Okta App
| eventType | Description | Sample | Rule |
|---|---|---|---|
| app. | Request to access an app was approved by an administrator-defined approver. | N | N |
| app. | Request to access an app was denied by an administrator-defined approver. | N | N |
| app. | Request to access an app was deleted by an administrator. | N | N |
| app. | Request to access an app was denied after at least one approver denied the request. | N | N |
| app. | Request to access an app expired by the system due to lack of approver action. | N | N |
| app. | Request to access an app was granted after all approvers approved the request. | N | N |
| app. | Request to access an app was performed by a user. | N | N |
| app. | Active Directory user account set to locked following profile update: user is locked in active directory. | N | N |
| app. | Skipping import of contact due to invalid attribute. | N | N |
| app. | Skipping import of user due to an invalid AD attribute. | N | N |
| app. | Skipping import of user due to a required AD attribute being null. | N | N |
| app. | Complete cancellation of migration campaign. | N | N |
| app. | Start cancellation of a password migration campaign. | N | N |
| app. | Create Active Directory password migration campaign. | N | N |
| app. | Complete password migration campaign. | N | N |
| app. | Start password migration campaign completion. | N | N |
| app. | Add group to Active Directory password migration campaign. | N | N |
| app. | Capture user password from Active Directory. | N | N |
| app. | Complete individual user password migration. | N | N |
| app. | Start individual user password migration. | N | N |
| app. | Activate an AI agent provider. | N | N |
| app. | Create an AI agent provider. | N | N |
| app. | Validate credentials for an AI agent import provider. | N | N |
| app. | Deactivate an AI agent provider. | N | N |
| app. | Delete an AI agent provider. | N | N |
| app. | Complete a bulk import of AI agents from an external provider. | N | N |
| app. | Start a bulk import of AI agents from an external provider. | N | N |
| app. | Update an AI agent provider. | N | N |
| app. | Certificate signing request (CSR) generated. | N | N |
| app. | Certificate signing request (CSR) published. | N | N |
| app. | Certificate signing request (CSR) revoked. | N | N |
| app. | Fired when a provision sync job has successfully completed. | N | N |
| app. | Fired when a provision sync job has failed. | N | N |
| app. | Fired when a provision sync job has successfully started. | N | N |
| app. | Create Cross App Access connection. | N | N |
| app. | Delete Cross App Access connection. | N | N |
| app. | Update Cross App Access connection. | N | N |
| app. | User attempted unauthorized access to app. | Y | Y |
| app. | Successful inbound delegated authentication request for user. | N | N |
| app. | Create interclient trust mapping. | N | N |
| app. | Delete interclient trust mapping. | N | N |
| app. | Delete all interclient trust mappings for app. | N | N |
| app. | Kerberos based rich client authentication failed: Could not find Office 365 app user for the AD user with principal id. | N | N |
| app. | Kerberos based rich client authentication failed: Unknown app instance id. | N | N |
| app. | Kerberos based rich client authentication failed: Multiple users with username found. | N | N |
| app. | Kerberos based rich client authentication successful for Office 365 user. | N | N |
| app. | Application signing key cloned. | N | N |
| app. | New signing key generated. | N | N |
| app. | Application signing key rotated. | N | N |
| app. | Password change failed. | N | N |
| app. | Administrator consent granted for scope. | Y | N |
| app. | Administrator consent revoked for scope. | N | N |
| app. | OAuth2 authorization request. | Y | N |
| app. | OAuth2 authorization code request. | Y | N |
| app. | OAuth2 authorization implicit access token request. | N | N |
| app. | OAuth2 authorization implicit ID token request. | N | N |
| app. | Some of the requested scopes were denied by the policy. | N | N |
| app. | User granted consent to app. | N | N |
| app. | Consent revoked. | N | N |
| app. | All consent revoked for authorization server. | N | N |
| app. | All consent revoked for client. | Y | N |
| app. | All consent revoked for scope. | N | N |
| app. | Consent for all scopes revoked for user. | N | N |
| app. | All consent revoked for user. | N | N |
| app. | User consent revoked for client. | N | N |
| app. | Claim evaluation for OAuth 2.0 token. | N | N |
| app. | Interaction code is generated by OIE. | N | N |
| app. | Interaction handle is generated by OIE. | N | N |
| app. | Custom Authorization Server token signing key rolled over. | Y | N |
| app. | Authorization server access token encryption key is activated. | N | N |
| app. | Authorization server access token encryption key is created. | N | N |
| app. | Authorization server access token encryption key is deactivated. | N | N |
| app. | Authorization server access token encryption key is deleted. | N | N |
| app. | Detect one-time refresh token attempted reuse. This event can be used by administrators to detect and audit attempted reuse of one-time refresh tokens. | N | Y |
| app. | OAuth2 token request. | Y | Y |
| app. | OAuth 2.0 access token is granted. | Y | N |
| app. | Grant an OAuth2 device_secret for the Native SSO flow. | N | N |
| app. | OAuth 2.0 ID token is granted. | Y | N |
| app. | Grant interclient token. Track the successful issuance of an Interclient token via OAuth token exchange. | N | N |
| app. | OAuth2 refresh token is granted. | Y | N |
| app. | OAuth2 token revocation request. | N | N |
| app. | OIDC authorization request. | Y | N |
| app. | OIDC authorization code request. | Y | N |
| app. | OIDC authorization implicit access token request. | N | N |
| app. | OIDC authorization implicit ID token request. | N | N |
| app. | Activate OAuth client. | Y | N |
| app. | Create OAuth client. | Y | N |
| app. | Deactivate OAuth client. | Y | N |
| app. | Delete OAuth client. | Y | N |
| app. | Update OAuth client. | Y | N |
| app. | An OAuth 2.0 client app's admin privileges changed. | Y | N |
| app. | All privileges for OAuth 2.0 client app were revoked. | Y | N |
| app. | Read OAuth client's secret(s). | Y | N |
| app. | Requests from a single client ID consumed the majority of an organization's OAuth2 endpoint rate limit. | N | N |
| app. | User granted consent to app. This event can be used to identify the org AS consent grant. | N | N |
| app. | OAuth client credentials (either client secret or JWK) is added for an application. | Y | N |
| app. | OAuth client credentials (either client secret or JWK) is activated for an application. | Y | N |
| app. | OAuth client credentials (either client secret or JWK) is deactivated for an application. | Y | N |
| app. | OAuth client credentials (either client secret or JWK) is deleted for an application. | Y | N |
| app. | Interaction code generated by OIE. | N | N |
| app. | Interaction handle generated by OIE. | N | N |
| app. | Multiple requests with invalid client credentials for client id. | N | N |
| app. | Org Authorization Server token signing key rolled over. | N | N |
| app. | User performed OIDC single sign on to app. | N | N |
| app. | Detect one-time refresh token attempted reuse. This event can be used by administrators to detect and audit attempted reuse of one-time refresh tokens. | N | Y |
| app. | OIDC token request. | Y | N |
| app. | OIDC access token is granted. | Y | N |
| app. | OAuth 2.0 Identity Assertion JWT Authorization Grant (ID-JAG) granted. | N | N |
| app. | OIDC id token is granted. | Y | N |
| app. | Grant interclient token. Track the successful issuance of an Interclient token via OAuth token exchange. | N | N |
| app. | Grant OAuth Security Token Service (STS) access token. | N | N |
| app. | OIDC refresh token is granted. | Y | N |
| app. | Grant Okta Privileged Access service account credentials. | N | N |
| app. | Grant Okta Privileged Access vaulted secret. | N | N |
| app. | Request OAuth tokens from a third-party authorization server. | N | N |
| app. | OIDC token revocation request. | Y | N |
| app. | Tokens revoked for authorization server. | N | N |
| app. | Tokens revoked for client. | N | N |
| app. | Tokens revoked for user. | Y | N |
| app. | Trusted authorization server is added. | N | N |
| app. | Trusted authorization server is removed. | N | N |
| app. | Successfully updated the domain federation from old settings to new settings. | N | N |
| app. | User is assigned to more than one instance of Active Directory, could not set Immutable ID. | N | N |
| app. | Could not determine status of Office 365 user, received error. | N | N |
| app. | Could not create user in Office 365, received error. | N | N |
| app. | Could not deactivate Office 365 user, received error. | N | N |
| app. | Could not download group/role/license data for your Office 365 instance, received error. | N | N |
| app. | Could not download all groups from your Office 365 instance, received error. | N | N |
| app. | Could not download all users from your Office 365 instance, received error. | N | N |
| app. | Unable to reach the Office 365 endpoint. | N | N |
| app. | Unable to read Office 365 directory sync for the company, received error. | N | N |
| app. | Unable to provision user to Office 365, because 'Directory Sync' value in Azure Active Directory is unsupported. | N | N |
| app. | Unable to provision user to Office 365, because 'Directory Sync' value in Azure Active Directory not yet in Activated state. | N | N |
| app. | Could not get users by group id from your Office 365 instance, received error. | N | N |
| app. | Could not create Office 365 group, received error. | N | N |
| app. | Could not create Office 365 group because the name is already in use, received error. | N | N |
| app. | Could not delete Office 365 group, received error. | N | N |
| app. | Could not update the Office 365 group membership, received error. | N | N |
| app. | Could not update the Office 365 group membership because the group could not be found, received error. | N | N |
| app. | Could not update Office 365 group, received error. | N | N |
| app. | Could not update Office 365 group because it was not found, received error. | N | N |
| app. | Could not import profile for Office 365 user, received error. | N | N |
| app. | Could not push password for Office 365 user, received error. | N | N |
| app. | Could not push profile for Office 365 user, received error. | N | N |
| app. | Could not reactivate Office 365 user, received error. | N | N |
| app. | Unable to remove the domain federation, received error. | N | N |
| app. | Unable to remove the domain federation because the admin user is not authorized to perform the task. | N | N |
| app. | Unable to remove the domain federation because the specified domain was not found. | N | N |
| app. | Failed to revoke refresh tokens for user. | N | N |
| app. | Unable to enable Office 365 directory sync for the company, received error. | N | N |
| app. | Unable to enable Office 365 directory sync for the company, because 'Directory Sync' value in Azure Active Directory is unsupported. | N | N |
| app. | Unable to setup the domain federation, received error. | N | N |
| app. | Unable to setup the domain federation because the admin user is not authorized to perform the task. | N | N |
| app. | Unable to setup the domain federation because the specified domain is the default domain. | N | N |
| app. | Unable to setup the domain federation because the specified domain was not found. | N | N |
| app. | Failed to sync contact, received error. | N | N |
| app. | Failed to finalize export to Office 365, received error. | N | N |
| app. | Failed to sync group, received error. | N | N |
| app. | Sync could not execute because Office 365 directory sync for the company not yet Activated. | N | N |
