Okta Application
| eventType | Description | Sample | Rule |
|---|---|---|---|
| application. | Confirm unmanaged app account and reconcile to an Okta user. | N | N |
| application. | Ignore unmanaged app account during reconciliation. | N | N |
| application. | Revoke unmanaged app account access and deprovision the user. | N | N |
| application. | Detect unmanaged app account during reconciliation. | N | N |
| application. | Update match between an unmanaged app account and an Okta user. | N | N |
| application. | Remove unmanaged app account detection after the source account was deleted. | N | N |
| application. | App user property mapping has invalid expressions. | N | N |
| application. | Event fired when a app list cache is invalidated because a new app is created. | Y | N |
| application. | Application configuration error detected. | N | N |
| application. | Disable delegated authentication for app. | N | N |
| application. | Disable Federation Broker Mode for app. | N | N |
| application. | Enable delegated authentication for app. | N | N |
| application. | Enable Federation Broker Mode for app. | N | N |
| application. | Okta couldn't download application configuration. | N | N |
| application. | A client secret in an MFA-only app has been read. | N | N |
| application. | Reset app logo. | N | N |
| application. | Okta couldn't verify api credentials. | Y | N |
| application. | Update API credentials due to user updating password. | N | N |
| application. | Change app logo. | N | N |
| application. | Update rate limits for an OAuth App. | N | N |
| application. | Unable to query remote API. | N | N |
| application. | Error authenticating. | Y | N |
| application. | Generic error occured. | N | N |
| application. | API rate limit exceeded. | N | Y |
| application. | Unable to transfer files. | N | N |
| application. | Activate application. | Y | Y |
| application. | Create application. | Y | Y |
| application. | Deactivate application. | Y | Y |
| application. | Delete application. | Y | Y |
| application. | Update application. | Y | Y |
| application. | Deny user access due to app sign on policy. | Y | N |
| application. | Create rule for app sign on policy. | N | N |
| application. | Delete rule from app sign on policy. | N | Y |
| application. | Update app sign on policy. | N | Y |
| application. | Event fired when field mapping rules modified. | N | N |
| application. | Fired when Okta provisions a new group on a remote application. | Y | N |
| application. | Fired when Okta downloads a remote group. | Y | N |
| application. | Fired when Okta removes a remote group. | N | N |
| application. | Fired when Okta updates the user group. | N | N |
| application. | Fired when group no longer exists on a remote application. | N | N |
| application. | Failed to assign a user to a group. | N | N |
| application. | Error while downloading memberships. | N | N |
| application. | Fired when there is an error while removing user(s) from group. | N | N |
| application. | Fired when there is an error while updating user group membership for group. | N | N |
| application. | Group push activated mappings. | Y | N |
| application. | Group push deactivated mappings. | Y | N |
| application. | Group push deleted application group. | Y | N |
| application. | An existing mapping and its target groups have been deleted because a mapping rule was deleted. | Y | N |
| application. | A mapped app group has been renamed because the source group was renamed. | Y | N |
| application. | A mapped app group couldn't be renamed when the source group was renamed. | Y | N |
| application. | A new mapping has been created. | Y | N |
| application. | A new mapping from a rule was not created due to a duplicate group name. | N | N |
| application. | A new mapping from a rule was not created due to another mapping will be created that has the same user group name. | N | N |
| application. | An upsert to a group caused group push rule re-evaluation. | Y | N |
| application. | An existing mapping has been deactivated because the source group was renamed. | N | N |
| application. | An existing mapping couldn't be deactivated when the source group was renamed. | N | N |
| application. | Group push mapping change failed and will be retried. | N | N |
| application. | Group push mapping change failed and cannot be retried. | Y | N |
| application. | Group push pushed memberships. | Y | N |
| application. | A group was pushed to an app. | Y | N |
| application. | A group was removed from an app. | Y | N |
| application. | A group was updated in an app. | Y | N |
| application. | Application integration API called. | N | N |
| application. | Activate user's application membership. | N | N |
| application. | Push user deactivation to external application. | Y | N |
| application. | Deprovision user from external application. | Y | N |
| application. | Deactivate user from external application. | N | N |
| application. | Import profile from external application. | Y | N |
| application. | Issue pushing user password to external application. | Y | N |
| application. | Push new user to external application. | Y | N |
| application. | Push user's Okta password to application. | N | N |
| application. | Push user's password to application. | Y | N |
| application. | Push user's profile to external application. | Y | N |
| application. | Push user reactivation in external application. | Y | N |
| application. | Sync user in external application. | Y | N |
| application. | Verify user exists in external application. | Y | N |
| application. | Create registration policy. | N | N |
| application. | Update registration policy. | N | N |
| application. | Add user to application membership. | Y | N |
| application. | User approved for application (assigned by not provisioned). | N | N |
| application. | Change application password for user. | N | N |
| application. | Change user's application username. | N | Y |
| application. | User deprovisioned from application (was previously revoked). | N | N |
| application. | User provisioned to application (was previously approved). | N | N |
| application. | Remove user's application membership. | Y | N |
| application. | Restore user assignment to an application. | N | N |
| application. | Restore user's password for an application. | N | N |
| application. | User revoked from application (unassigned but not yet deprovisioned). | N | N |
| application. | Show user's password for application. | N | Y |
| application. | Updated user application property. | Y | N |
| application. | Delete app user from application. | N | N |
| application. | Schedule deletion of app user from application. | N | N |
| application. | Remove entitlements from app user. | N | N |
| application. | Schedule removal of entitlements from app user. | N | N |
application.account.decision.confirm
#Description
Confirm unmanaged app account and reconcile to an Okta user. Track when an imported app account is accepted - either automatically or by an admin - and linked to an Okta user.
References #
application.account.decision.ignore
#Description
Ignore unmanaged app account during reconciliation. Audit ignore decisions for access reviews and detect accounts that are repeatedly ignored without follow-up remediation.
References #
application.account.decision.revoke
#Description
Revoke unmanaged app account access and deprovision the user. Track when an admin rejects an imported app account and the corresponding app user is deprovisioned.
References #
application.account.detect
#Description
Detect unmanaged app account during reconciliation. Track newly discovered app accounts that need to be reconciled with Okta users.
