<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00006zjgQfCAIOkta Classic EngineAdministrationAnswered2023-05-16T19:08:06.000Z2021-05-27T21:19:19.000Z2021-05-30T23:01:23.000Z

JamesK.45504 (Customer) asked a question.

Granting and Revoking Admin role logging

Wondering if anyone has found a good way to look at the logs to see when a user has been removed from a role and which role?

 

If the user only has the one role and are removed I am seeing an entry for "displayMessage=Revoke user privilege", but the event will show that all roles available in Okta are being removed.

 

Also if the user has multiple roles and only one or some have been removed the only event I am able to find is a "displayMessage=Grant user privilege" and shows roles that the user still holds.

 

On the other hand is there a way to see only the role that was added as well since if you add a role you see the grant user event, but it will show all roles that they hold so you can't tell if it was one or multiple roles applied at that time.


  • User15869520088343348455 (Vendor Management)

    Unfortunately, this is not possible at this point, I would recommend that you submit a feature request.

    While I was unable to find the Feature Request already listed, here's where you can submit your idea:

    https://support.okta.com/help/oktaideas

    This page is closely monitored by Engineering and used to filter and consider ideas for future implementation.

    Expand Post
This question is closed.
Loading
Granting and Revoking Admin role logging