Glossary
Plain-language definitions of the Okta System Log and identity incident-response terms used in our guides.
- Phishing-resistant MFA
- Authentication bound to the real site and device, such as FIDO2/WebAuthn keys or Okta FastPass, that a fake login page or push flood cannot defeat.
- Okta ThreatInsight
- Okta's service that flags and can block authentication requests from IP addresses seen in credential-based attacks across Okta customers.
- Okta API token (SSWS)
- A long-lived secret for the Okta management API that carries the permissions of the admin who created it, sent in an SSWS Authorization header.
- Super Administrator (Okta)
- The most privileged Okta admin role, able to manage every setting, admin and identity provider in the org; the main target of tenant takeovers.
- Cross-tenant impersonation
- Okta Security's name for attacks that use a second, attacker-controlled identity provider to sign in to a victim org as its real users.
- Inbound federation (external IdP)
- An Okta configuration that trusts an external identity provider to sign users in; legitimate for partners, and a persistence path in attacker hands.
- ASN (Autonomous System Number)
- The number identifying the network operator that announces an IP address; in the Okta System Log it tells you whose network a request came from.
- Factor reset
- An administrator action that removes a user's MFA enrollments so they can enroll again; routine for support, and the key step in helpdesk social engineering.
- Number challenge (Okta Verify)
- An Okta Verify push option that makes the user pick the number shown on the sign-in screen, so a push cannot be approved blindly.
- MFA fatigue (push bombing)
- An attack in which someone who has the password sends repeated MFA push prompts until the user approves one, tracked by MITRE ATT&CK as T1621.
- externalSessionId
- The Okta session identifier in authenticationContext, used to group every event of one sign-in session and to spot a session replayed from elsewhere.
- eventType (Okta)
- The dotted identifier that says what an Okta System Log event records, such as user.session.start or user.account.privilege.grant.
- Okta System Log
- The audit log of an Okta org: every sign-in, MFA challenge, session, admin change and app access, recorded as LogEvent objects and kept for 90 days.