Okta Application

eventTypeDescriptionSampleRule
application.account.decision.confirmConfirm unmanaged app account and reconcile to an Okta user.NN
application.account.decision.ignoreIgnore unmanaged app account during reconciliation.NN
application.account.decision.revokeRevoke unmanaged app account access and deprovision the user.NN
application.account.detectDetect unmanaged app account during reconciliation.NN
application.account.match.updateUpdate match between an unmanaged app account and an Okta user.NN
application.account.removeRemove unmanaged app account detection after the source account was deleted.NN
application.appuser.mapping.invalid.expressionApp user property mapping has invalid expressions.NN
application.cache.invalidateEvent fired when a app list cache is invalidated because a new app is created.YN
application.configuration.detect_errorApplication configuration error detected.NN
application.configuration.disable_delauth_outboundDisable delegated authentication for app.NN
application.configuration.disable_fed_broker_modeDisable Federation Broker Mode for app.NN
application.configuration.enable_delauth_outboundEnable delegated authentication for app.NN
application.configuration.enable_fed_broker_modeEnable Federation Broker Mode for app.NN
application.configuration.import_schemaOkta couldn't download application configuration.NN
application.configuration.read_client_secretA client secret in an MFA-only app has been read.NN
application.configuration.reset_logoReset app logo.NN
application.configuration.updateOkta couldn't verify api credentials.YN
application.configuration.update_api_credentials_for_pass_changeUpdate API credentials due to user updating password.NN
application.configuration.update_logoChange app logo.NN
application.configuration.update_rate_limitsUpdate rate limits for an OAuth App.NN
application.integration.api_queryUnable to query remote API.NN
application.integration.authentication_failureError authenticating.YN
application.integration.general_failureGeneric error occured.NN
application.integration.rate_limit_exceededAPI rate limit exceeded.NY
application.integration.transfer_filesUnable to transfer files.NN
application.lifecycle.activateActivate application.YY
application.lifecycle.createCreate application.YY
application.lifecycle.deactivateDeactivate application.YY
application.lifecycle.deleteDelete application.YY
application.lifecycle.updateUpdate application.YY
application.policy.sign_on.deny_accessDeny user access due to app sign on policy.YN
application.policy.sign_on.rule.createCreate rule for app sign on policy.NN
application.policy.sign_on.rule.deleteDelete rule from app sign on policy.NY
application.policy.sign_on.updateUpdate app sign on policy.NY
application.provision.field_mapping_rule.changeEvent fired when field mapping rules modified.NN
application.provision.group.addFired when Okta provisions a new group on a remote application.YN
application.provision.group.importFired when Okta downloads a remote group.YN
application.provision.group.removeFired when Okta removes a remote group.NN
application.provision.group.updateFired when Okta updates the user group.NN
application.provision.group.verify_existsFired when group no longer exists on a remote application.NN
application.provision.group_membership.addFailed to assign a user to a group.NN
application.provision.group_membership.importError while downloading memberships.NN
application.provision.group_membership.removeFired when there is an error while removing user(s) from group.NN
application.provision.group_membership.updateFired when there is an error while updating user group membership for group.NN
application.provision.group_push.activate_mappingGroup push activated mappings.YN
application.provision.group_push.deactivate_mappingGroup push deactivated mappings.YN
application.provision.group_push.delete_appgroupGroup push deleted application group.YN
application.provision.group_push.mapping.and.groups.deleted.rule.deletedAn existing mapping and its target groups have been deleted because a mapping rule was deleted.YN
application.provision.group_push.mapping.app.group.renamedA mapped app group has been renamed because the source group was renamed.YN
application.provision.group_push.mapping.app.group.renamed.failedA mapped app group couldn't be renamed when the source group was renamed.YN
application.provision.group_push.mapping.createdA new mapping has been created.YN
application.provision.group_push.mapping.created.from.rule.warning.duplicate.nameA new mapping from a rule was not created due to a duplicate group name.NN
application.provision.group_push.mapping.created.from.rule.warning.duplicate.name.tobecreatedA new mapping from a rule was not created due to another mapping will be created that has the same user group name.NN
application.provision.group_push.mapping.created.from.rule.warning.upsertGroup.duplicate.nameAn upsert to a group caused group push rule re-evaluation.YN
application.provision.group_push.mapping.deactivated.source.group.renamedAn existing mapping has been deactivated because the source group was renamed.NN
application.provision.group_push.mapping.deactivated.source.group.renamed.failedAn existing mapping couldn't be deactivated when the source group was renamed.NN
application.provision.group_push.mapping.update.or.delete.failedGroup push mapping change failed and will be retried.NN
application.provision.group_push.mapping.update.or.delete.failed.with.errorGroup push mapping change failed and cannot be retried.YN
application.provision.group_push.push_membershipsGroup push pushed memberships.YN
application.provision.group_push.pushedA group was pushed to an app.YN
application.provision.group_push.removedA group was removed from an app.YN
application.provision.group_push.updatedA group was updated in an app.YN
application.provision.integration.call_apiApplication integration API called.NN
application.provision.user.activateActivate user's application membership.NN
application.provision.user.deactivatePush user deactivation to external application.YN
application.provision.user.deprovisionDeprovision user from external application.YN
application.provision.user.importDeactivate user from external application.NN
application.provision.user.import_profileImport profile from external application.YN
application.provision.user.passwordIssue pushing user password to external application.YN
application.provision.user.pushPush new user to external application.YN
application.provision.user.push_okta_passwordPush user's Okta password to application.NN
application.provision.user.push_passwordPush user's password to application.YN
application.provision.user.push_profilePush user's profile to external application.YN
application.provision.user.reactivatePush user reactivation in external application.YN
application.provision.user.syncSync user in external application.YN
application.provision.user.verify_existsVerify user exists in external application.YN
application.registration_policy.lifecycle.createCreate registration policy.NN
application.registration_policy.lifecycle.updateUpdate registration policy.NN
application.user_membership.addAdd user to application membership.YN
application.user_membership.approveUser approved for application (assigned by not provisioned).NN
application.user_membership.change_passwordChange application password for user.NN
application.user_membership.change_usernameChange user's application username.NY
application.user_membership.deprovisionUser deprovisioned from application (was previously revoked).NN
application.user_membership.provisionUser provisioned to application (was previously approved).NN
application.user_membership.removeRemove user's application membership.YN
application.user_membership.restoreRestore user assignment to an application.NN
application.user_membership.restore_passwordRestore user's password for an application.NN
application.user_membership.revokeUser revoked from application (unassigned but not yet deprovisioned).NN
application.user_membership.show_passwordShow user's password for application.NY
application.user_membership.updateUpdated user application property.YN
application.provision.user.deleteDelete app user from application.NN
application.provision.user.delete.scheduleSchedule deletion of app user from application.NN
application.provision.user.remove_entitlementsRemove entitlements from app user.NN
application.provision.user.remove_entitlements.scheduleSchedule removal of entitlements from app user.NN

application.account.decision.confirm

#

Description

Confirm unmanaged app account and reconcile to an Okta user. Track when an imported app account is accepted - either automatically or by an admin - and linked to an Okta user.

