      "clientSecret": "4m700000000000000105",
      "requestUri": "/oauth2/v1/token",
      "requestedScopes": "okta.users.read, example:scope, example:scope, example:scope, example:scope, example:scope, okta.groups.read, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope",
      "threatSuspected": "false",
      "grantType": "client_credentials",
      "url": "/oauth2/v1/token?"
    }
  },
  "displayMessage": "OIDC access token is granted",
  "gatewayContext": null,
  "legacyEventType": "0000000000000000000000000000000000000000010",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

References #

app.oauth2.token.grant.id_jag

#

Description

OAuth 2.0 Identity Assertion JWT Authorization Grant (ID-JAG) granted. This event is triggered when an app successfully completes an OAuth token exchange to generate an Identity Assertion JWT Authorization Grant. The Identity Assertion relies on a valid ID token obtained from a single sign-on (SSO) flow and the ID-JAG JWT is used in Cross App Access.

References #

app.oauth2.token.grant.id_token

#

Description

OIDC id token is granted.

Example System Log Event #

{
  "published": 1785238977815,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000024",
  "actor": {
    "id": "0oa00000000000000106",
    "type": "PublicClientApp",
    "alternateId": "user23@dw-harness.example",
    "displayName": "DW Harness 37",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Node-oauth",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": "0oa00000000000000106",
    "ipAddress": "192.0.2.7",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000107",
      "type": "User",
      "alternateId": "user24@dw-harness.example",
      "displayName": "DW Harness 38",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "0000000000000000000000000000000000000000000006",
      "type": "id_token",
      "alternateId": null,
      "displayName": "DW Harness 20",
      "detailEntry": {
        "audience": "0oa00000000000000106",
        "expires": "2026-07-28T12:42:57.000Z",
        "subject": "00u00000000000000107",
        "hash": "0000000000000000000000000000000000000000011="
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.7",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.token.grant.id_token",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000019",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientAuthType": "client_secret_post",
      "grantedScopes": "openid, email, profile, offline_access",
      "requestId": "00000000000000000000000000000019",
      "responseTime": "248",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000015",
      "clientSecret": "j2r00000000000000108",
      "requestUri": "/oauth2/v1/token",
      "requestedScopes": "openid, email, profile, offline_access",
      "threatSuspected": "false",
      "grantType": "refresh_token",
      "url": "/oauth2/v1/token?"
    }
  },
  "displayMessage": "OIDC id token is granted",
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.token.grant.id_token_success",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

References #

app.oauth2.token.grant.interclient_token

#

Description

Grant interclient token. Track the successful issuance of an Interclient token via OAuth token exchange. This event will contain the target audience the interclient token is issued for.

References #

app.oauth2.token.grant.oauth_sts

#

Description

Grant OAuth Security Token Service (STS) access token. Audit when an application successfully exchanges an OAuth token for an access token from a third-party authorization server.

References #

app.oauth2.token.grant.refresh_token

#

Description

OIDC refresh token is granted.

Example System Log Event #

{
  "published": 1785254131176,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000025",
  "actor": {
    "id": "0oa00000000000000109",
    "type": "PublicClientApp",
    "alternateId": "user25@dw-harness.example",
    "displayName": "DW Harness 39",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": "0oa00000000000000109",
    "ipAddress": "192.0.2.5",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000110",
      "type": "User",
      "alternateId": "user26@dw-harness.example",
      "displayName": "DW Harness 40",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "oar00000000000000111",
      "type": "refresh_token",
      "alternateId": null,
      "displayName": "DW Harness 21",
      "detailEntry": {
        "expires": "2026-09-20T20:33:35.000Z",
        "subject": "00u00000000000000110",
        "refreshtokentype": "onetime",
        "hash": "0000000000000000000000000000000000000000012="
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.5",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.token.grant.refresh_token",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000020",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientAuthType": "none",
      "grantedScopes": "openid, email, profile, groups, offline_access",
      "requestId": "00000000000000000000000000000020",
      "responseTime": "116",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000016",
      "requestUri": "/oauth2/v1/token",
      "requestedScopes": "openid, email, profile, groups, offline_access",
      "threatSuspected": "false",
      "grantType": "refresh_token",
      "url": "/oauth2/v1/token?"
    }
  },
  "displayMessage": "OIDC refresh token is granted",
  "gatewayContext": null,
  "legacyEventType": "00000000000000000000000000000000000000000003",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

References #

app.oauth2.token.grant.service_account

#

Description

Grant Okta Privileged Access service account credentials. Audit when an application successfully exchanges an OAuth token for credentials for a service account in Okta Privileged Access.