References #
application.account.match.update
#Description
Update match between an unmanaged app account and an Okta user. Audit administrator overrides of the auto-detected match between an imported app account and an Okta user.
References #
application.account.remove
#Description
Remove unmanaged app account detection after the source account was deleted. Track when an import removes a previously detected app account because the upstream account no longer exists.
References #
application.appuser.mapping.invalid.expression
#Description
App user property mapping has invalid expressions. Can be used to identify invalid expressions. Note that a single event is fired for all invalid expressions.
References #
application.cache.invalidate
#Description
Event fired when a app list cache is invalidated because a new app is created. Can be used to make sure App List cache is invalidated after a new app is created.
Example System Log Event #
{
"published": 1785252675528,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000033",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": {
"rawUserAgent": "local-v2-sdk/0.0.0 golang/go1.26.2 linux/arm64 okta-terraform/6.13.0",
"os": "Linux",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "00000000-0000-0000-0000-000000000034",
"type": "APP",
"alternateId": "user37@dw-harness.example",
"displayName": "DW Harness 52",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": "Application updated"
},
"request": {
"ipChain": [
{
"ip": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "application.cache.invalidate",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000022",
"detail": {
"rootApiTokenId": "00t00000000000000150",
"requestApiTokenId": "00t00000000000000150"
}
},
"debugContext": {
"debugData": {
"requestId": "00000000000000000000000000000022",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000018",
"invalidatedAppId": "00000000-0000-0000-0000-000000000034",
"requestUri": "uv700000000000000151",
"url": "uv700000000000000151?"
}
},
"displayMessage": "Application updated",
"gatewayContext": null,
"legacyEventType": "invalidate_app_list.app.updated",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000152",
"externalSessionId": "trs00000000000000152"
}
}
References #
application.configuration.detect_error
#Description
Application configuration error detected.
References #
application.configuration.disable_delauth_outbound
#Description
Disable delegated authentication for app.
References #
application.configuration.disable_fed_broker_mode
#Description
Disable Federation Broker Mode for app.
References #
application.configuration.enable_delauth_outbound
#Description
Enable delegated authentication for app.
References #
application.configuration.enable_fed_broker_mode
#Description
Enable Federation Broker Mode for app.
References #
application.configuration.import_schema
#Description
Okta couldn't download application configuration. Can be used to identify when an app schema couldn't be downloaded from a remote application. Event fired when Okta couldn't download application-specific data from a remote app. This may happen when admin updates provisioning details.
References #
application.configuration.read_client_secret
#Description
A client secret in an MFA-only app has been read. Verify that a client secret in an MFA-only app has been read. This events indicates that a client secret in an MFA-only app has been read.
References #
application.configuration.update
#Description
Okta couldn't verify api credentials. Can be used when Okta couldn't check the credentials by execution some custom, application dependent, set of requests. Okta fires this event to notify issues with credentials validation. Could be issues with proper permissions as well.
Example System Log Event #
{
"published": 1780925968259,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000035",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:151.0) Gecko/20100101 Firefox/151.0",
"os": "Windows 10",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.20",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "FAILURE",
"reason": "Client received SOAP Fault from server: invalid username or password Please see the server log to find more detail regarding exact cause of the failure."
},
"request": {
"ipChain": [
{
"ip": "192.0.2.20",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "application.configuration.update",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000023",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000023",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "0000000000000000000000000000000000000000000000000000000000000000000000000002",
"url": "0000000000000000000000000000000000000000000000000000000000000000000000000002?"
}
},
"displayMessage": "Application Configuration Updated",
"gatewayContext": null,
"legacyEventType": "app.workday.api.error.validate",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New ASN",
"id": "bhv00000000000000155",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000156",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000157",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000158",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000159",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000160",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000161",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000162",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"externalSessionId": null
}
}
References #
application.configuration.update_api_credentials_for_pass_change
#Description
Update API credentials due to user updating password.
References #
application.configuration.update_rate_limits
#Description
Update rate limits for an OAuth App. This can be used to track the updates to rate limits for an OAuth application. When fired, this event contains details about the actor, who triggered the event, the OAuth app, for which the rate limit was updated, etc. Actual value change details can be found in debug data such as the old and new values.
References #
application.integration.api_query
#Description
Unable to query remote API. Can be used to determine when okta fails to query remote application. Okta fires this event for unspecified events which include remote api response processing.
References #
application.integration.authentication_failure
#Description
Error authenticating. Can be used when Okta couldn't authenticate with the provided credentials to a remote api. Okta fires this event when it couldn't access a remote api with provided credentials.
Example System Log Event #
{
"published": 1784836312457,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000036",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000163",
"type": "AppInstance",
"alternateId": "user39@dw-harness.example",
"displayName": "DW Harness 56",
"detailEntry": null
}
],
"outcome": {
"result": "FAILURE",
"reason": "Unauthorized. Errors reported by remote server: "
},
"request": {
"ipChain": [
{
"ip": "192.0.2.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "application.integration.authentication_failure",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000024",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000024",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000012",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000003",
"url": "00000000000000000000000000000000000000000000000000003?"
}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": "app.api.error.auth",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "BAD_REQUEST"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"externalSessionId": null
}
}
References #
application.integration.general_failure
#Description
Generic error occured. Can be used when there is some uncategorized error occurs. Okta fires this event for different unhandled exceptions.
References #
application.integration.rate_limit_exceeded
#Description
API rate limit exceeded. Can be used when Okta reaches api calls/minute rate limit. Okta fires this event when there are too many requests for a specific customer.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
References #
application.integration.transfer_files
#Description
Unable to transfer files. Can be used when Okta fails to transfer files from one user to another. Okta fires this event when it fails to process user-to-user file transfers.
References #
application.lifecycle.activate
#Description
Activate application.
Example System Log Event #
{
"published": 1784812089700,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000037",
"actor": {
"id": "00u00000000000000164",
"type": "User",
"alternateId": "user03@dw-harness.example",
"displayName": "DW Harness 04",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.3",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000165",
"type": "AppInstance",
"alternateId": "user40@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.3",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "application.lifecycle.activate",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000025",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000025",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000020",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "0000000000000000000000000000000000000000000000000000002",
"url": "0000000000000000000000000000000000000000000000000000002?"
