Okta User

eventTypeDescriptionSampleRule
user.account.expire_passwordFired when the user's Okta password is expired.YN
user.account.lockAuto-lock user account for Okta.YY
user.account.lock.limitUser account reached lockout limit and will not be automatically unlocked.NY
user.account.preference_updateUser preferences updated.NN
user.account.privilege.grantA User's admin privileges changed.YY
user.account.privilege.revokeAll of user's admin privilege revoked.YN
user.account.report_suspicious_activity_by_enduserUser reported suspicious activity.YY
user.account.reset_passwordUser's Okta password has been reset.YY
user.account.subscriptions.updateAdmin subscriptions update.YN
user.account.unlockAuto-unlock user account for Okta.NN
user.account.unlock_by_adminUser account unlock by admin.YN
user.account.unlock_failureFailed to schedule unlock job for user.NN
user.account.unlock_tokenIssued recovery token for self-service account unlock.NY
user.account.update_passwordUser update password for Okta.YY
user.account.update_primary_emailUser primary email updated.NN
user.account.update_profileUpdate user profile for Okta.YN
user.account.update_secondary_emailUser secondary email updated.NN
user.account.update_user_typeFires when a user changes from one type to another.NN
user.account.use_tokenInvalid self service recovery token used by user.NN
user.authentication.authAuthenticate user.NY
user.authentication.auth_identifier_not_in_policyAuthenticate a user with an identifier that's not in the User Profile Policy.NY
user.authentication.auth_unconfigured_identifierFired after a user authenticates via a directory instance that is not the highest priority profile source for the user.NY
user.authentication.auth_via_AD_agentAuthenticate user with AD agent.YY
user.authentication.auth_via_IDPAuthenticate user via IDP.NY
user.authentication.auth_via_LDAP_agentAuthenticate user via LDAP agent.NY
user.authentication.auth_via_inbound_SAMLAuthenticate user via inbound SAML.NY
user.authentication.auth_via_inbound_delauthAuthenticate user via inbound delauth.NY
user.authentication.auth_via_iwaAuthenticate user via IWA.NY
user.authentication.auth_via_mfaAuthentication of user via MFA.YY
user.authentication.auth_via_radiusAuthentication of user via Radius.NY
user.authentication.auth_via_richclientAuthentication of a user via Rich Client.NY
user.authentication.auth_via_socialAuthenticate user with social login.NY
user.authentication.authenticateAuthentication via device trust certificate.NY
user.authentication.dsso_via_non_priority_sourceDesktop Single Sign On (DSSO) authentication has been attempted using a profile source that is not the highest priority profile source for the given Okta user.NY
user.authentication.sloUser single logout out (SLO) from app.NY
user.authentication.ssoFired when a user performs a single sign-on (SSO) to an app instance and contains the client details of the user.YY
user.authentication.universal_logoutThis event is fired when an admin or system account triggers Universal Logout against an app instance.YY
user.authentication.universal_logout.scheduledThis event is fired when an admin manually triggers Universal Logout for a user.YY
user.authentication.verifyVerify user identity.YY
user.behavior.profile.resetUser behavior profile reset.NN
user.credential.enrollDevice Trust certificate enrollment.NN
user.device_session.endUser ended a device session.NN
user.device_session.startUser established a device session.NN
user.identity_snapshot.attestation.createCreate identity snapshot attestation for a user.NN
user.identity_verificationThis event is fired when a user is directed to complete an Identity Verification as a result of an Okta Account Management (OAMP) Policy evaluation.NN
user.identity_verification.startAn Okta account management policy (OAMP) prompted the user to verify their identity with an identity verification service.NN
user.import.passwordImported user password from external system during login.NN
user.lifecycle.activateActivate Okta user.YY
user.lifecycle.createCreate Okta user.YY
user.lifecycle.deactivateDeactivate Okta user.YN
user.lifecycle.delete.completedDelete Okta user completed.YN
user.lifecycle.delete.initiatedDelete Okta user initiated.YN
user.lifecycle.jit.error.read_onlyFailed to JIT create user.NN
user.lifecycle.password_mass_expiryMass expire all users' passwords initiated.NN
user.lifecycle.reactivateReactivate Okta user.NN
user.lifecycle.suspendSuspend Okta user.YN
user.lifecycle.unsuspendUnsuspend Okta user.YN
user.mfa.attempt_bypassAttempt bypass of factor.NY
user.mfa.factor.activateActivate factor or authenticator enrollment method for user.YY
user.mfa.factor.deactivateReset factor or authenticator enrollment method for user.YY
user.mfa.factor.reset_allReset all factors or authenticator enrollments for user.YY
user.mfa.factor.suspendSuspend factor or authenticator enrollment method for user.YY
user.mfa.factor.unsuspendUnsuspend factor or authenticator enrollment method for user.YN
user.mfa.factor.updateUpdate factor for user.YY
user.mfa.okta_verifyVerify user with Okta verify.NN
user.mfa.okta_verify.deny_pushUser rejected Okta push verify.NY
user.mfa.okta_verify.deny_push_upgrade_neededRejected Okta push verify as Upgrade Needed.NN
user.risk.changeIndicates a user's risk level has changed.NN
user.risk.detectIndicates a user risk was detected.YN
user.session.access_admin_appUser accessing Okta admin app.YY
user.session.clearClear user session.YN
user.session.context.changeUser session context changed.YN
user.session.endUser logout from Okta.YN
user.session.expireExpire user session.NN
user.session.impersonation.endEnd impersonation session.NN
user.session.impersonation.extendExtend impersonation session.NN
user.session.impersonation.grantEnable impersonation grant.NY
user.session.impersonation.initiateInitiate impersonation session.NY
user.session.impersonation.revokeRevoke impersonation grant.NN
user.session.startUser login to Okta.YY
user.mfa.promote_enrollmentPromote authenticator enrollment during login to Okta.NN
user.realm.updateUser realm updated.YN

user.account.expire_password

#

Description

Fired when the user's Okta password is expired. This can be used to audit cases where a user's password is expired by an administrator. When fired, this event contains information about the user whose password was expired, whether a temporary password was created for the user, or if the user's sessions were revoked.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000100",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Fired when the user's Okta password is expired",
  "eventType": "user.account.expire_password",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T19:04:45.545Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users/00u00000000000000021/lifecycle/expire_password",
      "url": "/api/v1/users/00u00000000000000021/lifecycle/expire_password?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

user.account.lock

#

Description

Auto-lock user account for Okta.

Example System Log Event #

{
  "actor": {
    "alternateId": "user16@dw-harness.example",
    "detailEntry": null,
    "displayName": "DW Harness 25",
    "id": "00u00000000000000022",
    "type": "User"
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": null,
    "externalSessionId": "0000000000000000000000101",
    "interface": null,
    "issuer": null
  },
  "client": {
    "device": "Computer",
    "geographicalContext": {
      "city": "Anytown",
      "country": "Placeholderland",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      },
      "postalCode": "00000",
      "state": "Anystate"
    },
    "id": null,
    "ipAddress": "198.51.100.10",
    "userAgent": {
      "browser": "CHROME",
      "os": "Mac OS 14.3.1 (Sonoma)",
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
    },
    "zone": "null"
  },
  "debugContext": {
    "debugData": {
      "authnRequestId": "00000000000000000000000000000006",
      "deviceFingerprint": "00000000000000000000000000000102",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000103",
      "oktaUserAgentExtended": "okta-auth-js/7.0.1 okta-signin-widget-7.15.1",
      "requestId": "00000000000000000000000000000104",
      "requestUri": "/idp/idx/identify",
      "threatSuspected": "false",
      "url": "/idp/idx/identify?"
    }
  },
  "device": null,
  "displayMessage": "Max sign in attempts exceeded",
  "eventType": "user.account.lock",
  "legacyEventType": "core.user_auth.account_locked",
  "outcome": {
    "reason": "LOCKED_OUT",
    "result": "FAILURE"
  },
  "published": "2024-03-01T20:49:05.312Z",
  "request": {
    "ipChain": [
      {
        "geographicalContext": {
          "city": "Anytown",
          "country": "Placeholderland",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          },
          "postalCode": "00000",
          "state": "Anystate"
        },
        "ip": "198.51.100.10",
        "source": null,
        "version": "V4"
      }
    ]
  },
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "domain": "example.com",
    "isProxy": false,
    "isp": "example-isp"
  },
  "severity": "DEBUG",
  "target": null,
  "transaction": {
    "detail": {},
    "id": "00000000000000000000000000000104",
    "type": "WEB"
  },
  "uuid": "00000000-0000-0000-0000-000000000016",
  "version": "0"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
All_Changes.object_category (splunk rule field)equser1 rulesplunk
count (splunk rule field)gt51 rulesplunk
security_result.action (Chronicle)eqBLOCK1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Attempts to Brute Force an Okta User Account source medium: Identifies when an Okta user account is locked out 3 times within a 3 hour window. An adversary may attempt a brute force or password spraying attack to obtain unauthorized access to user accounts. The default Okta authentication policy ensures that a user account is locked out after 10 failed authentication attempts.T1110, T1110.001, T1110.003

Splunk #

  • Okta Multiple Accounts Locked Out source: The following analytic detects multiple Okta accounts being locked out within a short period. It uses the user.account.lock event from Okta logs, aggregated over a 5-minute window, to identify this behavior. This activity is significant as…T1110

YARA-L #

Panther #

References #

user.account.lock.limit

#

Description

User account reached lockout limit and will not be automatically unlocked. This event indicates an account that will not be able to log in until remedial action is taken by the account admin. This event can be used to understand the specifics of an account lockout. Often this indicates a client application that is repeatedly attempting to authenticate with invalid credentials such as an old password.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
security_result.action (Chronicle)eqBLOCK1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

References #

user.account.preference_update

#

Description

User preferences updated. This can be used for debugging and auditing purposes. These preferences live outside the user profile.

