Skip to main content

Real-Time Account & Entitlement Events

Real-Time Account & Entitlement Events narrows the gap between "an account was created, disabled, deleted, or had an entitlement change" and OrbisID knowing about it — instead of waiting for the next scheduled or on-demand scan, OrbisID polls each source system's own audit/activity log (or drains a change-notification queue) on a short interval and applies just the specific change that occurred, without re-running a full scan.

Requires Pro or Enterprise edition — not available on Community.

Allow a few minutes for a change to be detected

A newly-made change is not detected instantly — expect up to the poll interval (5 minutes by default) plus a short delay before the vendor's own audit/activity log even contains the event. Check the Last Attempted / Last successful timestamps on the Real-Time Events tab before assuming something is wrong; if Last Attempted never advances, or shows an error, see Limitations below.

Every supported system (Okta, Entra ID, Google Workspace, PingOne, AWS, Google Cloud Platform, Active Directory) gets a Real-Time Events tab in its Add/Edit System dialog. Fast-poll and (where supported) the opt-in webhook are mutually exclusive — a single three-way control (Off / Fast-Poll / Webhook), not two independent toggles, since a system can only use one at a time.

What it covers​

Source systemMechanism
OktaPolls the Okta System Log API, or (opt-in) receives Okta Event Hooks
Microsoft Entra ID (Azure AD)Polls Microsoft Graph auditLogs/directoryAudits, or (opt-in) receives Graph Change Notifications
Google WorkspacePolls the Admin SDK Reports API, or (opt-in) receives Admin SDK push notifications
PingOnePolls the PingOne Activities API, or (opt-in) receives PingOne Webhooks
AWSDrains an SQS queue fed by CloudTrail via an EventBridge rule
Google Cloud PlatformPulls a Pub/Sub subscription fed by a Cloud Logging sink on Admin Activity audit logs
Active DirectoryReuses Endpoint Sensor event data from a domain controller

Every detected change (account created/enabled/disabled/deleted, entitlement added/removed) is applied directly to the specific account or entitlement it names — unlike a full scan, a fast-poll or queue-drain cycle never marks anything else in your estate as stale, since it only ever sees a small delta, not a complete re-enumeration.

Enabling fast-poll for a system​

For Okta, Entra ID, Google Workspace, and PingOne systems:

  1. Open the system in Systems and go to its Real-Time Events tab
  2. Select Fast-Poll
  3. Set the poll interval (5 minutes by default; 60 seconds is the minimum, to respect each vendor's own rate limits)
  4. Save the system

The tab shows a Last Attempted timestamp (every attempt, success or failure) with a refresh button, a separate Last successful timestamp, and — if the most recent attempt failed — the error and when it will next retry.

Enabling queue consumption for AWS / GCP​

AWS and GCP use the same Fast-Poll selection above, but the queue itself is configured through the target system's own Attributes, on the Connection tab:

SystemAttributeValue
AWSawsSqsQueueUrlThe full SQS queue URL your EventBridge rule delivers CloudTrail IAM events to
Google Cloud PlatformgcpPubSubSubscriptionThe full subscription path, e.g. projects/{project}/subscriptions/{subscription}

Setting these up on the AWS/GCP side (the EventBridge rule, the Cloud Logging sink, the queue/subscription itself) is a one-time piece of cloud configuration outside OrbisID — see your cloud provider's own documentation for routing CloudTrail management events to EventBridge → SQS, or Admin Activity audit logs to a Cloud Logging sink → Pub/Sub. No On-Premise Scan Agent is required for this — OrbisID drains the queue directly from the backend, the same way it polls Okta, Entra ID, Google Workspace, and PingOne.

Enabling AD real-time detection​

Active Directory has no dedicated poll or queue — it reuses account/group-membership events an Endpoint Sensor already collects from a domain controller's Security Event Log for threat detection. There is nothing AD-specific to configure beyond selecting Fast-Poll on the same Real-Time Events tab used everywhere else on this page.