}
},
"displayMessage": "Activate application",
"gatewayContext": null,
"legacyEventType": "app.generic.config.app_activated",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "BAD_REQUEST"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000166",
"externalSessionId": "10200000000000000166"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1078.004, T1556↳ also matches application.lifecycle.create, application.lifecycle.update
References #
application.lifecycle.create
#Description
Create application.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000003",
"externalSessionId": "trs00000000000000003"
},
"displayMessage": "Create application",
"eventType": "application.lifecycle.create",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:35:50.239Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"appVersion": "00000000-0000-0000-0000-000000000007",
"requestId": "00000000000000000000000000000002",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/apps",
"url": "/api/v1/apps?"
}
},
"gatewayContext": null,
"legacyEventType": "app.app_editor.app.create",
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000002",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000008",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000005",
"type": "AppInstance",
"alternateId": "user03@dw-harness.example",
"displayName": "DW Harness 03",
"detailEntry": null
},
{
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1078.004, T1556↳ also matches application.lifecycle.activate, application.lifecycle.update
References #
application.lifecycle.deactivate
#Description
Deactivate application.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000011",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Deactivate application",
"eventType": "application.lifecycle.deactivate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:35:52.119Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/apps/0oa00000000000000004/lifecycle/deactivate",
"url": "/api/v1/apps/0oa00000000000000004/lifecycle/deactivate?"
}
},
"legacyEventType": "app.generic.config.app_deactivated",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "AppInstance",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1489
References #
application.lifecycle.delete
#Description
Delete application.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000012",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Delete application",
"eventType": "application.lifecycle.delete",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:35:52.269Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/apps/0oa00000000000000004",
"url": "/api/v1/apps/0oa00000000000000004?"
}
},
"legacyEventType": "app.generic.config.app_deleted",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "AppInstance",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
eventType (sigma rule field) | eq | application.lifecycle.update | 1 rule | sigma |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1489
References #
application.lifecycle.update
#Description
Update application.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000013",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Update application",
"eventType": "application.lifecycle.update",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:35:50.774Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/apps",
"url": "/api/v1/apps?"
}
},
"legacyEventType": "app.generic.config.app_updated",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "AppInstance",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
eventType | eq | application.lifecycle.update | 2 rules | panther, sigma |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
Panther #
T1556T1078.004, T1556↳ also matches application.lifecycle.activate, application.lifecycle.create
References #
application.policy.sign_on.deny_access
#Description
Deny user access due to app sign on policy. When fired due to app assurance being evaluated as unsatisfiable (the policy requirements could not be satisfied by the users' current set of available authenticator enrollments), this event contains information about the user and the app that the user is trying to authenticate into.
Example System Log Event #
{
"published": 1782502291551,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000038",
"actor": {
"id": "spr00000000000000167",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
"os": "Mac OS 15.6.1 (Sequoia)",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.19",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": {
"id": null,
"name": null,
"os_platform": null,
"os_version": null,
"managed": null,
"registered": null,
"device_integrator": {
"DEVICE_IDP": {}
},
"disk_encryption_type": null,
"screen_lock_type": null,
"jailbreak": null,
"secure_hardware_present": null
},
"events": null,
"target": [
{
"id": "00000000-0000-0000-0000-000000000039",
"type": "APP",
"alternateId": "user42@dw-harness.example",
"displayName": "DW Harness 22",
"detailEntry": null
},
{
"id": "00u00000000000000118",
"type": "User",
"alternateId": "user30@dw-harness.example",
"displayName": "DW Harness 45",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
{
"id": "0oa00000000000000168",
"type": "AppInstance",
"alternateId": "user43@dw-harness.example",
"displayName": "DW Harness 22",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": "The policy requirements could not be satisfied by the users’ current set of available authenticator enrollments"
},
"request": {
"ipChain": [
{
"ip": "192.0.2.19",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "application.policy.sign_on.deny_access",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000026",
"detail": {}
},
"debugContext": {
"debugData": {
"authnRequestId": "00000000000000000000000000000027",
"deviceFingerprint": "00000000000000000000000000000028",
"behaviors": "{New Geo-Location=UNKNOWN, New Device=UNKNOWN, New ASN=UNKNOWN, New IP=UNKNOWN, New State=UNKNOWN, New Country=UNKNOWN, Velocity=UNKNOWN, New City=UNKNOWN}",
"requestId": "00000000000000000000000000000026",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000021",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Device, Anomalous Location, level=HIGH}",
"requestUri": "/idp/idx/identify",
"threatSuspected": "false",
"url": "/idp/idx/identify?"
}
},
"displayMessage": "Access has been denied because the policy requirements could not be satisfied by the users’ current set of available authenticator enrollments",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "HIGH",
"reasons": [
"Anomalous Device",
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New ASN",
"id": "bhv00000000000000155",
"result": "UNKNOWN"
},
{
"name": "New IP",
"id": "bhv00000000000000156",
"result": "UNKNOWN"
},
{
"name": "New State",
"id": "bhv00000000000000157",
"result": "UNKNOWN"
},
{
"name": "New Country",
"id": "bhv00000000000000158",
"result": "UNKNOWN"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000159",
"result": "UNKNOWN"
},
{
"name": "New Device",
"id": "bhv00000000000000160",
"result": "UNKNOWN"
},
{
"name": "Velocity",
"id": "bhv00000000000000161",
"result": "UNKNOWN"
},
{
"name": "New City",
"id": "bhv00000000000000162",
"result": "UNKNOWN"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "idx00000000000000169",
"externalSessionId": "idx00000000000000169"
}
}
References #
application.policy.sign_on.rule.delete
#Description
Delete rule from app sign on policy.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
okta::eventType (kusto rule field) | eq | user.session.start | 1 rule | kusto |
okta::eventType (kusto rule field) | in | user.mfa.factor.deactivate | 1 rule | kusto |
okta::eventType (kusto rule field) | in | user.mfa.factor.reset_all | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1556, T1556.009↳ also matches application.policy.sign_on.update Kusto #
T1078, T1098, T1556↳ also matches application.policy.sign_on.update
References #
application.policy.sign_on.update
#Description
Update app sign on policy.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
okta::eventType (kusto rule field) | eq | user.session.start | 1 rule | kusto |
okta::eventType (kusto rule field) | in | user.mfa.factor.deactivate | 1 rule | kusto |
okta::eventType (kusto rule field) | in | user.mfa.factor.reset_all | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1556, T1556.009↳ also matches application.policy.sign_on.rule.delete Kusto #
T1078, T1098, T1556↳ also matches application.policy.sign_on.rule.delete
References #
application.provision.field_mapping_rule.change
#Description
Event fired when field mapping rules modified. Can be used to make sure when custom mapping rules are modified.
