Okta Policy
| eventType | Description | Sample | Rule |
|---|---|---|---|
| policy. | Invocation of a post auth session action. | N | N |
| policy. | Evaluation of a post auth session. | N | N |
| policy. | Auth policy re-evaluation has occurred and has resulted in a policy violation. | Y | N |
| policy. | Deprecated: Continuous Access policy action invocation. | N | N |
| policy. | Deprecated: Evaluation of Continuous Access Policy. | N | N |
| policy. | Entity Risk policy action invocation. | N | N |
| policy. | Evaluation of Entity Risk policy. | Y | N |
| policy. | Okta evaluated sign-on policies in order to determine if the user attempting to access a resource meets the defined assurance criteria. | Y | Y |
| policy. | Start execution of policy for user. | N | N |
| policy. | Activate policy. | Y | N |
| policy. | Create policy. | Y | Y |
| policy. | Deactivate policy. | Y | Y |
| policy. | Delete policy. | Y | Y |
| policy. | Overwrite policy. | N | N |
| policy. | Update policy. | Y | Y |
| policy. | Create policy mapping. | Y | N |
| policy. | Scheduled execution of policy rule action. | N | N |
| policy. | Activate policy rule. | Y | N |
| policy. | Add policy rule. | Y | N |
| policy. | Deactivate policy rule. | Y | Y |
| policy. | Delete policy rule. | Y | Y |
| policy. | Invalidate policy rule. | N | N |
| policy. | Update policy rule. | Y | Y |
| policy. | Scheduled execution of policy. | Y | N |
policy.auth_reevaluate.action
#Description
Invocation of a post auth session action. This event is triggered when Okta logs a user out of their configured apps or runs a Workflow in response to an authentication or global session policy violation. This event is triggered when Okta logs a user out of their configured apps or runs a Workflow in response to an authentication or global session policy violation.
References #
policy.auth_reevaluate.enforce
#Description
Evaluation of a post auth session. This event is triggered when a post auth session evaluation occurs. This event is triggered when a post auth session evaluation occurs.
References #
policy.auth_reevaluate.fail
#Description
Auth policy re-evaluation has occurred and has resulted in a policy violation. Can be used to identify which user, apps, and session were involved in a policy violation event. Event fired when continuing access evaluation results in failure.
Example System Log Event #
{
"published": 1782414436621,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000074",
"actor": {
"id": "spr00000000000000171",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "rst00000000000000265",
"type": "Policy Evaluation",
"alternateId": null,
"displayName": "DW Harness 87",
"detailEntry": {
"matchedRuleAction": "ALLOW",
"matchedRuleDisplayName": "Example Rule 1",
"appInstanceIds": "[0oa00000000000000266]",
"matchedRuleAssuranceMet": "false",
"policyType": "Example Rule 2",
"matchedRuleId": "rul00000000000000267"
}
},
{
"id": "00u00000000000000268",
"type": "User",
"alternateId": "user61@dw-harness.example",
"displayName": "DW Harness 88",
"detailEntry": {
"realmId": "guo00000000000000044"
}
}
],
"outcome": {
"result": "FAILURE",
"reason": "One or more policy evaluations returned assurance requirements that were not met by the session."
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "WARN",
"eventType": "policy.auth_reevaluate.fail",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "cae00000000000000269",
"detail": {}
},
"debugContext": {
"debugData": {
"traceId": "00000000-0000-0000-0000-000000000075",
"serverStatus": "ACTIVE",
"risk": "{level=LOW}",
"postAuthEnforceMode": "LOG"
}
},
"displayMessage": "Monitoring: Post auth session reevaluate fail",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null,
"risk": {
"level": "LOW"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "idx00000000000000270",
"externalSessionId": "idx00000000000000270"
}
}
References #
policy.continuous_access.action
#Description
Deprecated: Continuous Access policy action invocation. Signal that an action associated with a continuous access policy evaluation has been invoked. Event fired when an action associated with a continuous access policy evaluation has been invoked. See the event type policy.auth_reevaluate.action that replaces this deprecated event.
References #
policy.continuous_access.evaluate
#Description
Deprecated: Evaluation of Continuous Access Policy. Signal that continuous access policy has been evaluated for a session which has failed CAE. Event fired when continuous access policy has been evaluated for a session which has failed CAE. See the event type policy.auth_reevaluate.enforce that replaces this deprecated event.
