Okta
Sign-ins, MFA changes and admin grants from the Okta System Log.
Category
Identity
Setup
About 10 minutes
Events Wardell reads
Sign-ins, MFA events, admin role grants, app assignments
Connect Okta with a read-only API token scoped to the System Log. Wardell pulls new events every 30 seconds and keeps the raw event on every case it builds.
The Okta pack catches impossible travel, MFA fatigue, factor resets followed by admin grants, and session tokens reused from a second device.
What Wardell watches
Impossible travel and new-device detections
MFA push fatigue and factor reset sequences
Admin role grants tied to the helpdesk session that made them
One-click session revoke from a case
Try it on your own logs
Connect this source with a read-only key. Within 48 hours a Wardell analyst sends a written report of what it would have caught.