References #
application.provision.group.add
#Description
Fired when Okta provisions a new group on a remote application. Can be used to identify when Okta provisions a group on a remote application. Event fired when the group provisioning failed for any reason.
Example System Log Event #
{
"published": 1785254306307,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000040",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000140",
"type": "AppInstance",
"alternateId": "user34@dw-harness.example",
"displayName": "DW Harness 52",
"detailEntry": null
}
],
"outcome": {
"result": "FAILURE",
"reason": "Not Found. Errors reported by remote server: "
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group.add",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gmr00000000000000170",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": "app.api.error.upsert_group",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"externalSessionId": null
}
}
References #
application.provision.group.import
#Description
Fired when Okta downloads a remote group. Can be used to identify when Okta tries to download remote group details. Event fired when Okta fails to reach the group detail from a remote application.
Example System Log Event #
{
"published": 1784746553047,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000041",
"actor": {
"id": "spr00000000000000171",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000163",
"type": "AppInstance",
"alternateId": "user39@dw-harness.example",
"displayName": "DW Harness 56",
"detailEntry": null
}
],
"outcome": {
"result": "FAILURE",
"reason": "Unauthorized. Errors reported by remote server: "
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group.import",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gmr00000000000000172",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000010"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": "app.api.error.get_group_by_id",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"externalSessionId": null
}
}
References #
application.provision.group.remove
#Description
Fired when Okta removes a remote group. Can be used to identify when a group has been unassigned. Event fired when Okta failed to delete group from remote application.
References #
application.provision.group.update
#Description
Fired when Okta updates the user group. Can be used to identify when a group has been updated. Event fired when Okta fails to update a remote group for any reason.
References #
application.provision.group.verify_exists
#Description
Fired when group no longer exists on a remote application. Can be used to identify when a group no longer exists on a remote application. Event fired when group push enhancement enabled and there is no group found on update or delete.
References #
application.provision.group_membership.add
#Description
Failed to assign a user to a group. Can be used when Okta failed to assign user to a group on remote application. Okta fires this event if there are any issues while provision a membership to a remote application.
References #
application.provision.group_membership.import
#Description
Error while downloading memberships. Can be used when Okta failed to download users and groups relationships. Okta fires this event if there are any issues while importing a membership from a remote application.
References #
application.provision.group_membership.remove
#Description
Fired when there is an error while removing user(s) from group. Can be used when Okta failed to unassign user from a group on remote application. Okta fires this event when there are any issues while provision a membership to a remote application.
References #
application.provision.group_membership.update
#Description
Fired when there is an error while updating user group membership for group. Can be used when Okta failed to push updated memberships to a remote application. Okta fires this event when couldn't update memberships on a remote application. Could be user removal/addition.
References #
application.provision.group_push.activate_mapping
#Description
Group push activated mappings.
Example System Log Event #
{
"published": 1785254305707,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000042",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "gpm00000000000000173",
"type": "GroupPushMapping",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 57",
"detailEntry": null
},
{
"id": "0oa00000000000000140",
"type": "AppInstance",
"alternateId": "user34@dw-harness.example",
"displayName": "DW Harness 52",
"detailEntry": null
},
{
"id": "00g00000000000000174",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 58",
"detailEntry": null
},
{
"id": "agr00000000000000175",
"type": "AppGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 58",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.activate_mapping",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "bae00000000000000176",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Group Push - activating mapping (Mapping: gpm00000000000000173)",
"gatewayContext": null,
"legacyEventType": "platform.group_push.activate_mapping",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000177",
"externalSessionId": "trs00000000000000178"
}
}
References #
application.provision.group_push.deactivate_mapping
#Description
Group push deactivated mappings. Can be used to audit when a group push mapping is deactivated or to trigger downstream automation. The corresponding event type for activating a group push mapping is application.provision.group_push.activate_mapping.
Example System Log Event #
{
"published": 1780156937152,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000043",
"actor": {
"id": "00u00000000000000179",
"type": "User",
"alternateId": "user44@dw-harness.example",
"displayName": "DW Harness 59",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.21",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "gpm00000000000000180",
"type": "GroupPushMapping",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 57",
"detailEntry": null
},
{
"id": "0oa00000000000000165",
"type": "AppInstance",
"alternateId": "user40@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
},
{
"id": "00g00000000000000181",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 60",
"detailEntry": null
},
{
"id": "agr00000000000000182",
"type": "AppGroup",
"alternateId": "user45@dw-harness.example",
"displayName": "DW Harness 60",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.21",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.deactivate_mapping",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000029",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000029",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000022",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000003",
"url": "00000000000000000000000000000000000000000000000000000000000000000000000003?"
}
},
"displayMessage": "Group Push - deactivating mapping (Mapping: gpm00000000000000180)",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "BAD_REQUEST"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000183",
"externalSessionId": "10200000000000000183"
}
}
References #
application.provision.group_push.delete_appgroup
#Description
Group push deleted application group.
Example System Log Event #
{
"published": 1785257219838,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000044",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "gpm00000000000000173",
"type": "GroupPushMapping",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 57",
"detailEntry": null
},
{
"id": "0oa00000000000000140",
"type": "AppInstance",
"alternateId": "user34@dw-harness.example",
"displayName": "DW Harness 52",
"detailEntry": null
},
{
"id": "agr00000000000000175",
"type": "AppGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 58",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.delete_appgroup",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "rdj00000000000000184",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Group Push - deleting AppGroup (Mapping: gpm00000000000000173)",
"gatewayContext": null,
"legacyEventType": "platform.group_push.delete_appgroup",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000142",
"externalSessionId": "trs00000000000000185"
}
}
References #
application.provision.group_push.mapping.and.groups.deleted.rule.deleted
#Description
An existing mapping and its target groups have been deleted because a mapping rule was deleted.