| app. | Failed to set attribute, received error. | N | N |
| app. | Failed to sync user, received error. | N | N |
| app. | An error occurred while creating the Azure Active Directory Graph API client. | N | N |
| app. | User does not have the Company Administrator role. | N | N |
| app. | Could not validate your Office 365 credentials, received error. | N | N |
| app. | X-MS-Forwarded-Client-IP header either empty or not found in the request. | N | N |
| app. | Successfully removed the domain federation. | N | N |
| app. | Successfully set up the domain federation with new settings. | N | N |
| app. | User sync completed. | N | N |
| app. | Heartbeat sent to Microsoft Azure Active Directory. | N | N |
| app. | Sync job completed. | N | N |
| app. | Sync job completed. | N | N |
| app. | Sync job completed. | N | N |
| app. | Sync job completed. | N | N |
| app. | Begin processing client access conversion for app instance. | N | N |
| app. | Skipping migration of client access rules for app instance. | N | N |
| app. | Skipping sync of conflict object. | N | N |
| app. | Skipping sync of critical system object. | N | N |
| app. | Skipping sync of non security object with invalid mail. | N | N |
| app. | Skipping sync of object with reserved attribute value. | N | N |
| app. | Skipping sync of system mailbox object. | N | N |
| app. | Skipping sync of non security object without name and display name. | N | N |
| app. | An error occurred while importing user. | N | N |
| app. | No MailBox found for Office 365 user. | N | N |
| app. | Rate limit exceeded for Microsoft Graph. | N | N |
| app. | Failure while trying to create service principal. | N | N |
| app. | Failure while trying to create service principal due to a Mircrosoft Graph authentication issue. | N | N |
| app. | End processing Office 365 service principal cleanup. | N | N |
| app. | The admin username or password is invalid. | N | N |
| app. | Begin performing Office 365 service principal cleanup. | N | N |
| app. | Skipping app instance during Office 365 service principal cleanup as it does not contain Office 365 admin user credentials. | N | N |
| app. | Skipping app instance during Office 365 service principal cleanup as it does not have a service principal. | N | N |
| app. | Unable to automatically delete the Office 365 service principal. | N | N |
| app. | Successfully deleted the Office 365 user. | N | N |
| app. | Unable to complete app user lifecycle action for AppUser. | N | N |
| app. | Successfully removed all the licenses for the Office 365 user. | N | N |
| app. | Update app sign on policy. | N | N |
| app. | Radius agent listener failed. | N | N |
| app. | Radius agent listener succeeded. | N | N |
| app. | Radius agent failed to listen on port. | N | N |
| app. | Radius agent was able to listen on port again. | N | N |
| app. | No permission accessing any Radius app info. | N | N |
| app. | No permission accessing info for part of Radius apps. | N | N |
| app. | Real time sync added new User. | N | N |
| app. | Real time sync removed existing User. | N | N |
| app. | Fired when a real time import includes an update to an existing user. | Y | N |
| app. | A user sent an application request. | N | N |
| app. | Error validating instance configuration. | N | N |
| app. | RUM API account is not configured or empty. | N | N |
| app. | Errors during execution. | N | N |
| app. | Error during package validation. | N | N |
| app. | Fired when a SAML assertion contains a sensitive attribute, and that sensitive attribute has been updated (modified/added/deleted). | N | N |
| app. | Imported new or deleted existing member of an application group. | Y | N |
| app. | A Group Push mapping to the group has been created from the rule. | Y | N |
| app. | A Group Push mapping to the group did not get created from rule because an existing mapping already existed. | Y | N |
| app. | A Group Push mapping to the group did not get created from rule because of the validation error. | N | N |
| app. | A Group Push mapping to the group did not get created from rule. | N | N |
| app. | Okta users ignored while pushing group to AppInstance. | N | N |
| app. | Error reading line from CSV. | N | N |
| app. | Successfully pushed new user account to app. | Y | N |
| app. | Could not apply import. | N | N |
| app. | Failed to create group from app. | N | N |
| app. | Deleted the group from app. | Y | N |
| app. | Failed to update group from app. | N | N |
| app. | Failed to import the group from app. | N | N |
| app. | Imported the group from app. | N | N |
| app. | Verify a stored Active Directory credential is valid. | N | N |
| app. | Confirm an AI agent staging item for registration. | N | N |
| app. | Ignore an AI agent staging item. | N | N |
| app. | Update the priority ordering of AI agent import providers. | N | N |
| app. | Creates a dedicated Microsoft Entra ID app that's registered and used for Office 365 provisioning. | N | N |
| app. | Rotates the client secret of the registered Microsoft Entra ID app that's used for Office 365 provisioning. | N | N |
app.access_request.approver.approve
#Description
Request to access an app was approved by an administrator-defined approver.
References #
app.access_request.approver.deny
#Description
Request to access an app was denied by an administrator-defined approver.
References #
app.access_request.delete
#Description
Request to access an app was deleted by an administrator.
References #
app.access_request.deny
#Description
Request to access an app was denied after at least one approver denied the request.
References #
app.access_request.expire
#Description
Request to access an app expired by the system due to lack of approver action.
References #
app.access_request.grant
#Description
Request to access an app was granted after all approvers approved the request.
References #
app.ad.api.user_import.account_locked
#Description
Active Directory user account set to locked following profile update: user is locked in active directory.
References #
app.ad.api.user_import.warn.skipped_contact.attribute_invalid_value
#Description
Skipping import of contact due to invalid attribute. Please consult with your Active Directory admin if you believe this contact should be imported.
References #
app.ad.api.user_import.warn.skipped_user.attribute_invalid_value
#Description
Skipping import of user due to an invalid AD attribute.
References #
app.ad.api.user_import.warn.skipped_user.missing_required_attribute
#Description
Skipping import of user due to a required AD attribute being null.
References #
app.ad.password_migration_campaign.cancel.end
#Description
Complete cancellation of migration campaign. This can be used to confirm that the process to cancel a password migration campaign intentionally is complete. This event marks the end of the cancellation process that began with an app.ad.password_migration_campaign.cancel.start event.
References #
app.ad.password_migration_campaign.cancel.start
#Description
Start cancellation of a password migration campaign. This can be used to track when the process to intentionally cancel a password migration campaign begins. This begins an asynchronous process. Its conclusion is marked by the app.ad.password_migration_campaign.cancel.end event.
References #
app.ad.password_migration_campaign.create
#Description
Create Active Directory password migration campaign. This can be used to identify when a migration is created to monitor its duration and impact on users. Marks the beginning of a password migration campaign.
References #
app.ad.password_migration_campaign.finish.end
#Description
Complete password migration campaign. This can be used to confirm that a Finish password migration campaign process has fully completed. This event marks the successful end of the entire campaign lifecycle. This is an asynchronous process and is preceded by an app.ad.password_migration_campaign.finish.start event.
References #
app.ad.password_migration_campaign.finish.start
#Description
Start password migration campaign completion. This can be used to track the start of the Finish Campaign process. This begins an asynchronous process. Its conclusion is marked by the app.ad.password_migration_campaign.finish.end event.
References #
app.ad.password_migration_campaign.group.add
#Description
Add group to Active Directory password migration campaign. This can be used to identify groups that have been included in a password migration campaign. This action expands the set of users eligible for password capture by the campaign.
References #
app.ad.password_migration_campaign.user.capture_password
#Description
Capture user password from Active Directory. This can be used to track progress for individual users and confirm password collection. This event does not signify the full migration of the user, only the successful capture of their password.
References #
app.ad.password_migration_campaign.user.migrate.end
#Description
Complete individual user password migration. This can be used as a record that a user's credential is fully migrated to Okta. The user's password is now fully migrated and active in Okta.
References #
app.ad.password_migration_campaign.user.migrate.start
#Description
Start individual user password migration. This can be used to confirm that a specific user's migration process has begun. The conclusion of this asynchronous process is marked by a corresponding app.ad.password_migration_campaign.user.migrate.end event.
References #
app.ai_agent_provider.activate
#Description
Activate an AI agent provider. Track when an AI agent import provider is enabled for scheduled imports.
References #
app.ai_agent_provider.create
#Description
Create an AI agent provider. Track when a new connection to an external AI agent provider is established for importing agents.
References #
app.ai_agent_provider.credential.validate
#Description
Validate credentials for an AI agent import provider. Verify that credentials for an AI agent import provider are valid before activating the provider. Typically follows provider.credential.update and precedes provider.activate.
References #
app.ai_agent_provider.deactivate
#Description
Deactivate an AI agent provider. Track when an AI agent import provider is disabled.
References #
app.ai_agent_provider.delete
#Description
Delete an AI agent provider. Track when a connection to an external AI agent provider is removed.
References #
app.ai_agent_provider.import.complete
#Description
Complete a bulk import of AI agents from an external provider. Audit the outcome of AI agent imports, including the number of agents found, imported, and errored. Paired with app.ai_agent_provider.import.start. Import outcome details are in the targets.
References #
app.ai_agent_provider.import.start
#Description
Start a bulk import of AI agents from an external provider. Audit when bulk imports of AI agents from external providers begin. A corresponding app.ai_agent_provider.import.complete event is fired when the import completes.
References #
app.ai_agent_provider.update
#Description
Update an AI agent provider. Track AI agent import provider changes, such as credential configuration, owner info, and schedule updates. This event refers to the OAuth2 credentials used to connect to an external AI agent provider. For AI agent workload identity credentials (JWK signing keys), see workload_principal.ai_agent.credential.* events.
References #
app.app_instance.provision_sync_job.completed
#Description
Fired when a provision sync job has successfully completed. This can be used to confirm that a provision sync job has finished running and is no longer processing users. When fired, this event contains details about number of users processed in the job. Related events include app.app_instance.provision_sync_job.started and app.app_instance.provision_sync_job.failed.
