Netwrix Auditor Add-on for Okta 1.0.25 — Update Notes

Overview

Okta is the identity provider for millions of organizations, but its audit log has always been siloed — visible only inside the Okta console and disconnected from the rest of your security data. Security and compliance teams had no way to correlate Okta identity events with Active Directory, file servers, and cloud activity in a single audit trail. Critical signals like MFA resets after suspicious logins, API token creation, or bulk account deactivations were invisible to Netwrix Auditor.

Description

The updated Okta Add-on pulls 35 targeted event types directly into Netwrix Auditor, covering every key domain of Okta activity:

Domain What you’ll see
Authentication SSO logins, MFA verifications, session start/end, admin app access
Policy Sign-on policy evaluations and access denials
User Accounts Profile updates, password changes, lock/unlock
User Lifecycle Create, activate, deactivate, suspend, unsuspend, delete
MFA Factors Factor activate, update, reset, deactivate
Groups Group create/delete, membership add/remove
API Tokens Token creation and revocation
Devices Device enrollment, activation, deactivation, deletion
App Memberships Username changes within application memberships

Each event is normalized to Netwrix Auditor’s standard format — Action, ObjectType, Who, What, Where, When — so it behaves identically to any other data source in the platform: the same search interface, the same alert rules, the same compliance reports.

Beyond the core fields, every record is enriched with up to 14 contextual details pulled directly from the Okta log payload: geo-location (country, city), client environment (OS, browser), MFA method and authentication provider, outcome reason, target display name, request URI, and transaction ID. Analysts no longer need to pivot back into the Okta console to answer the basic questions an investigation demands — who, from where, on what device, with what result.

The deeper event coverage also translates directly into detection capability. A successful SSO login from an unusual country followed immediately by an MFA factor reset is a textbook account takeover pattern — and it’s now fully visible and alertable. API token creation outside business hours, bulk group membership removals, a wave of device deletions — these are the anomalies that behavioral baselines are built on, and they require the kind of lifecycle-level event coverage this update provides.

The result is a single searchable audit trail that spans your entire environment. Incident investigation, offboarding verification, compliance evidence for SOC 2, ISO 27001, or HIPAA — it all flows through the same Netwrix Auditor console, without manual log exports from the Okta portal.