References #

user.account.privilege.grant

#

Description

A User's admin privileges changed. This can be used to audit the provisioning of admin privileges for users. When fired, this event contains information about the type of admin privileges the user currently has. The list of current privileges contain both individually assigned roles as well as the ones granted to the user through their group membership. Related events include: USER_ACCOUNT_PRIVILEGE_REVOKE.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000105",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Grant user privilege",
  "eventType": "user.account.privilege.grant",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:55:09.050Z",
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "privilegeGranted": "Read only admin"
    }
  },
  "legacyEventType": "core.user.admin_privilege.granted",
  "transaction": {
    "type": null,
    "id": "00000000000000000000",
    "detail": {}
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": []
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    },
    {
      "id": "00000000000000000000",
      "type": "ROLE_ASSIGNED",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    },
    {
      "id": "00000000000000000000",
      "type": "ROLE",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventTypeequser.account.privilege.grant3 rulespanther, sigma
eventTypeeqgroup.privilege.grant2 rulespanther, sigma
okta::eventType (kusto rule field)inpolicy.evaluate_sign_on1 rulekusto
okta::eventType (kusto rule field)insystem.api_token.create1 rulekusto
outcome.result (panther rule field)eqSUCCESS1 rulepanther
p_occurs_between (panther rule field)macro'2022-01-14' , '2022-03-22'1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Okta User Assigned Administrator Role source medium: Identifies when an administrator role is assigned to an Okta user or group. Adversaries may assign administrator privileges to compromised accounts to establish persistence, escalate privileges, and maintain long-term access to the environment. This detection monitors for both user-level and group-level administrator privilege grants, which can be used to bypass security controls and perform unauthorized administrative actions.T1098, T1098.003

Kusto #

Panther #

References #

user.account.privilege.revoke

#

Description

All of user's admin privilege revoked. This can be used to audit the deprovisioning of admin privileges from users. When fired, this event indicates the user has no more admin privileges. All of user's privileges were revoked including individually assigned roles as well as the ones granted to the user through their group membership. Related events include: USER_ACCOUNT_PRIVILEGE_GRANT.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000106",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Revoke user privilege",
  "eventType": "user.account.privilege.revoke",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:55:09.304Z",
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "privilegeRevoked": "Super administrator, Organization administrator, Application administrator (all), Application administrator, Read only admin, User administrator (all), User administrator, Help Desk administrator (all), Help Desk administrator, Mobile administrator, API Access Management administrator, Report administrator, Group Membership administrator"
    }
  },
  "legacyEventType": "core.user.admin_privilege.revoked",
  "transaction": {
    "type": null,
    "id": "00000000000000000000",
    "detail": {}
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": []
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    },
    {
      "id": "00000000000000000000",
      "type": "ROLE_UNASSIGNED_ALL_PRIVILEGES_REVOKED",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    },
    {
      "id": "00000000000000000000",
      "type": "ROLE",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

user.account.report_suspicious_activity_by_enduser

#

Description

User reported suspicious activity. This event is used to identify user account suspicious activity.

Example System Log Event #

{
  "actor": {
    "alternateId": "user11@dw-harness.example",
    "detailEntry": null,
    "displayName": "DW Harness 25",
    "id": "00u00000000000000022",
    "type": "User"
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": null,
    "externalSessionId": "0000000000000000000000107",
    "interface": null,
    "issuer": null
  },
  "client": {
    "device": "Computer",
    "geographicalContext": {
      "city": "Anytown",
      "country": "Placeholderland",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      },
      "postalCode": "00000",
      "state": "Anystate"
    },
    "id": null,
    "ipAddress": "198.51.100.10",
    "userAgent": {
      "browser": "CHROME",
      "os": "Mac OS 11.3.1 (Sonoma)",
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
    },
    "zone": "null"
  },
  "debugContext": {
    "debugData": {
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000103",
      "requestId": "00000000000000000000000000000108",
      "requestUri": "/api/internal/users/me/report-suspicious-activity",
      "suspiciousActivityBrowser": "CHROME",
      "suspiciousActivityEventCity": "Ohio",
      "suspiciousActivityEventCountry": "United States",
      "suspiciousActivityEventId": "00000000-0000-0000-0000-000000000017",
      "suspiciousActivityEventIp": "198.51.100.10",
      "suspiciousActivityEventLatitude": "20.7652",
      "suspiciousActivityEventLongitude": "-20.9588",
      "suspiciousActivityEventState": "Ohio",
      "suspiciousActivityEventTransactionId": "00000000000000000000000000000007",
      "suspiciousActivityEventType": "system.email.mfa_reset_notification.sent_message",
      "suspiciousActivityOs": "Mac OS 14.3.1 (Sonoma)",
      "suspiciousActivityTimestamp": "2024-03-11T16:28:18.184Z",
      "url": "/api/internal/users/me/report-suspicious-activity?i=0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002"
    }
  },
  "device": null,
  "displayMessage": "User report suspicious activity",
  "eventType": "user.account.report_suspicious_activity_by_enduser",
  "legacyEventType": "core.user.account.report_suspicious_activity_by_enduser",
  "outcome": {
    "reason": null,
    "result": "SUCCESS"
  },
  "published": "2024-03-11T16:28:40.048Z",
  "request": {
    "ipChain": [
      {
        "geographicalContext": {
          "city": "Anytown",
          "country": "Placeholderland",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          },
          "postalCode": "00000",
          "state": "Anystate"
        },
        "ip": "198.51.100.10",
        "source": null,
        "version": "V4"
      }
    ]
  },
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "domain": "example.com",
    "isProxy": false,
    "isp": "example-isp"
  },
  "severity": "WARN",
  "target": [
    {
      "alternateId": "user11@dw-harness.example",
      "detailEntry": null,
      "displayName": "DW Harness 26",
      "id": "00u00000000000000022",
      "type": "User"
    }
  ],
  "transaction": {
    "detail": {},
    "id": "00000000000000000000000000000108",
    "type": "WEB"
  },
  "uuid": "00000000-0000-0000-0000-000000000018",
  "version": "0"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventTypeequser.account.report_suspicious_activity_by_enduser2 rulessigma, splunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Suspicious Activity Reported by Okta User source medium: Detects when a user reports suspicious activity for their Okta account. These events should be investigated, as they can help security teams identify when an adversary is attempting to gain access to their network.T1078

Splunk #

  • Okta Suspicious Activity Reported source: The following analytic identifies when an associate reports a login attempt as suspicious via an email from Okta. It leverages Okta Identity Management logs, specifically the user.account.report_suspicious_activity_by_enduser event type.…T1078, T1078.001

YARA-L #

Panther #

  • Okta User Reported Suspicious Activity source high: Suspicious Activity Reporting provides an end user with the option to report unrecognized activity from an account activity email notification. This detection alerts when a user marks the raised activity as suspicious.

References #

user.account.reset_password

#

Description

User's Okta password has been reset.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000109",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Fired when the user's Okta password is reset",
  "eventType": "user.account.reset_password",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:54:57.536Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "traceId": "00000000-0000-0000-0000-000000000000",
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users/00u00000000000000023/lifecycle/reset_password",
      "url": "/api/v1/users/00u00000000000000023/lifecycle/reset_password?sendEmail=false"
    }
  },
  "legacyEventType": "core.user.config.user_status.password_reset",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventType (panther rule field)inuser.account.reset_password2 rulespanther
eventType (panther rule field)inuser.mfa.factor.update2 rulespanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

References #

user.account.subscriptions.update

#

Description

Admin subscriptions update. Use this event to track and audit updated email subscriptions for an admin. This event contains information about email subscription updates for an admin user. Email subscriptions determine the email notification type that Okta sends to an admin user.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000071",
    "externalSessionId": "trs00000000000000072"
  },
  "displayMessage": "Admin subscriptions updated",
  "eventType": "user.account.subscriptions.update",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:24:07.373Z",
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "severity": "DEBUG",
  "debugContext": {
    "debugData": {}
  },
  "gatewayContext": null,
  "legacyEventType": null,
  "transaction": {
    "type": null,
    "id": "0000002",
    "detail": {}
  },
  "uuid": "00000000-0000-0000-0000-000000000101",
  "version": "0",
  "request": {
    "ipChain": []
  },
  "target": [
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "OKTA_ISSUE"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "USER_LOCKED_OUT"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "AD_AGENT"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "OKTA_ANNOUNCEMENT"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "DISASTER_RECOVERY_NOTIFICATION"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "REPORT_SUSPICIOUS_ACTIVITY"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "RATELIMIT_NOTIFICATION"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "USER_DEPROVISION"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "IWA_AGENT"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "LDAP_AGENT"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "CONNECTOR_AGENT"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "APP_IMPORT"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "PROTECTED_ACTIONS_NOTIFICATION"
      }
    },
    {
      "id": "00u00000000000000073",
      "type": "User",
      "alternateId": null,
      "displayName": "DW Harness 03",
      "detailEntry": {
        "notificationStatus": "unsubscribed",
        "notificationChannels": "[email]",
        "notificationType": "OKTA_UPDATE"
      }
    }
  ]
}

References #

user.account.unlock

#

Description

Auto-unlock user account for Okta.

References #

user.account.unlock_by_admin

#

Description

User account unlock by admin.

Example System Log Event #

{
  "published": 1780403843261,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000129",
  "actor": {
    "id": "00u00000000000000164",
    "type": "User",
    "alternateId": "user03@dw-harness.example",
    "displayName": "DW Harness 04",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.5",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000330",
      "type": "User",
      "alternateId": "user72@dw-harness.example",
      "displayName": "DW Harness 113",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.5",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "user.account.unlock_by_admin",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000066",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000066",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000029",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "000000000000000000000000000000000000000000000000002",
      "url": "000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "User account unlock by admin",
  "gatewayContext": null,
  "legacyEventType": "core.user_auth.account_unlocked_by_admin",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000331",
    "externalSessionId": "10200000000000000331"
  }
}

References #

user.account.unlock_failure

#

Description

Failed to schedule unlock job for user.

