<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
User Risk Detections in System Log without Identity Threat Protection SKU
Okta Identity Engine
API Access Management
Overview

This article explains the conditions under which user.risk.detect events are displayed in the Okta System Log when Okta is configured as a Shared Signals Framework (SSF) receiver. It provides details regarding the required Identity Threat Protection (ITP) SKU and specific administrator exceptions for event visibility.

Applies To
  • Identity Threat Protection
  • Shared Signals Framework
  • Okta System Log
  • Adaptive Multi-Factor Authentication
  • Okta Identity Engine
Cause

When Okta acts as a Shared Signals Framework (SSF) receiver, security signals from third-party providers are ingested and reported as entity risk detections. However, visibility for these user.risk.detect events in the Okta System Log is generally restricted to organizations with an active Identity Threat Protection (ITP) SKU. Without this specific license, the system does not display these events for standard users, although an exception exists for the super admin role to ensure visibility for highly privileged accounts.

Solution
  • Verify the organization has the Identity Threat Protection (ITP) SKU enabled.

  • Ensure Okta is correctly configured as a Shared Signals Framework (SSF) receiver by following the steps in Configure an SSF receiver.

  • Sign in as a user with the super admin role to view user.risk.detect events if the ITP SKU is not present.

Loading
User Risk Detections in System Log without Identity Threat Protection SKU