References #

app.oauth2.token.grant.vaulted_secret

#

Description

Grant Okta Privileged Access vaulted secret. Audit when an application successfully exchanges an OAuth token for a vaulted secret in Okta Privileged Access.

References #

app.oauth2.token.oauth_sts.request_token

#

Description

Request OAuth tokens from a third-party authorization server. This event is triggered when Okta requests OAuth tokens from a third-party authorization server.

References #

app.oauth2.token.revoke

#

Description

OIDC token revocation request.

Example System Log Event #

{
  "published": 1785264415731,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000026",
  "actor": {
    "id": "00000000000000000000000000000000000000008",
    "type": "PublicClientApp",
    "alternateId": "user27@dw-harness.example",
    "displayName": "DW Harness 41",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.17",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": null,
  "outcome": {
    "result": "FAILURE",
    "reason": "invalid_token"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.17",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com",
          "ipServiceCategories": [
            {
              "operator": "GLOBAL_PROTECT_CLOUD_VPN",
              "type": "VPN",
              "isAnonymous": false
            }
          ]
        }
      }
    ]
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "app.oauth2.token.revoke",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000021",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "tunnels": [
        {
          "anonymous": false,
          "operator": "GLOBAL_PROTECT_CLOUD_VPN",
          "type": "VPN"
        }
      ],
      "requestId": "00000000000000000000000000000021",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000017",
      "origin": "https://app.example.com",
      "requestUri": "/oauth2/v1/revoke",
      "threatSuspected": "false",
      "url": "/oauth2/v1/revoke?"
    }
  },
  "displayMessage": "OIDC token revocation request",
  "gatewayContext": null,
  "legacyEventType": "app.oauth2.token.revoke_failure",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com",
      "ipServiceCategories": [
        {
          "operator": "GLOBAL_PROTECT_CLOUD_VPN",
          "type": "VPN",
          "isAnonymous": false
        }
      ]
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

References #

app.oauth2.token.revoke.implicit.as

#

Description

Tokens revoked for authorization server.

References #

app.oauth2.token.revoke.implicit.client

#

Description

Tokens revoked for client.

References #

app.oauth2.token.revoke.implicit.user

#

Description

Tokens revoked for user.

Example System Log Event #

{
  "published": 1783162998215,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000027",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000113",
      "type": "User",
      "alternateId": "user28@dw-harness.example",
      "displayName": "DW Harness 43",
      "detailEntry": {
        "realmId": "guo00000000000000044",
        "tokencount": "1"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.oauth2.token.revoke.implicit.user",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "otu00000000000000114",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000007"
    }
  },
  "debugContext": {
    "debugData": {
      "onOrBefore": "1783162997000"
    }
  },
  "displayMessage": "Tokens revoked for user",
  "gatewayContext": null,
  "legacyEventType": "000000000000000000000000000000000000000000002",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000115",
    "externalSessionId": "trs00000000000000116"
  }
}

References #

app.oauth2.trusted_server.add

#

Description

Trusted authorization server is added. Administrators can use this event to debug and audit trusted authorization server operations. When fired, this event contains the authorization server IDs of the servers involved.

References #

app.oauth2.trusted_server.delete

#

Description

Trusted authorization server is removed. Administrators can use this event to debug and audit trusted authorization server operations. When fired, this event contains the authorization server IDs of the servers involved.

References #

app.office365.api.change.domain.federation.success

#

Description

Successfully updated the domain federation from old settings to new settings.

References #

app.office365.api.error.ad.user

#

Description

User is assigned to more than one instance of Active Directory, could not set Immutable ID.

References #

app.office365.api.error.check.user.exists

#

Description

Could not determine status of Office 365 user, received error.

References #

app.office365.api.error.create.user

#

Description

Could not create user in Office 365, received error.

References #

app.office365.api.error.deactivate.user

#

Description

Could not deactivate Office 365 user, received error.

