Okta-Integrations Displays as the RawUserAgent with Okta IP Addresses
Last Updated:
Overview
The System Log displays login events or other activities where the RawUserAgent appears as Okta-Integrations originating from Okta IP addresses.
The following image displays an event in the Okta System Log when Okta services communicate internally.
This expected behavior occurs because Okta's internal systems use this agent for communication. Verify these events by comparing the associated IP address against the official Okta IP address allowlist.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- System Log
Cause
This occurrence is expected behavior. The Okta-Integrations RawUserAgent facilitates communication within Okta internal systems. Login events to the Admin Console display multiple occurrences of this behavior, including administrators who appear to sign in from an Okta IP address.
Solution
How to verify an Okta event that contains Okta-Integrations in the System Log?
Identify the IP address in the System Log and compare it against the official allowlist to verify that the event is a legitimate internal Okta communication.
- Identify the IP address associated with the
Okta-Integrationsevent in the System Log. - Compare the IP address against the official Okta IP address allowlist.
- If the allowlist contains the IP address, the event is a valid internal system process.