References #

application.account.decision.ignore

#

Description

Ignore unmanaged app account during reconciliation. Audit ignore decisions for access reviews and detect accounts that are repeatedly ignored without follow-up remediation.

References #

application.account.decision.revoke

#

Description

Revoke unmanaged app account access and deprovision the user. Track when an admin rejects an imported app account and the corresponding app user is deprovisioned.

References #

application.account.detect

#

Description

Detect unmanaged app account during reconciliation. Track newly discovered app accounts that need to be reconciled with Okta users.

References #

application.account.match.update

#

Description

Update match between an unmanaged app account and an Okta user. Audit administrator overrides of the auto-detected match between an imported app account and an Okta user.

References #

application.account.remove

#

Description

Remove unmanaged app account detection after the source account was deleted. Track when an import removes a previously detected app account because the upstream account no longer exists.

References #

application.appuser.mapping.invalid.expression

#

Description

App user property mapping has invalid expressions. Can be used to identify invalid expressions. Note that a single event is fired for all invalid expressions.

References #

application.cache.invalidate

#

Description

Event fired when a app list cache is invalidated because a new app is created. Can be used to make sure App List cache is invalidated after a new app is created.

Example System Log Event #

{
  "published": 1785252675528,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000033",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "local-v2-sdk/0.0.0 golang/go1.26.2 linux/arm64 okta-terraform/6.13.0",
      "os": "Linux",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.4",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00000000-0000-0000-0000-000000000034",
      "type": "APP",
      "alternateId": "user37@dw-harness.example",
      "displayName": "DW Harness 52",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": "Application updated"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.4",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.cache.invalidate",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000022",
    "detail": {
      "rootApiTokenId": "00t00000000000000150",
      "requestApiTokenId": "00t00000000000000150"
    }
  },
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000022",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000018",
      "invalidatedAppId": "00000000-0000-0000-0000-000000000034",
      "requestUri": "uv700000000000000151",
      "url": "uv700000000000000151?"
    }
  },
  "displayMessage": "Application updated",
  "gatewayContext": null,
  "legacyEventType": "invalidate_app_list.app.updated",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000152",
    "externalSessionId": "trs00000000000000152"
  }
}

References #

application.configuration.detect_error

#

Description

Application configuration error detected.

References #

application.configuration.disable_delauth_outbound

#

Description

Disable delegated authentication for app.

References #

application.configuration.disable_fed_broker_mode

#

Description

Disable Federation Broker Mode for app.

References #

application.configuration.enable_delauth_outbound

#

Description

Enable delegated authentication for app.

References #

application.configuration.enable_fed_broker_mode

#

Description

Enable Federation Broker Mode for app.

References #

application.configuration.import_schema

#

Description

Okta couldn't download application configuration. Can be used to identify when an app schema couldn't be downloaded from a remote application. Event fired when Okta couldn't download application-specific data from a remote app. This may happen when admin updates provisioning details.

References #

application.configuration.read_client_secret

#

Description

A client secret in an MFA-only app has been read. Verify that a client secret in an MFA-only app has been read. This events indicates that a client secret in an MFA-only app has been read.

References #

application.configuration.update

#

Description

Okta couldn't verify api credentials. Can be used when Okta couldn't check the credentials by execution some custom, application dependent, set of requests. Okta fires this event to notify issues with credentials validation. Could be issues with proper permissions as well.

Example System Log Event #

{
  "published": 1780925968259,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000035",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:151.0) Gecko/20100101 Firefox/151.0",
      "os": "Windows 10",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.20",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": "Client received SOAP Fault from server: invalid username or password Please see the server log to find more detail regarding exact cause of the failure."
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.20",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.configuration.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000023",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000023",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "0000000000000000000000000000000000000000000000000000000000000000000000000002",
      "url": "0000000000000000000000000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "Application Configuration Updated",
  "gatewayContext": null,
  "legacyEventType": "app.workday.api.error.validate",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "externalSessionId": null
  }
}

References #

application.configuration.update_api_credentials_for_pass_change

#

Description

Update API credentials due to user updating password.

References #

application.configuration.update_rate_limits

#

Description

Update rate limits for an OAuth App. This can be used to track the updates to rate limits for an OAuth application. When fired, this event contains details about the actor, who triggered the event, the OAuth app, for which the rate limit was updated, etc. Actual value change details can be found in debug data such as the old and new values.

References #

application.integration.api_query

#

Description

Unable to query remote API. Can be used to determine when okta fails to query remote application. Okta fires this event for unspecified events which include remote api response processing.

References #

application.integration.authentication_failure

#

Description

Error authenticating. Can be used when Okta couldn't authenticate with the provided credentials to a remote api. Okta fires this event when it couldn't access a remote api with provided credentials.

Example System Log Event #

{
  "published": 1784836312457,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000036",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000163",
      "type": "AppInstance",
      "alternateId": "user39@dw-harness.example",
      "displayName": "DW Harness 56",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": "Unauthorized. Errors reported by remote server: "
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.integration.authentication_failure",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000024",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000024",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000012",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000003",
      "url": "00000000000000000000000000000000000000000000000000003?"
    }
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": "app.api.error.auth",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "externalSessionId": null
  }
}

References #

application.integration.general_failure

#

Description

Generic error occured. Can be used when there is some uncategorized error occurs. Okta fires this event for different unhandled exceptions.

References #

application.integration.rate_limit_exceeded

#

Description

API rate limit exceeded. Can be used when Okta reaches api calls/minute rate limit. Okta fires this event when there are too many requests for a specific customer.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

application.integration.transfer_files

#

Description

Unable to transfer files. Can be used when Okta fails to transfer files from one user to another. Okta fires this event when it fails to process user-to-user file transfers.

References #

application.lifecycle.activate

#

Description

Activate application.