References #

user.account.unlock_token

#

Description

Issued recovery token for self-service account unlock.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.account.update_password

#

Description

User update password for Okta.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000110",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "User update password for Okta",
  "eventType": "user.account.update_password",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T19:04:45.332Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users",
      "url": "/api/v1/users?activate=true"
    }
  },
  "legacyEventType": "core.user.config.password_update.success",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventType (panther rule field)inuser.account.reset_password1 rulepanther
eventType (panther rule field)inuser.mfa.factor.update1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

user.account.update_primary_email

#

Description

User primary email updated.

References #

user.account.update_profile

#

Description

Update user profile for Okta.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000111",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Update user profile for Okta",
  "eventType": "user.account.update_profile",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:48.087Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users/00u00000000000000024",
      "changedAttributes": "nickName",
      "url": "/api/v1/users/00u00000000000000024?"
    }
  },
  "legacyEventType": "core.user.config.profile_update.success",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

user.account.update_secondary_email

#

Description

User secondary email updated.

References #

user.account.update_user_type

#

Description

Fires when a user changes from one type to another. Can be used to audit when a user gets converted from a contractor to a full-time employee, for example. Data includes the old and new type ids. There may be an accompanying update_profile event if values were changed.

References #

user.account.use_token

#

Description

Invalid self service recovery token used by user.

References #

user.authentication.auth

#

Description

Authenticate user.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)equser.session.start8 ruleselastic
EventType (elastic rule field)starts_withuser.authentication.8 ruleselastic
okta::actor.alternateId (elastic rule field)is_not_null6 ruleselastic
okta::outcome.reason (elastic rule field)ininvalid_credentials5 ruleselastic
okta::outcome.reason (elastic rule field)inlocked_out5 ruleselastic
Esql.total_attempts (elastic rule field)ge102 ruleselastic
Esql.total_attempts (elastic rule field)ge252 ruleselastic
Esql.unique_source_ips (elastic rule field)ge52 ruleselastic
okta::debugContext.debugData.dt_hash (elastic rule field)is_not_null1 ruleelastic
okta::debugContext.debugData.dt_hash (elastic rule field)ne-1 ruleelastic
okta::outcome.result (elastic rule field)eqsuccess1 ruleelastic
okta::securityContext.isProxy (elastic rule field)eqtrue1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.auth_identifier_not_in_policy

#

Description

Authenticate a user with an identifier that's not in the User Profile Policy. Identify users who authenticate with an identifier that's not in the User Profile Policy's configured identifier list. Add the identifier to the policy before delegated authentication is disabled (manually or through a Password Migration campaign) to prevent lockout. Distinct from user.authentication.auth_unconfigured_identifier, which concerns directory source priority rather than User Profile Policy identifier rules.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)equser.session.start8 ruleselastic
EventType (elastic rule field)starts_withuser.authentication.8 ruleselastic
okta::actor.alternateId (elastic rule field)is_not_null6 ruleselastic
okta::outcome.reason (elastic rule field)ininvalid_credentials5 ruleselastic
okta::outcome.reason (elastic rule field)inlocked_out5 ruleselastic
Esql.total_attempts (elastic rule field)ge102 ruleselastic
Esql.total_attempts (elastic rule field)ge252 ruleselastic
Esql.unique_source_ips (elastic rule field)ge52 ruleselastic
okta::debugContext.debugData.dt_hash (elastic rule field)is_not_null1 ruleelastic
okta::debugContext.debugData.dt_hash (elastic rule field)ne-1 ruleelastic
okta::outcome.result (elastic rule field)eqsuccess1 ruleelastic
okta::securityContext.isProxy (elastic rule field)eqtrue1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.auth_unconfigured_identifier

#

Description

Fired after a user authenticates via a directory instance that is not the highest priority profile source for the user. This can be used to track users that are using an identifier to login which is different from the admin configured identifier for that user which might result in unexpected login results. When fired, this event will contain useful information about the user, the directory instance that was used to login the user, and the directory instance that should have been used instead.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)equser.session.start8 ruleselastic
EventType (elastic rule field)starts_withuser.authentication.8 ruleselastic
okta::actor.alternateId (elastic rule field)is_not_null6 ruleselastic
okta::outcome.reason (elastic rule field)ininvalid_credentials5 ruleselastic
okta::outcome.reason (elastic rule field)inlocked_out5 ruleselastic
Esql.total_attempts (elastic rule field)ge102 ruleselastic
Esql.total_attempts (elastic rule field)ge252 ruleselastic
Esql.unique_source_ips (elastic rule field)ge52 ruleselastic
okta::debugContext.debugData.dt_hash (elastic rule field)is_not_null1 ruleelastic
okta::debugContext.debugData.dt_hash (elastic rule field)ne-1 ruleelastic
okta::outcome.result (elastic rule field)eqsuccess1 ruleelastic
okta::securityContext.isProxy (elastic rule field)eqtrue1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.auth_via_AD_agent

#

Description

Authenticate user with AD agent.

Example System Log Event #

{
  "actor": {
    "alternateId": "user15@dw-harness.example",
    "detailEntry": null,
    "displayName": "DW Harness 24",
    "id": "0000000000000000096",
    "type": "User"
  },
  "authenticationContext": {
    "authenticationProvider": "ACTIVE_DIRECTORY",
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": "PASSWORD",
    "externalSessionId": "0000000000000000000000097",
    "interface": "AD APP Instance",
    "issuer": null,
    "rootSessionId": "0000000000000000000000097"
  },
  "client": {
    "device": "Computer",
    "geographicalContext": {
      "city": "Anytown",
      "country": "Placeholderland",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      },
      "postalCode": "00000",
      "state": "Anystate"
    },
    "id": null,
    "ipAddress": "198.51.100.13",
    "userAgent": {
      "browser": "CHROME",
      "os": "Windows 10",
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36"
    },
    "zone": "null"
  },
  "debugContext": {
    "debugData": {
      "actionid": "rpc::0000000000000000000000000000000000000000000003//1731969275290//00000000000000000000000000000008:00000000-0000-0000-0000-000000000019:",
      "agentid": "a5300000000000000013",
      "authnRequestId": "00000000000000000000000000000005",
      "behaviors": "{New Geo-Location=POSITIVE, New Device=POSITIVE, New IP=POSITIVE, New State=POSITIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}",
      "delauthtimeout": "4000",
      "delauthtimespentatagent": "16",
      "delauthtimespentatdomaincontroller": "16",
      "delauthtimetotal": "184",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000112",
      "errorCode": "1326",
      "requestId": "00000000000000000000000000000113",
      "requestUri": "/idp/idx/challenge/answer",
      "risk": "{reasons=Anomalous Device, level=MEDIUM}",
      "threatSuspected": "false",
      "url": "/idp/idx/challenge/answer?"
    }
  },
  "device": null,
  "displayMessage": "Authenticate user with AD agent",
  "eventType": "user.authentication.auth_via_AD_agent",
  "legacyEventType": "app.ad.login.bad_password",
  "outcome": {
    "reason": "Authentication failed: bad username or password",
    "result": "FAILURE"
  },
  "published": "2024-11-18T22:34:31.474Z",
  "request": {
    "ipChain": [
      {
        "geographicalContext": {
          "city": "Anytown",
          "country": "Placeholderland",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          },
          "postalCode": "00000",
          "state": "Anystate"
        },
        "ip": "198.51.100.13",
        "source": null,
        "version": "V4"
      }
    ]
  },
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "domain": "example.com",
    "isProxy": false,
    "isp": "example-isp"
  },
  "severity": "ERROR",
  "target": [
    {
      "alternateId": "user17@dw-harness.example",
      "detailEntry": null,
      "displayName": "DW Harness 27",
      "id": "00000000000000000114",
      "type": "AppUser"
    },
    {
      "alternateId": "user18@dw-harness.example",
      "detailEntry": null,
      "displayName": "DW Harness 28",
      "id": "0oa00000000000000025",
      "type": "AppInstance"
    }
  ],
  "transaction": {
    "detail": {},
    "id": "00000000000000000000000000000113",
    "type": "WEB"
  },
  "uuid": "00000000-0000-0000-0000-000000000020",
  "version": "0"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)equser.session.start8 ruleselastic
EventType (elastic rule field)starts_withuser.authentication.8 ruleselastic
okta::actor.alternateId (elastic rule field)is_not_null6 ruleselastic
okta::outcome.reason (elastic rule field)ininvalid_credentials5 ruleselastic
okta::outcome.reason (elastic rule field)inlocked_out5 ruleselastic
Esql.total_attempts (elastic rule field)ge102 ruleselastic
Esql.total_attempts (elastic rule field)ge252 ruleselastic
Esql.unique_source_ips (elastic rule field)ge52 ruleselastic
is_anomalous (panther rule field)eqtrue1 rulepanther
okta::debugContext.debugData.dt_hash (elastic rule field)is_not_null1 ruleelastic
okta::debugContext.debugData.dt_hash (elastic rule field)ne-1 ruleelastic
okta::outcome.result (elastic rule field)eqsuccess1 ruleelastic
okta::securityContext.isProxy (elastic rule field)eqtrue1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

  • Okta AD Agent Authentication Anomaly - Z-Score Detection source medium linked query: Query.Okta.ADAgentAuthZScoreAnomaly: Detects potential Okta AD Agent token theft and credential abuse using statistical z-score analysis. This detection uses a lookup table containing 90-day behavioral baselines for each user's AD Agent authentication patterns, then calculates z-scores to identify suspicious activity in the last 7 days. PREREQUISITES: 1. Baseline builder query must run first: Query.Okta.ADAgentBaselineBuilder 2. Lookup table must be configured: okta_ad_pantherflow_baseline_90d 3. Allow 24 hours for initial baseline to populate Detection Logic: - Calculates mean and standard deviation for hourly authentication volume, IP diversity, country diversity, and device diversity - Alerts when recent activity shows BOTH: 1. Volume spike (z-score > 3 standard deviations) 2. Geographic/IP diversity spike (z-score > 2 standard deviations) Why This Matters: Token theft attacks have a distinct signature: stolen credentials are used from multiple locations/IPs simultaneously or in rapid succession. This creates both a volume spike and a diversity spike that this detection identifies. Complementary Detection: This rule complements Okta.ADAgent.TokenAbuse.Behavioral which detects admin actions (token creation, agent configuration) from new sources. This rule detects the actual USE of stolen tokens through authentication patterns.T1078, T1110, T1528
  • Query.Okta.ADAgentAuthZScoreAnomaly source: Detects anomalous authentication patterns via Okta AD Agent using z-score statistical analysis. Reads behavioral baseline from lookup table and alerts when recent activity shows volume spikes combined with geographic/IP diversity anomalies - indicators of token theft and credential abuse. PREREQUISITE: Requires the baseline builder query to populate the lookup table first.

