Okta Policy Rule Updated or Deleted

Alerts on Okta policy rule update or deletion events that may indicate tampering with authorization controls.

FreeReviewedSigma · Medium · v4
Product
okta
Service
okta
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-09-12
Updated
2026-07-31

What it detects

This rule flags Okta System Log events where a policy rule is modified or deleted. Attackers may change or remove access control rules to weaken enforcement or disrupt authentication and authorization policies. The detection relies on Okta event types for policy.rule.update and policy.rule.delete in the System Log telemetry.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.