References #
policy.entity_risk.action
#Description
Entity Risk policy action invocation. Signal that an action associated with an entity risk policy evaluation has been invoked. Event fired when an action associated with an entity risk policy evaluation has been invoked.
References #
policy.entity_risk.evaluate
#Description
Evaluation of Entity Risk policy. Signal that entity risk policy has been evaluated for an entity for which we have received a risk change event. Event fired when entity risk policy has been evaluated for an entity for which a risk change event was generated.
Example System Log Event #
{
"published": 1781037015154,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000076",
"actor": {
"id": "spr00000000000000167",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
"os": "Windows 11",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.5",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "rul00000000000000271",
"type": "Rule",
"alternateId": null,
"displayName": "DW Harness 89",
"detailEntry": null
},
{
"id": "rst00000000000000272",
"type": "Policy",
"alternateId": null,
"displayName": "DW Harness 90",
"detailEntry": null
},
{
"id": "00u00000000000000273",
"type": "User",
"alternateId": "user62@dw-harness.example",
"displayName": "DW Harness 91",
"detailEntry": {
"realmId": "guo00000000000000062"
}
}
],
"outcome": {
"result": "ALLOW",
"reason": "Entity Risk policy evaluated for Example App 61 user63@dw-harness.example"
},
"request": {
"ipChain": [
{
"ip": "192.0.2.5",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "policy.entity_risk.evaluate",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000039",
"detail": {}
},
"debugContext": {
"debugData": {
"traceId": "00000000-0000-0000-0000-000000000077",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000039",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000025",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "kzn00000000000000274",
"url": "kzn00000000000000274?"
}
},
"displayMessage": null,
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New ASN",
"id": "bhv00000000000000155",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000156",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000157",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000158",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000159",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000160",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000161",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000162",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000275",
"externalSessionId": "10200000000000000275"
}
}
References #
policy.evaluate_sign_on
#Description
Okta evaluated sign-on policies in order to determine if the user attempting to access a resource meets the defined assurance criteria. Identifies the policy rule evaluated during an authentication flow. This may be useful to confirm that policy rule has been configured as intended, or to identify why a user is unable to access a resource such as an application. The possible outcomes of this event are ALLOW(user is authenticated to access the resource), CHALLENGE(additional verification is required for user to access the resource), and DENY(user is denied from accessing the resource). For Okta Identity Engine (OIE), a single policy.evaluate_sign_on event may include the evaluation result of Okta global session policy and authentication policy. For Okta Classic Engine, the evaluation result of Okta sign-on policy and app sign-on policy will be recorded in individual policy.evaluate_sign_on events.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000128",
"type": "User",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 60",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
"os": "Windows 11",
"browser": "CHROMIUM_EDGE"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": {
"id": null,
"name": null,
"os_platform": null,
"os_version": null,
"managed": null,
"registered": null,
"device_integrator": {
"DEVICE_IDP": {}
},
"disk_encryption_type": null,
"screen_lock_type": null,
"jailbreak": null,
"secure_hardware_present": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "idx00000000000000131",
"externalSessionId": "idx00000000000000131"
},
"displayMessage": "Evaluation of sign-on policy",
"eventType": "policy.evaluate_sign_on",
"outcome": {
"result": "CHALLENGE",
"reason": "Sign-on policy evaluation resulted in ENROLL"
},
"published": "2026-07-26T00:27:42.599Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "HIGH",
"reasons": [
"Anomalous Location",
"Anomalous Device"
]
},
"userBehaviors": [
{
"name": "New ASN",
"id": "bhv00000000000000132",
"result": "UNKNOWN"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000133",
"result": "UNKNOWN"
},
{