References #

user.authentication.auth_via_IDP

#

Description

Authenticate user via IDP.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)equser.session.start8 ruleselastic
EventType (elastic rule field)starts_withuser.authentication.8 ruleselastic
okta::actor.alternateId (elastic rule field)is_not_null6 ruleselastic
okta::outcome.reason (elastic rule field)ininvalid_credentials5 ruleselastic
okta::outcome.reason (elastic rule field)inlocked_out5 ruleselastic
Esql.total_attempts (elastic rule field)ge102 ruleselastic
Esql.total_attempts (elastic rule field)ge252 ruleselastic
Esql.unique_source_ips (elastic rule field)ge52 ruleselastic
okta::debugContext.debugData.dt_hash (elastic rule field)is_not_null1 ruleelastic
okta::debugContext.debugData.dt_hash (elastic rule field)ne-1 ruleelastic
okta::outcome.result (elastic rule field)eqfailure1 ruleelastic
okta::outcome.result (elastic rule field)eqsuccess1 ruleelastic
okta::securityContext.isProxy (elastic rule field)eqtrue1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

  • Okta Identity Provider Sign-in source high: A user has signed in using a 3rd party Identity Provider. Attackers have been observed configuring a second Identity Provider to act as an "impersonation app" to access applications within the compromised Org on behalf of other users. This second Identity Provider, also controlled by the attacker, would act as a “source” IdP in an inbound federation relationship (sometimes called “Org2Org”) with the target. From this “source” IdP, the threat actor manipulated the username parameter for targeted users in the second “source” Identity Provider to match a real user in the compromised “target” Identity Provider. This provided the ability to Single sign-on (SSO) into applications in the target IdP as the targeted user. Do not use this rule if your organization uses legitimate 3rd-party Identity Providers.T1098, T1199

References #

user.authentication.auth_via_LDAP_agent

#

Description

Authenticate user via LDAP agent.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)equser.session.start8 ruleselastic
EventType (elastic rule field)starts_withuser.authentication.8 ruleselastic
okta::actor.alternateId (elastic rule field)is_not_null6 ruleselastic
okta::outcome.reason (elastic rule field)ininvalid_credentials5 ruleselastic
okta::outcome.reason (elastic rule field)inlocked_out5 ruleselastic
Esql.total_attempts (elastic rule field)ge102 ruleselastic
Esql.total_attempts (elastic rule field)ge252 ruleselastic
Esql.unique_source_ips (elastic rule field)ge52 ruleselastic
okta::debugContext.debugData.dt_hash (elastic rule field)is_not_null1 ruleelastic
okta::debugContext.debugData.dt_hash (elastic rule field)ne-1 ruleelastic
okta::outcome.result (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.auth_via_inbound_SAML

#

Description

Authenticate user via inbound SAML.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)equser.session.start8 ruleselastic
EventType (elastic rule field)starts_withuser.authentication.8 ruleselastic
okta::actor.alternateId (elastic rule field)is_not_null6 ruleselastic
okta::outcome.reason (elastic rule field)ininvalid_credentials5 ruleselastic
okta::outcome.reason (elastic rule field)inlocked_out5 ruleselastic
Esql.total_attempts (elastic rule field)ge102 ruleselastic
Esql.total_attempts (elastic rule field)ge252 ruleselastic
Esql.unique_source_ips (elastic rule field)ge52 ruleselastic
okta::debugContext.debugData.dt_hash (elastic rule field)is_not_null1 ruleelastic
okta::debugContext.debugData.dt_hash (elastic rule field)ne-1 ruleelastic
okta::outcome.result (elastic rule field)eqfailure1 ruleelastic
okta::outcome.result (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.auth_via_inbound_delauth

#

Description

Authenticate user via inbound delauth.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)equser.session.start8 ruleselastic
EventType (elastic rule field)starts_withuser.authentication.8 ruleselastic
okta::outcome.reason (elastic rule field)ininvalid_credentials5 ruleselastic
okta::outcome.reason (elastic rule field)inlocked_out5 ruleselastic
Esql.total_attempts (elastic rule field)ge102 ruleselastic
Esql.total_attempts (elastic rule field)ge252 ruleselastic
Esql.unique_source_ips (elastic rule field)ge52 ruleselastic
okta::debugContext.debugData.dt_hash (elastic rule field)is_not_null1 ruleelastic
okta::debugContext.debugData.dt_hash (elastic rule field)ne-1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.auth_via_iwa

#

Description

Authenticate user via IWA.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.auth_via_mfa

#

Description

Authentication of user via MFA. For Okta Classic orgs, this event will only fire for second factor verifications, whereas for Identity Engine orgs, this event will fire for both primary and second factor verifications.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000128",
    "type": "User",
    "alternateId": "user33@dw-harness.example",
    "displayName": "DW Harness 60",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
      "os": "Windows 11",
      "browser": "CHROMIUM_EDGE"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": {
    "id": null,
    "name": null,
    "os_platform": null,
    "os_version": null,
    "managed": null,
    "registered": null,
    "device_integrator": {
      "DEVICE_IDP": {}
    },
    "disk_encryption_type": null,
    "screen_lock_type": null,
    "jailbreak": null,
    "secure_hardware_present": null
  },
  "authenticationContext": {
    "authenticationProvider": "FACTOR_PROVIDER",
    "credentialProvider": "OKTA_CREDENTIAL_PROVIDER",
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000131",
    "externalSessionId": "idx00000000000000131"
  },
  "displayMessage": "Authentication of user via MFA",
  "eventType": "user.authentication.auth_via_mfa",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-26T00:27:43.233Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "HIGH",
      "reasons": [
        "Anomalous Location",
        "Anomalous Device"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000132",
        "result": "UNKNOWN"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000133",
        "result": "UNKNOWN"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000134",
        "result": "UNKNOWN"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000135",
        "result": "UNKNOWN"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000136",
        "result": "UNKNOWN"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000137",
        "result": "UNKNOWN"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000138",
        "result": "UNKNOWN"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000139",
        "result": "UNKNOWN"
      }
    ]
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "traceId": "00000000-0000-0000-0000-000000000155",
      "deviceFingerprint": "00000000000000000000000000000122",
      "behaviors": "{New Geo-Location=UNKNOWN, New Device=UNKNOWN, New ASN=UNKNOWN, New IP=UNKNOWN, New State=UNKNOWN, New Country=UNKNOWN, Velocity=UNKNOWN, New City=UNKNOWN}",
      "authenticatorMethodChallengeTime": "2026-07-26T00:27:42.721Z",
      "origin": "https://dev-00000.okta.com",
      "requestUri": "/idp/idx/challenge/answer",
      "url": "/idp/idx/challenge/answer?",
      "authnRequestId": "00000000000000000000000000000121",
      "requestId": "00000000000000000000000000000124",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000005",
      "risk": "{reasons=Anomalous Location, Anomalous Device, level=HIGH}",
      "threatSuspected": "false",
      "factor": "PASSWORD_AS_FACTOR",
      "factorIntent": "AUTHENTICATION"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "core.user.factor.attempt_success",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000124",
    "detail": {}
  },
  "uuid": "00000000-0000-0000-0000-000000000156",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00u00000000000000128",
      "type": "User",
      "alternateId": "user33@dw-harness.example",
      "displayName": "DW Harness 60",
      "detailEntry": null
    },
    {
      "id": "lae00000000000000144",
      "type": "AuthenticatorEnrollment",
      "alternateId": "user03@dw-harness.example",
      "displayName": "Password",
      "detailEntry": {
        "methodTypeUsed": "Password",
        "methodUsedVerifiedProperties": "[USER_PRESENCE]"
      }
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventTypeequser.authentication.auth_via_mfa6 rulespanther, sigma, splunk
okta::eventTypeequser.authentication.auth_via_mfa5 ruleselastic, kusto
okta::eventTypeequser.mfa.okta_verify.deny_push3 ruleselastic, kusto
okta::eventType (elastic rule field)inuser.authentication.auth_via_mfa3 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.sso3 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.verify3 ruleselastic
okta::eventType (elastic rule field)inuser.session.start3 ruleselastic
security_result.action (Chronicle)eqBLOCK3 ruleschronicle
okta::debugContext.debugData.factor (elastic rule field)eqOKTA_VERIFY_PUSH2 ruleselastic
okta::outcome.reason (elastic rule field)eqINVALID_CREDENTIALS2 ruleselastic
okta::outcome.result (elastic rule field)eqSUCCESS2 ruleselastic
okta::securityContext.isProxy (elastic rule field)eqtrue2 ruleselastic
outcome.reasoneqfastpass declined phishing attempt2 rulessigma, splunk
outcome.resulteqfailure2 rulessigma, splunk
security_result.detection_fields["factor"] (Chronicle)eqOKTA_VERIFY_PUSH2 ruleschronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Splunk #

Kusto #

YARA-L #

Panther #

References #

user.authentication.auth_via_radius

#

Description

Authentication of user via Radius.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.auth_via_richclient

#

Description

Authentication of a user via Rich Client.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.auth_via_social

#

Description

Authenticate user with social login.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::outcome.result (elastic rule field)eqfailure1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.authenticate

#

Description

Authentication via device trust certificate.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.dsso_via_non_priority_source

#

Description

Desktop Single Sign On (DSSO) authentication has been attempted using a profile source that is not the highest priority profile source for the given Okta user. This event may indicate a potential security risk as the highest priority profile source is often expected to be used in this flow. The presence of this event may be benign, or it may indicate an attempt to authenticate the user from a compromised Active Directory domain. The debugContext object in this event contains useful information regarding the Okta user, the prioritized profile source, and the profile source that was used in the DSSO attempt.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.slo

#

Description

User single logout out (SLO) from app.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.sso

#

Description

Fired when a user performs a single sign-on (SSO) to an app instance and contains the client details of the user. Can be used to identify when a user attempted to sign into an application for audit or debugging purposes. Note that the event is fired even when the sign-on is unsuccessful.