Example System Log Event #

{
  "published": 1784812089700,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000037",
  "actor": {
    "id": "00u00000000000000164",
    "type": "User",
    "alternateId": "user03@dw-harness.example",
    "displayName": "DW Harness 04",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.3",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000165",
      "type": "AppInstance",
      "alternateId": "user40@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.3",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.lifecycle.activate",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000025",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000025",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000020",
      "origin": "https://app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "0000000000000000000000000000000000000000000000000000002",
      "url": "0000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "Activate application",
  "gatewayContext": null,
  "legacyEventType": "app.generic.config.app_activated",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000166",
    "externalSessionId": "10200000000000000166"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

application.lifecycle.create

#

Description

Create application.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000003",
    "externalSessionId": "trs00000000000000003"
  },
  "displayMessage": "Create application",
  "eventType": "application.lifecycle.create",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:35:50.239Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "appVersion": "00000000-0000-0000-0000-000000000007",
      "requestId": "00000000000000000000000000000002",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/apps",
      "url": "/api/v1/apps?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "app.app_editor.app.create",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000002",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000008",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000005",
      "type": "AppInstance",
      "alternateId": "user03@dw-harness.example",
      "displayName": "DW Harness 03",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000002",
      "type": "User",
      "alternateId": "user02@dw-harness.example",
      "displayName": "DW Harness 02",
      "detailEntry": null
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

application.lifecycle.deactivate

#

Description

Deactivate application.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000011",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Deactivate application",
  "eventType": "application.lifecycle.deactivate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:52.119Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/apps/0oa00000000000000004/lifecycle/deactivate",
      "url": "/api/v1/apps/0oa00000000000000004/lifecycle/deactivate?"
    }
  },
  "legacyEventType": "app.generic.config.app_deactivated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "AppInstance",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Attempt to Deactivate an Okta Application source low: Detects attempts to deactivate an Okta application. An adversary may attempt to modify, deactivate, or delete an Okta application in order to weaken an organization's security controls or disrupt their business operations.T1489

References #

application.lifecycle.delete

#

Description

Delete application.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000012",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Delete application",
  "eventType": "application.lifecycle.delete",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:52.269Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/apps/0oa00000000000000004",
      "url": "/api/v1/apps/0oa00000000000000004?"
    }
  },
  "legacyEventType": "app.generic.config.app_deleted",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "AppInstance",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventType (sigma rule field)eqapplication.lifecycle.update1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Attempt to Delete an Okta Application source low: Detects attempts to delete an Okta application. An adversary may attempt to modify, deactivate, or delete an Okta application in order to weaken an organization's security controls or disrupt their business operations.T1489

References #

application.lifecycle.update

#

Description

Update application.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000013",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Update application",
  "eventType": "application.lifecycle.update",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:50.774Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/apps",
      "url": "/api/v1/apps?"
    }
  },
  "legacyEventType": "app.generic.config.app_updated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "AppInstance",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventTypeeqapplication.lifecycle.update2 rulespanther, sigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Attempt to Modify an Okta Application source low: Detects attempts to modify an Okta application. An adversary may attempt to modify, deactivate, or delete an Okta application in order to weaken an organization's security controls or disrupt their business operations.

Panther #

References #

application.policy.sign_on.deny_access

#

Description

Deny user access due to app sign on policy. When fired due to app assurance being evaluated as unsatisfiable (the policy requirements could not be satisfied by the users' current set of available authenticator enrollments), this event contains information about the user and the app that the user is trying to authenticate into.

Example System Log Event #

{
  "published": 1782502291551,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000038",
  "actor": {
    "id": "spr00000000000000167",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
      "os": "Mac OS 15.6.1 (Sequoia)",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.19",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": {
    "id": null,
    "name": null,
    "os_platform": null,
    "os_version": null,
    "managed": null,
    "registered": null,
    "device_integrator": {
      "DEVICE_IDP": {}
    },
    "disk_encryption_type": null,
    "screen_lock_type": null,
    "jailbreak": null,
    "secure_hardware_present": null
  },
  "events": null,
  "target": [
    {
      "id": "00000000-0000-0000-0000-000000000039",
      "type": "APP",
      "alternateId": "user42@dw-harness.example",
      "displayName": "DW Harness 22",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000118",
      "type": "User",
      "alternateId": "user30@dw-harness.example",
      "displayName": "DW Harness 45",
      "detailEntry": {
        "realmId": "guo00000000000000062"
      }
    },
    {
      "id": "0oa00000000000000168",
      "type": "AppInstance",
      "alternateId": "user43@dw-harness.example",
      "displayName": "DW Harness 22",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": "The policy requirements could not be satisfied by the users’ current set of available authenticator enrollments"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.19",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.policy.sign_on.deny_access",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000026",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "authnRequestId": "00000000000000000000000000000027",
      "deviceFingerprint": "00000000000000000000000000000028",
      "behaviors": "{New Geo-Location=UNKNOWN, New Device=UNKNOWN, New ASN=UNKNOWN, New IP=UNKNOWN, New State=UNKNOWN, New Country=UNKNOWN, Velocity=UNKNOWN, New City=UNKNOWN}",
      "requestId": "00000000000000000000000000000026",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000021",
      "origin": "https://app.example.com",
      "risk": "{reasons=Anomalous Device, Anomalous Location, level=HIGH}",
      "requestUri": "/idp/idx/identify",
      "threatSuspected": "false",
      "url": "/idp/idx/identify?"
    }
  },
  "displayMessage": "Access has been denied because the policy requirements could not be satisfied by the users’ current set of available authenticator enrollments",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "HIGH",
      "reasons": [
        "Anomalous Device",
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "UNKNOWN"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "UNKNOWN"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "UNKNOWN"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "UNKNOWN"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "UNKNOWN"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "UNKNOWN"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "UNKNOWN"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "UNKNOWN"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000169",
    "externalSessionId": "idx00000000000000169"
  }
}

References #

application.policy.sign_on.rule.create

#

Description

Create rule for app sign on policy.

References #

application.policy.sign_on.rule.delete

#

Description

Delete rule from app sign on policy.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::eventType (kusto rule field)equser.session.start1 rulekusto
okta::eventType (kusto rule field)inuser.mfa.factor.deactivate1 rulekusto
okta::eventType (kusto rule field)inuser.mfa.factor.reset_all1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

  • New Device/Location sign-in along with critical operation source medium: This query identifies users seen login from a new geo location/country and a new device, then correlates that sign-in with successful risky operations such as policy changes, MFA changes, API token actions etc. This can be an indication of an attacker gaining access to a user's credentials and then performing critical operations, which typically requires admin privileges. By detecting such patterns, organizations can quickly respond to potential security incidents and mitigate risks associated with unauthorized access and privilege escalation.T1078, T1098, T1556↳ also matches application.policy.sign_on.update

References #

application.policy.sign_on.update

#

Description

Update app sign on policy.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::eventType (kusto rule field)equser.session.start1 rulekusto
okta::eventType (kusto rule field)inuser.mfa.factor.deactivate1 rulekusto
okta::eventType (kusto rule field)inuser.mfa.factor.reset_all1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

  • New Device/Location sign-in along with critical operation source medium: This query identifies users seen login from a new geo location/country and a new device, then correlates that sign-in with successful risky operations such as policy changes, MFA changes, API token actions etc. This can be an indication of an attacker gaining access to a user's credentials and then performing critical operations, which typically requires admin privileges. By detecting such patterns, organizations can quickly respond to potential security incidents and mitigate risks associated with unauthorized access and privilege escalation.T1078, T1098, T1556↳ also matches application.policy.sign_on.rule.delete

References #

application.provision.field_mapping_rule.change

#

Description

Event fired when field mapping rules modified. Can be used to make sure when custom mapping rules are modified.

