Okta Directory

eventTypeDescriptionSampleRule
directory.app_user_profile.bootstrapBootstrap application user profile.YN
directory.app_user_profile.updateUpdate application user profile.YN
directory.external.group.membership.addExternal API call to add user group membership in a directory.NN
directory.external.group.membership.removeExternal API call to remove user group membership in a directory.NN
directory.linked_object.createAn admin can create a linked object that is related to user profiles.NN
directory.linked_object.deleteAn admin can delete a linked object that is related to user profiles.NN
directory.mapping.updateUpdate universal directory mappings.YN
directory.non_default_user_profile.createCreate non-default universal directory user profile.NN
directory.user_profile.bootstrapBootstrap universal directory user profile.NN
directory.user_profile.updateUpdate universal directory user profile directory.user_profile.update.YN

directory.app_user_profile.bootstrap

#

Description

Bootstrap application user profile.

Example System Log Event #

{
  "actor": {
    "id": "spr00000000000000006",
    "type": "SystemPrincipal",
    "alternateId": "system@okta.com",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000002",
    "externalSessionId": "trs00000000000000007"
  },
  "displayMessage": "Bootstrap application user profile",
  "eventType": "directory.app_user_profile.bootstrap",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:38:20.389Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "cvd.appuser_profile_bootstrapped",
  "transaction": {
    "type": null,
    "id": "0000002",
    "detail": {
      "rootApiTokenId": "00T00000000000000003"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000004",
  "version": "0",
  "request": {
    "ipChain": []
  },
  "target": [
    {
      "id": "oty00000000000000008",
      "type": "Schema",
      "alternateId": "user05@dw-harness.example",
      "displayName": "DW Harness 05",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000004",
      "type": "AppInstance",
      "alternateId": "user03@dw-harness.example",
      "displayName": "DW Harness 03",
      "detailEntry": {
        "appEventIsPersonal": "false"
      }
    }
  ]
}

References #

directory.app_user_profile.update

#

Description

Update application user profile.

Example System Log Event #

{
  "published": 1781015263189,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000068",
  "actor": {
    "id": "00u00000000000000246",
    "type": "User",
    "alternateId": "user56@dw-harness.example",
    "displayName": "DW Harness 79",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.17",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "oty00000000000000247",
      "type": "Schema",
      "alternateId": "user57@dw-harness.example",
      "displayName": "DW Harness 80",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": {
        "appEventIsPersonal": "false"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.17",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com",
          "ipServiceCategories": [
            {
              "operator": "GLOBAL_PROTECT_CLOUD_VPN",
              "type": "VPN",
              "isAnonymous": false
            }
          ]
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "directory.app_user_profile.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000035",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "attributesModified": "",
      "tunnels": [
        {
          "anonymous": false,
          "operator": "GLOBAL_PROTECT_CLOUD_VPN",
          "type": "VPN"
        }
      ],
      "attributesAdded": "emailAddressDataHomeEmailAddress",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000035",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000024",
      "origin": "https://app.example.com",
      "attributesDeleted": "",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "0000000000000000000000000000000000000000000000000000000000000000000000002",
      "url": "0000000000000000000000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "Update application Example App 61 profile",
  "gatewayContext": null,
  "legacyEventType": "cvd.appuser_profile_updated",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com",
      "ipServiceCategories": [
        {
          "operator": "GLOBAL_PROTECT_CLOUD_VPN",
          "type": "VPN",
          "isAnonymous": false
        }
      ]
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000248",
    "externalSessionId": "10200000000000000248"
  }
}

References #

directory.external.group.membership.add

#

Description

External API call to add user group membership in a directory. This event audits the directory integration API when it adds a user to a group in a directory. Note that the event is fired even when the API call is unsuccessful.

References #

directory.external.group.membership.remove

#

Description

External API call to remove user group membership in a directory. This event audits the directory integration API when it removes a user from a group in a directory. Note that the event is fired even when the API call is unsuccessful.

References #

directory.linked_object.create

#

Description

An admin can create a linked object that is related to user profiles. This event may be used to identify when a linked object is created, and who created the linked object. This may be useful for admins to validate why a change in the user profile has happened. While linked object creation does not trigger or happen as a result of another event, it is overall related to custom property update, creation and deletion. This event only indicates the creation of a linked object. See directory.linked_object.delete for deletion of linked objects.

References #

directory.linked_object.delete

#

Description

An admin can delete a linked object that is related to user profiles. This event may be used to identify when a linked object is deleted, and who deleted the linked object. This may be useful for admins to validate why a change in the user profile has happened. While linked object creation does not trigger or happen as a result of another event, it is overall related to custom property update, creation and deletion. This event only indicates the deletion of a linked object. See directory.linked_object.create for creation of linked objects.

References #

directory.mapping.update

#

Description

Update universal directory mappings.

Example System Log Event #

{
  "published": 1785252069310,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000069",
  "actor": {
    "id": "spr00000000000000171",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "prm00000000000000249",
      "type": "ProfileMapping",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 81",
      "detailEntry": {
        "targetProfile": "oty00000000000000250",
        "direction": "App to Okta",
        "sourceProfile": "oty00000000000000251"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "directory.mapping.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": null,
    "id": "0000003",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000018",
      "requestApiTokenId": "0000000000000000000000000000000000000000000018",
      "requestApiTokenClientId": "0oa00000000000000252"
    }
  },
  "debugContext": {
    "debugData": {
      "attributesModified": "",
      "attributesAdded": "",
      "attributesDeleted": ""
    }
  },
  "displayMessage": "Update universal directory mappings",
  "gatewayContext": null,
  "legacyEventType": "cvd.mappings_updated",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000253",
    "externalSessionId": "trs00000000000000254"
  }
}

References #

directory.non_default_user_profile.create

#

Description

Create non-default universal directory user profile. This can be used to audit that a new non-default universal directory user profile has been created. When fired, this event contains the name and id of the newly created user profile.

References #

directory.user_profile.bootstrap

#

Description

Bootstrap universal directory user profile.

References #

directory.user_profile.update

#

Description

Update universal directory user profile directory.user_profile.update.

Example System Log Event #

{
  "published": 1783523735049,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000070",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
      "os": "Windows 10",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.22",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "oty00000000000000255",
      "type": "Schema",
      "alternateId": "user58@dw-harness.example",
      "displayName": "DW Harness 82",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.22",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "directory.user_profile.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000036",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "attributesModified": "",
      "attributesAdded": "Is_Manager",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000036",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
      "origin": "https://app.example.com",
      "attributesDeleted": "",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000011",
      "url": "00000000000000000000000000000000000000011?"
    }
  },
  "displayMessage": "Update universal directory Example App 61 profile directory.Example App 61_profile.update",
  "gatewayContext": null,
  "legacyEventType": "cvd.user_profile_updated",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000256",
    "externalSessionId": "10200000000000000256"
  }
}

References #