References #

app.office365.api.error.download.custom.objects

#

Description

Could not download group/role/license data for your Office 365 instance, received error.

References #

app.office365.api.error.download.groups

#

Description

Could not download all groups from your Office 365 instance, received error.

References #

app.office365.api.error.download.users

#

Description

Could not download all users from your Office 365 instance, received error.

References #

app.office365.api.error.endpoint.unavailable

#

Description

Unable to reach the Office 365 endpoint.

References #

app.office365.api.error.get.company.dirsync.failure

#

Description

Unable to read Office 365 directory sync for the company, received error.

References #

app.office365.api.error.get.company.dirsync.status.failure

#

Description

Unable to provision user to Office 365, because 'Directory Sync' value in Azure Active Directory is unsupported. Please visit the Azure Active Directory portal and set 'Directory Sync' state to Activated and retry.

References #

app.office365.api.error.get.company.dirsync.status.pending

#

Description

Unable to provision user to Office 365, because 'Directory Sync' value in Azure Active Directory not yet in Activated state. This may take up to 72 hours. Please visit the Azure Active Directory portal and retry when in Activated state.

References #

app.office365.api.error.get.object.ids.by.group.id

#

Description

Could not get users by group id from your Office 365 instance, received error.

References #

app.office365.api.error.group.create.failure

#

Description

Could not create Office 365 group, received error.

References #

app.office365.api.error.group.create.failure.name.in.use

#

Description

Could not create Office 365 group because the name is already in use, received error.

References #

app.office365.api.error.group.delete.failure

#

Description

Could not delete Office 365 group, received error.

References #

app.office365.api.error.group.membership.update.failure

#

Description

Could not update the Office 365 group membership, received error.

References #

app.office365.api.error.group.membership.update.group.not.found.failure

#

Description

Could not update the Office 365 group membership because the group could not be found, received error.

References #

app.office365.api.error.group.update.failure

#

Description

Could not update Office 365 group, received error.

References #

app.office365.api.error.group.update.failure.not.found

#

Description

Could not update Office 365 group because it was not found, received error.

References #

app.office365.api.error.import.profile

#

Description

Could not import profile for Office 365 user, received error.

References #

app.office365.api.error.push.password

#

Description

Could not push password for Office 365 user, received error.

References #

app.office365.api.error.push.profile

#

Description

Could not push profile for Office 365 user, received error.

References #

app.office365.api.error.reactivate.user

#

Description

Could not reactivate Office 365 user, received error.

References #

app.office365.api.error.remove.domain.federation.failure

#

Description

Unable to remove the domain federation, received error.

References #

app.office365.api.error.remove.domain.federation.failure.access.denied

#

Description

Unable to remove the domain federation because the admin user is not authorized to perform the task.

References #

app.office365.api.error.remove.domain.federation.failure.domain.not.found

#

Description

Unable to remove the domain federation because the specified domain was not found.

References #

app.office365.api.error.revoke.refresh.token

#

Description

Failed to revoke refresh tokens for user.

References #

app.office365.api.error.set.company.dirsync.failure

#

Description

Unable to enable Office 365 directory sync for the company, received error.

References #

app.office365.api.error.set.company.dirsync.status.failure

#

Description

Unable to enable Office 365 directory sync for the company, because 'Directory Sync' value in Azure Active Directory is unsupported. Please visit the Azure Active Directory portal and set 'Directory Sync' state to Activated.

References #

app.office365.api.error.set.domain.federation.failure

#

Description

Unable to setup the domain federation, received error.

References #

app.office365.api.error.set.domain.federation.failure.access.denied

#

Description

Unable to setup the domain federation because the admin user is not authorized to perform the task.

References #

app.office365.api.error.set.domain.federation.failure.domain.default

#

Description

Unable to setup the domain federation because the specified domain is the default domain.

References #

app.office365.api.error.set.domain.federation.failure.domain.not.found

#

Description

Unable to setup the domain federation because the specified domain was not found.

References #

app.office365.api.error.sync.contact

#

Description

Failed to sync contact, received error.

References #

app.office365.api.error.sync.finalize

#

Description

Failed to finalize export to Office 365, received error.