Example System Log Event #
{
"published": 1785257220094,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000045",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "gpm00000000000000186",
"type": "GroupPushMapping",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 57",
"detailEntry": null
},
{
"id": "00g00000000000000187",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 61",
"detailEntry": null
},
{
"id": "0oa00000000000000140",
"type": "AppInstance",
"alternateId": "user34@dw-harness.example",
"displayName": "DW Harness 52",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.mapping.and.groups.deleted.rule.deleted",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "rdj00000000000000184",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "The Group push mapping to the group Example Group 22 has been deleted.",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.mapping.and.groups.deleted.rule.deleted",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000142",
"externalSessionId": "trs00000000000000185"
}
}
References #
application.provision.group_push.mapping.app.group.renamed
#Description
A mapped app group has been renamed because the source group was renamed.
Example System Log Event #
{
"published": 1780596052484,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000002",
"actor": {
"id": "00u00000000000000164",
"type": "User",
"alternateId": "user03@dw-harness.example",
"displayName": "DW Harness 04",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "gpm00000000000000188",
"type": "GroupPushMapping",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 57",
"detailEntry": null
},
{
"id": "agr00000000000000189",
"type": "AppGroup",
"alternateId": "user46@dw-harness.example",
"displayName": "DW Harness 62",
"detailEntry": null
},
{
"id": "0oa00000000000000124",
"type": "AppInstance",
"alternateId": "user31@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.mapping.app.group.renamed",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "rgj00000000000000190",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "A Group push mapping to the group Example Group 2 was renamed because the source group was renamed.",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.mapping.app.group.renamed",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000191",
"externalSessionId": "trs00000000000000192"
}
}
References #
application.provision.group_push.mapping.app.group.renamed.failed
#Description
A mapped app group couldn't be renamed when the source group was renamed.
Example System Log Event #
{
"published": 1784835867655,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000046",
"actor": {
"id": "0oa00000000000000123",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 46",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "00000000000000000002",
"type": "GroupPushMapping",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 57",
"detailEntry": null
},
{
"id": "00g00000000000000193",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 63",
"detailEntry": null
},
{
"id": "0oa00000000000000163",
"type": "AppInstance",
"alternateId": "user39@dw-harness.example",
"displayName": "DW Harness 56",
"detailEntry": null
}
],
"outcome": {
"result": "FAILURE",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.mapping.app.group.renamed.failed",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "rgj00000000000000194",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000011"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "A Group push mapping to the group Example Group 11 could not be renamed when the source group was renamed",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.mapping.app.group.renamed.failed",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000195",
"externalSessionId": "trs00000000000000196"
}
}
References #
application.provision.group_push.mapping.created
#Description
A new mapping has been created.
Example System Log Event #
{
"published": 1783623908401,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000047",
"actor": {
"id": "0oa00000000000000123",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 46",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "gpm00000000000000128",
"type": "GroupPushMapping",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 57",
"detailEntry": null
},
{
"id": "00g00000000000000125",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 48",
"detailEntry": null
},
{
"id": "0oa00000000000000124",
"type": "AppInstance",
"alternateId": "user31@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.mapping.created",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "rej00000000000000126",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000008"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "A Group Push mapping to the group Example Group 5 has been created.",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.mapping.created",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000129",
"externalSessionId": "trs00000000000000130"
}
}
References #
application.provision.group_push.mapping.created.from.rule.warning.duplicate.name
#Description
A new mapping from a rule was not created due to a duplicate group name.
References #
application.provision.group_push.mapping.created.from.rule.warning.duplicate.name.tobecreated
#Description
A new mapping from a rule was not created due to another mapping will be created that has the same user group name.
References #
application.provision.group_push.mapping.created.from.rule.warning.upsertGroup.duplicate.name
#Description
An upsert to a group caused group push rule re-evaluation. A new mapping from a rule was not created due to a duplicate group name.
Example System Log Event #
{
"published": 1785241632629,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000048",
"actor": {
"id": "00u00000000000000131",
"type": "User",
"alternateId": "user32@dw-harness.example",
"displayName": "DW Harness 49",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "gpr00000000000000197",
"type": "GroupPushMappingRule",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 64",
"detailEntry": null
},
{
"id": "gpr00000000000000197",
"type": "GroupPushMappingFromRuleConfig",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 65",
"detailEntry": null
},
{
"id": "00g00000000000000198",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 66",
"detailEntry": null
},
{
"id": "0oa00000000000000140",
"type": "AppInstance",
"alternateId": "user34@dw-harness.example",
"displayName": "DW Harness 52",
"detailEntry": null
}
],
"outcome": {
"result": "FAILURE",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.mapping.created.from.rule.warning.upsertGroup.duplicate.name",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "rej00000000000000199",
"detail": {
"rootApiTokenId": "00t00000000000000134"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "UserGroup was created or updated. A Group Push mapping did not get created from rule gpr00000000000000197 to UserGroup Example Group 15 since group with same name already exists in AppInstance 0oa00000000000000200",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.mapping.created.from.rule.warning.upsertGroup.duplicate.name",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000201",
"externalSessionId": "trs00000000000000202"
}
}
References #
application.provision.group_push.mapping.deactivated.source.group.renamed
#Description
An existing mapping has been deactivated because the source group was renamed.
References #
application.provision.group_push.mapping.deactivated.source.group.renamed.failed
#Description
An existing mapping couldn't be deactivated when the source group was renamed.
References #
application.provision.group_push.mapping.update.or.delete.failed
#Description
Group push mapping change failed and will be retried. Can be used to identify transient errors that may temporarily impact the group push mapping but likely do not require admin intervention. This event typically requires no action as the corresponding operation will be retried. Refer to application.provision.group_push.mapping.update.or.delete.failed for events that may require intervention.
References #
application.provision.group_push.mapping.update.or.delete.failed.with.error
#Description
Group push mapping change failed and cannot be retried. Can be used to identify group push mapping errors which may require admin intervention to address. Unlike the similarly named event, application.provision.group_push.mapping.update.or.delete.failed, when this event is fired the corresponding action that triggered it will not be retried by Okta and may indicate a configuration problem. For example, invalid authorization credentials with the target application due to an expired password or invalid access token.
