Okta Super Admins - Part 3: How to Identify Super Admin Activity

Event Types Exclusive to Okta Super Admins

This is part 3 of a series on Okta Super Admins. Part 1 asked, ARE You Eligible for Okta Super Admin? Part 2 explained that, You Don’t Need So Many Super Admins.

Wouldn’t it be nice if Okta made it clear in the Event Log when a Super Org Admin has used their Super powers to make a change? Yes, Oktually thinks it would be too!

Here is Oktually’s take on the events that will tell you who has been using their Super Admin authority, YMMV.

This list is available from Okta support, but all of the events except user.account.privilege.grant can be triggered by non-Super Admins.

#Super Admin PermissionEvent Type
1Grant access to Okta Supportsystem.directory.debugger.grant
system.directory.debugger.revoke
2Manage sensitive attributesapp.saml.sensitive.attribute.update
3Add, remove, and view administratorsuser.account.privilege.grant
user.account.privilege.revoke
group.privilege.grant
group.privilege.revoke
4Edit default email settings for other adminsiam.role.subscriptions.update*
5Manage log streamingsystem.log_stream.lifecycle.activate
system.log_stream.lifecycle.create
system.log_stream.lifecycle.deactivate
system.log_stream.lifecycle.delete
system.log_stream.lifecycle.update
6View import monitoringUnknown
7Add users to a group with assigned admin privilegesIncluded in #3
8Assign admin privileges to a groupAlso included in #3
9Create and configure hooksevent_hook.activated
event_hook.created
event_hook.deactivated
event_hook.deleted
event_hook.updated
inline_hook.activated
inline_hook.created
inline_hook.deactivated
inline_hook.deleted
system.hook.key.created
system.hook.key.deleted
system.hook.key.updated
10Add/update/delete user profile policiespolicy.rule.activate**
policy.rule.add**
policy.rule.deactivate**
policy.rule.delete**
policy.rule.invalidate**
policy.rule.update**
11Drag and drop policies for prioritizationAs mentioned in part 2, it seems this doesn’t require Super Admin
12Edit MFA authenticators in policiesSame as #11
13Enable MFA for the Admin DashboardNot relevant since August 2024

* Not in the standard Event List
** With a policy type of Okta:ProfileEnrollment

Join us in part 4 to find out about The Okta Admin Downgrade Path!