Okta Policy

eventTypeDescriptionSampleRule
policy.auth_reevaluate.actionInvocation of a post auth session action.NN
policy.auth_reevaluate.enforceEvaluation of a post auth session.NN
policy.auth_reevaluate.failAuth policy re-evaluation has occurred and has resulted in a policy violation.YN
policy.continuous_access.actionDeprecated: Continuous Access policy action invocation.NN
policy.continuous_access.evaluateDeprecated: Evaluation of Continuous Access Policy.NN
policy.entity_risk.actionEntity Risk policy action invocation.NN
policy.entity_risk.evaluateEvaluation of Entity Risk policy.YN
policy.evaluate_sign_onOkta evaluated sign-on policies in order to determine if the user attempting to access a resource meets the defined assurance criteria.YY
policy.execute.user.startStart execution of policy for user.NN
policy.lifecycle.activateActivate policy.YN
policy.lifecycle.createCreate policy.YY
policy.lifecycle.deactivateDeactivate policy.YY
policy.lifecycle.deleteDelete policy.YY
policy.lifecycle.overwriteOverwrite policy.NN
policy.lifecycle.updateUpdate policy.YY
policy.mapping.createCreate policy mapping.YN
policy.rule.action.executeScheduled execution of policy rule action.NN
policy.rule.activateActivate policy rule.YN
policy.rule.addAdd policy rule.YN
policy.rule.deactivateDeactivate policy rule.YY
policy.rule.deleteDelete policy rule.YY
policy.rule.invalidateInvalidate policy rule.NN
policy.rule.updateUpdate policy rule.YY
policy.scheduled.executeScheduled execution of policy.YN

policy.auth_reevaluate.action

#

Description

Invocation of a post auth session action. This event is triggered when Okta logs a user out of their configured apps or runs a Workflow in response to an authentication or global session policy violation. This event is triggered when Okta logs a user out of their configured apps or runs a Workflow in response to an authentication or global session policy violation.

References #

policy.auth_reevaluate.enforce

#

Description

Evaluation of a post auth session. This event is triggered when a post auth session evaluation occurs. This event is triggered when a post auth session evaluation occurs.

References #

policy.auth_reevaluate.fail

#

Description

Auth policy re-evaluation has occurred and has resulted in a policy violation. Can be used to identify which user, apps, and session were involved in a policy violation event. Event fired when continuing access evaluation results in failure.

Example System Log Event #

{
  "published": 1782414436621,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000074",
  "actor": {
    "id": "spr00000000000000171",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "rst00000000000000265",
      "type": "Policy Evaluation",
      "alternateId": null,
      "displayName": "DW Harness 87",
      "detailEntry": {
        "matchedRuleAction": "ALLOW",
        "matchedRuleDisplayName": "Example Rule 1",
        "appInstanceIds": "[0oa00000000000000266]",
        "matchedRuleAssuranceMet": "false",
        "policyType": "Example Rule 2",
        "matchedRuleId": "rul00000000000000267"
      }
    },
    {
      "id": "00u00000000000000268",
      "type": "User",
      "alternateId": "user61@dw-harness.example",
      "displayName": "DW Harness 88",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": "One or more policy evaluations returned assurance requirements that were not met by the session."
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "policy.auth_reevaluate.fail",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "cae00000000000000269",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "traceId": "00000000-0000-0000-0000-000000000075",
      "serverStatus": "ACTIVE",
      "risk": "{level=LOW}",
      "postAuthEnforceMode": "LOG"
    }
  },
  "displayMessage": "Monitoring: Post auth session reevaluate fail",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null,
    "risk": {
      "level": "LOW"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000270",
    "externalSessionId": "idx00000000000000270"
  }
}

References #

policy.continuous_access.action

#

Description

Deprecated: Continuous Access policy action invocation. Signal that an action associated with a continuous access policy evaluation has been invoked. Event fired when an action associated with a continuous access policy evaluation has been invoked. See the event type policy.auth_reevaluate.action that replaces this deprecated event.

References #

policy.continuous_access.evaluate

#

Description

Deprecated: Evaluation of Continuous Access Policy. Signal that continuous access policy has been evaluated for a session which has failed CAE. Event fired when continuous access policy has been evaluated for a session which has failed CAE. See the event type policy.auth_reevaluate.enforce that replaces this deprecated event.