References #

application.provision.group.add

#

Description

Fired when Okta provisions a new group on a remote application. Can be used to identify when Okta provisions a group on a remote application. Event fired when the group provisioning failed for any reason.

Example System Log Event #

{
  "published": 1785254306307,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000040",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000140",
      "type": "AppInstance",
      "alternateId": "user34@dw-harness.example",
      "displayName": "DW Harness 52",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": "Not Found. Errors reported by remote server: "
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group.add",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gmr00000000000000170",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": "app.api.error.upsert_group",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "externalSessionId": null
  }
}

References #

application.provision.group.import

#

Description

Fired when Okta downloads a remote group. Can be used to identify when Okta tries to download remote group details. Event fired when Okta fails to reach the group detail from a remote application.

Example System Log Event #

{
  "published": 1784746553047,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000041",
  "actor": {
    "id": "spr00000000000000171",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000163",
      "type": "AppInstance",
      "alternateId": "user39@dw-harness.example",
      "displayName": "DW Harness 56",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": "Unauthorized. Errors reported by remote server: "
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group.import",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gmr00000000000000172",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000010"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": "app.api.error.get_group_by_id",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "externalSessionId": null
  }
}

References #

application.provision.group.remove

#

Description

Fired when Okta removes a remote group. Can be used to identify when a group has been unassigned. Event fired when Okta failed to delete group from remote application.

References #

application.provision.group.update

#

Description

Fired when Okta updates the user group. Can be used to identify when a group has been updated. Event fired when Okta fails to update a remote group for any reason.

References #

application.provision.group.verify_exists

#

Description

Fired when group no longer exists on a remote application. Can be used to identify when a group no longer exists on a remote application. Event fired when group push enhancement enabled and there is no group found on update or delete.

References #

application.provision.group_membership.add

#

Description

Failed to assign a user to a group. Can be used when Okta failed to assign user to a group on remote application. Okta fires this event if there are any issues while provision a membership to a remote application.

References #

application.provision.group_membership.import

#

Description

Error while downloading memberships. Can be used when Okta failed to download users and groups relationships. Okta fires this event if there are any issues while importing a membership from a remote application.

References #

application.provision.group_membership.remove

#

Description

Fired when there is an error while removing user(s) from group. Can be used when Okta failed to unassign user from a group on remote application. Okta fires this event when there are any issues while provision a membership to a remote application.

References #

application.provision.group_membership.update

#

Description

Fired when there is an error while updating user group membership for group. Can be used when Okta failed to push updated memberships to a remote application. Okta fires this event when couldn't update memberships on a remote application. Could be user removal/addition.

References #

application.provision.group_push.activate_mapping

#

Description

Group push activated mappings.

Example System Log Event #

{
  "published": 1785254305707,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000042",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "gpm00000000000000173",
      "type": "GroupPushMapping",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 57",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000140",
      "type": "AppInstance",
      "alternateId": "user34@dw-harness.example",
      "displayName": "DW Harness 52",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000174",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 58",
      "detailEntry": null
    },
    {
      "id": "agr00000000000000175",
      "type": "AppGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 58",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.activate_mapping",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "bae00000000000000176",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Group Push - activating mapping (Mapping: gpm00000000000000173)",
  "gatewayContext": null,
  "legacyEventType": "platform.group_push.activate_mapping",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000177",
    "externalSessionId": "trs00000000000000178"
  }
}

References #

application.provision.group_push.deactivate_mapping

#

Description

Group push deactivated mappings. Can be used to audit when a group push mapping is deactivated or to trigger downstream automation. The corresponding event type for activating a group push mapping is application.provision.group_push.activate_mapping.

Example System Log Event #

{
  "published": 1780156937152,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000043",
  "actor": {
    "id": "00u00000000000000179",
    "type": "User",
    "alternateId": "user44@dw-harness.example",
    "displayName": "DW Harness 59",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.21",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "gpm00000000000000180",
      "type": "GroupPushMapping",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 57",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000165",
      "type": "AppInstance",
      "alternateId": "user40@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000181",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 60",
      "detailEntry": null
    },
    {
      "id": "agr00000000000000182",
      "type": "AppGroup",
      "alternateId": "user45@dw-harness.example",
      "displayName": "DW Harness 60",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.21",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.deactivate_mapping",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000029",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000029",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000022",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000003",
      "url": "00000000000000000000000000000000000000000000000000000000000000000000000003?"
    }
  },
  "displayMessage": "Group Push - deactivating mapping (Mapping: gpm00000000000000180)",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000183",
    "externalSessionId": "10200000000000000183"
  }
}

References #

application.provision.group_push.delete_appgroup

#

Description

Group push deleted application group.

Example System Log Event #

{
  "published": 1785257219838,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000044",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "gpm00000000000000173",
      "type": "GroupPushMapping",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 57",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000140",
      "type": "AppInstance",
      "alternateId": "user34@dw-harness.example",
      "displayName": "DW Harness 52",
      "detailEntry": null
    },
    {
      "id": "agr00000000000000175",
      "type": "AppGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 58",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.delete_appgroup",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rdj00000000000000184",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Group Push - deleting AppGroup (Mapping: gpm00000000000000173)",
  "gatewayContext": null,
  "legacyEventType": "platform.group_push.delete_appgroup",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000142",
    "externalSessionId": "trs00000000000000185"
  }
}

References #

application.provision.group_push.mapping.and.groups.deleted.rule.deleted

#

Description

An existing mapping and its target groups have been deleted because a mapping rule was deleted.

Example System Log Event #

{
  "published": 1785257220094,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000045",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "gpm00000000000000186",
      "type": "GroupPushMapping",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 57",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000187",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 61",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000140",
      "type": "AppInstance",
      "alternateId": "user34@dw-harness.example",
      "displayName": "DW Harness 52",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.mapping.and.groups.deleted.rule.deleted",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rdj00000000000000184",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "The Group push mapping to the group Example Group 22 has been deleted.",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.mapping.and.groups.deleted.rule.deleted",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000142",
    "externalSessionId": "trs00000000000000185"
  }
}

References #

application.provision.group_push.mapping.app.group.renamed

#

Description

A mapped app group has been renamed because the source group was renamed.

