Okta Policy Lifecycle Updated or Deleted

Flags Okta events indicating a policy was updated or deleted.

FreeReviewedSigma · Low · v4
Product
okta
Service
okta
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-09-12
Updated
2026-07-31

What it detects

This rule flags Okta system log events where a policy is updated or deleted. Attackers and administrators alike can use policy changes to alter authentication or authorization behavior, so tracking these lifecycle events helps identify potentially unauthorized impact. The detection relies on Okta event types indicating policy lifecycle updates and policy deletions from the Okta system logs.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.