References #
app.app_instance.provision_sync_job.failed
#Description
Fired when a provision sync job has failed. This can be used to identify when a provision sync job has failed. When fired, this event contains information about the reason the provision sync job failed. Related events include app.app_instance.provision_sync_job.started and app.app_instance.provision_sync_job.completed.
References #
app.app_instance.provision_sync_job.started
#Description
Fired when a provision sync job has successfully started. This can be used to confirm that a provision sync job has successfully started. Related events include app.app_instance.provision_sync_job.completed and app.app_instance.provision_sync_job.failed.
References #
app.cross_app_access.connection.create
#Description
Create Cross App Access connection. Audit when a requesting application is configured to connect with one or more resource applications. This is useful for security investigations and for compliance reviews of inter-application trust establishment.
Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.References #
app.cross_app_access.connection.delete
#Description
Delete Cross App Access connection. Audit when existing Cross App Access connections are removed. This is useful for tracking application lifecycle management and for security posture cleanup of inter-application trust relationships.
Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.References #
app.cross_app_access.connection.update
#Description
Update Cross App Access connection. Audit when existing Cross App Access connection configuration is modified, such as toggling enabled status. The changeDetails field tracks specific modifications. It is useful for generating alerts about unexpected changes to inter-application trusts.
Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.References #
app.generic.unauth_app_access_attempt
#Description
User attempted unauthorized access to app.
Example System Log Event #
{
"actor": {
"alternateId": "user02@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 02",
"id": "00u00000000000000002",
"type": "User"
},
"authenticationContext": {
"authenticationProvider": null,
"authenticationStep": 0,
"credentialProvider": null,
"credentialType": null,
"externalSessionId": null,
"interface": null,
"issuer": null
},
"client": {
"device": "Computer",
"geographicalContext": {
"city": "Anytown",
"country": "Placeholderland",
"geolocation": {
"lat": 0.0,
"lon": 0.0
},
"postalCode": "00000",
"state": "Anystate"
},
"id": null,
"ipAddress": "198.51.100.2",
"userAgent": {
"browser": "CHROME",
"os": "Mac OS 13.4.0 (Ventura)",
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
},
"zone": "null"
},
"debugContext": {
"debugData": {
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestId": "00000000000000000000000000000003",
"requestUri": "/error/enduser-error-page",
"url": "/error/enduser-error-page?error_description=The+resource+owner+or+authorization+server+denied+the+request."
}
},
"device": null,
"displayMessage": "User attempted unauthorized access to app",
"eventType": "app.generic.unauth_app_access_attempt",
"legacyEventType": "app.generic.unauth_app_access_attempt",
"outcome": {
"reason": null,
"result": "FAILURE"
},
"published": "2024-02-29T22:50:39.032Z",
"request": {
"ipChain": [
{
"geographicalContext": {
"city": "Anytown",
"country": "Placeholderland",
"geolocation": {
"lat": 0.0,
"lon": 0.0
},
"postalCode": "00000",
"state": "Anystate"
},
"ip": "198.51.100.3",
"source": null,
"version": "V4"
}
]
},
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"domain": "example.com",
"isProxy": false,
"isp": "example-isp"
},
"severity": "WARN",
"target": [
{
"alternateId": "Okta Dashboard",
"detailEntry": null,
"displayName": "Okta Dashboard",
"id": "0oa00000000000000003",
"type": "AppInstance"
}
],
"transaction": {
"detail": {},
"id": "00000000000000000000000000000003",
"type": "WEB"
},
"uuid": "00000000-0000-0000-0000-000000000002",
"version": "0"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
event_action (splunk rule field) | eq | failure | 1Â rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1078, T1078.004Splunk #
T1087, T1087.004Panther #
References #
app.inbound_del_auth.login_success
#Description
Successful inbound delegated authentication request for user.
References #
app.interclient_mapping.create
#Description
Create interclient trust mapping. Audit the creation of a trust mapping between a target app and a requesting app via the interclient access API.
References #
app.interclient_mapping.delete
#Description
Delete interclient trust mapping. Audit the deletion of a trust mapping between a target app and a requesting app via the interclient access API.
References #
app.interclient_mapping.delete_all
#Description
Delete all interclient trust mappings for app. Identify the automatic cleanup of all trust mappings associated with a deleted application instance.
References #
app.kerberos_rich_client.account_not_found
#Description
Kerberos based rich client authentication failed: Could not find Office 365 app user for the AD user with principal id.
References #
app.kerberos_rich_client.instance_not_found
#Description
Kerberos based rich client authentication failed: Unknown app instance id.
References #
app.kerberos_rich_client.multiple_accounts_found
#Description
Kerberos based rich client authentication failed: Multiple users with username found.
References #
app.kerberos_rich_client.user_authentication_successful
#Description
Kerberos based rich client authentication successful for Office 365 user.
References #
app.oauth2.admin.consent.grant
#Description
Administrator consent granted for scope. This event can be used to track when an administrator grants consent to a client to request a specific scope. This event is fired when an admin grants consent.
Example System Log Event #
{
"published": 1784904737523,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000009",
"actor": {
"id": "00u00000000000000026",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000027"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0",
"os": "Windows 10",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "oag00000000000000028",
"type": "ConsentGrant",
"alternateId": null,
"displayName": "DW Harness 11",
"detailEntry": {
"publicclientapp": "0oa00000000000000029"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.admin.consent.grant",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000003",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000003",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "qei00000000000000030",
"url": "qei00000000000000030?"
}
},
"displayMessage": "Administrator consent granted.",
"gatewayContext": null,
"legacyEventType": "app.oauth2.admin.consent.grant_success",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Device",
"id": "bhv00000000000000031",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000032",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000033",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000034",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000035",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000036",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000037",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000038",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000039",
"externalSessionId": "10200000000000000039"
}
}
References #
app.oauth2.admin.consent.revoke
#Description
Administrator consent revoked for scope. This event can be used to track when an administrator revokes consent to a client to request a specific scope. This event is fired when an admin revokes consent.
References #
app.oauth2.as.consent.revoke.implicit.as
#Description
All consent revoked for authorization server.
References #
app.oauth2.as.consent.revoke.implicit.client
#Description
All consent revoked for client.
Example System Log Event #
{
"published": 1781189345991,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000005",
"actor": {
"id": "00u00000000000000061",
"type": "User",
"alternateId": "user12@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000063",
"type": "PublicClientApp",
"alternateId": null,
"displayName": "DW Harness 17",
"detailEntry": {
"tokencount": "4"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "00000000000000000000000000000000000000000002",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "otc00000000000000064",
"detail": {}
},
"debugContext": {
"debugData": {
"onOrBefore": "1781189345000"
}
},
"displayMessage": "All consent revoked for client",
"gatewayContext": null,
"legacyEventType": "0000000000000000000000000000000000000000000000000002",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000065",
"externalSessionId": "trs00000000000000066"
}
}
References #
app.oauth2.as.consent.revoke.implicit.user
#Description
Consent for all scopes revoked for user.
References #
app.oauth2.as.evaluate.claim
#Description
Claim evaluation for OAuth 2.0 token. This event is triggered when the OAuth 2.0 authorization server's claim evaluation process can't be completed and fails. This event is useful when detecting misconfigured claims. Recorded details include the requester's ID, the client ID, the user ID, and the claims that couldn't be evaluated. This verification ensures that access tokens are granted only to requests that fully comply with established security policies, thus safeguarding access to protected resources.
References #
app.oauth2.as.interact.interaction_code
#Description
Interaction code is generated by OIE. This event can be used by administrators to audit interaction_code generation, and troubleshoot why the IdX transaction has failed. When fired, this event contains hashed values of the interaction_code and interaction_handle, as well as information about the client to which they were issued.
References #
app.oauth2.as.interact.interaction_handle
#Description
Interaction handle is generated by OIE. This event can be used by administrators to detect if additional interaction is required and an interaction handle has been issued. When fired this event contains interaction handle hash and the client to which it was issued.
References #
app.oauth2.as.key.rollover
#Description
Custom Authorization Server token signing key rolled over.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000074",
"externalSessionId": "trs00000000000000074"
},
"displayMessage": "Custom Authorization Server token signing key rolled over",
"eventType": "app.oauth2.as.key.rollover",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-24T03:47:55.578Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"authorizationServer": "aus00000000000000075",
"requestId": "00000000000000000000000000000088",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"kid": "0000000000000000000000000000000000000000002",
"requestUri": "/api/v1/authorizationServers",
"defaultAuthorizationServer": "false",
"url": "/api/v1/authorizationServers?"
}
},
"gatewayContext": null,
"legacyEventType": "app.oauth2.as.key.rollover.legacy",
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000088",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000101",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "aus00000000000000075",
"type": "AuthorizationServer",
"alternateId": null,
"displayName": "DW Harness 35",
"detailEntry": null
}
]
}
References #
app.oauth2.as.resource_server.credentials.lifecycle.activate
#Description
Authorization server access token encryption key is activated. Use this event to find out if a new access token encryption key has been activated for an authorization server. This could be used to audit changes made to authorization server access token encryption keys.
References #
app.oauth2.as.resource_server.credentials.lifecycle.create
#Description
Authorization server access token encryption key is created. Use this event to find out if a new access token encryption key has been created for an authorization server. This could be used to audit changes made to authorization server access token encryption keys.
References #
app.oauth2.as.resource_server.credentials.lifecycle.deactivate
#Description
Authorization server access token encryption key is deactivated. Use this event to find out if a new access token encryption key has been deactivated for an authorization server. This could be used to audit changes made to authorization server access token encryption keys.
References #
app.oauth2.as.resource_server.credentials.lifecycle.delete
#Description
Authorization server access token encryption key is deleted. Use this event to find out if a new access token encryption key has been deleted for an authorization server. This could be used to audit changes made to authorization server access token encryption keys.
References #
app.oauth2.as.token.detect_reuse
#Description
Detect one-time refresh token attempted reuse. This event can be used by administrators to detect and audit attempted reuse of one-time refresh tokens. When fired this event contains information about the user, client to which the refresh token was minted, and the hash of the refresh tokens.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
References #
app.oauth2.as.token.grant
#Description
OAuth2 token request.
