Okta sign-in review board with location and VPN checks

By General Input

See two weeks of Okta sign-ins grouped by person, with the city, network owner and VPN status behind every address, plus one-click lockdown.

Integrations

  • Okta
  • IPinfo
  • Slack Bot

Type

App

Categories

  • Operations
  • Engineering

Build me an app my security team opens each morning to review where our Okta sign-ins are actually coming from. It is a working console, not a report: the geography evidence and the response buttons live on the same screen.

Main view: a sign-in review board. Pull the last 14 days of successful and failed sign-in events with the Okta List System Log Events operation (session start, authentication and policy-deny events), following the cursor pagination until the window is complete. Group the events by user, not by raw event, so one traveller does not flood the board. Each user row shows their name and login, how many successful and failed sign-ins they had, how many distinct addresses and countries they signed in from, which applications were involved, and when they were last seen.

IP enrichment: collect every distinct address across the fetched events, deduplicate it, and enrich the whole set once per run with the IPinfo Batch IP Lookup operation, using Core / Plus IP Lookup for the richer record where the account's plan allows it. Cache each address once per run and persist the enrichment so reopening the board does not re-spend IPinfo quota, which is metered per plan and per day. For every address show the city and region, the country, the network owner (the autonomous system number and organisation name), and flags for VPN, proxy, Tor exit, relay and hosting or datacenter address.

Degrade gracefully on enrichment. IPinfo's privacy and VPN detection and its company data are paid-plan features: when the token's plan omits them, those fields are simply absent or the request is refused for that field. Do not let that break a row or the board. Fall back to the free country plus network owner signal and label the row from the organisation name, since a hosting or transit network name is still a strong tell that this is not a normal employee connection. Private and non-routable addresses come back marked as bogons with no geography, so render those as internal rather than unknown.

Sort users by risk, highest first. First, impossible travel: two successful sign-ins whose locations are too far apart for the time elapsed between them. Compute the great-circle distance between the two coordinates and the implied travel speed, and flag anything above a configurable threshold, defaulting to roughly 800 km/h. Second, the first time we have ever seen that user signing in from that country, compared against the countries seen for that user in the fetched window and in the app's own stored history. Third, sign-ins from hosting, datacenter or anonymizer networks. Everything else sits below, and benign repeats (same provider and same city that user has used before) sink to the bottom. Show the reason a user is ranked where they are, in plain words, on the row itself.

Filters across the top for user, country and application. Clicking a user opens a detail panel with their full timeline for the window: each sign-in with its timestamp, result, application, address, city and country, network owner, and any privacy flags.

Response buttons on each user row and in the detail panel, each behind a confirmation step: Okta Revoke All User Sessions to sign them out everywhere, Okta Reset User MFA Factors so they re-enrol, and Okta Reset User Password to start the reset flow. Record who pressed which button and when, and show that action history on the row so the next reviewer sees what was already done.

A cleared state that persists server side. Marking a case cleared removes it from the default board and it does not come back tomorrow unless that user has new risky activity after the cleared timestamp. Include a toggle to show cleared cases, with who cleared them and when.

A share button on each case that posts the case to the security channel using the Slack Bot Send a Message operation: the user, why they are flagged, the addresses involved with their city, country, network owner and privacy flags, and what has already been actioned. Make the destination channel a setting in the app.

An "Investigate this account" button that kicks off a background agent for that one user. The agent pulls that user's last 30 days of events with Okta List System Log Events, collects every distinct address they used, enriches them with IPinfo Batch IP Lookup and Get Full IP Details, and looks up the owning networks with IPinfo Get ASN Details to see who really operates each one. It then writes a plain English timeline of the account's activity and a verdict (looks like normal travel, looks compromised, or needs more information) with the evidence behind it. Store that output against the user's case and render it in the same detail panel the reviewer is already reading, with a status of queued, running or complete and a finished-at timestamp so nobody has to leave the app to check on it.

Practical notes to bake in: Okta system log history is retained for a limited window, 90 days by default, so keep the board window and the investigation window inside it and surface a clear message if a request reaches past retention. Respect Okta rate limits by honouring the reset headers rather than hammering the log endpoint. Batch every IP lookup and never look up the same address twice in a run. Make the review window (default 14 days) and the impossible-travel speed threshold configurable in the app's settings.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them

Stop eyeballing the Okta log every morning.

Get the sign-in geography, the VPN evidence and the lockdown buttons on one screen your security team can work from.

Use prompt

Create a free account to use this prompt. No credit card required.