References #

policy.entity_risk.action

#

Description

Entity Risk policy action invocation. Signal that an action associated with an entity risk policy evaluation has been invoked. Event fired when an action associated with an entity risk policy evaluation has been invoked.

References #

policy.entity_risk.evaluate

#

Description

Evaluation of Entity Risk policy. Signal that entity risk policy has been evaluated for an entity for which we have received a risk change event. Event fired when entity risk policy has been evaluated for an entity for which a risk change event was generated.

Example System Log Event #

{
  "published": 1781037015154,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000076",
  "actor": {
    "id": "spr00000000000000167",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
      "os": "Windows 11",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.5",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "rul00000000000000271",
      "type": "Rule",
      "alternateId": null,
      "displayName": "DW Harness 89",
      "detailEntry": null
    },
    {
      "id": "rst00000000000000272",
      "type": "Policy",
      "alternateId": null,
      "displayName": "DW Harness 90",
      "detailEntry": null
    },
    {
      "id": "00u00000000000000273",
      "type": "User",
      "alternateId": "user62@dw-harness.example",
      "displayName": "DW Harness 91",
      "detailEntry": {
        "realmId": "guo00000000000000062"
      }
    }
  ],
  "outcome": {
    "result": "ALLOW",
    "reason": "Entity Risk policy evaluated for Example App 61 user63@dw-harness.example"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.5",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "policy.entity_risk.evaluate",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000039",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "traceId": "00000000-0000-0000-0000-000000000077",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000039",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000025",
      "origin": "https://app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "kzn00000000000000274",
      "url": "kzn00000000000000274?"
    }
  },
  "displayMessage": null,
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000275",
    "externalSessionId": "10200000000000000275"
  }
}