Example System Log Event #
{
"actor": {
"id": "0oa00000000000000006",
"type": "PublicClientApp",
"alternateId": "user07@dw-harness.example",
"displayName": "DW Harness 07",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": "0oa00000000000000006",
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000007",
"externalSessionId": "0000000000000000000000007"
},
"displayMessage": "OAuth2 token request",
"eventType": "app.oauth2.as.token.grant",
"outcome": {
"result": "FAILURE",
"reason": "password_auth_denied_policy"
},
"published": "2026-07-26T00:00:36.765Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "WARN",
"debugContext": {
"debugData": {
"clientAuthType": "client_secret_post",
"grantedScopes": "",
"authorizationServerName": "dw-harn-090975f0-as-grant",
"authorizationServer": "aus00000000000000012",
"responseTime": "425",
"requestUri": "/oauth2/aus00000000000000012/v1/token",
"requestedScopes": "openid, offline_access",
"url": "/oauth2/aus00000000000000012/v1/token?",
"authnRequestId": "00000000000000000000000000000008",
"requestId": "00000000000000000000000000000008",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000003",
"clientSecret": "zBj00000000000000010",
"threatSuspected": "false",
"grantType": "password",
"defaultAuthorizationServer": "false"
}
},
"gatewayContext": null,
"legacyEventType": "app.oauth2.as.token.grant_failure",
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000008",
"detail": {}
},
"uuid": "00000000-0000-0000-0000-000000000018",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": null
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
okta::outcome.result (elastic rule field) | eq | failure | 1Â rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
okta.actor.display_name field value has not been seen in the last 14 days regarding this event.T1078, T1078.004, T1550, T1550.001
References #
app.oauth2.as.token.grant.access_token
#Description
OAuth 2.0 access token is granted. This event is triggered within OAuth 2.0 frameworks when an app successfully grants an access token to a user or service. The event occurs post-authentication and authorization, marking the final step in accessing protected resources. Use this event as a comprehensive audit trail for issued tokens. The event captures details such as the client ID, subject ID, token attributes (for example: scope, validity period), and the grant type used. This information helps with security audits, ensuring compliance with access policies and troubleshooting authorization flows. Specifically, variations in token attributes and grant type offer insights into the security posture and operational efficiency of OAuth 2.0 implementations. While this event primarily signifies successfully issued tokens, the event details are helpful in many areas. They help flag potential misuse of token grants or anomalies in token attributes. The event details also help facilitate a prompt response to deviations from established security practices.
Example System Log Event #
{
"actor": {
"id": "0oa00000000000000004",
"type": "PublicClientApp",
"alternateId": "user07@dw-harness.example",
"displayName": "DW Harness 07",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": "0oa00000000000000004",
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000002",
"externalSessionId": "0000002"
},
"displayMessage": "OAuth2 access token is granted",
"eventType": "app.oauth2.as.token.grant.access_token",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:38:22.556Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"clientAuthType": "client_secret_post",
"grantedScopes": "dw.harness.d82abed7.grant",
"authorizationServerName": "dw-harn-d82abed7-as-grant",
"authorizationServer": "aus00000000000000011",
"responseTime": "230",
"rule": "0pr00000000000000016",
"requestUri": "/oauth2/aus00000000000000011/v1/token",
"requestedScopes": "dw.harness.d82abed7.grant",
"url": "/oauth2/aus00000000000000011/v1/token?",
"requestId": "00000000000000000000000000000007",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000003",
"clientSecret": "RhK00000000000000010",
"threatSuspected": "false",
"grantType": "client_credentials",
"defaultAuthorizationServer": "false",
"policy": "00p00000000000000014"
}
},
"gatewayContext": null,
"legacyEventType": "0000000000000000000000000000000000000000000002",
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000007",
"detail": {}
},
"uuid": "00000000-0000-0000-0000-000000000015",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0000000000000000000000000000000000000000000003",
"type": "access_token",
"alternateId": null,
"displayName": "DW Harness 12",
"detailEntry": {
"audience": "api://dw-harn-d82abed7-grant",
"expires": "2026-07-25T23:43:22.000Z",
"subject": "0oa00000000000000004",
"hash": "3xY00000000000000017+RAO2/Pow="
}
}
]
}
References #
app.oauth2.as.token.grant.device_secret
#Description
Grant an OAuth2 device_secret for the Native SSO flow. This event adds tracking to let admins know when Native SSO is being used to protect desktop or mobile apps. When fired this event contains the device secret id which administrators can use to correlate with single logout events across native desktop apps.
References #
app.oauth2.as.token.grant.id_token
#Description
OAuth 2.0 ID token is granted. This event occurs when an OAuth 2.0 authorization server grants an ID token to a client after successful authentication. The ID token, which encapsulates the user's identity information, verifies the user's identity to the client app. Recorded details include the client ID, user ID, token issuance time, and claims associated with the user's identity. You can use this data for security audits, enabling precise tracking of user identity verification across apps. The issuance of an ID token follows established protocols for secure authentication. This ensures that sensitive user information is transmitted securely between the authorization server and the client.
Example System Log Event #
{
"published": 1783623388112,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000012",
"actor": {
"id": "0oa00000000000000067",
"type": "PublicClientApp",
"alternateId": "user13@dw-harness.example",
"displayName": "DW Harness 18",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Amazon/Cognito",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": "0oa00000000000000067",
"ipAddress": "192.0.2.18",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "00u00000000000000068",
"type": "User",
"alternateId": "user14@dw-harness.example",
"displayName": "DW Harness 19",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "0000000000000000000000000000000000000000000003",
"type": "id_token",
"alternateId": null,
"displayName": "DW Harness 20",
"detailEntry": {
"audience": "0oa00000000000000067",
"expires": "2026-07-09T19:56:28.000Z",
"subject": "00u00000000000000068",
"hash": "0000000000000000000000000000000000000000004="
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.18",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.as.token.grant.id_token",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000006",
"detail": {}
},
"debugContext": {
"debugData": {
"clientAuthType": "client_secret_post",
"redirectUri": "https://app.example.com App app.example.com/oauth2/idpresponse",
"grantedScopes": "openid, email",
"authCode": "v3g00000000000000069",
"authorizationServerName": "default",
"authorizationServer": "aus00000000000000070",
"responseTime": "247",
"requestUri": "/oauth2/default/v1/token",
"requestedScopes": "",
"url": "/oauth2/default/v1/token?",
"authnRequestId": "00000000000000000000000000000007",
"requestId": "00000000000000000000000000000006",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000005",
"clientSecret": "ykm00000000000000071",
"threatSuspected": "false",
"grantType": "authorization_code",
"defaultAuthorizationServer": "true"
}
},
"displayMessage": "OAuth2 id token is granted",
"gatewayContext": null,
"legacyEventType": "000000000000000000000000000000000000000002",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "idx00000000000000072",
"externalSessionId": "idx00000000000000072"
}
}
References #
app.oauth2.as.token.grant.interclient_token
#Description
Grant interclient token. Track the successful issuance of an Interclient token via OAuth token exchange. This event will contain the target audience the interclient token is issued for.
References #
app.oauth2.as.token.grant.refresh_token
#Description
OAuth2 refresh token is granted.
Example System Log Event #
{
"published": 1785240727639,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000013",
"actor": {
"id": "0oa00000000000000042",
"type": "PublicClientApp",
"alternateId": "user10@dw-harness.example",
"displayName": "DW Harness 14",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "openid-client/v6.8.1",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": "0oa00000000000000042",
"ipAddress": "192.0.2.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "00u00000000000000043",
"type": "User",
"alternateId": "user11@dw-harness.example",
"displayName": "DW Harness 15",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "oar00000000000000073",
"type": "refresh_token",
"alternateId": null,
"displayName": "DW Harness 21",
"detailEntry": {
"expires": "2026-10-26T12:12:07.000Z",
"subject": "00u00000000000000043",
"refreshtokentype": "persistent",
"hash": "0000000000000000000000000000000000000000005="
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.as.token.grant.refresh_token",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000008",
"detail": {}
},
"debugContext": {
"debugData": {
"clientAuthType": "none",
"redirectUri": "kiro://app.example.com/callback",
"grantedScopes": "example:scope, offline_access, example:scope",
"authCode": "mot00000000000000045",
"authorizationServerName": "Example Auth Server 1",
"authorizationServer": "aus00000000000000046",
"responseTime": "251",
"requestUri": "6vb00000000000000074",
"requestedScopes": "",
"url": "6vb00000000000000074?",
"authnRequestId": "00000000000000000000000000000005",
"requestId": "00000000000000000000000000000008",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000006",
"threatSuspected": "false",
"grantType": "authorization_code",
"defaultAuthorizationServer": "false"
}
},
"displayMessage": "OAuth2 refresh token is granted",
"gatewayContext": null,
"legacyEventType": "00000000000000000000000000000000000000000000002",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "idx00000000000000060",
"externalSessionId": "idx00000000000000060"
}
}
References #
app.oauth2.client.lifecycle.activate
#Description
Activate OAuth client.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000003",
"externalSessionId": "trs00000000000000003"
},
"displayMessage": null,
"eventType": "app.oauth2.client.lifecycle.activate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:35:50.283Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000005",
"clientName": "dw-harn-c1bf671d-oauth-service",
"requestId": "00000000000000000000000000000002",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/apps",
"url": "/api/v1/apps?"
}
},
"gatewayContext": null,
"legacyEventType": "app.oauth2.client.lifecycle.activate",
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000002",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000005",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000005",
"type": "PublicClientAppEntity",
"alternateId": "user04@dw-harness.example",
"displayName": "DW Harness 06",
"detailEntry": null
}
]
}
References #
app.oauth2.client.lifecycle.create
#Description
Create OAuth client.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000003",
"externalSessionId": "trs00000000000000003"
},
"displayMessage": null,
"eventType": "app.oauth2.client.lifecycle.create",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:35:50.238Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000005",
"clientName": "dw-harn-c1bf671d-oauth-service",
"requestId": "00000000000000000000000000000002",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/apps",
"url": "/api/v1/apps?"