Example System Log Event #

{
  "actor": {
    "alternateId": "user10@dw-harness.example",
    "detailEntry": null,
    "displayName": "DW Harness 13",
    "id": "00u00000000000000012",
    "type": "User"
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": null,
    "externalSessionId": "0000000000000000000000052",
    "interface": null,
    "issuer": null
  },
  "client": {
    "device": "Computer",
    "geographicalContext": {
      "city": "Anytown",
      "country": "Placeholderland",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      },
      "postalCode": "00000",
      "state": "Anystate"
    },
    "id": "00000000000000000000000000000000000000118",
    "ipAddress": "198.51.100.8",
    "userAgent": {
      "browser": "CHROME",
      "os": "Mac OS 13.6.6 (Ventura)",
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
    },
    "zone": "null"
  },
  "debugContext": {
    "debugData": {
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000119",
      "initiationType": "NA",
      "redirectUri": "https://dev-00000.okta.com/enduser/callback",
      "requestId": "00000000000000000000000000000120",
      "requestUri": "/oauth2/v1/token",
      "signOnMode": "OpenID Connect",
      "threatSuspected": "false",
      "url": "/oauth2/v1/token?"
    }
  },
  "device": null,
  "displayMessage": "User single sign on to app",
  "eventType": "user.authentication.sso",
  "legacyEventType": "app.auth.sso",
  "outcome": {
    "reason": null,
    "result": "SUCCESS"
  },
  "published": "2024-04-08T19:08:02.941Z",
  "request": {
    "ipChain": [
      {
        "geographicalContext": {
          "city": "Anytown",
          "country": "Placeholderland",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          },
          "postalCode": "00000",
          "state": "Anystate"
        },
        "ip": "198.51.100.8",
        "source": null,
        "version": "V4"
      }
    ]
  },
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "domain": "example.com",
    "isProxy": false,
    "isp": "example-isp"
  },
  "severity": "INFO",
  "target": [
    {
      "alternateId": "Okta Dashboard",
      "detailEntry": {
        "signOnModeType": "OPENID_CONNECT"
      },
      "displayName": "Okta Dashboard",
      "id": "0oa00000000000000003",
      "type": "AppInstance"
    },
    {
      "alternateId": "user10@dw-harness.example",
      "detailEntry": null,
      "displayName": "DW Harness 13",
      "id": "00000000000000000121",
      "type": "AppUser"
    }
  ],
  "transaction": {
    "detail": {},
    "id": "00000000000000000000000000000120",
    "type": "WEB"
  },
  "uuid": "00000000-0000-0000-0000-000000000022",
  "version": "0"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::eventType (elastic rule field)equser.authentication.auth_via_mfa2 ruleselastic
okta::eventType (elastic rule field)equser.mfa.okta_verify.deny_push2 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.sso4 ruleselastic
okta::eventType (elastic rule field)inuser.session.start4 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.auth_via_mfa3 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.verify3 ruleselastic
eventTypeequser.authentication.sso2 rulespanther, splunk
eventType (splunk rule field)eqpolicy.evaluate_sign_on1 rulesplunk
okta::debugContext.debugData.factor (elastic rule field)eqOKTA_VERIFY_PUSH2 ruleselastic
okta::outcome.reason (elastic rule field)eqINVALID_CREDENTIALS2 ruleselastic
okta::outcome.result (elastic rule field)eqSUCCESS2 ruleselastic
okta::securityContext.isProxy (elastic rule field)eqtrue2 ruleselastic
admin_email (panther rule field)is_not_null1 rulepanther
is_anomalous (panther rule field)eqtrue1 rulepanther
okta::actor.alternateId (elastic rule field)nesystem@okta.com1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

YARA-L #

Panther #

  • Okta Potentially Stolen Session source high: This rule looks for the same session being used from two devices, indicating a compromised session token.T1539↳ also matches user.session.start
  • SIGNAL - Okta SSO to AWS source informational
  • Okta SWA Bulk Access, New Source, and Credential Extraction - Behavioral source high linked query: Query.Okta.SWABulkAccessBehavioral: Detects Okta SWA (Secure Web Authentication) bulk credential extraction, abuse, and access from previously unseen IP addresses or user agents using behavioral z-score and source novelty analysis. SWA apps store credentials in Okta's encrypted vault. Admin accounts with SWA access can view or rotate credentials for users across many apps. This detection builds a 90-day behavioral baseline for each admin's SWA access, credential change patterns, and known source IPs/user agents, then identifies anomalous spikes or new sources in the last 7 days. Detection Logic: - Z-score: SWA authentication volume spike (> 3σ above baseline) - Z-score: Unique SWA app diversity spike (many different apps accessed in one hour) (> 3σ) - Z-score: Credential extraction volume spike (> 3σ) - Z-score: Victim diversity spike (credential changes across many users) (> 2σ) - Cold-start: First-time bulk SWA access (>= 10 events, no prior baseline) - Cold-start: First-time credential extraction (>= 5 extractions, no prior baseline) - New source: SWA access from IP address not seen in 90-day baseline - New source: SWA access from user agent not seen in 90-day baseline - Critical compound: New IP + any credential extraction events Why This Matters: SWA credential extraction is a powerful lateral movement technique. An attacker with admin access can silently retrieve plaintext credentials for hundreds of SWA-protected applications without triggering MFA or generating obvious authentication failures. New source detection catches the initial access phase when a compromised admin account is used from an unfamiliar device or location. Complementary Detection: Use alongside Okta.SWA.OffHoursAccess.Behavioral which detects the same attack vector occurring outside normal business hours.T1078, T1213, T1555

References #

user.authentication.universal_logout

#

Description

This event is fired when an admin or system account triggers Universal Logout against an app instance. It contains the app instance details for which the Universal Logout API was fired. This event identifies when applications have had Universal Logout triggered for audit or debugging purposes. This event is only fired once. It's only fired for applications that have been configured for Universal Logout. You can configure it under Risk policy, Post Auth Session policy, or in an admin-initiated Clear User Session.

Example System Log Event #

{
  "published": 1782417655119,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000130",
  "actor": {
    "id": "00u00000000000000332",
    "type": "User",
    "alternateId": "user73@dw-harness.example",
    "displayName": "DW Harness 114",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000333",
      "type": "User",
      "alternateId": "user03@dw-harness.example",
      "displayName": "DW Harness 04",
      "detailEntry": {
        "realmId": "guo00000000000000062"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "user.authentication.universal_logout",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rsu00000000000000334",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "traceId": "00000000-0000-0000-0000-000000000131",
      "appInstanceIds": []
    }
  },
  "displayMessage": "Universal Logout",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000335",
    "externalSessionId": "trs00000000000000336"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.universal_logout.scheduled

#

Description

This event is fired when an admin manually triggers Universal Logout for a user. It contains context about the initiating request, such as where the request originated and how the Universal Logout endpoint was invoked. After Universal Logout is complete, the user.authentication.universal_logout event is fired, and you can correlate both events using the traceID. This event identifies the geolocation, IP address, and IP chain of the requesting entity. This event is only fired once. You can correlate this event with the user.authentication.universal_logout event using traceID.

Example System Log Event #

{
  "published": 1782417654400,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000132",
  "actor": {
    "id": "00u00000000000000332",
    "type": "User",
    "alternateId": "user73@dw-harness.example",
    "displayName": "DW Harness 114",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
      "os": "Windows 11",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.5",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000333",
      "type": "User",
      "alternateId": "user03@dw-harness.example",
      "displayName": "DW Harness 04",
      "detailEntry": {
        "realmId": "guo00000000000000062"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.5",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "user.authentication.universal_logout.scheduled",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000067",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "traceId": "00000000-0000-0000-0000-000000000131",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000067",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000025",
      "origin": "https://app.example.com App app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "/oauth2/v1/global-token-revocation",
      "url": "/oauth2/v1/global-token-revocation?"
    }
  },
  "displayMessage": "Universal Logout scheduled",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000335",
    "externalSessionId": "10200000000000000335"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

user.authentication.verify

#

Description

Verify user identity.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000147",
    "type": "User",
    "alternateId": "user39@dw-harness.example",
    "displayName": "DW Harness 64",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000148",
    "externalSessionId": "10200000000000000148"
  },
  "displayMessage": "Verify user identity",
  "eventType": "user.authentication.verify",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-26T00:41:14.179Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "authnRequestId": "00000000000000000000000000000128",
      "requestId": "00000000000000000000000000000128",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000006",
      "requestUri": "/api/v1/authn",
      "threatSuspected": "false",
      "url": "/api/v1/authn?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000128",
    "detail": {}
  },
  "uuid": "00000000-0000-0000-0000-000000000163",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": null
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::eventType (elastic rule field)equser.authentication.auth_via_mfa2 ruleselastic
okta::eventType (elastic rule field)equser.mfa.okta_verify.deny_push2 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.auth_via_mfa3 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.sso3 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.verify3 ruleselastic
okta::eventType (elastic rule field)inuser.session.start3 ruleselastic
okta::debugContext.debugData.factor (elastic rule field)eqOKTA_VERIFY_PUSH2 ruleselastic
okta::outcome.reason (elastic rule field)eqINVALID_CREDENTIALS2 ruleselastic
okta::outcome.result (elastic rule field)eqSUCCESS2 ruleselastic
okta::securityContext.isProxy (elastic rule field)eqtrue2 ruleselastic
action (splunk rule field)eqsuccess1 rulesplunk
eventType (splunk rule field)equser.authentication.auth_via_mfa1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

References #

user.behavior.profile.reset

#

Description

User behavior profile reset. This event can be used to identify resets to a user behavior profiles, which may be helpful when troubleshooting unexpected behavior detection evaluations. This event is triggered when an administrator manually resets a user's behavior profile in the Admin Console.