Example System Log Event #
{
"published": 1785254306309,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000049",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "gpm00000000000000203",
"type": "GroupPushMapping",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 57",
"detailEntry": null
},
{
"id": "00g00000000000000204",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 67",
"detailEntry": null
},
{
"id": "0oa00000000000000140",
"type": "AppInstance",
"alternateId": "user34@dw-harness.example",
"displayName": "DW Harness 52",
"detailEntry": null
}
],
"outcome": {
"result": "FAILURE",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.mapping.update.or.delete.failed.with.error",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gmr00000000000000170",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Changes to the Group push mapping for the group Example Group 17 could not take effect due to error: Error while creating user group Example Group 17: Not Found. Errors reported by remote server: ",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.mapping.update.or.delete.failed.with.error",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000177",
"externalSessionId": "trs00000000000000205"
}
}
References #
application.provision.group_push.push_memberships
#Description
Group push pushed memberships.
Example System Log Event #
{
"published": 1785238927668,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000050",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "okta-sdk-python/2.9.13 python/3.12.13 Linux/5.10.255-259-299.1043.amzn2.x86_64",
"os": "Linux",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.16",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "gpm00000000000000206",
"type": "GroupPushMapping",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 57",
"detailEntry": null
},
{
"id": "0oa00000000000000124",
"type": "AppInstance",
"alternateId": "user31@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
},
{
"id": "00g00000000000000207",
"type": "UserGroup",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 68",
"detailEntry": null
},
{
"id": "agr00000000000000208",
"type": "AppGroup",
"alternateId": "user47@dw-harness.example",
"displayName": "DW Harness 68",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.16",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.push_memberships",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000030",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000012",
"requestApiTokenId": "0000000000000000000000000000000000000000000012",
"requestApiTokenClientId": "0oa00000000000000112"
}
},
"debugContext": {
"debugData": {
"requestId": "00000000000000000000000000000030",
"requestUri": "00000000000000000000000000000000000000000000000000000000000002",
"url": "00000000000000000000000000000000000000000000000000000000000002?"
}
},
"displayMessage": "Group Push - pushing memberships (Mapping: gpm00000000000000206)",
"gatewayContext": null,
"legacyEventType": "platform.group_push.push_memberships",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000209",
"externalSessionId": "trs00000000000000209"
}
}
References #
application.provision.group_push.pushed
#Description
A group was pushed to an app.
Example System Log Event #
{
"published": 1785238928805,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000051",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "agr00000000000000208",
"type": "AppGroup",
"alternateId": "user47@dw-harness.example",
"displayName": "DW Harness 68",
"detailEntry": null
},
{
"id": "0oa00000000000000124",
"type": "AppInstance",
"alternateId": "user31@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.pushed",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gmr00000000000000210",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000012"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Group Push group Example Group 23 pushed to app.",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.pushed",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000209",
"externalSessionId": "trs00000000000000211"
}
}
References #
application.provision.group_push.removed
#Description
A group was removed from an app.
Example System Log Event #
{
"published": 1780422794719,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000052",
"actor": {
"id": "spr00000000000000171",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "agr00000000000000212",
"type": "AppGroup",
"alternateId": "user48@dw-harness.example",
"displayName": "DW Harness 69",
"detailEntry": null
},
{
"id": "0oa00000000000000078",
"type": "AppInstance",
"alternateId": "user49@dw-harness.example",
"displayName": "DW Harness 23",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.removed",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gmr00000000000000213",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000013"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Group Push group Example Group 27 removed from app.",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.removed",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000214",
"externalSessionId": "trs00000000000000215"
}
}
References #
application.provision.group_push.updated
#Description
A group was updated in an app.
Example System Log Event #
{
"published": 1785238929228,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000053",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "agr00000000000000208",
"type": "AppGroup",
"alternateId": "user47@dw-harness.example",
"displayName": "DW Harness 68",
"detailEntry": null
},
{
"id": "0oa00000000000000124",
"type": "AppInstance",
"alternateId": "user31@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.group_push.updated",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gmr00000000000000210",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000012"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Group Push group Example Group 23 updated in app.",
"gatewayContext": null,
"legacyEventType": "app.user_management.grouppush.updated",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000209",
"externalSessionId": "trs00000000000000211"
}
}
References #
application.provision.integration.call_api
#Description
Application integration API called.
References #
application.provision.user.deactivate
#Description
Push user deactivation to external application.
Example System Log Event #
{
"published": 1781348649384,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000054",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000216",
"type": "AppUser",
"alternateId": "user50@dw-harness.example",
"displayName": "DW Harness 70",
"detailEntry": null
},
{
"id": "00u00000000000000217",
"type": "User",
"alternateId": "user50@dw-harness.example",
"displayName": "DW Harness 70",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "0oa00000000000000144",
"type": "AppInstance",
"alternateId": "user35@dw-harness.example",
"displayName": "DW Harness 53",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.user.deactivate",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "duj00000000000000218",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000014"
}
},
"debugContext": {
"debugData": {
"appname": "Example App 11"
}
},
"displayMessage": "Push user deactivation to external application",
"gatewayContext": null,
"legacyEventType": "app.user_management.deactivate_user",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000219",
"externalSessionId": "trs00000000000000220"
}
}
References #
application.provision.user.deprovision
#Description
Deprovision user from external application.