}
},
"gatewayContext": null,
"legacyEventType": "app.oauth2.client.lifecycle.create",
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000002",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000006",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000005",
"type": "PublicClientAppEntity",
"alternateId": "user04@dw-harness.example",
"displayName": "DW Harness 06",
"detailEntry": {
"tokenendpointauthmethod": "client_secret_post",
"clientid": "0oa00000000000000005",
"responsetypes": "[TOKEN]",
"clientname": "dw-harn-c1bf671d-oauth-service",
"clientsecret": "0000000000000000000002",
"hasexternalclientsecret": "false",
"applicationtype": "service",
"granttypes": "[CLIENT_CREDENTIALS]",
"redirecturis": []
}
}
]
}
References #
app.oauth2.client.lifecycle.deactivate
#Description
Deactivate OAuth client.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000007",
"externalSessionId": "0000000000000000000000007"
},
"displayMessage": null,
"eventType": "app.oauth2.client.lifecycle.deactivate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:35:52.737Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000005",
"clientName": "dw-harn-c1bf671d-oauth-service",
"requestId": "00000000000000000000000000000012",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/apps/0oa00000000000000005/lifecycle/deactivate",
"url": "/api/v1/apps/0oa00000000000000005/lifecycle/deactivate?"
}
},
"gatewayContext": null,
"legacyEventType": "app.oauth2.client.lifecycle.deactivate",
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000012",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000019",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000005",
"type": "PublicClientAppEntity",
"alternateId": "user04@dw-harness.example",
"displayName": "DW Harness 06",
"detailEntry": null
}
]
}
References #
app.oauth2.client.lifecycle.delete
#Description
Delete OAuth client.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000017",
"externalSessionId": "trs00000000000000017"
},
"displayMessage": null,
"eventType": "app.oauth2.client.lifecycle.delete",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:35:53.028Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000005",
"clientName": "dw-harn-c1bf671d-oauth-service",
"requestId": "00000000000000000000000000000013",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/apps/0oa00000000000000005",
"url": "/api/v1/apps/0oa00000000000000005?"
}
},
"gatewayContext": null,
"legacyEventType": "app.oauth2.client.lifecycle.delete",
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000013",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000022",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000005",
"type": "PublicClientAppEntity",
"alternateId": "user04@dw-harness.example",
"displayName": "DW Harness 06",
"detailEntry": null
}
]
}
References #
app.oauth2.client.lifecycle.update
#Description
Update OAuth client.
Example System Log Event #
{
"published": 1780091784209,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000016",
"actor": {
"id": "00u00000000000000082",
"type": "User",
"alternateId": "user18@dw-harness.example",
"displayName": "DW Harness 25",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0",
"os": "Linux",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000083",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 26",
"detailEntry": {
"tokenendpointauthmethod": "client_secret_basic",
"clientid": "0oa00000000000000083",
"responsetypes": "[CODE]",
"clientname": "Example App 29",
"clientsecret": "ti400000000000000084",
"hasexternalclientsecret": "false",
"applicationtype": "web",
"granttypes": "[AUTHORIZATION_CODE]",
"redirecturis": "[http://app.example.com/auth/callback, https://app.example.com/auth/callback]"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.client.lifecycle.update",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000012",
"detail": {}
},
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000083",
"clientName": "Example App 29",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000012",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000011",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "kzk00000000000000085",
"url": "kzk00000000000000085?"
}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": "app.oauth2.client.lifecycle.update",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "BAD_REQUEST"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000086",
"externalSessionId": "10200000000000000086"
}
}
References #
app.oauth2.client.privilege.grant
#Description
An OAuth 2.0 client app's admin privileges changed. This can be used to audit the provisioning of admin privileges for OAuth 2.0 client apps. When fired, this event contains information about the type of admin privileges the OAuth 2.0 client app currently has. Related events include: APP_OAUTH2_CLIENT_PRIVILEGE_REVOKE.
Example System Log Event #
{
"published": 1781189321136,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000004",
"actor": {
"id": "00u00000000000000061",
"type": "User",
"alternateId": "user12@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000087",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 17",
"detailEntry": null
},
{
"id": "0000000000002",
"type": "ROLE_ASSIGNED",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 27",
"detailEntry": null
},
{
"id": "0000000000003",
"type": "ROLE",
"alternateId": "user19@dw-harness.example",
"displayName": "DW Harness 28",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.client.privilege.grant",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": null,
"id": "0000003",
"detail": {}
},
"debugContext": {
"debugData": {
"privilegeGranted": "Super administrator"
}
},
"displayMessage": "Grant public client app privilege",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000065",
"externalSessionId": "trs00000000000000088"
}
}
References #
app.oauth2.client.privilege.revoke
#Description
All privileges for OAuth 2.0 client app were revoked. This can be used to audit the deprovisioning of admin privileges from OAuth 2.0 client apps. When fired, this event indicates the OAuth 2.0 client app has no more admin privileges. All of OAuth 2.0 client app's privileges were revoked. Related events include: APP_OAUTH2_CLIENT_PRIVILEGE_GRANT.
Example System Log Event #
{
"published": 1781189346099,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000007",
"actor": {
"id": "00u00000000000000061",
"type": "User",
"alternateId": "user12@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000063",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 17",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.client.privilege.revoke",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "rcr00000000000000089",
"detail": {}
},
"debugContext": {
"debugData": {
"privilegeRevoked": "Super administrator, Organization administrator, Application administrator (all), Application administrator, Read only admin, User administrator (all), User administrator, Help Desk administrator (all), Help Desk administrator, Mobile administrator, API Access Management administrator, Report administrator, Group Membership administrator"
}
},
"displayMessage": "Revoke public client app privilege",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000065",
"externalSessionId": "trs00000000000000090"
}
}
References #
app.oauth2.client.read_client_secret
#Description
Read OAuth client's secret(s). Use this event to verify that an OAuth client's secret(s) have been read when the client is returned in certain API responses. For example, an admin might use this event to audit if a client's secrets were read when using the client credentials management API. When fired, this event indicates that an OAuth client's secrets were read. The targets array may include references to multiple client secrets.
Example System Log Event #
{
"published": 1780091747879,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000017",
"actor": {
"id": "00u00000000000000082",
"type": "User",
"alternateId": "user18@dw-harness.example",
"displayName": "DW Harness 25",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0",
"os": "Linux",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000040",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 12",
"detailEntry": null
},
{
"id": "ocs00000000000000091",
"type": "oau00000000000000092",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 29",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.client.read_client_secret",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000013",
"detail": {}
},
"debugContext": {
"debugData": {
"requestId": "00000000000000000000000000000013",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000011",
"requestUri": "00000000000000000000000000000000000000000000000000002",
"url": "00000000000000000000000000000000000000000000000000002?"
}
},
"displayMessage": "Read OAuth client's secret(s).",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000086",
"externalSessionId": "10200000000000000086"
}
}
References #
app.oauth2.client_id_rate_limit_warning
#Description
Requests from a single client ID consumed the majority of an organization's OAuth2 endpoint rate limit. This event can be used by admins to discover and deactivate a rogue client. The admin is able to manage the client via the Syslog UI. When fired, this event contains information about the responsible client id. As of release, this event is fired when a single client id consumes 90% of an org's OAuth2 rate limit; this threshold is subject to change.
References #
app.oauth2.consent.grant
#Description
User granted consent to app. This event can be used to identify the org AS consent grant. When fired, the event contains information about the successful consent grant by org AS.
References #
app.oauth2.credentials.lifecycle.activate
#Description
OAuth client credentials (either client secret or JWK) is added for an application. Use this event to find out if an application has a new client secret or private/public key that has been added. This could be used to audit changes made to client credentials.
Example System Log Event #
{
"published": 1781290372590,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000018",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.9",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "ocs00000000000000094",
"type": "oau00000000000000092",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 31",
"detailEntry": {
"clientid": "0oa00000000000000095",
"clientsecret": "njh00000000000000096",
"clientcredentialstype": "secret",
"status": "active"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.9",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "00000000000000000000000000000000000000007",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000014",
"detail": {}
},
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000095",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000014",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000012",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000002",
"url": "00000000000000000000000000000000000000000000000000000000000000000000000002?"
}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": "00000000000000000000000000000000000000007",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "BAD_REQUEST"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000097",
"externalSessionId": "10200000000000000097"
}
}
References #
app.oauth2.credentials.lifecycle.create
#Description
OAuth client credentials (either client secret or JWK) is activated for an application. Use this event to find out if an application has activated a new client secret or private/public key. This could be used to audit changes made to client credentials.
Example System Log Event #
{
"published": 1781290372583,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000019",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.9",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "ocs00000000000000094",
"type": "oau00000000000000092",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 31",
"detailEntry": {
"clientid": "0oa00000000000000095",
"clientsecret": "njh00000000000000096",
"clientcredentialstype": "secret",
"status": "active"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.9",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.credentials.lifecycle.create",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000014",
"detail": {}
},
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000095",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000014",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000012",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000002",
"url": "00000000000000000000000000000000000000000000000000000000000000000000000002?"
}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": "app.oauth2.credentials.lifecycle.create",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "BAD_REQUEST"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000097",
"externalSessionId": "10200000000000000097"
}
}
References #
app.oauth2.credentials.lifecycle.deactivate
#Description
OAuth client credentials (either client secret or JWK) is deactivated for an application. Use this event to find out if an application has an existing client secret or private/public key that has been deactivated. This could be used to audit changes made to client credentials.
Example System Log Event #
{
"published": 1780091765668,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000020",
"actor": {
"id": "00u00000000000000082",
"type": "User",
"alternateId": "user18@dw-harness.example",
"displayName": "DW Harness 25",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0",
"os": "Linux",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "ocs00000000000000098",
"type": "oau00000000000000092",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 32",
"detailEntry": {
"clientid": "0oa00000000000000083",
"clientcredentialstype": "secret",
"datecreated": "2026-05-22T19:35:44.000Z",
"status": "inactive"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "0000000000000000000000000000000000000000007",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000015",
"detail": {}
},
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000083",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000015",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000011",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002",
"url": "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002?"
}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": "0000000000000000000000000000000000000000007",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "BAD_REQUEST"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000086",
"externalSessionId": "10200000000000000086"
}
}
References #
app.oauth2.credentials.lifecycle.delete
#Description
OAuth client credentials (either client secret or JWK) is deleted for an application. Use this event to find out if an application has an existing client secret or private/public key that has been deleted. This could be used to audit changes made to client credentials.
Example System Log Event #
{
"published": 1781290504504,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000021",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.9",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "ocs00000000000000099",
"type": "oau00000000000000092",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 33",
"detailEntry": {
"clientid": "0oa00000000000000095",
"clientsecret": "5q000000000000000100",
"clientcredentialstype": "secret",
"datecreated": "2026-04-13T22:42:25.000Z",
"status": "inactive"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.9",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.credentials.lifecycle.delete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000016",
"detail": {}
},
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000095",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000016",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000012",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000003",
"url": "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000003?"