References #

user.credential.enroll

#

Description

Device Trust certificate enrollment.

References #

user.device_session.end

#

Description

User ended a device session. This event is fired when a user logs out or locks their desktop. This may be useful to audit when the lifecycle of a given device session has ended.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

References #

user.device_session.start

#

Description

User established a device session. This event may be used to identify users which are using Device-Bound SSO. This may be useful to audit when a user established their device session, either at desktop logon or after a successful authentication in the browser. After the device session is established, the resultant deviceSessionId will appear in the authenticationContext of events fired where the device session was used.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

References #

user.identity_snapshot.attestation.create

#

Description

Create identity snapshot attestation for a user. This event can be used by administrators to audit identity snapshot attestations minted for a user. The user and the application are in the event, signifying which user the attestation token is being minted for, and which application is requesting it.

References #

user.identity_verification

#

Description

This event is fired when a user is directed to complete an Identity Verification as a result of an Okta Account Management (OAMP) Policy evaluation. This event indicates an identity verification request has occurred and will contain the results of the id verification. Completion of an id verification will determine whether the trigger OAMP operation can be completed; start is recorded by user.identity_verification.start.

References #

user.identity_verification.start

#

Description

An Okta account management policy (OAMP) prompted the user to verify their identity with an identity verification service. Helps admins audit identity-verification prompts and troubleshoot IDV-flow issues. Initiates the prompt for identity-verification flow; completion is recorded by user.identity_verification event.

References #

user.import.password

#

Description

Imported user password from external system during login. This can be used to understand if a user password import attempt was successful or if it failed. If the attempt failed, the password import will be tried again on a subsequent successful login. When fired, this event contains information about the import type, and whether or not the password import was successful. If the import is successful, it is safe to "clean up" that user from an external system. If the import failed, Okta will continue retrying the import during every successful authentication attempt until the password is successfully imported. Check the failure reason for details about whether any action is needed for the import to succeed.

References #

user.lifecycle.activate

#

Description

Activate Okta user.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000123",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Activate Okta user",
  "eventType": "user.lifecycle.activate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:49.164Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users",
      "url": "/api/v1/users?activate=true"
    }
  },
  "legacyEventType": "core.user.config.user_activated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventType (sigma rule field)equser.lifecycle.create1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

user.lifecycle.create

#

Description

Create Okta user.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000123",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Create okta user",
  "eventType": "user.lifecycle.create",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:49.047Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users",
      "url": "/api/v1/users?activate=true"
    }
  },
  "legacyEventType": "core.user.config.user_creation.success",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventType (sigma rule field)equser.lifecycle.create2 rulessigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

user.lifecycle.deactivate

#

Description

Deactivate Okta user.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000124",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Deactivate Okta User",
  "eventType": "user.lifecycle.deactivate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:49.506Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users/00u00000000000000011/lifecycle/deactivate",
      "url": "/api/v1/users/00u00000000000000011/lifecycle/deactivate?"
    }
  },
  "legacyEventType": "core.user.config.user_deactivated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

user.lifecycle.delete.completed

#

Description

Delete Okta user completed.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000008",
    "externalSessionId": "trs00000000000000008"
  },
  "displayMessage": "Delete Okta user completed",
  "eventType": "user.lifecycle.delete.completed",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:17:38.037Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000005",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/users/00u00000000000000007",
      "url": "/api/v1/users/00u00000000000000007?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "core.user.config.user_status.delete.completed",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000005",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000010",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00u00000000000000007",
      "type": "User",
      "alternateId": "user04@dw-harness.example",
      "displayName": "DW Harness 03",
      "detailEntry": null
    }
  ]
}

References #

user.lifecycle.delete.initiated

#

Description

Delete Okta user initiated.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000125",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Delete Okta user initiated",
  "eventType": "user.lifecycle.delete.initiated",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:49.621Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users/00u00000000000000011",
      "url": "/api/v1/users/00u00000000000000011?"
    }
  },
  "legacyEventType": "core.user.config.user_status.delete.initiated",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

user.lifecycle.jit.error.read_only

#

Description

Failed to JIT create user.

References #

user.lifecycle.password_mass_expiry

#

Description

Mass expire all users' passwords initiated.

References #

user.lifecycle.reactivate

#

Description

Reactivate Okta user.

References #

user.lifecycle.suspend

#

Description

Suspend Okta user.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000126",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Suspend Okta user",
  "eventType": "user.lifecycle.suspend",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:54:58.217Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users/00u00000000000000023/lifecycle/suspend",
      "url": "/api/v1/users/00u00000000000000023/lifecycle/suspend?"
    }
  },
  "legacyEventType": "core.user.config.user_status.suspended",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

user.lifecycle.unsuspend

#

Description

Unsuspend Okta user.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000127",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Unsuspend Okta user",
  "eventType": "user.lifecycle.unsuspend",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:54:58.348Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users/00u00000000000000023/lifecycle/unsuspend",
      "url": "/api/v1/users/00u00000000000000023/lifecycle/unsuspend?"
    }
  },
  "legacyEventType": "core.user.config.user_status.unsuspended",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

user.mfa.attempt_bypass

#

Description

Attempt bypass of factor.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventType (panther rule field)inuser.account.reset_password1 rulepanther
eventType (panther rule field)inuser.mfa.factor.update1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Attempted Bypass of Okta MFA source high: Detects attempts to bypass Okta multi-factor authentication (MFA). An adversary may attempt to bypass the Okta MFA policies configured for an organization in order to obtain unauthorized access to an application.T1111

Kusto #

Panther #

References #

user.mfa.factor.activate

#

Description

Activate factor or authenticator enrollment method for user. Provides org admins with audit log and oversight utility for an MFA factor when it is activated. When fired, the event contains information about the MFA factor that has been activated, as well as the target user and the user activating the factor. For Identity Engine orgs, this event will fire when an authentication method is enrolled.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000123",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Activate factor for user",
  "eventType": "user.mfa.factor.activate",
  "outcome": {
    "result": "SUCCESS",
    "reason": "User set up EMAIL_FACTOR factor"
  },
  "published": "2026-07-02T18:35:49.039Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "traceId": "00000000-0000-0000-0000-000000000000",
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users",
      "url": "/api/v1/users?activate=true"
    }
  },
  "legacyEventType": "core.user.factor.activate",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
admin_email (panther rule field)is_not_null1 rulepanther
is_anomalous (panther rule field)eqtrue1 rulepanther
okta::eventType (elastic rule field)inuser.mfa.factor.deactivate1 ruleelastic
okta::eventType (elastic rule field)inuser.mfa.factor.reset_all1 ruleelastic
okta::outcome.result (elastic rule field)eqSUCCESS1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

  • Okta Authentication Bypass via Skeleton Key Injection - Behavioral source high linked query: Query.Okta.SkeletonKeyBypassBehavioral: Detects potential Okta authentication bypass via skeleton key injection using behavioral z-score analysis. Skeleton key attacks in Okta involve manipulating authentication policies to weaken MFA requirements (disabling requireFactor, zeroing maxSessionLifetime) and bulk-enrolling attacker-controlled authenticators on victim accounts. This detection builds a 90-day behavioral baseline for each admin's policy change and factor enrollment patterns, then identifies anomalous spikes in the last 7 days. Detection Logic: - Z-score: Spike in security-weakening policy changes (> 2σ above baseline) - Z-score: Spike in admin-on-behalf-of MFA factor enrollments (> 3σ above baseline) - Cold-start: First-time security weakening (no prior baseline - immediate high-confidence signal) - Cold-start: First-time admin-enrolled factors for other users Why This Matters: Skeleton key attacks require two steps: weaken authentication policies to reduce MFA friction, then enroll attacker-controlled authenticators on victim accounts. This detection catches both steps using behavioral baselines that adapt to legitimate admin workflows. Complementary Detection: Use alongside Okta.ADAgent.TokenAbuse.Behavioral for admin credential theft scenarios.T1098, T1556
  • Query.Okta.SkeletonKeyBypassBehavioral source: Detects Okta authentication bypass attempts via skeleton key injection using behavioral z-score analysis. Reads pre-computed 90-day baselines from the okta_baseline_90d lookup table, then compares recent (last 7 days) admin policy change and MFA factor enrollment patterns against those baselines. DETECTION LOGIC: - Z-score: Security-weakening policy changes (requireFactor=false, maxSessionLifetime=0) > 2σ - Z-score: Admin-on-behalf-of MFA factor enrollments for other users > 3σ - Cold-start: First-time security weakening with no prior baseline - Cold-start: First-time admin-enrolled factors for other users PREREQUISITE: okta_baseline_90d lookup table must be populated.