"name": "New Device",
"id": "bhv00000000000000134",
"result": "UNKNOWN"
},
{
"name": "New State",
"id": "bhv00000000000000135",
"result": "UNKNOWN"
},
{
"name": "New IP",
"id": "bhv00000000000000136",
"result": "UNKNOWN"
},
{
"name": "Velocity",
"id": "bhv00000000000000137",
"result": "UNKNOWN"
},
{
"name": "New Country",
"id": "bhv00000000000000138",
"result": "UNKNOWN"
},
{
"name": "New City",
"id": "bhv00000000000000139",
"result": "UNKNOWN"
}
]
},
"severity": "INFO",
"debugContext": {
"debugData": {
"authnRequestId": "00000000000000000000000000000121",
"deviceFingerprint": "00000000000000000000000000000122",
"oktaUserAgentExtended": "okta-auth-js/7.14.5 okta-signin-widget-7.47.2 okta-hosted",
"requestId": "00000000000000000000000000000123",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000005",
"origin": "https://dev-00000.okta.com",
"challengeAuthenticatorsList": "[{Okta Verify : totp}, {Okta Verify : signed_nonce}]",
"requestUri": "/idp/idx/identify",
"threatSuspected": "false",
"url": "/idp/idx/identify?",
"logOnlySecurityData": {
"risk": {
"reasons": "Anomalous Location, Anomalous Device",
"level": "HIGH"
},
"behaviors": {
"New Geo-Location": "UNKNOWN",
"New Device": "UNKNOWN",
"New ASN": "UNKNOWN",
"New IP": "UNKNOWN",
"New State": "UNKNOWN",
"New Country": "UNKNOWN",
"Velocity": "UNKNOWN",
"New City": "UNKNOWN"
}
}
}
},
"gatewayContext": null,
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000123",
"detail": {}
},
"uuid": "00000000-0000-0000-0000-000000000154",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000129",
"type": "AppInstance",
"alternateId": "user34@dw-harness.example",
"displayName": "DW Harness 45",
"detailEntry": {
"signOnModeType": "OPENID_CONNECT",
"signOnModeEvaluationResult": "CHALLENGE"
}
},
{
"id": "0pr00000000000000140",
"type": "Rule",
"alternateId": "user35@dw-harness.example",
"displayName": "DW Harness 61",
"detailEntry": {
"policyRulePriority": "0",
"policyId": "00p00000000000000141",
"policyName": "Default Policy",
"policyRuleFactorMode": "1FA"
}
},
{
"id": "rul00000000000000142",
"type": "Rule",
"alternateId": "user36@dw-harness.example",
"displayName": "DW Harness 62",
"detailEntry": {
"policyRulePriority": "99",
"policyId": "rst00000000000000090",
"policyName": "Any two factors",
"policyRuleFactorMode": "2FA"
}
},
{
"id": "0pr00000000000000143",
"type": "Rule",
"alternateId": "user37@dw-harness.example",
"displayName": "DW Harness 61",
"detailEntry": {
"policyName": "Default Policy"
}
},
{
"id": "00u00000000000000128",
"type": "User",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 60",
"detailEntry": {
"identifyingAttribute": "login"
}
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
eventType | eq | policy.evaluate_sign_on | 3 rules | sigma, splunk |
eventType (splunk rule field) | eq | user.authentication.sso | 1 rule | splunk |
okta::eventType | in | policy.evaluate_sign_on | 2 rules | elastic, kusto |
okta::eventType | in | user.session.start | 2 rules | elastic, kusto |
okta::eventType (kusto rule field) | in | system.api_token.create | 1 rule | kusto |
okta::eventType (elastic rule field) | in | user.authentication.sso | 1 rule | elastic |
security_result.action (Chronicle) | eq | CHALLENGE | 2 rules | chronicle |
okta::actor.alternateId (elastic rule field) | ne | system@okta.com | 1 rule | elastic |
ratio (splunk rule field) | lt | 0.5 | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.004Elastic #
T1539, T1550, T1550.004Splunk #
T1538, T1550, T1550.004T1539Kusto #
T1078, T1078.004, T1098YARA-L #
T1550T1539Panther #
T1078.004
References #
policy.lifecycle.activate
#Description
Activate policy.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000057",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Activate policy",
"eventType": "policy.lifecycle.activate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:54:59.171Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/policies/00p00000000000000014/lifecycle/activate",
"url": "/api/v1/policies/00p00000000000000014/lifecycle/activate?"
}
},
"legacyEventType": "policy.activated",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "PolicyEntity",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": {
"policyType": "OKTA_SIGN_ON"
}
}
]
}
References #
policy.lifecycle.create
#Description
Create policy.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000116",
"externalSessionId": "trs00000000000000116"
},
"displayMessage": "Create policy",
"eventType": "policy.lifecycle.create",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:58:28.583Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000000000000112",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/authorizationServers/aus00000000000000117/policies",
"url": "/api/v1/authorizationServers/aus00000000000000117/policies?"