}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": "app.oauth2.credentials.lifecycle.delete",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "BAD_REQUEST"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000097",
"externalSessionId": "10200000000000000097"
}
}
References #
app.oauth2.interact.interaction_code
#Description
Interaction code generated by OIE. This event can be used by administrators to audit interaction_code generation, and troubleshoot why the IdX transaction has failed. When fired, this event contains hashed values of the interaction_code and interaction_handle, as well as information about the client to which they were issued.
References #
app.oauth2.interact.interaction_handle
#Description
Interaction handle generated by OIE. This event can be used by administrators to detect if additional interaction is required and an interaction handle has been issued. When fired this event contains interaction handle hash and the client to which it was issued.
References #
app.oauth2.invalid_client_credentials
#Description
Multiple requests with invalid client credentials for client id.
References #
app.oauth2.key.rollover
#Description
Org Authorization Server token signing key rolled over.
References #
app.oauth2.token.detect_reuse
#Description
Detect one-time refresh token attempted reuse. This event can be used by administrators to detect and audit attempted reuse of one-time refresh tokens. When fired this event contains information about the user, client to which the refresh token was minted, and the hash of the refresh tokens.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
References #
app.oauth2.token.grant
#Description
OIDC token request.
Example System Log Event #
{
"published": 1785260588711,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000022",
"actor": {
"id": "0oa00000000000000101",
"type": "PublicClientApp",
"alternateId": "user21@dw-harness.example",
"displayName": "DW Harness 34",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.32.5",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "192.0.2.14",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "",
"type": "refresh_token",
"alternateId": null,
"displayName": "DW Harness 21",
"detailEntry": {
"hash": "0000000000000000000000000000000000000000008="
}
}
],
"outcome": {
"result": "FAILURE",
"reason": "invalid_refresh_token"
},
"request": {
"ipChain": [
{
"ip": "192.0.2.14",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "WARN",
"eventType": "app.oauth2.token.grant",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000017",
"detail": {}
},
"debugContext": {
"debugData": {
"clientAuthType": "client_secret_basic",
"grantedScopes": "",
"requestId": "00000000000000000000000000000017",
"responseTime": "42",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000013",
"clientSecret": "cio00000000000000102",
"requestUri": "/oauth2/v1/token",
"requestedScopes": "",
"threatSuspected": "false",
"grantType": "refresh_token",
"url": "/oauth2/v1/token?"
}
},
"displayMessage": "OIDC token request",
"gatewayContext": null,
"legacyEventType": "app.oauth2.token.grant_failure",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000003",
"externalSessionId": "0000003"
}
}
References #
app.oauth2.token.grant.access_token
#Description
OIDC access token is granted.
Example System Log Event #
{
"published": 1785260615868,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000023",
"actor": {
"id": "0oa00000000000000103",
"type": "PublicClientApp",
"alternateId": "user22@dw-harness.example",
"displayName": "DW Harness 35",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "dr000000000000000104",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "192.0.2.15",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "0000000000000000000000000000000000000000000005",
"type": "access_token",
"alternateId": null,
"displayName": "DW Harness 36",
"detailEntry": {
"audience": "https://app.example.com",
"expires": "2026-07-28T18:43:35.000Z",
"subject": "0oa00000000000000103",
"hash": "0000000000000000000000000000000000000000009="
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.15",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.token.grant.access_token",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000018",
"detail": {}
},
"debugContext": {
"debugData": {
"clientAuthType": "client_secret_basic",
"grantedScopes": "okta.users.read, example:scope, example:scope, example:scope, example:scope, okta.groups.read, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope",
"requestId": "00000000000000000000000000000018",
"responseTime": "213",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000014",
"clientSecret": "4m700000000000000105",
"requestUri": "/oauth2/v1/token",
"requestedScopes": "okta.users.read, example:scope, example:scope, example:scope, example:scope, example:scope, okta.groups.read, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope, example:scope",
"threatSuspected": "false",
"grantType": "client_credentials",
"url": "/oauth2/v1/token?"
}
},
"displayMessage": "OIDC access token is granted",
"gatewayContext": null,
"legacyEventType": "0000000000000000000000000000000000000000010",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000003",
"externalSessionId": "0000003"
}
}
References #
app.oauth2.token.grant.id_jag
#Description
OAuth 2.0 Identity Assertion JWT Authorization Grant (ID-JAG) granted. This event is triggered when an app successfully completes an OAuth token exchange to generate an Identity Assertion JWT Authorization Grant. The Identity Assertion relies on a valid ID token obtained from a single sign-on (SSO) flow and the ID-JAG JWT is used in Cross App Access.
References #
app.oauth2.token.grant.id_token
#Description
OIDC id token is granted.
Example System Log Event #
{
"published": 1785238977815,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000024",
"actor": {
"id": "0oa00000000000000106",
"type": "PublicClientApp",
"alternateId": "user23@dw-harness.example",
"displayName": "DW Harness 37",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Node-oauth",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": "0oa00000000000000106",
"ipAddress": "192.0.2.7",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "00u00000000000000107",
"type": "User",
"alternateId": "user24@dw-harness.example",
"displayName": "DW Harness 38",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "0000000000000000000000000000000000000000000006",
"type": "id_token",
"alternateId": null,
"displayName": "DW Harness 20",
"detailEntry": {
"audience": "0oa00000000000000106",
"expires": "2026-07-28T12:42:57.000Z",
"subject": "00u00000000000000107",
"hash": "0000000000000000000000000000000000000000011="
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.7",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.token.grant.id_token",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000019",
"detail": {}
},
"debugContext": {
"debugData": {
"clientAuthType": "client_secret_post",
"grantedScopes": "openid, email, profile, offline_access",
"requestId": "00000000000000000000000000000019",
"responseTime": "248",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000015",
"clientSecret": "j2r00000000000000108",
"requestUri": "/oauth2/v1/token",
"requestedScopes": "openid, email, profile, offline_access",
"threatSuspected": "false",
"grantType": "refresh_token",
"url": "/oauth2/v1/token?"
}
},
"displayMessage": "OIDC id token is granted",
"gatewayContext": null,
"legacyEventType": "app.oauth2.token.grant.id_token_success",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000003",
"externalSessionId": "0000003"
}
}
References #
app.oauth2.token.grant.interclient_token
#Description
Grant interclient token. Track the successful issuance of an Interclient token via OAuth token exchange. This event will contain the target audience the interclient token is issued for.
References #
app.oauth2.token.grant.oauth_sts
#Description
Grant OAuth Security Token Service (STS) access token. Audit when an application successfully exchanges an OAuth token for an access token from a third-party authorization server.
References #
app.oauth2.token.grant.refresh_token
#Description
OIDC refresh token is granted.
Example System Log Event #
{
"published": 1785254131176,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000025",
"actor": {
"id": "0oa00000000000000109",
"type": "PublicClientApp",
"alternateId": "user25@dw-harness.example",
"displayName": "DW Harness 39",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": "0oa00000000000000109",
"ipAddress": "192.0.2.5",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "00u00000000000000110",
"type": "User",
"alternateId": "user26@dw-harness.example",
"displayName": "DW Harness 40",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "oar00000000000000111",
"type": "refresh_token",
"alternateId": null,
"displayName": "DW Harness 21",
"detailEntry": {
"expires": "2026-09-20T20:33:35.000Z",
"subject": "00u00000000000000110",
"refreshtokentype": "onetime",
"hash": "0000000000000000000000000000000000000000012="
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.5",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.token.grant.refresh_token",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000020",
"detail": {}
},
"debugContext": {
"debugData": {
"clientAuthType": "none",
"grantedScopes": "openid, email, profile, groups, offline_access",
"requestId": "00000000000000000000000000000020",
"responseTime": "116",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000016",
"requestUri": "/oauth2/v1/token",
"requestedScopes": "openid, email, profile, groups, offline_access",
"threatSuspected": "false",
"grantType": "refresh_token",
"url": "/oauth2/v1/token?"
}
},
"displayMessage": "OIDC refresh token is granted",
"gatewayContext": null,
"legacyEventType": "00000000000000000000000000000000000000000003",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000003",
"externalSessionId": "0000003"
}
}
References #
app.oauth2.token.grant.service_account
#Description
Grant Okta Privileged Access service account credentials. Audit when an application successfully exchanges an OAuth token for credentials for a service account in Okta Privileged Access.
References #
app.oauth2.token.grant.vaulted_secret
#Description
Grant Okta Privileged Access vaulted secret. Audit when an application successfully exchanges an OAuth token for a vaulted secret in Okta Privileged Access.
References #
app.oauth2.token.oauth_sts.request_token
#Description
Request OAuth tokens from a third-party authorization server. This event is triggered when Okta requests OAuth tokens from a third-party authorization server.
References #
app.oauth2.token.revoke
#Description
OIDC token revocation request.
Example System Log Event #
{
"published": 1785264415731,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000026",
"actor": {
"id": "00000000000000000000000000000000000000008",
"type": "PublicClientApp",
"alternateId": "user27@dw-harness.example",
"displayName": "DW Harness 41",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.17",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": null,
"outcome": {
"result": "FAILURE",
"reason": "invalid_token"
},
"request": {
"ipChain": [
{
"ip": "192.0.2.17",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"ipServiceCategories": [
{
"operator": "GLOBAL_PROTECT_CLOUD_VPN",
"type": "VPN",
"isAnonymous": false
}
]
}
}
]
},
"version": "0",
"severity": "WARN",
"eventType": "app.oauth2.token.revoke",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000021",
"detail": {}
},
"debugContext": {
"debugData": {
"tunnels": [
{
"anonymous": false,
"operator": "GLOBAL_PROTECT_CLOUD_VPN",
"type": "VPN"
}
],
"requestId": "00000000000000000000000000000021",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000017",
"origin": "https://app.example.com",
"requestUri": "/oauth2/v1/revoke",
"threatSuspected": "false",
"url": "/oauth2/v1/revoke?"
}
},
"displayMessage": "OIDC token revocation request",
"gatewayContext": null,
"legacyEventType": "app.oauth2.token.revoke_failure",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"ipServiceCategories": [
{
"operator": "GLOBAL_PROTECT_CLOUD_VPN",
"type": "VPN",
"isAnonymous": false
}
]
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000003",
"externalSessionId": "0000003"
}
}
References #
app.oauth2.token.revoke.implicit.user
#Description
Tokens revoked for user.