References #

policy.evaluate_sign_on

#

Description

Okta evaluated sign-on policies in order to determine if the user attempting to access a resource meets the defined assurance criteria. Identifies the policy rule evaluated during an authentication flow. This may be useful to confirm that policy rule has been configured as intended, or to identify why a user is unable to access a resource such as an application. The possible outcomes of this event are ALLOW(user is authenticated to access the resource), CHALLENGE(additional verification is required for user to access the resource), and DENY(user is denied from accessing the resource). For Okta Identity Engine (OIE), a single policy.evaluate_sign_on event may include the evaluation result of Okta global session policy and authentication policy. For Okta Classic Engine, the evaluation result of Okta sign-on policy and app sign-on policy will be recorded in individual policy.evaluate_sign_on events.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000128",
    "type": "User",
    "alternateId": "user33@dw-harness.example",
    "displayName": "DW Harness 60",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
      "os": "Windows 11",
      "browser": "CHROMIUM_EDGE"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": {
    "id": null,
    "name": null,
    "os_platform": null,
    "os_version": null,
    "managed": null,
    "registered": null,
    "device_integrator": {
      "DEVICE_IDP": {}
    },
    "disk_encryption_type": null,
    "screen_lock_type": null,
    "jailbreak": null,
    "secure_hardware_present": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000131",
    "externalSessionId": "idx00000000000000131"
  },
  "displayMessage": "Evaluation of sign-on policy",
  "eventType": "policy.evaluate_sign_on",
  "outcome": {
    "result": "CHALLENGE",
    "reason": "Sign-on policy evaluation resulted in ENROLL"
  },
  "published": "2026-07-26T00:27:42.599Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "HIGH",
      "reasons": [
        "Anomalous Location",
        "Anomalous Device"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000132",
        "result": "UNKNOWN"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000133",
        "result": "UNKNOWN"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000134",
        "result": "UNKNOWN"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000135",
        "result": "UNKNOWN"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000136",
        "result": "UNKNOWN"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000137",
        "result": "UNKNOWN"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000138",
        "result": "UNKNOWN"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000139",
        "result": "UNKNOWN"
      }
    ]
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "authnRequestId": "00000000000000000000000000000121",
      "deviceFingerprint": "00000000000000000000000000000122",
      "oktaUserAgentExtended": "okta-auth-js/7.14.5 okta-signin-widget-7.47.2 okta-hosted",
      "requestId": "00000000000000000000000000000123",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000005",
      "origin": "https://dev-00000.okta.com",
      "challengeAuthenticatorsList": "[{Okta Verify : totp}, {Okta Verify : signed_nonce}]",
      "requestUri": "/idp/idx/identify",
      "threatSuspected": "false",
      "url": "/idp/idx/identify?",
      "logOnlySecurityData": {
        "risk": {
          "reasons": "Anomalous Location, Anomalous Device",
          "level": "HIGH"
        },
        "behaviors": {
          "New Geo-Location": "UNKNOWN",
          "New Device": "UNKNOWN",
          "New ASN": "UNKNOWN",
          "New IP": "UNKNOWN",
          "New State": "UNKNOWN",
          "New Country": "UNKNOWN",
          "Velocity": "UNKNOWN",
          "New City": "UNKNOWN"
        }
      }
    }
  },
  "gatewayContext": null,
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000123",
    "detail": {}
  },
  "uuid": "00000000-0000-0000-0000-000000000154",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000129",
      "type": "AppInstance",
      "alternateId": "user34@dw-harness.example",
      "displayName": "DW Harness 45",
      "detailEntry": {
        "signOnModeType": "OPENID_CONNECT",
        "signOnModeEvaluationResult": "CHALLENGE"
      }
    },
    {
      "id": "0pr00000000000000140",
      "type": "Rule",
      "alternateId": "user35@dw-harness.example",
      "displayName": "DW Harness 61",
      "detailEntry": {
        "policyRulePriority": "0",
        "policyId": "00p00000000000000141",
        "policyName": "Default Policy",
        "policyRuleFactorMode": "1FA"
      }
    },
    {
      "id": "rul00000000000000142",
      "type": "Rule",
      "alternateId": "user36@dw-harness.example",
      "displayName": "DW Harness 62",
      "detailEntry": {
        "policyRulePriority": "99",
        "policyId": "rst00000000000000090",
        "policyName": "Any two factors",
        "policyRuleFactorMode": "2FA"
      }
    },
    {
      "id": "0pr00000000000000143",
      "type": "Rule",
      "alternateId": "user37@dw-harness.example",
      "displayName": "DW Harness 61",
      "detailEntry": {
        "policyName": "Default Policy"
      }
    },
    {
      "id": "00u00000000000000128",
      "type": "User",
      "alternateId": "user33@dw-harness.example",
      "displayName": "DW Harness 60",
      "detailEntry": {
        "identifyingAttribute": "login"
      }
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventTypeeqpolicy.evaluate_sign_on3 rulessigma, splunk
eventType (splunk rule field)equser.authentication.sso1 rulesplunk
okta::eventTypeinpolicy.evaluate_sign_on2 ruleselastic, kusto
okta::eventTypeinuser.session.start2 ruleselastic, kusto
okta::eventType (kusto rule field)insystem.api_token.create1 rulekusto
okta::eventType (elastic rule field)inuser.authentication.sso1 ruleelastic
security_result.action (Chronicle)eqCHALLENGE2 ruleschronicle
okta::actor.alternateId (elastic rule field)nesystem@okta.com1 ruleelastic
ratio (splunk rule field)lt0.51 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Okta AiTM Session Cookie Replay source high: Detects potential Adversary-in-the-Middle (AiTM) session cookie replay attacks against Okta. This rule identifies when an Okta session is used from multiple IP addresses or with suspicious non-browser user agents after initial authentication. AiTM attacks capture session cookies via phishing proxies (e.g., Evilginx, Modlishka) and replay them from attacker infrastructure, bypassing MFA. The detection correlates session start events with subsequent policy evaluations or SSO attempts that occur from different IPs or programmatic user agents.T1539, T1550, T1550.004

Splunk #

Kusto #

  • High-Risk Admin Activity source medium: The Okta risk engine auto-assigns risk levels to each login attempt. This rule identifies successful admin operations that correlate with successful high-risk Okta authentication or session start events.T1078, T1078.004, T1098

YARA-L #

Panther #

References #

policy.execute.user.start

#

Description

Start execution of policy for user.