}
},
"gatewayContext": null,
"legacyEventType": "policy.created",
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000112",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000140",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00p00000000000000118",
"type": "PolicyEntity",
"alternateId": "user03@dw-harness.example",
"displayName": "DW Harness 56",
"detailEntry": {
"policyType": "OAUTH_AUTHORIZATION_POLICY"
},
"changeDetails": {
"from": null,
"to": {
"policyDescription": "dw harness temporary password-grant policy",
"policyExtensiblePropertiesJson": {
"clients": {
"include": [
"ALL_CLIENTS"
]
}
},
"policyName": "dw-harn-6195aee2-password-policy",
"policyPriority": 1
}
}
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
okta::eventType (kusto rule field) | eq | user.session.start | 1 rule | kusto |
okta::eventType (kusto rule field) | in | user.mfa.factor.deactivate | 1 rule | kusto |
okta::eventType (kusto rule field) | in | user.mfa.factor.reset_all | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1098, T1556↳ also matches policy.lifecycle.deactivate, policy.lifecycle.delete, policy.lifecycle.update, policy.rule.deactivate, policy.rule.delete, policy.rule.update
References #
policy.lifecycle.deactivate
#Description
Deactivate policy.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000058",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Deactivate policy",
"eventType": "policy.lifecycle.deactivate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:54:59.482Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/policies/00p00000000000000014/lifecycle/deactivate",
"url": "/api/v1/policies/00p00000000000000014/lifecycle/deactivate?"
}
},
"legacyEventType": "policy.deactivated",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "PolicyEntity",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": {
"policyType": "OKTA_SIGN_ON"
}
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
okta::eventType (kusto rule field) | eq | user.session.start | 1 rule | kusto |
okta::eventType (kusto rule field) | in | user.mfa.factor.deactivate | 1 rule | kusto |
okta::eventType (kusto rule field) | in | user.mfa.factor.reset_all | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1556, T1556.006, T1562, T1562.007Kusto #
T1078, T1098, T1556↳ also matches policy.lifecycle.create, policy.lifecycle.delete, policy.lifecycle.update, policy.rule.deactivate, policy.rule.delete, policy.rule.update
References #
policy.lifecycle.delete
#Description
Delete policy.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000059",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Delete policy",
"eventType": "policy.lifecycle.delete",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:54:59.645Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/policies/00p00000000000000014",
"url": "/api/v1/policies/00p00000000000000014?"
}
},
"legacyEventType": "policy.deleted",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "PolicyEntity",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": {
"policyType": "OKTA_SIGN_ON"
}
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
okta::eventType (kusto rule field) | eq | user.session.start | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1556, T1556.006, T1562, T1562.007Kusto #
T1078, T1098, T1556↳ also matches policy.lifecycle.create, policy.lifecycle.deactivate, policy.lifecycle.update, policy.rule.deactivate, policy.rule.delete, policy.rule.update
References #
policy.lifecycle.update
#Description
Update policy.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000060",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Update policy",
"eventType": "policy.lifecycle.update",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:54:59.295Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/policies/00p00000000000000014",
"url": "/api/v1/policies/00p00000000000000014?"
}
},
"legacyEventType": "policy.updated",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "PolicyEntity",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": {
"policyType": "OKTA_SIGN_ON"
},
"changeDetails": {
"from": {
"policyDescription": "dw harness throwaway",
"policyName": "dw-harn-eeb5dfe9-policy"
},
"to": {
"policyName": "dw-harn-eeb5dfe9-policy-upd"
}
}
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
admin_email (panther rule field) | is_not_null | | 1 rule | panther |
is_anomalous (panther rule field) | eq | true | 1 rule | panther |
okta::eventType (kusto rule field) | eq | user.session.start | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1484, T1556, T1562, T1562.007Kusto #
T1078, T1098, T1556↳ also matches policy.lifecycle.create, policy.lifecycle.deactivate, policy.lifecycle.delete, policy.rule.deactivate, policy.rule.delete, policy.rule.update Panther #
Okta.ADAgent.TokenAbuse.Behavioral for admin credential theft scenarios.T1098, T1556↳ also matches policy.rule.update
References #
policy.mapping.create
#Description
Create policy mapping. This event is used to audit when a policy is mapped to a resource. This event is fired when a policy is mapped to a resource. The isPreviousPolicy attribute within the Policy Targets' Details denotes whether or not it was the previous or new policy being mapped.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000013",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Create policy mapping",
"eventType": "policy.mapping.create",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:35:50.810Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/apps",
"url": "/api/v1/apps?"