Example System Log Event #
{
"published": 1783162998215,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000027",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "00u00000000000000113",
"type": "User",
"alternateId": "user28@dw-harness.example",
"displayName": "DW Harness 43",
"detailEntry": {
"realmId": "guo00000000000000044",
"tokencount": "1"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "app.oauth2.token.revoke.implicit.user",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "otu00000000000000114",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000007"
}
},
"debugContext": {
"debugData": {
"onOrBefore": "1783162997000"
}
},
"displayMessage": "Tokens revoked for user",
"gatewayContext": null,
"legacyEventType": "000000000000000000000000000000000000000000002",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000115",
"externalSessionId": "trs00000000000000116"
}
}
References #
app.oauth2.trusted_server.add
#Description
Trusted authorization server is added. Administrators can use this event to debug and audit trusted authorization server operations. When fired, this event contains the authorization server IDs of the servers involved.
References #
app.oauth2.trusted_server.delete
#Description
Trusted authorization server is removed. Administrators can use this event to debug and audit trusted authorization server operations. When fired, this event contains the authorization server IDs of the servers involved.
References #
app.office365.api.change.domain.federation.success
#Description
Successfully updated the domain federation from old settings to new settings.
References #
app.office365.api.error.ad.user
#Description
User is assigned to more than one instance of Active Directory, could not set Immutable ID.
References #
app.office365.api.error.check.user.exists
#Description
Could not determine status of Office 365 user, received error.
References #
app.office365.api.error.create.user
#Description
Could not create user in Office 365, received error.
References #
app.office365.api.error.deactivate.user
#Description
Could not deactivate Office 365 user, received error.
References #
app.office365.api.error.download.custom.objects
#Description
Could not download group/role/license data for your Office 365 instance, received error.
References #
app.office365.api.error.download.groups
#Description
Could not download all groups from your Office 365 instance, received error.
References #
app.office365.api.error.download.users
#Description
Could not download all users from your Office 365 instance, received error.
References #
app.office365.api.error.get.company.dirsync.failure
#Description
Unable to read Office 365 directory sync for the company, received error.
References #
app.office365.api.error.get.company.dirsync.status.failure
#Description
Unable to provision user to Office 365, because 'Directory Sync' value in Azure Active Directory is unsupported. Please visit the Azure Active Directory portal and set 'Directory Sync' state to Activated and retry.
References #
app.office365.api.error.get.company.dirsync.status.pending
#Description
Unable to provision user to Office 365, because 'Directory Sync' value in Azure Active Directory not yet in Activated state. This may take up to 72 hours. Please visit the Azure Active Directory portal and retry when in Activated state.
References #
app.office365.api.error.get.object.ids.by.group.id
#Description
Could not get users by group id from your Office 365 instance, received error.
References #
app.office365.api.error.group.create.failure
#Description
Could not create Office 365 group, received error.
References #
app.office365.api.error.group.create.failure.name.in.use
#Description
Could not create Office 365 group because the name is already in use, received error.
References #
app.office365.api.error.group.delete.failure
#Description
Could not delete Office 365 group, received error.
References #
app.office365.api.error.group.membership.update.failure
#Description
Could not update the Office 365 group membership, received error.
References #
app.office365.api.error.group.membership.update.group.not.found.failure
#Description
Could not update the Office 365 group membership because the group could not be found, received error.
References #
app.office365.api.error.group.update.failure
#Description
Could not update Office 365 group, received error.
References #
app.office365.api.error.group.update.failure.not.found
#Description
Could not update Office 365 group because it was not found, received error.
References #
app.office365.api.error.import.profile
#Description
Could not import profile for Office 365 user, received error.
References #
app.office365.api.error.push.password
#Description
Could not push password for Office 365 user, received error.
References #
app.office365.api.error.push.profile
#Description
Could not push profile for Office 365 user, received error.
References #
app.office365.api.error.reactivate.user
#Description
Could not reactivate Office 365 user, received error.
References #
app.office365.api.error.remove.domain.federation.failure
#Description
Unable to remove the domain federation, received error.
References #
app.office365.api.error.remove.domain.federation.failure.access.denied
#Description
Unable to remove the domain federation because the admin user is not authorized to perform the task.
References #
app.office365.api.error.remove.domain.federation.failure.domain.not.found
#Description
Unable to remove the domain federation because the specified domain was not found.
References #
app.office365.api.error.revoke.refresh.token
#Description
Failed to revoke refresh tokens for user.
References #
app.office365.api.error.set.company.dirsync.status.failure
#Description
Unable to enable Office 365 directory sync for the company, because 'Directory Sync' value in Azure Active Directory is unsupported. Please visit the Azure Active Directory portal and set 'Directory Sync' state to Activated.
References #
app.office365.api.error.set.domain.federation.failure
#Description
Unable to setup the domain federation, received error.
References #
app.office365.api.error.set.domain.federation.failure.access.denied
#Description
Unable to setup the domain federation because the admin user is not authorized to perform the task.
References #
app.office365.api.error.set.domain.federation.failure.domain.default
#Description
Unable to setup the domain federation because the specified domain is the default domain.
References #
app.office365.api.error.set.domain.federation.failure.domain.not.found
#Description
Unable to setup the domain federation because the specified domain was not found.
References #
app.office365.api.error.sync.finalize
#Description
Failed to finalize export to Office 365, received error.
References #
app.office365.api.error.sync.not.activated
#Description
Sync could not execute because Office 365 directory sync for the company not yet Activated. Sync will retry after a period of time.
References #
app.office365.api.error.sync.set.attribute
#Description
Failed to set attribute, received error.
References #
app.office365.api.error.unable.to.create.graph.client
#Description
An error occurred while creating the Azure Active Directory Graph API client. Please try the last operation again. If this error persists, please contact Okta support.
References #
app.office365.api.error.validate.admin.creds
#Description
User does not have the Company Administrator role. Please try again with a user which has this role.
References #
app.office365.api.error.validate.creds
#Description
Could not validate your Office 365 credentials, received error.
References #
app.office365.api.error.x-ms-forwarded-client-ip-header.absent
#Description
X-MS-Forwarded-Client-IP header either empty or not found in the request.
References #
app.office365.api.remove.domain.federation.success
#Description
Successfully removed the domain federation.
References #
app.office365.api.set.domain.federation.success
#Description
Successfully set up the domain federation with new settings.
References #
app.office365.api.sync.heartbeat.sent
#Description
Heartbeat sent to Microsoft Azure Active Directory.
References #
app.office365.clientplatform.conversion.job.processing.app.instance
#Description
Begin processing client access conversion for app instance.
References #
app.office365.clientplatform.conversion.job.skipping.migration
#Description
Skipping migration of client access rules for app instance.
References #
app.office365.dirsync.skipping.conflict-object
#Description
Skipping sync of conflict object.
References #
app.office365.dirsync.skipping.critical-system-object
#Description
Skipping sync of critical system object.
References #
app.office365.dirsync.skipping.non-security-group-invalid-mail
#Description
Skipping sync of non security object with invalid mail.
References #
app.office365.dirsync.skipping.reserved-attribute-value
#Description
Skipping sync of object with reserved attribute value.
References #
app.office365.dirsync.skipping.systemmailbox
#Description
Skipping sync of system mailbox object.
References #
app.office365.dirsync.skipping.without-name-and-displayname
#Description
Skipping sync of non security object without name and display name.
References #
app.office365.graph.api.error.no.mailbox.found
#Description
No MailBox found for Office 365 user.
References #
app.office365.graph.api.error.rate-limit.exceeded
#Description
Rate limit exceeded for Microsoft Graph.
References #
app.office365.graph.api.error.service.principal.creation.failed
#Description
Failure while trying to create service principal.
References #
app.office365.graph.api.error.service.principal.msgraph.authentication.failure
#Description
Failure while trying to create service principal due to a Mircrosoft Graph authentication issue.
References #
app.office365.service.principal.cleanup.job.complete
#Description
End processing Office 365 service principal cleanup.
References #
app.office365.service.principal.cleanup.job.invalid.credentials
#Description
The admin username or password is invalid. Please use the Azure Active Directory cmdlets to execute the command 'Remove-MsolServicePrincipal -AppPrincipalId' to manually cleanup the service principal.
References #
app.office365.service.principal.cleanup.job.processing
#Description
Begin performing Office 365 service principal cleanup.
References #
app.office365.service.principal.cleanup.job.skipping.missing.creds
#Description
Skipping app instance during Office 365 service principal cleanup as it does not contain Office 365 admin user credentials. Please use the Azure Active Directory cmdlets to execute the command 'Remove-MsolServicePrincipal -AppPrincipalId' to manually cleanup the service principal.
References #
app.office365.service.principal.cleanup.job.skipping.no.service.principal
#Description
Skipping app instance during Office 365 service principal cleanup as it does not have a service principal.
References #
app.office365.service.principal.cleanup.job.unable.to.delete.service.principal
#Description
Unable to automatically delete the Office 365 service principal. Please use the Azure Active Directory cmdlets to execute the command 'Remove-MsolServicePrincipal -AppPrincipalId' to manually cleanup the service principal.
References #
app.office365.user.lifecycle.action.failed
#Description
Unable to complete app user lifecycle action for AppUser.
References #
app.office365.user.remove.licenses.success
#Description
Successfully removed all the licenses for the Office 365 user.
References #
app.policy.sign_on.update
#Description
Update app sign on policy. This event is used to audit when an app sign on policy is updated. This event is fired when an admin updates an app's sign on policy and logs what was changed.
References #
app.radius.info_access.no_permission
#Description
No permission accessing any Radius app info. This event can be used to monitor and notify admins when some users who access radius app info have no permission. Fired when users who access radius app info have no permission.
References #
app.radius.info_access.partial_permission
#Description
No permission accessing info for part of Radius apps. This event can be used to monitor and notify admins when some users who access radius app info have only partial permission. Fired when users who access radius app info have partial permission.
References #
app.realtimesync.import.details.delete_user
#Description
Real time sync removed existing User.
References #
app.realtimesync.import.details.update_user
#Description
Fired when a real time import includes an update to an existing user. This can be used to see details about the user updates included in a real time sync import. When fired, this event contains information about the type of update made, including whether or not a user was suspend or unsuspended. Related events include: app.realtimesync.import.details_add_user and app.realtimesync.import.details_delete_user.