References #

app.office365.api.error.sync.group

#

Description

Failed to sync group, received error.

References #

app.office365.api.error.sync.not.activated

#

Description

Sync could not execute because Office 365 directory sync for the company not yet Activated. Sync will retry after a period of time.

References #

app.office365.api.error.sync.set.attribute

#

Description

Failed to set attribute, received error.

References #

app.office365.api.error.sync.user

#

Description

Failed to sync user, received error.

References #

app.office365.api.error.unable.to.create.graph.client

#

Description

An error occurred while creating the Azure Active Directory Graph API client. Please try the last operation again. If this error persists, please contact Okta support.

References #

app.office365.api.error.validate.admin.creds

#

Description

User does not have the Company Administrator role. Please try again with a user which has this role.

References #

app.office365.api.error.validate.creds

#

Description

Could not validate your Office 365 credentials, received error.

References #

app.office365.api.error.x-ms-forwarded-client-ip-header.absent

#

Description

X-MS-Forwarded-Client-IP header either empty or not found in the request.

References #

app.office365.api.remove.domain.federation.success

#

Description

Successfully removed the domain federation.

References #

app.office365.api.set.domain.federation.success

#

Description

Successfully set up the domain federation with new settings.

References #

app.office365.api.sync.complete

#

Description

User sync completed.

References #

app.office365.api.sync.heartbeat.sent

#

Description

Heartbeat sent to Microsoft Azure Active Directory.

References #

app.office365.api.sync.job.complete

#

app.office365.api.sync.job.complete.contact

#

app.office365.api.sync.job.complete.group

#

app.office365.api.sync.job.complete.user

#

app.office365.clientplatform.conversion.job.processing.app.instance

#

Description

Begin processing client access conversion for app instance.

References #

app.office365.clientplatform.conversion.job.skipping.migration

#

Description

Skipping migration of client access rules for app instance.

References #

app.office365.dirsync.skipping.conflict-object

#

Description

Skipping sync of conflict object.

References #

app.office365.dirsync.skipping.critical-system-object

#

Description

Skipping sync of critical system object.

References #

app.office365.dirsync.skipping.non-security-group-invalid-mail

#

Description

Skipping sync of non security object with invalid mail.

References #

app.office365.dirsync.skipping.reserved-attribute-value

#

Description

Skipping sync of object with reserved attribute value.

References #

app.office365.dirsync.skipping.systemmailbox

#

Description

Skipping sync of system mailbox object.

References #

app.office365.dirsync.skipping.without-name-and-displayname

#

Description

Skipping sync of non security object without name and display name.

References #

app.office365.error.importing.user

#

Description

An error occurred while importing user.

References #

app.office365.graph.api.error.no.mailbox.found

#

Description

No MailBox found for Office 365 user.

References #

app.office365.graph.api.error.rate-limit.exceeded

#

Description

Rate limit exceeded for Microsoft Graph.

References #

app.office365.graph.api.error.service.principal.creation.failed

#

Description

Failure while trying to create service principal.

References #

app.office365.graph.api.error.service.principal.msgraph.authentication.failure

#

Description

Failure while trying to create service principal due to a Mircrosoft Graph authentication issue.

References #

app.office365.service.principal.cleanup.job.complete

#

Description

End processing Office 365 service principal cleanup.

References #

app.office365.service.principal.cleanup.job.invalid.credentials

#

Description

The admin username or password is invalid. Please use the Azure Active Directory cmdlets to execute the command 'Remove-MsolServicePrincipal -AppPrincipalId' to manually cleanup the service principal.

References #

app.office365.service.principal.cleanup.job.processing

#

Description

Begin performing Office 365 service principal cleanup.

References #

app.office365.service.principal.cleanup.job.skipping.missing.creds

#

Description

Skipping app instance during Office 365 service principal cleanup as it does not contain Office 365 admin user credentials. Please use the Azure Active Directory cmdlets to execute the command 'Remove-MsolServicePrincipal -AppPrincipalId' to manually cleanup the service principal.

References #

app.office365.service.principal.cleanup.job.skipping.no.service.principal

#

Description

Skipping app instance during Office 365 service principal cleanup as it does not have a service principal.

