Administration

System logs for Admin role assignment changes

Ricky Yang

Introduction

Role assignments are a powerful way to give permissions and access to various different functionalities within the Admin console. However, our system logs to help customers see which roles were assigned to who and how they were assigned were severely lacking. For the past year or so, there were customers that wanted a more detailed overview on the changes that were made to their admins. Starting in May of 2024, we made a conscious effort for the next 3 months to overhaul the way system logs were fired for role assignment changes to include relevant information so that customers have a better understanding of the admin role assignment changes that were made in their orgs.


Admin role types

There are two types of admin roles: custom roles and out-of-the-box (OOTB) roles. Custom roles are customer defined to provide more fine-grained permission authorizations and OOTB roles are default roles that Okta provides for more general use cases. Both types of roles can be scoped to target resources, which means the admins assigned to these roles can only take action on those specific resources. 


For these system log enhancements, we took both admin role types into account. and provide clear details on which role we changed and if we made any changes to the target resources.


Gaps in the legacy implementation

  • No indication which role was changed. In order to see what was changed, customers had to either make api calls or compare the last few events.
  • No indication whether a role was added or removed. All changes - except for the last removal always resulted in a privilege.grant event which made it confusing for the customer to know whether the system log was a result of a grant or a revoke.
  • No indication for which target was added or removed and for which role. Nothing was shown to connect the role that was constrained or loosened to the target resource that was added or removed
  • privilege.revoke event showed all OOTB roles even if they were not assigned to the admin. 

New enhancements

  • Role that was changed is shown in target details. The privilege.grant events now have a target for the added, removed or changed roles.
  • Clear indication that a role was either assigned or unassigned
  • Target that was changed is shown in target details along with the impacted role and if it was added or removed
  • Clear indication if the role assignment change was because of an individual assignment or group-based change.
  • Clear indication of whether or not the role assignment change was a custom role assignment change or a standard OOTB role change
  • Last role that was revoked - resulting in a privilege.revoke event - added as a specific target

Side-by-side comparisons

We won’t go through every enhancement we made to the system logs in this section, but here are some examples that showcase how much of an improvement we’ve made.


Assigning “Report Administrator” to an existing organization administrator


Legacy event



As you can see in the image above, the legacy event really doesn’t show a lot of information. The DebugData field only shows which roles the user currently has and not much else.


Enhanced event


In contrast, the enhanced system log clearly shows that the role of “Report Administrator” was assigned. (Enhanced targets are highlighted by a black box.) 


Adding a new target resource to a user’s group admin role when they’re also a help desk admin


Legacy event


Above, the request-URI provides some details about the target group that was changed, but it doesn’t specify whether it was added or removed. The changed role is also shown in the report-URI, but it appears as an encoded string, which doesn’t provide much value to the customer


Enhanced event


Here in the enhanced event, there’s a clear indication that the target was assigned to the “Group Administrator” role along with the display name of the target and the ID.


Organization Administrator assigned to a group

Legacy event


Not really much different from when a user is directly assigned a role.


Enhanced event


The Legacy event clearly tells you that the role was assigned as a result of a group role change.


We’ve made important strides in the clarity of our system log enhancements for role assignments. Now, admins can see more details about how a role assignment was changed, which will improve the auditing process and in turn help strengthen the security of our customers.


Our team strives to maintain the quality of system log events for our future projects and features to deliver coherent data to our customers and provide the tools they need to secure their workforce identity. Llearn more about Admin Roles here

  • 0 Likes
  • 0 Comments
  • 785 Views
Skip Feed

Nothing here yet?

Log in to post to this feed.

End of Feed
Nothing here yet?Log in to post to this feed.