Example System Log Event #
{
"published": 1781348650032,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000055",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0dt00000000000000221",
"type": "DeprovisionTask",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 71",
"detailEntry": {
"completedAt": "2026-06-13T11:04:09.000Z",
"initiatedAt": "2026-06-13T11:04:09.000Z",
"appUserId": "0ua00000000000000222",
"resolution": "Auto Deprovisioned",
"initiatedBy": "pca00000000000000223"
}
},
{
"id": "0ua00000000000000222",
"type": "AppUser",
"alternateId": "user51@dw-harness.example",
"displayName": "DW Harness 72",
"detailEntry": {
"appInstanceId": "0oa00000000000000144",
"appUsername": "user51@dw-harness.example",
"userId": "00u00000000000000224"
}
},
{
"id": "0oa00000000000000144",
"type": "AppInstance",
"alternateId": "user35@dw-harness.example",
"displayName": "DW Harness 53",
"detailEntry": null
},
{
"id": "00u00000000000000224",
"type": "User",
"alternateId": "user51@dw-harness.example",
"displayName": "DW Harness 73",
"detailEntry": {
"realmId": "guo00000000000000044"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.user.deprovision",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "duj00000000000000225",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000014"
}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Deprovision user from external application",
"gatewayContext": null,
"legacyEventType": "app.user_management.deprovision_task_complete",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000226",
"externalSessionId": "trs00000000000000227"
}
}
References #
application.provision.user.import_profile
#Description
Import profile from external application.
Example System Log Event #
{
"published": 1782502954246,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000056",
"actor": {
"id": "00u00000000000000117",
"type": "User",
"alternateId": "user29@dw-harness.example",
"displayName": "DW Harness 44",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Java/17.0.19",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "192.0.2.12",
"geographicalContext": {
"city": null,
"state": null,
"country": "Placeholderland",
"postalCode": null,
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
},
{
"id": "00000000000000000000000000000031",
"type": "APPUSER",
"alternateId": null,
"displayName": null,
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": "Realtime sync scheduled successfully"
},
"request": {
"ipChain": [
{
"ip": "192.0.2.12",
"geographicalContext": {
"city": null,
"state": null,
"country": "Placeholderland",
"postalCode": null,
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.user.import_profile",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000032",
"detail": {
"rootApiTokenId": "00t00000000000000120",
"requestApiTokenId": "00t00000000000000120"
}
},
"debugContext": {
"debugData": {
"requestId": "00000000000000000000000000000032",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000023",
"requestUri": "00000000000000000000000000000000000000000004",
"url": "00000000000000000000000000000000000000000004?"
}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": "app.generic.config.app_updated",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000121",
"externalSessionId": "trs00000000000000121"
}
}
References #
application.provision.user.password
#Description
Issue pushing user password to external application.
Example System Log Event #
{
"published": 1785256723810,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000057",
"actor": {
"id": "00u00000000000000139",
"type": "User",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000228",
"type": "AppInstance",
"alternateId": "user52@dw-harness.example",
"displayName": "DW Harness 74",
"detailEntry": null
},
{
"id": "00u00000000000000139",
"type": "User",
"alternateId": "user53@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": null
},
{
"id": "0ua00000000000000229",
"type": "AppUser",
"alternateId": "user53@dw-harness.example",
"displayName": "DW Harness 75",
"detailEntry": null
}
],
"outcome": {
"result": "FAILURE",
"reason": "Not Found. Errors reported by remote server: Invalid JSON: Unexpected character ('<' (code 60)): expected a valid value (JSON String, Number, Array, Object or token 'null', 'true' or 'false')\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.user.password",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "pwj00000000000000230",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": "app.api.error.push_password_update",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"externalSessionId": null
}
}
References #
application.provision.user.push
#Description
Push new user to external application.
Example System Log Event #
{
"published": 1785256677526,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000058",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000138",
"type": "AppUser",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": null
},
{
"id": "00u00000000000000139",
"type": "User",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "0oa00000000000000140",
"type": "AppInstance",
"alternateId": "user34@dw-harness.example",
"displayName": "DW Harness 52",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.user.push",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "puj00000000000000141",
"detail": {}
},
"debugContext": {
"debugData": {
"appname": "Example App 16"
}
},
"displayMessage": "Push new user to external application",
"gatewayContext": null,
"legacyEventType": "app.user_management.push_new_user",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000142",
"externalSessionId": "trs00000000000000143"
}
}
References #
application.provision.user.push_okta_password
#Description
Push user's Okta password to application.
References #
application.provision.user.push_password
#Description
Push user's password to application.
Example System Log Event #
{
"published": 1785256723789,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000059",
"actor": {
"id": "00u00000000000000139",
"type": "User",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000229",
"type": "AppUser",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": null
},
{
"id": "00u00000000000000139",
"type": "User",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "0oa00000000000000228",
"type": "AppInstance",
"alternateId": "user52@dw-harness.example",
"displayName": "DW Harness 74",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.user.push_password",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "pwj00000000000000230",
"detail": {}
},
"debugContext": {
"debugData": {
"appname": "Example App 19"
}
},
"displayMessage": "Push user's password to application",
"gatewayContext": null,
"legacyEventType": "app.user_management.push_unique_password_update",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "idx00000000000000231",
"externalSessionId": "trs00000000000000232"
}
}
References #
application.provision.user.push_profile
#Description
Push user's profile to external application.
Example System Log Event #
{
"published": 1785243553471,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000060",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000233",
"type": "AppUser",
"alternateId": "user51@dw-harness.example",
"displayName": "DW Harness 73",
"detailEntry": null
},
{
"id": "00u00000000000000224",
"type": "User",
"alternateId": "user51@dw-harness.example",
"displayName": "DW Harness 73",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "0oa00000000000000144",
"type": "AppInstance",
"alternateId": "user35@dw-harness.example",
"displayName": "DW Harness 53",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.user.push_profile",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "puj00000000000000234",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000015"
}
},
"debugContext": {
"debugData": {
"appname": "Example App 11"
}
},
"displayMessage": "Push user's profile to external application",
"gatewayContext": null,
"legacyEventType": "app.user_management.push_profile_success",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000235",
"externalSessionId": "trs00000000000000236"
}
}
References #
application.provision.user.reactivate
#Description
Push user reactivation in external application.
Example System Log Event #
{
"published": 1785243552966,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000061",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000233",
"type": "AppUser",
"alternateId": "user51@dw-harness.example",
"displayName": "DW Harness 73",
"detailEntry": null
},
{
"id": "00u00000000000000224",
"type": "User",
"alternateId": "user51@dw-harness.example",
"displayName": "DW Harness 73",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "0oa00000000000000144",
"type": "AppInstance",
"alternateId": "user35@dw-harness.example",
"displayName": "DW Harness 53",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.user.reactivate",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "puj00000000000000234",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000015"
}
},
"debugContext": {
"debugData": {
"appname": "Example App 11"
}
},
"displayMessage": "Push user reactivation in external application",
"gatewayContext": null,
"legacyEventType": "app.user_management.reactivate_user",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000235",
"externalSessionId": "trs00000000000000236"
}
}
References #
application.provision.user.sync
#Description
Sync user in external application.