References #

app.office365.service.principal.cleanup.job.unable.to.delete.service.principal

#

Description

Unable to automatically delete the Office 365 service principal. Please use the Azure Active Directory cmdlets to execute the command 'Remove-MsolServicePrincipal -AppPrincipalId' to manually cleanup the service principal.

References #

app.office365.user.delete.success

#

Description

Successfully deleted the Office 365 user.

References #

app.office365.user.lifecycle.action.failed

#

Description

Unable to complete app user lifecycle action for AppUser.

References #

app.office365.user.remove.licenses.success

#

Description

Successfully removed all the licenses for the Office 365 user.

References #

app.policy.sign_on.update

#

Description

Update app sign on policy. This event is used to audit when an app sign on policy is updated. This event is fired when an admin updates an app's sign on policy and logs what was changed.

References #

app.radius.agent.listener.failed

#

Description

Radius agent listener failed.

References #

app.radius.agent.listener.succeeded

#

Description

Radius agent listener succeeded.

References #

app.radius.agent.port_inaccessible

#

Description

Radius agent failed to listen on port.

References #

app.radius.agent.port_reaccessible

#

Description

Radius agent was able to listen on port again.

References #

app.radius.info_access.no_permission

#

Description

No permission accessing any Radius app info. This event can be used to monitor and notify admins when some users who access radius app info have no permission. Fired when users who access radius app info have no permission.

References #

app.radius.info_access.partial_permission

#

Description

No permission accessing info for part of Radius apps. This event can be used to monitor and notify admins when some users who access radius app info have only partial permission. Fired when users who access radius app info have partial permission.

References #

app.realtimesync.import.details.add_user

#

Description

Real time sync added new User.

References #

app.realtimesync.import.details.delete_user

#

Description

Real time sync removed existing User.

References #

app.realtimesync.import.details.update_user

#

Description

Fired when a real time import includes an update to an existing user. This can be used to see details about the user updates included in a real time sync import. When fired, this event contains information about the type of update made, including whether or not a user was suspend or unsuspended. Related events include: app.realtimesync.import.details_add_user and app.realtimesync.import.details_delete_user.

Example System Log Event #

{
  "published": 1782502956446,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000028",
  "actor": {
    "id": "00u00000000000000117",
    "type": "User",
    "alternateId": "user29@dw-harness.example",
    "displayName": "DW Harness 44",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000118",
      "type": "User",
      "alternateId": "user30@dw-harness.example",
      "displayName": "DW Harness 45",
      "detailEntry": {
        "realmId": "guo00000000000000062"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.realtimesync.import.details.update_user",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "prj00000000000000119",
    "detail": {
      "rootApiTokenId": "00t00000000000000120"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "RealTimeSync for user update was successful",
  "gatewayContext": null,
  "legacyEventType": "app.realtimesync.import.details.update_user",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000121",
    "externalSessionId": "trs00000000000000122"
  }
}

References #

app.request_new.notify

#

Description

A user sent an application request. Used to notify admins that a user made an application request from the Enduser Dashboard. The application request attempts to send an email to an admin with the user's request. This event only indicates that the request was made, not necessarily that the email was successfully delivered.

References #

app.rum.config.validation.error

#

Description

Error validating instance configuration. Can be used to identify configuration issues with remote user management.

References #

app.rum.is.api.account.error

#

Description

RUM API account is not configured or empty. Can be used to identify RUM API account configuration issues.

References #

app.rum.package.thrown.error

#

Description

Errors during execution. Can be used to identify any errors during execution of remote user management.

References #

app.rum.validation.error

#

Description

Error during package validation. Can be used to identify validation issues with remote user management packages.

References #

app.saml.sensitive.attribute.update

#

Description

Fired when a SAML assertion contains a sensitive attribute, and that sensitive attribute has been updated (modified/added/deleted). This event does not fire when non-sensitive SAML attributes are updated. This can be used to audit that a sensitive attribute attached to an outbound SAML assertion has been correctly modified, added, or deleted. When fired, this event contains the specific attributes that have been modified, added, or deleted to/from the SAML assertion. Related events include: application.lifecycle.update.

References #

app.user_management

#

Description

Imported new or deleted existing member of an application group.