Example System Log Event #

{
  "published": 1780596052484,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000002",
  "actor": {
    "id": "00u00000000000000164",
    "type": "User",
    "alternateId": "user03@dw-harness.example",
    "displayName": "DW Harness 04",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "gpm00000000000000188",
      "type": "GroupPushMapping",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 57",
      "detailEntry": null
    },
    {
      "id": "agr00000000000000189",
      "type": "AppGroup",
      "alternateId": "user46@dw-harness.example",
      "displayName": "DW Harness 62",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000124",
      "type": "AppInstance",
      "alternateId": "user31@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.mapping.app.group.renamed",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rgj00000000000000190",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "A Group push mapping to the group Example Group 2 was renamed because the source group was renamed.",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.mapping.app.group.renamed",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000191",
    "externalSessionId": "trs00000000000000192"
  }
}

References #

application.provision.group_push.mapping.app.group.renamed.failed

#

Description

A mapped app group couldn't be renamed when the source group was renamed.

Example System Log Event #

{
  "published": 1784835867655,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000046",
  "actor": {
    "id": "0oa00000000000000123",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 46",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00000000000000000002",
      "type": "GroupPushMapping",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 57",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000193",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 63",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000163",
      "type": "AppInstance",
      "alternateId": "user39@dw-harness.example",
      "displayName": "DW Harness 56",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.mapping.app.group.renamed.failed",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rgj00000000000000194",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000011"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "A Group push mapping to the group Example Group 11 could not be renamed when the source group was renamed",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.mapping.app.group.renamed.failed",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000195",
    "externalSessionId": "trs00000000000000196"
  }
}

References #

application.provision.group_push.mapping.created

#

Description

A new mapping has been created.

Example System Log Event #

{
  "published": 1783623908401,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000047",
  "actor": {
    "id": "0oa00000000000000123",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 46",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "gpm00000000000000128",
      "type": "GroupPushMapping",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 57",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000125",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 48",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000124",
      "type": "AppInstance",
      "alternateId": "user31@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.mapping.created",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rej00000000000000126",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000008"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "A Group Push mapping to the group Example Group 5 has been created.",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.mapping.created",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000129",
    "externalSessionId": "trs00000000000000130"
  }
}

References #

application.provision.group_push.mapping.created.from.rule.warning.duplicate.name

#

Description

A new mapping from a rule was not created due to a duplicate group name.

References #

application.provision.group_push.mapping.created.from.rule.warning.duplicate.name.tobecreated

#

Description

A new mapping from a rule was not created due to another mapping will be created that has the same user group name.

References #

application.provision.group_push.mapping.created.from.rule.warning.upsertGroup.duplicate.name

#

Description

An upsert to a group caused group push rule re-evaluation. A new mapping from a rule was not created due to a duplicate group name.

Example System Log Event #

{
  "published": 1785241632629,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000048",
  "actor": {
    "id": "00u00000000000000131",
    "type": "User",
    "alternateId": "user32@dw-harness.example",
    "displayName": "DW Harness 49",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "gpr00000000000000197",
      "type": "GroupPushMappingRule",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 64",
      "detailEntry": null
    },
    {
      "id": "gpr00000000000000197",
      "type": "GroupPushMappingFromRuleConfig",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 65",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000198",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 66",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000140",
      "type": "AppInstance",
      "alternateId": "user34@dw-harness.example",
      "displayName": "DW Harness 52",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.mapping.created.from.rule.warning.upsertGroup.duplicate.name",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rej00000000000000199",
    "detail": {
      "rootApiTokenId": "00t00000000000000134"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "UserGroup was created or updated. A Group Push mapping did not get created from rule gpr00000000000000197 to UserGroup Example Group 15 since group with same name already exists in AppInstance 0oa00000000000000200",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.mapping.created.from.rule.warning.upsertGroup.duplicate.name",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000201",
    "externalSessionId": "trs00000000000000202"
  }
}

References #

application.provision.group_push.mapping.deactivated.source.group.renamed

#

Description

An existing mapping has been deactivated because the source group was renamed.

References #

application.provision.group_push.mapping.deactivated.source.group.renamed.failed

#

Description

An existing mapping couldn't be deactivated when the source group was renamed.

References #

application.provision.group_push.mapping.update.or.delete.failed

#

Description

Group push mapping change failed and will be retried. Can be used to identify transient errors that may temporarily impact the group push mapping but likely do not require admin intervention. This event typically requires no action as the corresponding operation will be retried. Refer to application.provision.group_push.mapping.update.or.delete.failed for events that may require intervention.

References #

application.provision.group_push.mapping.update.or.delete.failed.with.error

#

Description

Group push mapping change failed and cannot be retried. Can be used to identify group push mapping errors which may require admin intervention to address. Unlike the similarly named event, application.provision.group_push.mapping.update.or.delete.failed, when this event is fired the corresponding action that triggered it will not be retried by Okta and may indicate a configuration problem. For example, invalid authorization credentials with the target application due to an expired password or invalid access token.

Example System Log Event #

{
  "published": 1785254306309,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000049",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "gpm00000000000000203",
      "type": "GroupPushMapping",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 57",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000204",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 67",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000140",
      "type": "AppInstance",
      "alternateId": "user34@dw-harness.example",
      "displayName": "DW Harness 52",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.mapping.update.or.delete.failed.with.error",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gmr00000000000000170",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Changes to the Group push mapping for the group Example Group 17 could not take effect due to error: Error while creating user group Example Group 17: Not Found. Errors reported by remote server: ",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.mapping.update.or.delete.failed.with.error",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000177",
    "externalSessionId": "trs00000000000000205"
  }
}

References #

application.provision.group_push.push_memberships

#

Description

Group push pushed memberships.

Example System Log Event #

{
  "published": 1785238927668,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000050",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "okta-sdk-python/2.9.13 python/3.12.13 Linux/5.10.255-259-299.1043.amzn2.x86_64",
      "os": "Linux",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.16",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "gpm00000000000000206",
      "type": "GroupPushMapping",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 57",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000124",
      "type": "AppInstance",
      "alternateId": "user31@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    },
    {
      "id": "00g00000000000000207",
      "type": "UserGroup",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 68",
      "detailEntry": null
    },
    {
      "id": "agr00000000000000208",
      "type": "AppGroup",
      "alternateId": "user47@dw-harness.example",
      "displayName": "DW Harness 68",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.16",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.push_memberships",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000030",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000012",
      "requestApiTokenId": "0000000000000000000000000000000000000000000012",
      "requestApiTokenClientId": "0oa00000000000000112"
    }
  },
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000030",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000002",
      "url": "00000000000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "Group Push - pushing memberships (Mapping: gpm00000000000000206)",
  "gatewayContext": null,
  "legacyEventType": "platform.group_push.push_memberships",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000209",
    "externalSessionId": "trs00000000000000209"
  }
}

References #

application.provision.group_push.pushed

#

Description

A group was pushed to an app.

