<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta-Integrations Displays as the RawUserAgent with Okta IP Addresses

Administration
Okta Classic Engine
Okta Identity Engine

Overview

The System Log displays login events or other activities where the RawUserAgent appears as Okta-Integrations originating from Okta IP addresses.

The following image displays an event in the Okta System Log when Okta services communicate internally.

Okta-Integrations

This expected behavior occurs because Okta's internal systems use this agent for communication. Verify these events by comparing the associated IP address against the official Okta IP address allowlist.

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • System Log

Cause

This occurrence is expected behavior. The Okta-Integrations RawUserAgent facilitates communication within Okta internal systems. Login events to the Admin Console display multiple occurrences of this behavior, including administrators who appear to sign in from an Okta IP address.

Solution

How to verify an Okta event that contains Okta-Integrations in the System Log?

Identify the IP address in the System Log and compare it against the official allowlist to verify that the event is a legitimate internal Okta communication.

  1. Identify the IP address associated with the Okta-Integrations event in the System Log.
  2. Compare the IP address against the official Okta IP address allowlist.
  3. If the allowlist contains the IP address, the event is a valid internal system process.
Loading
Okta-Integrations Displays as the RawUserAgent with Okta IP Addresses | Okta Support