var(--variable-pPCZ3gsG2)

Okta

Sign-ins, MFA changes and admin grants from the Okta System Log.

Category

Identity

Setup

About 10 minutes

Events Wardell reads

Sign-ins, MFA events, admin role grants, app assignments

Connect Okta with a read-only API token scoped to the System Log. Wardell pulls new events every 30 seconds and keeps the raw event on every case it builds.

The Okta pack catches impossible travel, MFA fatigue, factor resets followed by admin grants, and session tokens reused from a second device.

What Wardell watches

  • Impossible travel and new-device detections

  • MFA push fatigue and factor reset sequences

  • Admin role grants tied to the helpdesk session that made them

  • One-click session revoke from a case

Try it on your own logs

Connect this source with a read-only key. Within 48 hours a Wardell analyst sends a written report of what it would have caught.

Use this free template

Create a free website with Framer, the website builder loved by startups, designers and agencies.