Skip to content

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.

Glossary

Plain-language definitions of the Okta System Log and identity incident-response terms used in our guides.

Phishing-resistant MFA
Authentication bound to the real site and device, such as FIDO2/WebAuthn keys or Okta FastPass, that a fake login page or push flood cannot defeat.
Okta ThreatInsight
Okta's service that flags and can block authentication requests from IP addresses seen in credential-based attacks across Okta customers.
Okta API token (SSWS)
A long-lived secret for the Okta management API that carries the permissions of the admin who created it, sent in an SSWS Authorization header.
Super Administrator (Okta)
The most privileged Okta admin role, able to manage every setting, admin and identity provider in the org; the main target of tenant takeovers.
Cross-tenant impersonation
Okta Security's name for attacks that use a second, attacker-controlled identity provider to sign in to a victim org as its real users.
Inbound federation (external IdP)
An Okta configuration that trusts an external identity provider to sign users in; legitimate for partners, and a persistence path in attacker hands.
ASN (Autonomous System Number)
The number identifying the network operator that announces an IP address; in the Okta System Log it tells you whose network a request came from.
Factor reset
An administrator action that removes a user's MFA enrollments so they can enroll again; routine for support, and the key step in helpdesk social engineering.
Number challenge (Okta Verify)
An Okta Verify push option that makes the user pick the number shown on the sign-in screen, so a push cannot be approved blindly.
MFA fatigue (push bombing)
An attack in which someone who has the password sends repeated MFA push prompts until the user approves one, tracked by MITRE ATT&CK as T1621.
externalSessionId
The Okta session identifier in authenticationContext, used to group every event of one sign-in session and to spot a session replayed from elsewhere.
eventType (Okta)
The dotted identifier that says what an Okta System Log event records, such as user.session.start or user.account.privilege.grant.
Okta System Log
The audit log of an Okta org: every sign-in, MFA challenge, session, admin change and app access, recorded as LogEvent objects and kept for 90 days.

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.