Okta Directory
| eventType | Description | Sample | Rule |
|---|---|---|---|
| directory. | Bootstrap application user profile. | Y | N |
| directory. | Update application user profile. | Y | N |
| directory. | External API call to add user group membership in a directory. | N | N |
| directory. | External API call to remove user group membership in a directory. | N | N |
| directory. | An admin can create a linked object that is related to user profiles. | N | N |
| directory. | An admin can delete a linked object that is related to user profiles. | N | N |
| directory. | Update universal directory mappings. | Y | N |
| directory. | Create non-default universal directory user profile. | N | N |
| directory. | Bootstrap universal directory user profile. | N | N |
| directory. | Update universal directory user profile directory.user_profile.update. | Y | N |
directory.app_user_profile.bootstrap
#Description
Bootstrap application user profile.
Example System Log Event #
{
"actor": {
"id": "spr00000000000000006",
"type": "SystemPrincipal",
"alternateId": "system@okta.com",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000002",
"externalSessionId": "trs00000000000000007"
},
"displayMessage": "Bootstrap application user profile",
"eventType": "directory.app_user_profile.bootstrap",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:38:20.389Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002"
}
},
"gatewayContext": null,
"legacyEventType": "cvd.appuser_profile_bootstrapped",
"transaction": {
"type": null,
"id": "0000002",
"detail": {
"rootApiTokenId": "00T00000000000000003"
}
},
"uuid": "00000000-0000-0000-0000-000000000004",
"version": "0",
"request": {
"ipChain": []
},
"target": [
{
"id": "oty00000000000000008",
"type": "Schema",
"alternateId": "user05@dw-harness.example",
"displayName": "DW Harness 05",
"detailEntry": null
},
{
"id": "0oa00000000000000004",
"type": "AppInstance",
"alternateId": "user03@dw-harness.example",
"displayName": "DW Harness 03",
"detailEntry": {
"appEventIsPersonal": "false"
}
}
]
}
References #
directory.app_user_profile.update
#Description
Update application user profile.
Example System Log Event #
{
"published": 1781015263189,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000068",
"actor": {
"id": "00u00000000000000246",
"type": "User",
"alternateId": "user56@dw-harness.example",
"displayName": "DW Harness 79",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.17",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "oty00000000000000247",
"type": "Schema",
"alternateId": "user57@dw-harness.example",
"displayName": "DW Harness 80",
"detailEntry": null
},
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": {
"appEventIsPersonal": "false"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.17",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"ipServiceCategories": [
{
"operator": "GLOBAL_PROTECT_CLOUD_VPN",
"type": "VPN",
"isAnonymous": false
}
]
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "directory.app_user_profile.update",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000035",
"detail": {}
},
"debugContext": {
"debugData": {
"attributesModified": "",
"tunnels": [
{
"anonymous": false,
"operator": "GLOBAL_PROTECT_CLOUD_VPN",
"type": "VPN"
}
],
"attributesAdded": "emailAddressDataHomeEmailAddress",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000035",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000024",
"origin": "https://app.example.com",
"attributesDeleted": "",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "0000000000000000000000000000000000000000000000000000000000000000000000002",
"url": "0000000000000000000000000000000000000000000000000000000000000000000000002?"
}
},
"displayMessage": "Update application Example App 61 profile",
"gatewayContext": null,
"legacyEventType": "cvd.appuser_profile_updated",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"ipServiceCategories": [
{
"operator": "GLOBAL_PROTECT_CLOUD_VPN",
"type": "VPN",
"isAnonymous": false
}
]
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New ASN",
"id": "bhv00000000000000155",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000156",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000157",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000158",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000159",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000160",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000161",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000162",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000248",
"externalSessionId": "10200000000000000248"
}
}
References #
directory.external.group.membership.add
#Description
External API call to add user group membership in a directory. This event audits the directory integration API when it adds a user to a group in a directory. Note that the event is fired even when the API call is unsuccessful.
References #
directory.external.group.membership.remove
#Description
External API call to remove user group membership in a directory. This event audits the directory integration API when it removes a user from a group in a directory. Note that the event is fired even when the API call is unsuccessful.
References #
directory.linked_object.create
#Description
An admin can create a linked object that is related to user profiles. This event may be used to identify when a linked object is created, and who created the linked object. This may be useful for admins to validate why a change in the user profile has happened. While linked object creation does not trigger or happen as a result of another event, it is overall related to custom property update, creation and deletion. This event only indicates the creation of a linked object. See directory.linked_object.delete for deletion of linked objects.
References #
directory.linked_object.delete
#Description
An admin can delete a linked object that is related to user profiles. This event may be used to identify when a linked object is deleted, and who deleted the linked object. This may be useful for admins to validate why a change in the user profile has happened. While linked object creation does not trigger or happen as a result of another event, it is overall related to custom property update, creation and deletion. This event only indicates the deletion of a linked object. See directory.linked_object.create for creation of linked objects.
References #
directory.mapping.update
#Description
Update universal directory mappings.
Example System Log Event #
{
"published": 1785252069310,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000069",
"actor": {
"id": "spr00000000000000171",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "prm00000000000000249",
"type": "ProfileMapping",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 81",
"detailEntry": {
"targetProfile": "oty00000000000000250",
"direction": "App to Okta",
"sourceProfile": "oty00000000000000251"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "directory.mapping.update",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": null,
"id": "0000003",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000018",
"requestApiTokenId": "0000000000000000000000000000000000000000000018",
"requestApiTokenClientId": "0oa00000000000000252"
}
},
"debugContext": {
"debugData": {
"attributesModified": "",
"attributesAdded": "",
"attributesDeleted": ""
}
},
"displayMessage": "Update universal directory mappings",
"gatewayContext": null,
"legacyEventType": "cvd.mappings_updated",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000253",
"externalSessionId": "trs00000000000000254"
}
}
References #
directory.non_default_user_profile.create
#Description
Create non-default universal directory user profile. This can be used to audit that a new non-default universal directory user profile has been created. When fired, this event contains the name and id of the newly created user profile.
References #
directory.user_profile.update
#Description
Update universal directory user profile directory.user_profile.update.
Example System Log Event #
{
"published": 1783523735049,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000070",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
"os": "Windows 10",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "oty00000000000000255",
"type": "Schema",
"alternateId": "user58@dw-harness.example",
"displayName": "DW Harness 82",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "directory.user_profile.update",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000036",
"detail": {}
},
"debugContext": {
"debugData": {
"attributesModified": "",
"attributesAdded": "Is_Manager",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000036",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
"origin": "https://app.example.com",
"attributesDeleted": "",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000011",
"url": "00000000000000000000000000000000000000011?"
}
},
"displayMessage": "Update universal directory Example App 61 profile directory.Example App 61_profile.update",
"gatewayContext": null,
"legacyEventType": "cvd.user_profile_updated",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New ASN",
"id": "bhv00000000000000155",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000156",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000157",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000158",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000159",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000160",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000161",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000162",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000256",
"externalSessionId": "10200000000000000256"
}
}