All templates

Automated Okta Sign-In Anomaly Monitoring

Every morning, WebRun signs in to Okta, reads yesterday's system log events, groups sign-in failures by user and application, flags locked out accounts and sign-ins from countries your team does not work from, posts the summary to Slack, and texts the IT lead when one account shows a burst of failures.

Runs on WebRun · Strict Lockdown policy
Every day at 8:00 AM WebRunorchestrates each step
1 Okta read yesterday's sign-in events
2 Twilio text the IT lead
3 Slack post the morning summary
In short

How do I review Okta sign-in failures and lockouts each morning?

WebRun reviews your Okta sign-in activity every morning. It reads yesterday's system log, groups failures by user and application, flags locked out accounts and sign-ins from unusual locations, posts the summary to Slack, and texts your IT lead when one account shows a burst of failures.

  • A credential problem is handled the same day it appears
  • Lockouts and unusual locations arrive grouped by user, not event by event
  • No account is suspended automatically: a person always decides

Built for IT leads · security teams · identity administrators · IT operations

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens login.okta.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Okta - read yesterday's sign-in events
    okta.com
    WebRun in Okta: read yesterday's sign-in events
    WebRun opens Okta to read yesterday's sign-in events.
    • Sign in to Okta and open the system log filtered to yesterday
    • Group sign-in failures by user and by application
    • List every account that was locked out and how many times
    • Flag successful sign-ins from countries or networks your team does not normally use

    Done when Yesterday's failures, lockouts, and unusual locations are grouped by user.

  3. 2
    Twilio - text the IT lead
    twilio.com
    WebRun in Twilio: text the IT lead
    WebRun opens Twilio to text the IT lead.
    • Text the IT lead when one account crosses your failure threshold in a single day
    • Name the user, the application, the failure count, and the location
    • Send nothing on quiet mornings
    • Never suspend, reset, or lock an account: WebRun reports and the IT lead acts

    Done when The IT lead has been texted about any account under sustained failure.

  4. 3
    Slack - post the morning summary
    slack.com
    WebRun in Slack: post the morning summary
    WebRun opens Slack to post the morning summary.
    • Post the morning summary to the IT channel
    • Lead with locked out accounts, then unusual locations, then repeated failures
    • Show yesterday's totals against the daily average so a spike is obvious
    • Leave every account action to a person

    Done when The IT channel has yesterday's sign-in summary.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
login.okta.com
ScheduleRuns automatically on this cadence
Every day at 8:00 AM
DeliveryHow each run's result reaches you
Sign-in summary · Slack
OutputWhat each run produces - A daily summary of failed sign-ins, lockouts, and sign-ins from unusual locations, grouped by user.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Can it suspend or reset an account?

No. WebRun reads the system log and reports. Suspending a user, forcing a password reset, or clearing a lockout stays with your IT lead, because a wrong action locks out a real person.

How does it decide a location is unusual?

You list the countries and networks your team works from once. Successful sign-ins from anywhere outside that list are flagged in the morning summary with the user and the application.

Will it flood the channel on a noisy day?

No. Failures are grouped by user and application rather than posted event by event, and only accounts crossing your threshold trigger a text, so the summary stays one readable post.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.