Automated Okta Sign-In Anomaly Monitoring
Every morning, WebRun signs in to Okta, reads yesterday's system log events, groups sign-in failures by user and application, flags locked out accounts and sign-ins from countries your team does not work from, posts the summary to Slack, and texts the IT lead when one account shows a burst of failures.
How do I review Okta sign-in failures and lockouts each morning?
WebRun reviews your Okta sign-in activity every morning. It reads yesterday's system log, groups failures by user and application, flags locked out accounts and sign-ins from unusual locations, posts the summary to Slack, and texts your IT lead when one account shows a burst of failures.
- A credential problem is handled the same day it appears
- Lockouts and unusual locations arrive grouped by user, not event by event
- No account is suspended automatically: a person always decides
Built for IT leads · security teams · identity administrators · IT operations
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
login.okta.comin a real browser with your saved login - no setup, no API keys. -
1
Okta - read yesterday's sign-in events
WebRun opens Okta to read yesterday's sign-in events. - Sign in to Okta and open the system log filtered to yesterday
- Group sign-in failures by user and by application
- List every account that was locked out and how many times
- Flag successful sign-ins from countries or networks your team does not normally use
Done when Yesterday's failures, lockouts, and unusual locations are grouped by user.
-
2
Twilio - text the IT lead
WebRun opens Twilio to text the IT lead. - Text the IT lead when one account crosses your failure threshold in a single day
- Name the user, the application, the failure count, and the location
- Send nothing on quiet mornings
- Never suspend, reset, or lock an account: WebRun reports and the IT lead acts
Done when The IT lead has been texted about any account under sustained failure.
-
3
Slack - post the morning summary
WebRun opens Slack to post the morning summary. - Post the morning summary to the IT channel
- Lead with locked out accounts, then unusual locations, then repeated failures
- Show yesterday's totals against the daily average so a spike is obvious
- Leave every account action to a person
Done when The IT channel has yesterday's sign-in summary.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Can it suspend or reset an account?
No. WebRun reads the system log and reports. Suspending a user, forcing a password reset, or clearing a lockout stays with your IT lead, because a wrong action locks out a real person.
How does it decide a location is unusual?
You list the countries and networks your team works from once. Successful sign-ins from anywhere outside that list are flagged in the morning summary with the user and the application.
Will it flood the channel on a noisy day?
No. Failures are grouped by user and application rather than posted event by event, and only accounts crossing your threshold trigger a text, so the summary stays one readable post.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.