Example System Log Event #

{
  "published": 1785238928805,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000051",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "agr00000000000000208",
      "type": "AppGroup",
      "alternateId": "user47@dw-harness.example",
      "displayName": "DW Harness 68",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000124",
      "type": "AppInstance",
      "alternateId": "user31@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.pushed",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gmr00000000000000210",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000012"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Group Push group Example Group 23 pushed to app.",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.pushed",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000209",
    "externalSessionId": "trs00000000000000211"
  }
}

References #

application.provision.group_push.removed

#

Description

A group was removed from an app.

Example System Log Event #

{
  "published": 1780422794719,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000052",
  "actor": {
    "id": "spr00000000000000171",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "agr00000000000000212",
      "type": "AppGroup",
      "alternateId": "user48@dw-harness.example",
      "displayName": "DW Harness 69",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000078",
      "type": "AppInstance",
      "alternateId": "user49@dw-harness.example",
      "displayName": "DW Harness 23",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.removed",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gmr00000000000000213",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000013"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Group Push group Example Group 27 removed from app.",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.removed",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000214",
    "externalSessionId": "trs00000000000000215"
  }
}

References #

application.provision.group_push.updated

#

Description

A group was updated in an app.

Example System Log Event #

{
  "published": 1785238929228,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000053",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "agr00000000000000208",
      "type": "AppGroup",
      "alternateId": "user47@dw-harness.example",
      "displayName": "DW Harness 68",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000124",
      "type": "AppInstance",
      "alternateId": "user31@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.group_push.updated",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gmr00000000000000210",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000012"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Group Push group Example Group 23 updated in app.",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.grouppush.updated",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000209",
    "externalSessionId": "trs00000000000000211"
  }
}

References #

application.provision.integration.call_api

#

Description

Application integration API called.

References #

application.provision.user.activate

#

Description

Activate user's application membership.

References #

application.provision.user.deactivate

#

Description

Push user deactivation to external application.

Example System Log Event #

{
  "published": 1781348649384,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000054",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000216",
      "type": "AppUser",
      "alternateId": "user50@dw-harness.example",
      "displayName": "DW Harness 70",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000217",
      "type": "User",
      "alternateId": "user50@dw-harness.example",
      "displayName": "DW Harness 70",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "0oa00000000000000144",
      "type": "AppInstance",
      "alternateId": "user35@dw-harness.example",
      "displayName": "DW Harness 53",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.user.deactivate",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "duj00000000000000218",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000014"
    }
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 11"
    }
  },
  "displayMessage": "Push user deactivation to external application",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.deactivate_user",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000219",
    "externalSessionId": "trs00000000000000220"
  }
}

References #

application.provision.user.deprovision

#

Description

Deprovision user from external application.

Example System Log Event #

{
  "published": 1781348650032,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000055",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0dt00000000000000221",
      "type": "DeprovisionTask",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 71",
      "detailEntry": {
        "completedAt": "2026-06-13T11:04:09.000Z",
        "initiatedAt": "2026-06-13T11:04:09.000Z",
        "appUserId": "0ua00000000000000222",
        "resolution": "Auto Deprovisioned",
        "initiatedBy": "pca00000000000000223"
      }
    },
    {
      "id": "0ua00000000000000222",
      "type": "AppUser",
      "alternateId": "user51@dw-harness.example",
      "displayName": "DW Harness 72",
      "detailEntry": {
        "appInstanceId": "0oa00000000000000144",
        "appUsername": "user51@dw-harness.example",
        "userId": "00u00000000000000224"
      }
    },
    {
      "id": "0oa00000000000000144",
      "type": "AppInstance",
      "alternateId": "user35@dw-harness.example",
      "displayName": "DW Harness 53",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000224",
      "type": "User",
      "alternateId": "user51@dw-harness.example",
      "displayName": "DW Harness 73",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.user.deprovision",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "duj00000000000000225",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000014"
    }
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Deprovision user from external application",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.deprovision_task_complete",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000226",
    "externalSessionId": "trs00000000000000227"
  }
}

References #

application.provision.user.import

#

Description

Deactivate user from external application.

References #

application.provision.user.import_profile

#

Description

Import profile from external application.

Example System Log Event #

{
  "published": 1782502954246,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000056",
  "actor": {
    "id": "00u00000000000000117",
    "type": "User",
    "alternateId": "user29@dw-harness.example",
    "displayName": "DW Harness 44",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Java/17.0.19",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "192.0.2.12",
    "geographicalContext": {
      "city": null,
      "state": null,
      "country": "Placeholderland",
      "postalCode": null,
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    },
    {
      "id": "00000000000000000000000000000031",
      "type": "APPUSER",
      "alternateId": null,
      "displayName": null,
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": "Realtime sync scheduled successfully"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.12",
        "geographicalContext": {
          "city": null,
          "state": null,
          "country": "Placeholderland",
          "postalCode": null,
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.user.import_profile",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000032",
    "detail": {
      "rootApiTokenId": "00t00000000000000120",
      "requestApiTokenId": "00t00000000000000120"
    }
  },
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000032",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000023",
      "requestUri": "00000000000000000000000000000000000000000004",
      "url": "00000000000000000000000000000000000000000004?"
    }
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": "app.generic.config.app_updated",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000121",
    "externalSessionId": "trs00000000000000121"
  }
}

References #

application.provision.user.password

#

Description

Issue pushing user password to external application.

Example System Log Event #

{
  "published": 1785256723810,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000057",
  "actor": {
    "id": "00u00000000000000139",
    "type": "User",
    "alternateId": "user33@dw-harness.example",
    "displayName": "DW Harness 51",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000228",
      "type": "AppInstance",
      "alternateId": "user52@dw-harness.example",
      "displayName": "DW Harness 74",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000139",
      "type": "User",
      "alternateId": "user53@dw-harness.example",
      "displayName": "DW Harness 51",
      "detailEntry": null
    },
    {
      "id": "0ua00000000000000229",
      "type": "AppUser",
      "alternateId": "user53@dw-harness.example",
      "displayName": "DW Harness 75",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": "Not Found. Errors reported by remote server: Invalid JSON: Unexpected character ('<' (code 60)): expected a valid value (JSON String, Number, Array, Object or token 'null', 'true' or 'false')\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.user.password",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "pwj00000000000000230",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": "app.api.error.push_password_update",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "externalSessionId": null
  }
}

References #

application.provision.user.push

#

Description

Push new user to external application.