References #

policy.lifecycle.activate

#

Description

Activate policy.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000057",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Activate policy",
  "eventType": "policy.lifecycle.activate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:54:59.171Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/policies/00p00000000000000014/lifecycle/activate",
      "url": "/api/v1/policies/00p00000000000000014/lifecycle/activate?"
    }
  },
  "legacyEventType": "policy.activated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "PolicyEntity",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": {
        "policyType": "OKTA_SIGN_ON"
      }
    }
  ]
}

References #

policy.lifecycle.create

#

Description

Create policy.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000116",
    "externalSessionId": "trs00000000000000116"
  },
  "displayMessage": "Create policy",
  "eventType": "policy.lifecycle.create",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:58:28.583Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000112",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/authorizationServers/aus00000000000000117/policies",
      "url": "/api/v1/authorizationServers/aus00000000000000117/policies?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "policy.created",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000112",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000140",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00p00000000000000118",
      "type": "PolicyEntity",
      "alternateId": "user03@dw-harness.example",
      "displayName": "DW Harness 56",
      "detailEntry": {
        "policyType": "OAUTH_AUTHORIZATION_POLICY"
      },
      "changeDetails": {
        "from": null,
        "to": {
          "policyDescription": "dw harness temporary password-grant policy",
          "policyExtensiblePropertiesJson": {
            "clients": {
              "include": [
                "ALL_CLIENTS"
              ]
            }
          },
          "policyName": "dw-harn-6195aee2-password-policy",
          "policyPriority": 1
        }
      }
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::eventType (kusto rule field)equser.session.start1 rulekusto
okta::eventType (kusto rule field)inuser.mfa.factor.deactivate1 rulekusto
okta::eventType (kusto rule field)inuser.mfa.factor.reset_all1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

policy.lifecycle.deactivate

#

Description

Deactivate policy.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000058",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Deactivate policy",
  "eventType": "policy.lifecycle.deactivate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:54:59.482Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/policies/00p00000000000000014/lifecycle/deactivate",
      "url": "/api/v1/policies/00p00000000000000014/lifecycle/deactivate?"
    }
  },
  "legacyEventType": "policy.deactivated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "PolicyEntity",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": {
        "policyType": "OKTA_SIGN_ON"
      }
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::eventType (kusto rule field)equser.session.start1 rulekusto
okta::eventType (kusto rule field)inuser.mfa.factor.deactivate1 rulekusto
okta::eventType (kusto rule field)inuser.mfa.factor.reset_all1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Attempt to Deactivate an Okta Policy source low: Detects attempts to deactivate an Okta policy. An adversary may attempt to deactivate an Okta policy in order to weaken an organization's security controls. For example, an adversary may attempt to deactivate an Okta multi-factor authentication (MFA) policy in order to weaken the authentication requirements for user accounts.T1556, T1556.006, T1562, T1562.007

Kusto #

References #

policy.lifecycle.delete

#

Description

Delete policy.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000059",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Delete policy",
  "eventType": "policy.lifecycle.delete",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:54:59.645Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/policies/00p00000000000000014",
      "url": "/api/v1/policies/00p00000000000000014?"
    }
  },
  "legacyEventType": "policy.deleted",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "PolicyEntity",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": {
        "policyType": "OKTA_SIGN_ON"
      }
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::eventType (kusto rule field)equser.session.start1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Attempt to Delete an Okta Policy source medium: Detects attempts to delete an Okta policy. An adversary may attempt to delete an Okta policy in order to weaken an organization's security controls. For example, an adversary may attempt to delete an Okta multi-factor authentication (MFA) policy in order to weaken the authentication requirements for user accounts.T1556, T1556.006, T1562, T1562.007

Kusto #

References #

policy.lifecycle.overwrite

#

Description

Overwrite policy.

References #

policy.lifecycle.update

#

Description

Update policy.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000060",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Update policy",
  "eventType": "policy.lifecycle.update",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:54:59.295Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/policies/00p00000000000000014",
      "url": "/api/v1/policies/00p00000000000000014?"
    }
  },
  "legacyEventType": "policy.updated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "PolicyEntity",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": {
        "policyType": "OKTA_SIGN_ON"
      },
      "changeDetails": {
        "from": {
          "policyDescription": "dw harness throwaway",
          "policyName": "dw-harn-eeb5dfe9-policy"
        },
        "to": {
          "policyName": "dw-harn-eeb5dfe9-policy-upd"
        }
      }
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
admin_email (panther rule field)is_not_null1 rulepanther
is_anomalous (panther rule field)eqtrue1 rulepanther
okta::eventType (kusto rule field)equser.session.start1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Attempt to Modify an Okta Policy source low: Detects attempts to modify an Okta policy. An adversary may attempt to modify an Okta policy in order to weaken an organization's security controls. For example, an adversary may attempt to modify an Okta multi-factor authentication (MFA) policy in order to weaken the authentication requirements for user accounts.T1484, T1556, T1562, T1562.007