Example System Log Event #
{
"published": 1785256678993,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000062",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000138",
"type": "AppUser",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": null
},
{
"id": "00u00000000000000139",
"type": "User",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "0oa00000000000000140",
"type": "AppInstance",
"alternateId": "user34@dw-harness.example",
"displayName": "DW Harness 52",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.provision.user.sync",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "puj00000000000000141",
"detail": {}
},
"debugContext": {
"debugData": {
"appname": "Example App 16"
}
},
"displayMessage": "Sync user in external application",
"gatewayContext": null,
"legacyEventType": "app.user_management.provision_user",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000142",
"externalSessionId": "trs00000000000000143"
}
}
References #
application.provision.user.verify_exists
#Description
Verify user exists in external application.
Example System Log Event #
{
"published": 1785243552963,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000063",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000233",
"type": "AppUser",
"alternateId": "user51@dw-harness.example",
"displayName": "DW Harness 73",
"detailEntry": null
},
{
"id": "00u00000000000000224",
"type": "User",
"alternateId": "user51@dw-harness.example",
"displayName": "DW Harness 73",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
{
"id": "0oa00000000000000144",
"type": "AppInstance",
"alternateId": "user35@dw-harness.example",
"displayName": "DW Harness 53",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "DEBUG",
"eventType": "application.provision.user.verify_exists",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "puj00000000000000234",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000015"
}
},
"debugContext": {
"debugData": {
"appname": "Example App 11"
}
},
"displayMessage": "Verify user exists in external application",
"gatewayContext": null,
"legacyEventType": "app.user_management.verified_user_with_thirdparty",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000235",
"externalSessionId": "trs00000000000000236"
}
}
References #
application.user_membership.add
#Description
Add user to application membership.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000014",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Add user to application membership",
"eventType": "application.user_membership.add",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:35:51.467Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"appname": "bookmark",
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/apps/0oa00000000000000004/users",
"url": "/api/v1/apps/0oa00000000000000004/users?"
}
},
"legacyEventType": "app.generic.provision.assign_user_to_app",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "AppUser",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
{
"id": "00000000000000000000",
"type": "AppInstance",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
{
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
References #
application.user_membership.approve
#Description
User approved for application (assigned by not provisioned).
References #
application.user_membership.change_password
#Description
Change application password for user.
References #
application.user_membership.change_username
#Description
Change user's application username.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
admin_email (panther rule field) | is_not_null | | 2 rules | panther |
is_anomalous (panther rule field) | eq | true | 2 rules | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
Okta.SWA.OffHoursAccess.Behavioral which detects the same attack vector occurring outside normal business hours.T1078, T1213, T1555Okta.SWA.BulkAccess.Behavioral which detects the same attack vector based on volume rather than temporal patterns.T1078, T1555
References #
application.user_membership.deprovision
#Description
User deprovisioned from application (was previously revoked).
References #
application.user_membership.provision
#Description
User provisioned to application (was previously approved).
References #
application.user_membership.remove
#Description
Remove user's application membership.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000015",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Remove user's application membership",
"eventType": "application.user_membership.remove",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:35:51.603Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"appname": "bookmark",
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/apps/0oa00000000000000004/users/00u00000000000000006",
"url": "/api/v1/apps/0oa00000000000000004/users/00u00000000000000006?"
}
},
"legacyEventType": "app.generic.provision.deactivate_user_from_app",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "AppUser",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
{
"id": "00000000000000000000",
"type": "AppInstance",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
{
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
References #
application.user_membership.restore
#Description
Restore user assignment to an application.
References #
application.user_membership.restore_password
#Description
Restore user's password for an application.
References #
application.user_membership.revoke
#Description
User revoked from application (unassigned but not yet deprovisioned).
References #
application.user_membership.show_password
#Description
Show user's password for application.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1552
References #
application.user_membership.update
#Description
Updated user application property.
Example System Log Event #
{
"published": 1785236603510,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000064",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000237",
"type": "AppUser",
"alternateId": "user54@dw-harness.example",
"displayName": "DW Harness 76",
"detailEntry": null
},
{
"id": "0oa00000000000000238",
"type": "AppInstance",
"alternateId": "user55@dw-harness.example",
"displayName": "DW Harness 77",
"detailEntry": null
},
{
"id": "00u00000000000000239",
"type": "User",
"alternateId": "user54@dw-harness.example",
"displayName": "DW Harness 76",
"detailEntry": {
"realmId": "guo00000000000000044"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "application.user_membership.update",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "psj00000000000000240",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000016"
}
},
"debugContext": {
"debugData": {
"changedAttributes": "givenName,familyName"
}
},
"displayMessage": "Updated user application property",
"gatewayContext": null,
"legacyEventType": "app.generic.config.app_user_property_update",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000241",
"externalSessionId": "trs00000000000000242"
}
}
References #
application.provision.user.delete
#Description
Delete app user from application. Can be used to audit when a user was deleted from a downstream SCIM application during granular deprovisioning. Fires for both immediate and delayed execution. Gated by kill switch. Nothing runs after delete.
References #
application.provision.user.delete.schedule
#Description
Schedule deletion of app user from application. Can be used to audit when a delayed user deletion job was scheduled for future execution during granular deprovisioning. Fires only for delayed configurations. Immediate actions do not produce a schedule event. Gated by kill switch.
References #
application.provision.user.remove_entitlements
#Description
Remove entitlements from app user. Can be used to audit when managed entitlements (groups and roles) were removed from a user in a downstream SCIM application during granular deprovisioning. Fires for both immediate and delayed execution. Only managed groups (pushed/assigned via Okta) are removed.
References #
application.provision.user.remove_entitlements.schedule
#Description
Schedule removal of entitlements from app user. Can be used to audit when a delayed entitlement removal job was scheduled for future execution during granular deprovisioning. Fires only for delayed configurations. Immediate actions do not produce a schedule event.