Example System Log Event #

{
  "published": 1785256677526,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000058",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000138",
      "type": "AppUser",
      "alternateId": "user33@dw-harness.example",
      "displayName": "DW Harness 51",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000139",
      "type": "User",
      "alternateId": "user33@dw-harness.example",
      "displayName": "DW Harness 51",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "0oa00000000000000140",
      "type": "AppInstance",
      "alternateId": "user34@dw-harness.example",
      "displayName": "DW Harness 52",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.user.push",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "puj00000000000000141",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 16"
    }
  },
  "displayMessage": "Push new user to external application",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.push_new_user",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000142",
    "externalSessionId": "trs00000000000000143"
  }
}

References #

application.provision.user.push_okta_password

#

Description

Push user's Okta password to application.

References #

application.provision.user.push_password

#

Description

Push user's password to application.

Example System Log Event #

{
  "published": 1785256723789,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000059",
  "actor": {
    "id": "00u00000000000000139",
    "type": "User",
    "alternateId": "user33@dw-harness.example",
    "displayName": "DW Harness 51",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000229",
      "type": "AppUser",
      "alternateId": "user33@dw-harness.example",
      "displayName": "DW Harness 51",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000139",
      "type": "User",
      "alternateId": "user33@dw-harness.example",
      "displayName": "DW Harness 51",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "0oa00000000000000228",
      "type": "AppInstance",
      "alternateId": "user52@dw-harness.example",
      "displayName": "DW Harness 74",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.user.push_password",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "pwj00000000000000230",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 19"
    }
  },
  "displayMessage": "Push user's password to application",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.push_unique_password_update",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000231",
    "externalSessionId": "trs00000000000000232"
  }
}

References #

application.provision.user.push_profile

#

Description

Push user's profile to external application.

Example System Log Event #

{
  "published": 1785243553471,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000060",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000233",
      "type": "AppUser",
      "alternateId": "user51@dw-harness.example",
      "displayName": "DW Harness 73",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000224",
      "type": "User",
      "alternateId": "user51@dw-harness.example",
      "displayName": "DW Harness 73",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "0oa00000000000000144",
      "type": "AppInstance",
      "alternateId": "user35@dw-harness.example",
      "displayName": "DW Harness 53",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.user.push_profile",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "puj00000000000000234",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000015"
    }
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 11"
    }
  },
  "displayMessage": "Push user's profile to external application",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.push_profile_success",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000235",
    "externalSessionId": "trs00000000000000236"
  }
}

References #

application.provision.user.reactivate

#

Description

Push user reactivation in external application.

Example System Log Event #

{
  "published": 1785243552966,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000061",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000233",
      "type": "AppUser",
      "alternateId": "user51@dw-harness.example",
      "displayName": "DW Harness 73",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000224",
      "type": "User",
      "alternateId": "user51@dw-harness.example",
      "displayName": "DW Harness 73",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "0oa00000000000000144",
      "type": "AppInstance",
      "alternateId": "user35@dw-harness.example",
      "displayName": "DW Harness 53",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.user.reactivate",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "puj00000000000000234",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000015"
    }
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 11"
    }
  },
  "displayMessage": "Push user reactivation in external application",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.reactivate_user",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000235",
    "externalSessionId": "trs00000000000000236"
  }
}

References #

application.provision.user.sync

#

Description

Sync user in external application.

Example System Log Event #

{
  "published": 1785256678993,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000062",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000138",
      "type": "AppUser",
      "alternateId": "user33@dw-harness.example",
      "displayName": "DW Harness 51",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000139",
      "type": "User",
      "alternateId": "user33@dw-harness.example",
      "displayName": "DW Harness 51",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "0oa00000000000000140",
      "type": "AppInstance",
      "alternateId": "user34@dw-harness.example",
      "displayName": "DW Harness 52",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.provision.user.sync",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "puj00000000000000141",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 16"
    }
  },
  "displayMessage": "Sync user in external application",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.provision_user",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000142",
    "externalSessionId": "trs00000000000000143"
  }
}

References #

application.provision.user.verify_exists

#

Description

Verify user exists in external application.

Example System Log Event #

{
  "published": 1785243552963,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000063",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000233",
      "type": "AppUser",
      "alternateId": "user51@dw-harness.example",
      "displayName": "DW Harness 73",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000224",
      "type": "User",
      "alternateId": "user51@dw-harness.example",
      "displayName": "DW Harness 73",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "0oa00000000000000144",
      "type": "AppInstance",
      "alternateId": "user35@dw-harness.example",
      "displayName": "DW Harness 53",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "DEBUG",
  "eventType": "application.provision.user.verify_exists",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "puj00000000000000234",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000015"
    }
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 11"
    }
  },
  "displayMessage": "Verify user exists in external application",
  "gatewayContext": null,
  "legacyEventType": "app.user_management.verified_user_with_thirdparty",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000235",
    "externalSessionId": "trs00000000000000236"
  }
}

References #

application.registration_policy.lifecycle.create

#

application.registration_policy.lifecycle.update

#

application.user_membership.add

#

Description

Add user to application membership.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000014",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Add user to application membership",
  "eventType": "application.user_membership.add",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:51.467Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "appname": "bookmark",
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/apps/0oa00000000000000004/users",
      "url": "/api/v1/apps/0oa00000000000000004/users?"
    }
  },
  "legacyEventType": "app.generic.provision.assign_user_to_app",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "AppUser",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    },
    {
      "id": "00000000000000000000",
      "type": "AppInstance",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    },
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

application.user_membership.approve

#

Description

User approved for application (assigned by not provisioned).

References #

application.user_membership.change_password

#

Description

Change application password for user.

