Skip to main content

User Audit

The Audit tab provides a history of important activities associated with a user account.

Administrators can use audit information to review account changes, authentication activity, access changes, and other security-relevant events.


Accessing User Audit​

To view a user's audit history:

Users → Select a User → Audit

  1. Open Users.
  2. Select the required user.
  3. Select the Audit tab.


Audit Events​

Audit records can include events related to:

  • User account changes.
  • Authentication activity.
  • Session activity.
  • Role and access changes.
  • MFA and passkey changes.
  • Linked identity changes.
  • Administrative actions.

Reviewing Audit Activity​

When investigating a user account:

  1. Open the Audit tab.
  2. Review the available events.
  3. Identify unexpected or unfamiliar activity.
  4. Compare the activity with the user's sessions and authentication factors.
  5. Take corrective action when necessary.

Security Investigations​

Audit history can help administrators investigate:

  • Unexpected sign-ins.
  • Changes to user access.
  • Authentication factor changes.
  • Session termination.
  • Administrative actions.
  • Changes to linked identities.

For example, if an unfamiliar session appears under User Sessions, administrators can use the Audit page to review related activity.