References #

user.mfa.factor.deactivate

#

Description

Reset factor or authenticator enrollment method for user. Provides org admins with audit log and oversight utility for the change in MFA factor lifecycle status when a specific factor is permanently deactivated. When fired, the event contains information about the MFA factor that has been deactivated, as well as the target user and the user deactivating the factor. For Identity Engine orgs, this event will fire when an authentication method is unenrolled.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000152",
    "externalSessionId": "0000000000000000000000069"
  },
  "displayMessage": "Reset factor for user",
  "eventType": "user.mfa.factor.deactivate",
  "outcome": {
    "result": "SUCCESS",
    "reason": "User reset OKTA_SOFT_TOKEN factor"
  },
  "published": "2026-07-26T00:47:27.258Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000130",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/users/00u00000000000000150/factors/ost00000000000000151",
      "url": "/api/v1/users/00u00000000000000150/factors/ost00000000000000151?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": "core.user.factor.deactivate",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000130",
    "detail": {
      "rootApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000166",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00u00000000000000150",
      "type": "User",
      "alternateId": "user40@dw-harness.example",
      "displayName": "DW Harness 60",
      "detailEntry": null
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::eventTypeinuser.mfa.factor.deactivate2 ruleselastic, kusto
okta::eventTypeinuser.mfa.factor.reset_all2 ruleselastic, kusto
okta::outcome.resulteqSUCCESS2 ruleselastic, kusto
All_Changes.action (splunk rule field)eqmodified1 rulesplunk
All_Changes.object_category (splunk rule field)equser1 rulesplunk
eventType (panther rule field)inuser.account.reset_password1 rulepanther
eventType (panther rule field)inuser.mfa.factor.update1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Splunk #

  • Okta Multi-Factor Authentication Disabled source: The following analytic identifies an attempt to disable multi-factor authentication (MFA) for an Okta user. It leverages OktaIM2 logs to detect when the 'user.mfa.factor.deactivate' command is executed. This activity is significant because…T1556, T1556.006

Kusto #

  • New Device/Location sign-in along with critical operation source medium: This query identifies users seen login from a new geo location/country and a new device, then correlates that sign-in with successful risky operations such as policy changes, MFA changes, API token actions etc. This can be an indication of an attacker gaining access to a user's credentials and then performing critical operations, which typically requires admin privileges. By detecting such patterns, organizations can quickly respond to potential security incidents and mitigate risks associated with unauthorized access and privilege escalation.T1078, T1098, T1556↳ also matches user.mfa.attempt_bypass, user.mfa.factor.reset_all, user.session.start

YARA-L #

Panther #

References #

user.mfa.factor.reset_all

#

Description

Reset all factors or authenticator enrollments for user. Provides org admins with audit log and oversight utility for the change in MFA factor lifecycle statuses when all MFA factors for a user are permanently deactivated. When fired, the event contains information about the target user for whom all factors have been deactivated, as well as the user resetting the factors. For Identity Engine orgs, this event contains information about a target user for whom all authenticator enrollments have been reset.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000130",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Reset all factors for user",
  "eventType": "user.mfa.factor.reset_all",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:54:57.859Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users/00u00000000000000023/lifecycle/reset_factors",
      "url": "/api/v1/users/00u00000000000000023/lifecycle/reset_factors?"
    }
  },
  "legacyEventType": "core.user.factor.reset_all",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::eventTypeinuser.mfa.factor.deactivate2 ruleselastic, kusto
okta::eventTypeinuser.mfa.factor.reset_all2 ruleselastic, kusto
okta::outcome.resulteqSUCCESS2 ruleselastic, kusto
eventType (panther rule field)inuser.account.reset_password1 rulepanther
eventType (panther rule field)inuser.mfa.factor.update1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

  • New Device/Location sign-in along with critical operation source medium: This query identifies users seen login from a new geo location/country and a new device, then correlates that sign-in with successful risky operations such as policy changes, MFA changes, API token actions etc. This can be an indication of an attacker gaining access to a user's credentials and then performing critical operations, which typically requires admin privileges. By detecting such patterns, organizations can quickly respond to potential security incidents and mitigate risks associated with unauthorized access and privilege escalation.T1078, T1098, T1556↳ also matches user.mfa.attempt_bypass, user.mfa.factor.deactivate, user.session.start

YARA-L #

Panther #

References #

user.mfa.factor.suspend

#

Description

Suspend factor or authenticator enrollment method for user. Provides org admins with audit log and oversight utility for the change in MFA factor lifecycle status when a factor is suspended, usually as a result of suspected compromise. When fired, the event contains information about the MFA factor that has been suspended, as well as the target user and the user suspending the factor. When unsuspended, related event user.mfa.factor.unsuspend will be fired.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

Example System Log Event #

{
  "published": 1782423539742,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000133",
  "actor": {
    "id": "00u00000000000000332",
    "type": "User",
    "alternateId": "user73@dw-harness.example",
    "displayName": "DW Harness 114",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
      "os": "Windows 11",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.5",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000333",
      "type": "User",
      "alternateId": "user03@dw-harness.example",
      "displayName": "DW Harness 04",
      "detailEntry": {
        "realmId": "guo00000000000000062"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": "User suspended SIGNED_NONCE factor"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.5",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "user.mfa.factor.suspend",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000068",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000068",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000025",
      "origin": "https://app.example.com App app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "000000000000000000000000000000000000000000000000000002",
      "url": "000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "Suspend factor for Example App 61",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000337",
    "externalSessionId": "10200000000000000337"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventType (panther rule field)inuser.account.reset_password1 rulepanther
eventType (panther rule field)inuser.mfa.factor.update1 rulepanther
okta::eventType (kusto rule field)insystem.api_token.create1 rulekusto
outcome.result (panther rule field)eqSUCCESS1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

Panther #

References #

user.mfa.factor.unsuspend

#

Description

Unsuspend factor or authenticator enrollment method for user. Provides org admins with audit log and oversight utility for the change in MFA factor lifecycle status when a factor is reactivated from a state of suspension, after it has been determined that the authenticator is secure. When fired, the event contains information about the MFA factor that has been unsuspended, as well as the target user and the user reactivating the suspended factor. Before suspension, related event user.mfa.factor.suspend would have been fired.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

Example System Log Event #

{
  "published": 1782423542964,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000134",
  "actor": {
    "id": "00u00000000000000332",
    "type": "User",
    "alternateId": "user73@dw-harness.example",
    "displayName": "DW Harness 114",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
      "os": "Windows 11",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.5",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000333",
      "type": "User",
      "alternateId": "user03@dw-harness.example",
      "displayName": "DW Harness 04",
      "detailEntry": {
        "realmId": "guo00000000000000062"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": "User unsuspended SIGNED_NONCE factor"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.5",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "user.mfa.factor.unsuspend",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000069",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000069",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000025",
      "origin": "https://app.example.com App app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000002",
      "url": "00000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "Unsuspend factor for Example App 61",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000337",
    "externalSessionId": "10200000000000000337"
  }
}

References #

user.mfa.factor.update

#

Description

Update factor for user.

Example System Log Event #

{
  "published": 1780124575422,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000135",
  "actor": {
    "id": "00u00000000000000338",
    "type": "User",
    "alternateId": "user74@dw-harness.example",
    "displayName": "DW Harness 115",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "app.example.com.android.auth/8.26.0 Android/16 motorola/motorola_edge_plus_2023 7cs00000000000000339",
      "os": "Android",
      "browser": "EDGE"
    },
    "zone": "null",
    "device": "Mobile",
    "id": null,
    "ipAddress": "192.0.2.37",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000338",
      "type": "User",
      "alternateId": "user74@dw-harness.example",
      "displayName": "DW Harness 115",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": "User updated OKTA_VERIFY_PUSH factor"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.37",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "user.mfa.factor.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000070",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000070",
      "requestUri": "000000000000000000000000000000000000000000004",
      "url": "000000000000000000000000000000000000000000004?"
    }
  },
  "displayMessage": "Update factor for Example App 61",
  "gatewayContext": null,
  "legacyEventType": "core.user.factor.update",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000340",
    "externalSessionId": "trs00000000000000340"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventType (panther rule field)inuser.account.reset_password2 rulespanther
eventType (panther rule field)inuser.mfa.factor.update2 rulespanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

References #

user.mfa.okta_verify

#

Description

Verify user with Okta verify.

References #

user.mfa.okta_verify.deny_push

#

Description

User rejected Okta push verify. This event is triggered in classic V1 API calls. In OIE we use a generic event for factor verification failure: user.authentication.auth_via_mfa with reason INVALID_CREDENTIALS.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::eventTypeequser.authentication.auth_via_mfa3 ruleselastic, kusto
okta::eventTypeequser.mfa.okta_verify.deny_push3 ruleselastic, kusto
okta::eventType (elastic rule field)inuser.authentication.auth_via_mfa2 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.sso2 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.verify2 ruleselastic
okta::eventType (elastic rule field)inuser.session.start2 ruleselastic
okta::debugContext.debugData.factor (elastic rule field)eqOKTA_VERIFY_PUSH2 ruleselastic
okta::outcome.reason (elastic rule field)eqINVALID_CREDENTIALS2 ruleselastic
okta::outcome.result (elastic rule field)eqSUCCESS2 ruleselastic
security_result.detection_fields["factor"] (Chronicle)eqOKTA_VERIFY_PUSH1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

YARA-L #

References #

user.mfa.okta_verify.deny_push_upgrade_needed

#

Description

Rejected Okta push verify as Upgrade Needed. This can be used to audit events where Okta push verify was rejected as the app needed upgrade. Note that the event is fired when Okta Verify push is rejected. It is possible that the user might have chosen another factor and made successful login as well.

References #

user.risk.change

#

Description

Indicates a user's risk level has changed. This event can be used to monitor risk level changes for users. This event triggers when Okta determines that a user is associated with a change in risk activity or context.

References #

user.risk.detect

#

Description

Indicates a user risk was detected. This event can be used to monitor risk level detections for users. This event triggers when Okta detects that a user is associated with risk activity or context.

Example System Log Event #

{
  "published": 1782417655134,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000136",
  "actor": {
    "id": "spr00000000000000167",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000333",
      "type": "User",
      "alternateId": "user03@dw-harness.example",
      "displayName": "DW Harness 04",
      "detailEntry": {
        "realmId": "guo00000000000000062"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "user.risk.detect",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "rsu00000000000000334",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "traceId": "00000000-0000-0000-0000-000000000131",
      "risk": "{previousLevel=NONE, level=LOW, detectionName=Admin Mitigated User Risk, reasons=Universal app logout cleared all Example App 61 sessions, issuer=OKTA}"
    }
  },
  "displayMessage": "User risk was detected",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null,
    "risk": {
      "level": "LOW",
      "reasons": [
        "Universal app logout cleared all user sessions"
      ],
      "previousLevel": "NONE",
      "detectionName": "Admin Mitigated User Risk",
      "issuer": "OKTA"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000335",
    "externalSessionId": "trs00000000000000336"
  }
}

References #

user.session.access_admin_app

#

Description

User accessing Okta admin app.