}
},
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "PolicyEntity",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": {
"policyType": "PROFILE_ENROLLMENT",
"previousPolicy": "false"
}
},
{
"id": "00000000000000000000",
"type": "AppInstance",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
References #
policy.rule.activate
#Description
Activate policy rule.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000061",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Activate policy rule",
"eventType": "policy.rule.activate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T19:00:41.710Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016/lifecycle/activate",
"url": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016/lifecycle/activate?"
}
},
"legacyEventType": "policy.rule.activated",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "PolicyEntity",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": {
"policyType": "OKTA_SIGN_ON"
}
},
{
"id": "00000000000000000000",
"type": "PolicyRule",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
References #
policy.rule.add
#Description
Add policy rule.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000062",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Add policy rule",
"eventType": "policy.rule.add",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T19:00:41.331Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/policies/00p00000000000000015/rules",
"url": "/api/v1/policies/00p00000000000000015/rules?"
}
},
"legacyEventType": "policy.rule.added",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "PolicyEntity",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": {
"policyType": "OKTA_SIGN_ON"
}
},
{
"id": "00000000000000000000",
"type": "PolicyRule",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
References #
policy.rule.deactivate
#Description
Deactivate policy rule.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000063",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Deactivate policy rule",
"eventType": "policy.rule.deactivate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T19:00:41.581Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016/lifecycle/deactivate",
"url": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016/lifecycle/deactivate?"
}
},
"legacyEventType": "policy.rule.deactivated",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "PolicyEntity",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": {
"policyType": "OKTA_SIGN_ON"
}
},
{
"id": "00000000000000000000",
"type": "PolicyRule",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1556, T1562, T1562.007Kusto #
T1078, T1098, T1556↳ also matches policy.lifecycle.create, policy.lifecycle.deactivate, policy.lifecycle.delete, policy.lifecycle.update, policy.rule.delete, policy.rule.update
References #
policy.rule.delete
#Description
Delete policy rule.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000064",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Delete policy rule",
"eventType": "policy.rule.delete",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T19:00:42.143Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016",
"url": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016?"
}
},
"legacyEventType": "policy.rule.deleted",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "PolicyEntity",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": {
"policyType": "OKTA_SIGN_ON"
}
},
{
"id": "00000000000000000000",
"type": "PolicyRule",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1484, T1562, T1562.007Kusto #
T1078, T1098, T1556↳ also matches policy.lifecycle.create, policy.lifecycle.deactivate, policy.lifecycle.delete, policy.lifecycle.update, policy.rule.deactivate, policy.rule.update
References #
policy.rule.update
#Description
Update policy rule.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000065",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Update policy rule",
"eventType": "policy.rule.update",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T19:00:41.947Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016",
"url": "/api/v1/policies/00p00000000000000015/rules/0pr00000000000000016?"
}
},
"legacyEventType": "policy.rule.updated",
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "PolicyEntity",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": {
"policyType": "OKTA_SIGN_ON"
}
},
{
"id": "00000000000000000000",
"type": "PolicyRule",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null,
"changeDetails": {
"from": {
"policyRuleName": "dw-harn-f001873b-rule"
},
"to": {
"policyRuleName": "dw-harn-f001873b-rule-upd"
}
}
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
admin_email (panther rule field) | is_not_null | | 1 rule | panther |
is_anomalous (panther rule field) | eq | true | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1484, T1562, T1562.007Kusto #
T1078, T1098, T1556↳ also matches policy.lifecycle.create, policy.lifecycle.deactivate, policy.lifecycle.delete, policy.lifecycle.update, policy.rule.deactivate, policy.rule.delete Panther #
Okta.ADAgent.TokenAbuse.Behavioral for admin credential theft scenarios.T1098, T1556↳ also matches policy.lifecycle.update
References #
policy.scheduled.execute
#Description
Scheduled execution of policy.
Example System Log Event #
{
"published": 1780242501236,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000078",
"actor": {
"id": "spr00000000000000167",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "00p00000000000000276",
"type": "PolicyEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 92",
"detailEntry": {
"policyType": "Example Rule 6"
}
}
],
"outcome": {
"result": "FAILURE",
"reason": "Policy has inactive status"
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "policy.scheduled.execute",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "spe00000000000000277",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Scheduled execution of policy",
"gatewayContext": null,
"legacyEventType": "policy.scheduled.execute",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000278",
"externalSessionId": "trs00000000000000279"
}
}