References #

application.user_membership.change_username

#

Description

Change user's application username.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
admin_email (panther rule field)is_not_null2 rulespanther
is_anomalous (panther rule field)eqtrue2 rulespanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Okta SWA Bulk Access, New Source, and Credential Extraction - Behavioral source high linked query: Query.Okta.SWABulkAccessBehavioral: Detects Okta SWA (Secure Web Authentication) bulk credential extraction, abuse, and access from previously unseen IP addresses or user agents using behavioral z-score and source novelty analysis. SWA apps store credentials in Okta's encrypted vault. Admin accounts with SWA access can view or rotate credentials for users across many apps. This detection builds a 90-day behavioral baseline for each admin's SWA access, credential change patterns, and known source IPs/user agents, then identifies anomalous spikes or new sources in the last 7 days. Detection Logic: - Z-score: SWA authentication volume spike (> 3σ above baseline) - Z-score: Unique SWA app diversity spike (many different apps accessed in one hour) (> 3σ) - Z-score: Credential extraction volume spike (> 3σ) - Z-score: Victim diversity spike (credential changes across many users) (> 2σ) - Cold-start: First-time bulk SWA access (>= 10 events, no prior baseline) - Cold-start: First-time credential extraction (>= 5 extractions, no prior baseline) - New source: SWA access from IP address not seen in 90-day baseline - New source: SWA access from user agent not seen in 90-day baseline - Critical compound: New IP + any credential extraction events Why This Matters: SWA credential extraction is a powerful lateral movement technique. An attacker with admin access can silently retrieve plaintext credentials for hundreds of SWA-protected applications without triggering MFA or generating obvious authentication failures. New source detection catches the initial access phase when a compromised admin account is used from an unfamiliar device or location. Complementary Detection: Use alongside Okta.SWA.OffHoursAccess.Behavioral which detects the same attack vector occurring outside normal business hours.T1078, T1213, T1555
  • Okta SWA Off-Hours Credential Access - Behavioral source high linked query: Query.Okta.SWAOffHoursAccessBehavioral: Detects Okta SWA credential access occurring outside normal business hours using behavioral z-score analysis on temporal patterns. Compromised admin accounts often access SWA credentials at unusual times - late at night, during weekends, or from a different geographic location than normal. This detection builds a 90-day baseline for each admin's temporal credential access patterns, then identifies anomalous shifts toward off-hours, late-night, and weekend activity in the last 7 days. Detection Logic: - Z-score: Off-hours ratio spike (> 3σ above normal off-hours proportion) - Z-score: Late-night ratio spike (2 AM - 6 AM accesses) (> 2σ) - Z-score: Weekend ratio spike (> 2σ) - Cold-start: First-time off-hours credential access (>= 3 events, no prior baseline) - Cold-start: First-time late-night access (>= 2 events, no prior baseline) - Cold-start: First-time weekend access (>= 2 events, no prior baseline) - Compound: Geographic shift + off-hours activity (high-confidence indicator) Why This Matters: Attackers using stolen admin credentials typically operate at off-hours to avoid detection and minimize interference with active users. A sudden shift in the time distribution of SWA credential accesses is a strong indicator of account compromise. Complementary Detection: Use alongside Okta.SWA.BulkAccess.Behavioral which detects the same attack vector based on volume rather than temporal patterns.T1078, T1555
  • Query.Okta.SWABulkAccessBehavioral source: Detects Okta SWA bulk credential extraction, abuse, and access from new network sources using behavioral z-score analysis. Reads pre-computed 90-day baselines from the okta_baseline_90d lookup table, then compares recent (last 7 days) admin SWA access and credential extraction patterns against those baselines. DETECTION LOGIC: - Z-score: SWA authentication volume spike (> 3σ above baseline) - Z-score: Unique SWA app diversity spike (accessing many different apps in an hour) (> 3σ) - Z-score: Credential extraction volume spike (> 3σ) - Z-score: Victim diversity spike (targeting many different users) (> 2σ) - Cold-start: First-time bulk SWA access (>= 10 events, no baseline) - Cold-start: First-time credential extraction (>= 5 events, no baseline) - New source: SWA access from IP address not seen in 90-day baseline (requires baseline or >= 3 recent events) - New source: SWA access from user agent not seen in 90-day baseline - Critical compound: New IP + any credential extraction events PREREQUISITE: okta_baseline_90d lookup table must be populated.

References #

application.user_membership.deprovision

#

Description

User deprovisioned from application (was previously revoked).

References #

application.user_membership.provision

#

Description

User provisioned to application (was previously approved).

References #

application.user_membership.remove

#

Description

Remove user's application membership.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000015",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Remove user's application membership",
  "eventType": "application.user_membership.remove",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:51.603Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "appname": "bookmark",
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/apps/0oa00000000000000004/users/00u00000000000000006",
      "url": "/api/v1/apps/0oa00000000000000004/users/00u00000000000000006?"
    }
  },
  "legacyEventType": "app.generic.provision.deactivate_user_from_app",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "AppUser",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    },
    {
      "id": "00000000000000000000",
      "type": "AppInstance",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    },
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

application.user_membership.restore

#

Description

Restore user assignment to an application.

References #

application.user_membership.restore_password

#

Description

Restore user's password for an application.

References #

application.user_membership.revoke

#

Description

User revoked from application (unassigned but not yet deprovisioned).

References #

application.user_membership.show_password

#

Description

Show user's password for application.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

application.user_membership.update

#

Description

Updated user application property.

Example System Log Event #

{
  "published": 1785236603510,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000064",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000237",
      "type": "AppUser",
      "alternateId": "user54@dw-harness.example",
      "displayName": "DW Harness 76",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000238",
      "type": "AppInstance",
      "alternateId": "user55@dw-harness.example",
      "displayName": "DW Harness 77",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000239",
      "type": "User",
      "alternateId": "user54@dw-harness.example",
      "displayName": "DW Harness 76",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "application.user_membership.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "psj00000000000000240",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000016"
    }
  },
  "debugContext": {
    "debugData": {
      "changedAttributes": "givenName,familyName"
    }
  },
  "displayMessage": "Updated user application property",
  "gatewayContext": null,
  "legacyEventType": "app.generic.config.app_user_property_update",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000241",
    "externalSessionId": "trs00000000000000242"
  }
}

References #

application.provision.user.delete

#

Description

Delete app user from application. Can be used to audit when a user was deleted from a downstream SCIM application during granular deprovisioning. Fires for both immediate and delayed execution. Gated by kill switch. Nothing runs after delete.

References #

application.provision.user.delete.schedule

#

Description

Schedule deletion of app user from application. Can be used to audit when a delayed user deletion job was scheduled for future execution during granular deprovisioning. Fires only for delayed configurations. Immediate actions do not produce a schedule event. Gated by kill switch.

References #

application.provision.user.remove_entitlements

#

Description

Remove entitlements from app user. Can be used to audit when managed entitlements (groups and roles) were removed from a user in a downstream SCIM application during granular deprovisioning. Fires for both immediate and delayed execution. Only managed groups (pushed/assigned via Okta) are removed.

References #

application.provision.user.remove_entitlements.schedule

#

Description

Schedule removal of entitlements from app user. Can be used to audit when a delayed entitlement removal job was scheduled for future execution during granular deprovisioning. Fires only for delayed configurations. Immediate actions do not produce a schedule event.

References #