Kusto #

Panther #

  • Okta Authentication Bypass via Skeleton Key Injection - Behavioral source high linked query: Query.Okta.SkeletonKeyBypassBehavioral: Detects potential Okta authentication bypass via skeleton key injection using behavioral z-score analysis. Skeleton key attacks in Okta involve manipulating authentication policies to weaken MFA requirements (disabling requireFactor, zeroing maxSessionLifetime) and bulk-enrolling attacker-controlled authenticators on victim accounts. This detection builds a 90-day behavioral baseline for each admin's policy change and factor enrollment patterns, then identifies anomalous spikes in the last 7 days. Detection Logic: - Z-score: Spike in security-weakening policy changes (> 2σ above baseline) - Z-score: Spike in admin-on-behalf-of MFA factor enrollments (> 3σ above baseline) - Cold-start: First-time security weakening (no prior baseline - immediate high-confidence signal) - Cold-start: First-time admin-enrolled factors for other users Why This Matters: Skeleton key attacks require two steps: weaken authentication policies to reduce MFA friction, then enroll attacker-controlled authenticators on victim accounts. This detection catches both steps using behavioral baselines that adapt to legitimate admin workflows. Complementary Detection: Use alongside Okta.ADAgent.TokenAbuse.Behavioral for admin credential theft scenarios.T1098, T1556↳ also matches policy.rule.update
  • Query.Okta.SkeletonKeyBypassBehavioral source: Detects Okta authentication bypass attempts via skeleton key injection using behavioral z-score analysis. Reads pre-computed 90-day baselines from the okta_baseline_90d lookup table, then compares recent (last 7 days) admin policy change and MFA factor enrollment patterns against those baselines. DETECTION LOGIC: - Z-score: Security-weakening policy changes (requireFactor=false, maxSessionLifetime=0) > 2σ - Z-score: Admin-on-behalf-of MFA factor enrollments for other users > 3σ - Cold-start: First-time security weakening with no prior baseline - Cold-start: First-time admin-enrolled factors for other users PREREQUISITE: okta_baseline_90d lookup table must be populated.↳ also matches policy.rule.update

References #

policy.mapping.create

#

Description

Create policy mapping. This event is used to audit when a policy is mapped to a resource. This event is fired when a policy is mapped to a resource. The isPreviousPolicy attribute within the Policy Targets' Details denotes whether or not it was the previous or new policy being mapped.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000013",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Create policy mapping",
  "eventType": "policy.mapping.create",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:50.810Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/apps",
      "url": "/api/v1/apps?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "PolicyEntity",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": {
        "policyType": "PROFILE_ENROLLMENT",
        "previousPolicy": "false"
      }
    },
    {
      "id": "00000000000000000000",
      "type": "AppInstance",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

policy.rule.action.execute

#

Description

Scheduled execution of policy rule action.

References #

policy.rule.activate

#

Description

Activate policy rule.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000061",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Activate policy rule",
  "eventType": "policy.rule.activate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T19:00:41.710Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016/lifecycle/activate",
      "url": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016/lifecycle/activate?"
    }
  },
  "legacyEventType": "policy.rule.activated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "PolicyEntity",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": {
        "policyType": "OKTA_SIGN_ON"
      }
    },
    {
      "id": "00000000000000000000",
      "type": "PolicyRule",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

policy.rule.add

#

Description

Add policy rule.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000062",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Add policy rule",
  "eventType": "policy.rule.add",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T19:00:41.331Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/policies/00p00000000000000015/rules",
      "url": "/api/v1/policies/00p00000000000000015/rules?"
    }
  },
  "legacyEventType": "policy.rule.added",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "PolicyEntity",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": {
        "policyType": "OKTA_SIGN_ON"
      }
    },
    {
      "id": "00000000000000000000",
      "type": "PolicyRule",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

policy.rule.deactivate

#

Description

Deactivate policy rule.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000063",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Deactivate policy rule",
  "eventType": "policy.rule.deactivate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T19:00:41.581Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016/lifecycle/deactivate",
      "url": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016/lifecycle/deactivate?"
    }
  },
  "legacyEventType": "policy.rule.deactivated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "PolicyEntity",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": {
        "policyType": "OKTA_SIGN_ON"
      }
    },
    {
      "id": "00000000000000000000",
      "type": "PolicyRule",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