Example System Log Event #
{
"published": 1782502956446,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000028",
"actor": {
"id": "00u00000000000000117",
"type": "User",
"alternateId": "user29@dw-harness.example",
"displayName": "DW Harness 44",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "00u00000000000000118",
"type": "User",
"alternateId": "user30@dw-harness.example",
"displayName": "DW Harness 45",
"detailEntry": {
"realmId": "guo00000000000000062"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "app.realtimesync.import.details.update_user",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "prj00000000000000119",
"detail": {
"rootApiTokenId": "00t00000000000000120"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "RealTimeSync for user update was successful",
"gatewayContext": null,
"legacyEventType": "app.realtimesync.import.details.update_user",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000121",
"externalSessionId": "trs00000000000000122"
}
}
References #
app.request_new.notify
#Description
A user sent an application request. Used to notify admins that a user made an application request from the Enduser Dashboard. The application request attempts to send an email to an admin with the user's request. This event only indicates that the request was made, not necessarily that the email was successfully delivered.
References #
app.rum.config.validation.error
#Description
Error validating instance configuration. Can be used to identify configuration issues with remote user management.
References #
app.rum.is.api.account.error
#Description
RUM API account is not configured or empty. Can be used to identify RUM API account configuration issues.
References #
app.rum.package.thrown.error
#Description
Errors during execution. Can be used to identify any errors during execution of remote user management.
References #
app.rum.validation.error
#Description
Error during package validation. Can be used to identify validation issues with remote user management packages.
References #
app.saml.sensitive.attribute.update
#Description
Fired when a SAML assertion contains a sensitive attribute, and that sensitive attribute has been updated (modified/added/deleted). This event does not fire when non-sensitive SAML attributes are updated. This can be used to audit that a sensitive attribute attached to an outbound SAML assertion has been correctly modified, added, or deleted. When fired, this event contains the specific attributes that have been modified, added, or deleted to/from the SAML assertion. Related events include: application.lifecycle.update.
References #
app.user_management
#Description
Imported new or deleted existing member of an application group.
Example System Log Event #
{
"actor": {
"alternateId": "system@okta.com",
"detailEntry": null,
"displayName": "Okta System",
"id": "00000000000000000004",
"type": "SystemPrincipal"
},
"authenticationContext": {
"authenticationProvider": null,
"authenticationStep": 0,
"credentialProvider": null,
"credentialType": null,
"externalSessionId": "00000000000000000000000000000005",
"interface": null,
"issuer": null
},
"client": {
"device": null,
"geographicalContext": null,
"id": null,
"ipAddress": null,
"userAgent": null,
"zone": null
},
"debugContext": {
"debugData": {}
},
"device": null,
"displayMessage": "Successfully imported new member to an app group",
"eventType": "app.user_management",
"legacyEventType": "app.user_management.app_group_member_import.insert_success",
"outcome": {
"reason": null,
"result": "SUCCESS"
},
"published": "2023-04-27T00:56:17.750Z",
"request": {
"ipChain": []
},
"securityContext": {
"asNumber": null,
"asOrg": null,
"domain": null,
"isProxy": null,
"isp": null
},
"severity": "INFO",
"target": [
{
"alternateId": "user03@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 03",
"id": "00000000000000000000000000000006",
"type": "AppUser"
},
{
"alternateId": "user04@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 04",
"id": "00000000000000000000000000000007",
"type": "AppGroup"
},
{
"alternateId": "user03@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 05",
"id": "00000000000000000000000000000008",
"type": "User"
},
{
"alternateId": "user05@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 06",
"id": "00000000000000000000000000000009",
"type": "AppInstance"
}
],
"transaction": {
"detail": {},
"id": "00000000000000000000000000000010",
"type": "JOB"
},
"uuid": "00000000-0000-0000-0000-000000000003",
"version": "0"
}
References #
app.user_management.grouppush.mapping.created.from.rule
#Description
A Group Push mapping to the group has been created from the rule.
Example System Log Event #
{
"published": 1783623908402,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000029",
"actor": {
"id": "0oa00000000000000123",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 46",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000124",
"type": "AppInstance",
"alternateId": "user31@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
},
{
"id": "00g00000000000000125",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 48",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "app.user_management.grouppush.mapping.created.from.rule",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "rej00000000000000126",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000008"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "A Group Push mapping to the group Example Group 5 has been created from the rule gpr00000000000000127 with the id - gpm00000000000000128.",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.mapping.created.from.rule",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000129",
"externalSessionId": "trs00000000000000130"
}
}
References #
app.user_management.grouppush.mapping.created.from.rule.error.duplicate
#Description
A Group Push mapping to the group did not get created from rule because an existing mapping already existed.
Example System Log Event #
{
"published": 1784131457676,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000030",
"actor": {
"id": "00u00000000000000131",
"type": "User",
"alternateId": "user32@dw-harness.example",
"displayName": "DW Harness 49",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000124",
"type": "AppInstance",
"alternateId": "user31@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
},
{
"id": "00g00000000000000132",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 50",
"detailEntry": null
}
],
"outcome": {
"result": "FAILURE",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "app.user_management.grouppush.mapping.created.from.rule.error.duplicate",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "rej00000000000000133",
"detail": {
"rootApiTokenId": "00t00000000000000134"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "A Group Push mapping to the group Example Group 10 did not get created from rule gpr00000000000000135 because an existing mapping already existed.",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.mapping.created.from.rule.error.duplicate",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000136",
"externalSessionId": "trs00000000000000137"
}
}
References #
app.user_management.grouppush.mapping.created.from.rule.error.validation
#Description
A Group Push mapping to the group did not get created from rule because of the validation error.
References #
app.user_management.grouppush.mapping.created.from.rule.errors
#Description
A Group Push mapping to the group did not get created from rule.
References #
app.user_management.grouppush.mapping.okta.users.ignored
#Description
Okta users ignored while pushing group to AppInstance.
References #
app.user_management.push_new_user_success
#Description
Successfully pushed new user account to app.
Example System Log Event #
{
"published": 1785256678979,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000031",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000138",
"type": "AppUser",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": null
},
{
"id": "00u00000000000000139",
"type": "User",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "0oa00000000000000140",
"type": "AppInstance",
"alternateId": "user34@dw-harness.example",
"displayName": "DW Harness 52",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "app.user_management.push_new_user_success",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "puj00000000000000141",
"detail": {}
},
"debugContext": {
"debugData": {
"appname": "Example App 16"
}
},
"displayMessage": "Successfully pushed new user account to app",
"gatewayContext": null,
"legacyEventType": "app.user_management.push_new_user_success",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000142",
"externalSessionId": "trs00000000000000143"
}
}
References #
app.user_management.user_group_import.create_failure
#Description
Failed to create group from app.
References #
app.user_management.user_group_import.delete_success
#Description
Deleted the group from app.
Example System Log Event #
{
"published": 1783702998845,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000032",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000144",
"type": "AppInstance",
"alternateId": "user35@dw-harness.example",
"displayName": "DW Harness 53",
"detailEntry": null
},
{
"id": "0oa00000000000000144",
"type": "AppInstance",
"alternateId": "user35@dw-harness.example",
"displayName": "DW Harness 53",
"detailEntry": null
},
{
"id": "agr00000000000000145",
"type": "AppGroup",
"alternateId": "user36@dw-harness.example",
"displayName": "DW Harness 54",
"detailEntry": null
},
{
"id": "00g00000000000000146",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 54",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "app.user_management.user_group_import.delete_success",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gmr00000000000000147",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000009"
}
},
"debugContext": {
"debugData": {
"appname": "Example App 11"
}
},
"displayMessage": "Deleted the Example Group 9 group from app",
"gatewayContext": null,
"legacyEventType": "app.user_management.user_group_import.delete_success",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000148",
"externalSessionId": "trs00000000000000149"
}
}
References #
app.user_management.user_group_import.update_failure
#Description
Failed to update group from app.
References #
app.user_management.user_group_import.upsert_fail
#Description
Failed to import the group from app. This event helps identify when a group is failed to be imported. Fired when we skip processing an import of a group.
References #
app.user_management.user_group_import.upsert_success
#Description
Imported the group from app.
References #
app.ad.credential.verify
#Description
Verify a stored Active Directory credential is valid. Use this event to audit AD credential drift checks performed by privileged-access flows (e.g., Okta Privileged Access). Unlike a real AD authentication, this verification creates no Okta session and does not update user state. outcome.result = SUCCESS indicates the stored credential is valid against AD. FAILURE indicates the credential is invalid for any reason (e.g., drifted, rotated, revoked, or similar).
References #
app.ai_agent_provider.import_staging.confirm
#Description
Confirm an AI agent staging item for registration. Audit when an imported agent is accepted into the identity store, either as a new registration or merged with an existing agent from another provider. A corresponding workload_principal.register event is fired when the confirmed agent is registered.
References #
app.ai_agent_provider.import_staging.ignore
#Description
Ignore an AI agent staging item. Audit when an imported agent is dismissed and excluded from the identity store.
References #
app.ai_agent_provider.priority.update
#Description
Update the priority ordering of AI agent import providers. Audit when the import provider priority ordering changes; the new order determines which provider's profile attributes take precedence for agents imported from multiple sources. changeDetails contains the ordered list of app instance IDs before and after the change, matching the order of the replace request.
References #
app.office365.provisioning_app.create
#Description
Creates a dedicated Microsoft Entra ID app that's registered and used for Office 365 provisioning. Confirms Okta has provisioned the Entra ID app registration required for Office 365 app-based provisioning. Correlate with the app in Microsoft Entra via app_registration_client_id.
References #
app.office365.provisioning_app_credential.rotate
#Description
Rotates the client secret of the registered Microsoft Entra ID app that's used for Office 365 provisioning. Outcome.Result distinguishes SUCCESS from FAILURE. Tracks scheduled rotations of the Entra ID app registration's client secret. Alert on Outcome.Result = FAILURE via Event Hook to catch stuck secrets before expiry. 'rotate' is outside the currently approved action-verb list (create/update/assign/revoke/generate/execute/delete/activate/deactivate); prior art exists (app.keys.rotate, pam.apikey.rotate, pam.client_enrollment_policy_token.rotate, pam.offline_group.secrets.rotate) and no approved verb captures the semantics of an in-place credential refresh.