Example System Log Event #

{
  "actor": {
    "alternateId": "system@okta.com",
    "detailEntry": null,
    "displayName": "Okta System",
    "id": "00000000000000000004",
    "type": "SystemPrincipal"
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": null,
    "externalSessionId": "00000000000000000000000000000005",
    "interface": null,
    "issuer": null
  },
  "client": {
    "device": null,
    "geographicalContext": null,
    "id": null,
    "ipAddress": null,
    "userAgent": null,
    "zone": null
  },
  "debugContext": {
    "debugData": {}
  },
  "device": null,
  "displayMessage": "Successfully imported new member to an app group",
  "eventType": "app.user_management",
  "legacyEventType": "app.user_management.app_group_member_import.insert_success",
  "outcome": {
    "reason": null,
    "result": "SUCCESS"
  },
  "published": "2023-04-27T00:56:17.750Z",
  "request": {
    "ipChain": []
  },
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "domain": null,
    "isProxy": null,
    "isp": null
  },
  "severity": "INFO",
  "target": [
    {
      "alternateId": "user03@dw-harness.example",
      "detailEntry": null,
      "displayName": "DW Harness 03",
      "id": "00000000000000000000000000000006",
      "type": "AppUser"
    },
    {
      "alternateId": "user04@dw-harness.example",
      "detailEntry": null,
      "displayName": "DW Harness 04",
      "id": "00000000000000000000000000000007",
      "type": "AppGroup"
    },
    {
      "alternateId": "user03@dw-harness.example",
      "detailEntry": null,
      "displayName": "DW Harness 05",
      "id": "00000000000000000000000000000008",
      "type": "User"
    },
    {
      "alternateId": "user05@dw-harness.example",
      "detailEntry": null,
      "displayName": "DW Harness 06",
      "id": "00000000000000000000000000000009",
      "type": "AppInstance"
    }
  ],
  "transaction": {
    "detail": {},
    "id": "00000000000000000000000000000010",
    "type": "JOB"
  },
  "uuid": "00000000-0000-0000-0000-000000000003",
  "version": "0"
}

References #

app.user_management.grouppush.mapping.created.from.rule

#

Description

A Group Push mapping to the group has been created from the rule.

Example System Log Event #

{
  "published": 1783623908402,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000029",
  "actor": {
    "id": "0oa00000000000000123",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 46",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000124",
      "type": "AppInstance",
      "alternateId": "user31@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000125",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 48",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.user_management.grouppush.mapping.created.from.rule",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rej00000000000000126",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000008"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "A Group Push mapping to the group Example Group 5 has been created from the rule gpr00000000000000127 with the id - gpm00000000000000128.",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.mapping.created.from.rule",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000129",
    "externalSessionId": "trs00000000000000130"
  }
}

References #

app.user_management.grouppush.mapping.created.from.rule.error.duplicate

#

Description

A Group Push mapping to the group did not get created from rule because an existing mapping already existed.

Example System Log Event #

{
  "published": 1784131457676,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000030",
  "actor": {
    "id": "00u00000000000000131",
    "type": "User",
    "alternateId": "user32@dw-harness.example",
    "displayName": "DW Harness 49",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000124",
      "type": "AppInstance",
      "alternateId": "user31@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000132",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 50",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.user_management.grouppush.mapping.created.from.rule.error.duplicate",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rej00000000000000133",
    "detail": {
      "rootApiTokenId": "00t00000000000000134"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "A Group Push mapping to the group Example Group 10 did not get created from rule gpr00000000000000135 because an existing mapping already existed.",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.mapping.created.from.rule.error.duplicate",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000136",
    "externalSessionId": "trs00000000000000137"
  }
}

References #

app.user_management.grouppush.mapping.created.from.rule.error.validation

#

Description

A Group Push mapping to the group did not get created from rule because of the validation error.

References #

app.user_management.grouppush.mapping.created.from.rule.errors

#

Description

A Group Push mapping to the group did not get created from rule.

References #

app.user_management.grouppush.mapping.okta.users.ignored

#

Description

Okta users ignored while pushing group to AppInstance.

References #

app.user_management.import.csv.line.error

#

Description

Error reading line from CSV.

References #

app.user_management.push_new_user_success

#

Description

Successfully pushed new user account to app.

