Settings and activity
3 results found
-
4 votes
An error occurred while saving the comment -
4 votes
An error occurred while saving the comment wanted to follow up here with an update. Thanks to Chris for flagging earlier that a ticket had already been created for this — we wanted to dig back in and see where things stood as Chris is not in the company anymore.
We took a closer look together with our front-end engineering team, and it turns out this is currently limited by Okta itself: the Sign-In Widget doesn't support setting up separate, more specific inline error messages for blocked or suspended users versus general authentication/access failures. Okta intentionally shows a generic, hardcoded security message in these blocked/suspended cases, mainly to avoid leaking information that could help a bad actor figure out an account exists and is simply blocked.
So unfortunately, we don't have a way to customize this messaging within the standard widget as it stands today.
-
6 votes
An error occurred while saving the comment Thank you for raising this, and for the detail, it's a helpful description of the problem.
You're right that this isn't supported today. Changing roles on a product instance that's already assigned to a group currently means removing the instance and re-adding it with the roles you want. We recognise that's more disruptive than it should be, particularly for larger groups where the instance is briefly removed for every member.
This is a known gap and it's on our backlog. It's been on our radar for a while and we're planning to prioritise it in the coming quarter. Support for editing roles in place is the intended behaviour here, the current add-and-remove model isn't where we want to leave it.
Hi, thank you for raising this — it's a completely valid concern and we take security visibility seriously.
Good news: this capability already exists in Admin Center today. Under Settings → Usage & Billing, there is an Opti ID User Activity Log that captures exactly what you're looking for — including who added or removed users, what was changed, when it happened, and whether the action was performed by a human admin or the system. So if an unknown external email was added as a Super Admin, that action would appear in this log with the actor's details.
You can also download the log in multiple formats (CSV, Excel, HTML etc.) by clicking the three-dot menu in the top right corner of the table, making it easy to share or audit offline.
This feature is currently tucked away under Usage & Billing, which isn't the most intuitive place to look when you're investigating a security concern. That's something we're looking at improving so it's easier to find.
In the meantime, we'd recommend bookmarking that page and using the filters to narrow down by event action (e.g. 'added') and date range whenever you need to investigate a specific change.
Thanks again for taking the time to share this — it directly helps us prioritize where to improve.