Example System Log Event #

{
  "published": 1780234878322,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000137",
  "actor": {
    "id": "00u00000000000000179",
    "type": "User",
    "alternateId": "user44@dw-harness.example",
    "displayName": "DW Harness 59",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.21",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000179",
      "type": "AppUser",
      "alternateId": "user44@dw-harness.example",
      "displayName": "DW Harness 59",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.21",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "user.session.access_admin_app",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000071",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "traceId": "00000000-0000-0000-0000-000000000138",
      "requestId": "00000000000000000000000000000071",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000022",
      "idpType": "OKTA",
      "requestUri": "/admin/sso/callback",
      "threatSuspected": "false",
      "url": "/admin/sso/callback?code=******&state=00000000000000000000000000000072"
    }
  },
  "displayMessage": "User accessing Okta admin app",
  "gatewayContext": null,
  "legacyEventType": "app.admin.sso.login.success",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000341",
    "externalSessionId": "10200000000000000342"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

user.session.clear

#

Description

Clear user session.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000124",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Clear user session",
  "eventType": "user.session.clear",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:35:49.526Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/users/00u00000000000000011/lifecycle/deactivate",
      "url": "/api/v1/users/00u00000000000000011/lifecycle/deactivate?"
    }
  },
  "legacyEventType": "core.user_auth.session_clear",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "User",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

user.session.context.change

#

Description

User session context changed. This event indicates that the context in which the session is being used has changed significantly enough from the context in which the event was created, that re-evaluation of policy may be required. Often this indicates a security issue related to the session.

Example System Log Event #

{
  "published": 1781352320466,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000139",
  "actor": {
    "id": "spr00000000000000171",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "OktaVerify/6.10.2.0 WPFDeviceSDK/6.10.2.0 Windows/10.0.26200.8655 Dell_Inc./Dell_Pro_Max_16_MC16250 1ef1f27b-0039-4c03-8c54-be987e",
      "os": "Windows",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.38",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000343",
      "type": "User",
      "alternateId": "user75@dw-harness.example",
      "displayName": "DW Harness 116",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    },
    {
      "id": "guo00000000000000344",
      "type": "UDDevice",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 71",
      "detailEntry": null
    },
    {
      "id": "idx00000000000000345",
      "type": "Session",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 71",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.38",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "user.session.context.change",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000073",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "traceId": "00000000-0000-0000-0000-000000000140",
      "changedDeviceSignals": {
        "diskEncryptionType": {
          "oldValue": "NONE",
          "newValue": "ALL_INTERNAL_VOLUMES"
        }
      },
      "newIpAddress": "192.0.2.17",
      "previousIpAddress": "192.0.2.17",
      "arePoliciesReevaluated": "true",
      "externalSessionId": "idx00000000000000345",
      "requestUri": "xsl00000000000000346",
      "source": "OKTA",
      "url": "xsl00000000000000346?",
      "requestId": "00000000000000000000000000000073",
      "causes": "[deviceContext.change]",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000032",
      "risk": "{level=LOW}",
      "associatedProxies": [
        "LUMINATI_PROXY"
      ]
    }
  },
  "displayMessage": "User session context changed",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "LOW"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

References #

user.session.end

#

Description

User logout from Okta.

Example System Log Event #

{
  "actor": {
    "alternateId": "user20@dw-harness.example",
    "detailEntry": null,
    "displayName": "DW Harness 30",
    "id": "00u00000000000000026",
    "type": "User"
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": null,
    "externalSessionId": "0000000000000000000000131",
    "interface": null,
    "issuer": null
  },
  "client": {
    "device": "Computer",
    "geographicalContext": {
      "city": "Anytown",
      "country": "Placeholderland",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      },
      "postalCode": "00000",
      "state": "Anystate"
    },
    "id": null,
    "ipAddress": "198.51.100.14",
    "userAgent": {
      "browser": "FIREFOX",
      "os": "Mac OS X",
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:72.0) Gecko/20100101 Firefox/72.0"
    },
    "zone": "null"
  },
  "debugContext": {
    "debugData": {
      "authnRequestId": "000000000000000000000000010",
      "requestId": "000000000000000000000000132",
      "requestUri": "/login/signout",
      "threatSuspected": "false",
      "url": "/login/signout?message=login_page_messages.session_has_expired"
    }
  },
  "displayMessage": "User logout from Okta",
  "eventType": "user.session.end",
  "legacyEventType": "core.user_auth.logout_success",
  "outcome": {
    "reason": null,
    "result": "SUCCESS"
  },
  "published": "2020-02-14T22:18:51.843Z",
  "request": {
    "ipChain": [
      {
        "geographicalContext": {
          "city": "Anytown",
          "country": "Placeholderland",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          },
          "postalCode": "00000",
          "state": "Anystate"
        },
        "ip": "198.51.100.14",
        "source": null,
        "version": "V4"
      }
    ]
  },
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "domain": null,
    "isProxy": null,
    "isp": null
  },
  "severity": "INFO",
  "target": null,
  "transaction": {
    "detail": {},
    "id": "000000000000000000000000132",
    "type": "WEB"
  },
  "uuid": "00000000-0000-0000-0000-000000000025",
  "version": "0"
}

References #

user.session.expire

#

Description

Expire user session. This event does not appear in the system logs unless the user explicitly signs out or the user session is revoked by an admin.

References #

user.session.impersonation.end

#

Description

End impersonation session.

References #

user.session.impersonation.extend

#

Description

Extend impersonation session.

References #

user.session.impersonation.grant

#

Description

Enable impersonation grant.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
p_occurs_between (panther rule field)macro'2022-01-14' , '2022-03-22'1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

Panther #

References #

user.session.impersonation.initiate

#

Description

Initiate impersonation session.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
p_occurs_between (panther rule field)macro'2022-01-14' , '2022-03-22'1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Okta User Session Impersonation source high: A user has initiated a session impersonation granting them access to the environment with the permissions of the user they are impersonating. This would likely indicate Okta administrative access and should only ever occur if requested and expected.T1078, T1078.004

Kusto #

  • User Session Impersonation(Okta) source medium: This query detects instances of user session impersonation, where an attacker successfully initiates a session impersonation event. The query extracts detailed information about the target user and the actor involved in the impersonation, providing insights into potential privilege escalation activities.T1134, T1134.003

Panther #

References #

user.session.impersonation.revoke

#

Description

Revoke impersonation grant.

References #

user.session.start

#

Description

User login to Okta.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000147",
    "type": "User",
    "alternateId": "user39@dw-harness.example",
    "displayName": "DW Harness 64",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000148",
    "externalSessionId": "10200000000000000148"
  },
  "displayMessage": "User login to Okta",
  "eventType": "user.session.start",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-26T00:41:14.122Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "HIGH",
      "reasons": [
        "Anomalous Device",
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000132",
        "result": "UNKNOWN"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000133",
        "result": "UNKNOWN"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000134",
        "result": "UNKNOWN"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000135",
        "result": "UNKNOWN"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000136",
        "result": "UNKNOWN"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000137",
        "result": "UNKNOWN"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000138",
        "result": "UNKNOWN"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000139",
        "result": "UNKNOWN"
      }
    ]
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000128",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000006",
      "requestUri": "/api/v1/authn",
      "threatSuspected": "false",
      "url": "/api/v1/authn?",
      "logOnlySecurityData": {
        "risk": {
          "reasons": "Anomalous Device, Anomalous Location",
          "level": "HIGH"
        },
        "behaviors": {
          "New Geo-Location": "UNKNOWN",
          "New Device": "UNKNOWN",
          "New ASN": "UNKNOWN",
          "New IP": "UNKNOWN",
          "New State": "UNKNOWN",
          "New Country": "UNKNOWN",
          "Velocity": "UNKNOWN",
          "New City": "UNKNOWN"
        }
      }
    }
  },
  "gatewayContext": null,
  "legacyEventType": "core.user_auth.login_success",
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000128",
    "detail": {}
  },
  "uuid": "00000000-0000-0000-0000-000000000162",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": null
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::actor.alternateIdis_not_null7 ruleselastic, kusto
okta::eventTypeequser.session.start5 ruleselastic, kusto
okta::eventType (elastic rule field)equser.authentication.auth_via_mfa2 ruleselastic
okta::eventType (elastic rule field)equser.mfa.okta_verify.deny_push2 ruleselastic
okta::eventTypeinuser.session.start5 ruleselastic, kusto
okta::eventType (elastic rule field)inuser.authentication.sso4 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.auth_via_mfa3 ruleselastic
okta::eventType (elastic rule field)inuser.authentication.verify3 ruleselastic
eventTypeequser.session.start4 rulespanther, sigma
okta::outcome.resulteqSUCCESS3 ruleselastic, kusto
okta::outcome.resulteqsuccess3 ruleselastic, kusto
outcome:result (panther rule field)eqsuccess3 rulespanther
client:device (panther rule field)eqcomputer2 rulespanther
client:ipAddress (panther rule field)wildcard*.*.*.*2 rulespanther
okta::debugContext.debugData.factor (elastic rule field)eqOKTA_VERIFY_PUSH2 ruleselastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Splunk #

Kusto #

YARA-L #

Panther #

References #

user.mfa.promote_enrollment

#

Description

Promote authenticator enrollment during login to Okta. Track user facing promotion screen shown to promote authenticator enrollment and the corresponding user action taken. An outcome.result = SUCCESS indicates that the user enrolled in the authenticator and an outcome.result = SKIPPED indicates that the user skipped enrollment.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

References #

user.realm.update

#

Description

User realm updated.

Example System Log Event #

{
  "published": 1782501746096,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000002",
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": {
      "realmId": "guo00000000000000003"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
      "os": "Windows 10",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.22",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000004",
      "type": "User",
      "alternateId": "user03@dw-harness.example",
      "displayName": "DW Harness 03",
      "detailEntry": {
        "realmId": "guo00000000000000003"
      }
    },
    {
      "id": "guo00000000000000003",
      "type": "Realm",
      "alternateId": "user04@dw-harness.example",
      "displayName": "DW Harness 04",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.22",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "user.realm.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000002",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000002",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "origin": "https://app.example.com App app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000002",
      "url": "00000000000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "User Realm Updated",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000005",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000006",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000007",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000008",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000009",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000010",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000011",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000012",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000013",
    "externalSessionId": "10200000000000000013"
  }
}

References #