policy.rule.delete

#

Description

Delete policy rule.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000064",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Delete policy rule",
  "eventType": "policy.rule.delete",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T19:00:42.143Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016",
      "url": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016?"
    }
  },
  "legacyEventType": "policy.rule.deleted",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "PolicyEntity",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": {
        "policyType": "OKTA_SIGN_ON"
      }
    },
    {
      "id": "00000000000000000000",
      "type": "PolicyRule",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

References #

policy.rule.invalidate

#

Description

Invalidate policy rule.

References #

policy.rule.update

#

Description

Update policy rule.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000065",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Update policy rule",
  "eventType": "policy.rule.update",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T19:00:41.947Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016",
      "url": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016?"
    }
  },
  "legacyEventType": "policy.rule.updated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "PolicyEntity",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": {
        "policyType": "OKTA_SIGN_ON"
      }
    },
    {
      "id": "00000000000000000000",
      "type": "PolicyRule",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null,
      "changeDetails": {
        "from": {
          "policyRuleName": "dw-harn-f001873b-rule"
        },
        "to": {
          "policyRuleName": "dw-harn-f001873b-rule-upd"
        }
      }
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
admin_email (panther rule field)is_not_null1 rulepanther
is_anomalous (panther rule field)eqtrue1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

Panther #

  • Okta Authentication Bypass via Skeleton Key Injection - Behavioral source high linked query: Query.Okta.SkeletonKeyBypassBehavioral: Detects potential Okta authentication bypass via skeleton key injection using behavioral z-score analysis. Skeleton key attacks in Okta involve manipulating authentication policies to weaken MFA requirements (disabling requireFactor, zeroing maxSessionLifetime) and bulk-enrolling attacker-controlled authenticators on victim accounts. This detection builds a 90-day behavioral baseline for each admin's policy change and factor enrollment patterns, then identifies anomalous spikes in the last 7 days. Detection Logic: - Z-score: Spike in security-weakening policy changes (> 2σ above baseline) - Z-score: Spike in admin-on-behalf-of MFA factor enrollments (> 3σ above baseline) - Cold-start: First-time security weakening (no prior baseline - immediate high-confidence signal) - Cold-start: First-time admin-enrolled factors for other users Why This Matters: Skeleton key attacks require two steps: weaken authentication policies to reduce MFA friction, then enroll attacker-controlled authenticators on victim accounts. This detection catches both steps using behavioral baselines that adapt to legitimate admin workflows. Complementary Detection: Use alongside Okta.ADAgent.TokenAbuse.Behavioral for admin credential theft scenarios.T1098, T1556↳ also matches policy.lifecycle.update
  • Query.Okta.SkeletonKeyBypassBehavioral source: Detects Okta authentication bypass attempts via skeleton key injection using behavioral z-score analysis. Reads pre-computed 90-day baselines from the okta_baseline_90d lookup table, then compares recent (last 7 days) admin policy change and MFA factor enrollment patterns against those baselines. DETECTION LOGIC: - Z-score: Security-weakening policy changes (requireFactor=false, maxSessionLifetime=0) > 2σ - Z-score: Admin-on-behalf-of MFA factor enrollments for other users > 3σ - Cold-start: First-time security weakening with no prior baseline - Cold-start: First-time admin-enrolled factors for other users PREREQUISITE: okta_baseline_90d lookup table must be populated.↳ also matches policy.lifecycle.update

References #

policy.scheduled.execute

#

Description

Scheduled execution of policy.

Example System Log Event #

{
  "published": 1780242501236,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000078",
  "actor": {
    "id": "spr00000000000000167",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00p00000000000000276",
      "type": "PolicyEntity",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 92",
      "detailEntry": {
        "policyType": "Example Rule 6"
      }
    }
  ],
  "outcome": {
    "result": "FAILURE",
    "reason": "Policy has inactive status"
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "policy.scheduled.execute",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "spe00000000000000277",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Scheduled execution of policy",
  "gatewayContext": null,
  "legacyEventType": "policy.scheduled.execute",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000278",
    "externalSessionId": "trs00000000000000279"
  }
}

References #