Example System Log Event #

{
  "published": 1785256678979,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000031",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000138",
      "type": "AppUser",
      "alternateId": "user33@dw-harness.example",
      "displayName": "DW Harness 51",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000139",
      "type": "User",
      "alternateId": "user33@dw-harness.example",
      "displayName": "DW Harness 51",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "0oa00000000000000140",
      "type": "AppInstance",
      "alternateId": "user34@dw-harness.example",
      "displayName": "DW Harness 52",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.user_management.push_new_user_success",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "puj00000000000000141",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 16"
    }
  },
  "displayMessage": "Successfully pushed new user account to app",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.push_new_user_success",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000142",
    "externalSessionId": "trs00000000000000143"
  }
}

References #

app.user_management.update_from_master_failed

#

app.user_management.user_group_import.create_failure

#

Description

Failed to create group from app.

References #

app.user_management.user_group_import.delete_success

#

Description

Deleted the group from app.

Example System Log Event #

{
  "published": 1783702998845,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000032",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000144",
      "type": "AppInstance",
      "alternateId": "user35@dw-harness.example",
      "displayName": "DW Harness 53",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000144",
      "type": "AppInstance",
      "alternateId": "user35@dw-harness.example",
      "displayName": "DW Harness 53",
      "detailEntry": null
    },
    {
      "id": "agr00000000000000145",
      "type": "AppGroup",
      "alternateId": "user36@dw-harness.example",
      "displayName": "DW Harness 54",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000146",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 54",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "app.user_management.user_group_import.delete_success",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gmr00000000000000147",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000009"
    }
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 11"
    }
  },
  "displayMessage": "Deleted the Example Group 9 group from app",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.user_group_import.delete_success",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000148",
    "externalSessionId": "trs00000000000000149"
  }
}

References #

app.user_management.user_group_import.update_failure

#

Description

Failed to update group from app.

References #

app.user_management.user_group_import.upsert_fail

#

Description

Failed to import the group from app. This event helps identify when a group is failed to be imported. Fired when we skip processing an import of a group.

References #

app.user_management.user_group_import.upsert_success

#

app.ad.credential.verify

#

Description

Verify a stored Active Directory credential is valid. Use this event to audit AD credential drift checks performed by privileged-access flows (e.g., Okta Privileged Access). Unlike a real AD authentication, this verification creates no Okta session and does not update user state. outcome.result = SUCCESS indicates the stored credential is valid against AD. FAILURE indicates the credential is invalid for any reason (e.g., drifted, rotated, revoked, or similar).

References #

app.ai_agent_provider.import_staging.confirm

#

Description

Confirm an AI agent staging item for registration. Audit when an imported agent is accepted into the identity store, either as a new registration or merged with an existing agent from another provider. A corresponding workload_principal.register event is fired when the confirmed agent is registered.

References #

app.ai_agent_provider.import_staging.ignore

#

Description

Ignore an AI agent staging item. Audit when an imported agent is dismissed and excluded from the identity store.

References #

app.ai_agent_provider.priority.update

#

Description

Update the priority ordering of AI agent import providers. Audit when the import provider priority ordering changes; the new order determines which provider's profile attributes take precedence for agents imported from multiple sources. changeDetails contains the ordered list of app instance IDs before and after the change, matching the order of the replace request.

References #

app.office365.provisioning_app.create

#

Description

Creates a dedicated Microsoft Entra ID app that's registered and used for Office 365 provisioning. Confirms Okta has provisioned the Entra ID app registration required for Office 365 app-based provisioning. Correlate with the app in Microsoft Entra via app_registration_client_id.

References #

app.office365.provisioning_app_credential.rotate

#

Description

Rotates the client secret of the registered Microsoft Entra ID app that's used for Office 365 provisioning. Outcome.Result distinguishes SUCCESS from FAILURE. Tracks scheduled rotations of the Entra ID app registration's client secret. Alert on Outcome.Result = FAILURE via Event Hook to catch stuck secrets before expiry. 'rotate' is outside the currently approved action-verb list (create/update/assign/revoke/generate/execute/delete/activate/deactivate); prior art exists (app.keys.rotate, pam.apikey.rotate, pam.client_enrollment_policy_token.rotate, pam.offline_group.secrets.rotate) and no approved verb captures the semantics of an in-place credential refresh.

References #