This requires:

  1. An Endpoint Sensor enrolled against this same system record (the domain controller) — Endpoint Sensors require Enterprise edition, and
  2. The domain controller's User Account Management and Security Group Management audit subcategories enabled (auditpol /set /subcategory:"User Account Management" /success:enable /failure:enable, and the same for Security Group Management) — the Endpoint Sensor warns in its own logs if either is off.

Once both are true, account create/enable/disable/delete and group membership add/remove flow through automatically — no separate subscription or attribute is needed.

Enabling opt-in inbound webhooks​

For Okta, Entra ID, Google Workspace, and PingOne systems on a deployment with an internet-reachable backend, a webhook gets true push delivery instead of waiting for the next poll interval. On the system's Real-Time Events tab, select Webhook — OrbisID generates the URL and secret for you.

Each system gets its own separate webhook URL and its own separate secret — nothing is shared across systems, including two systems of the same OS type. The secret is shown exactly once — it isn't stored in plaintext and can't be retrieved again; re-enabling generates a new one and invalidates the old (update the vendor-side config too, or delivery breaks). The URL itself isn't sensitive and is shown persistently in the System dialog's Real-Time Events tab for as long as the webhook is active, with a Revoke Secret button to invalidate it immediately. Register the URL and secret with the vendor yourself:

VendorWhere to registerHow the secret is presented
OktaAdmin Console → Workflow → Event HooksA static Authorization header value on the hook config
Entra ID (Graph)Create a subscription via the Graph API yourself, pointing notificationUrl at the webhook URLThe clientState field on the subscription
Google WorkspaceCreate a users.watch channel yourself, pointing address at the webhook URLThe channel's token field
PingOnePlatform → Notifications → WebhooksA static Authorization header value on the subscription config

OrbisID does not call any of these vendor APIs to create or renew the subscription/channel/hook itself — registering it is a manual, one-time (Okta/PingOne) or periodically-renewed (Graph subscriptions and Google Workspace channels both expire) piece of admin work outside OrbisID. Graph's subscription validation handshake (a validationToken query parameter) is handled automatically by the webhook endpoint, so only the renewal itself needs your attention.

Fast-poll and webhook are mutually exclusive — enabling a webhook for a system automatically disables fast-poll for it, and vice versa. In the System dialog's Real-Time Events tab this is presented as a single three-way choice (Off / Fast-Poll / Webhook), not two independent toggles.

Okta and PingOne webhook payloads are parsed directly (same event mapping as their polling path). Graph and Google Workspace notifications carry no event detail — receiving one simply triggers an immediate fast-poll cycle for that system instead.

Limitations​

  • PingOne detection relies on best-effort parsing of the Activities API / webhook payload and may not catch every event shape a given tenant produces.
  • AWS has no clean "disable a user" signal. IAM doesn't have an account-disable concept the way Okta/Entra/AD/Workspace/PingOne do — only account creation/deletion and policy/group membership changes are detected.
  • GCP entitlement changes are not detected. Only service account lifecycle (create/delete/enable/disable) is covered — IAM policy binding (role grant/revoke) changes are not.
  • AD real-time detection requires an Endpoint Sensor on the domain controller, which requires Enterprise edition. There is no alternative for domain controllers without a sensor, and no way to detect an attribute change (e.g. a description or title field) via this path — only the account/group-membership events listed above.
  • OrbisID does not create or renew vendor-side webhook subscriptions. Registering the hook/subscription/channel, and renewing Graph subscriptions and Google Workspace channels before they expire, is manual admin work — see Enabling opt-in inbound webhooks.
  • Webhook secret verification is a static shared-secret comparison, not HMAC request signing — the secret itself is the only thing standing between a leaked value and a forged event.
  • A failing poll backs off rather than retrying at a fixed cadence — it honours a vendor's rate-limit guidance when given, otherwise widens the interval on repeated failure, capped at 1 hour. On a vendor account with very tight API limits, a system can still end up rate-limited at that ceiling; if so, either raise the poll interval further or switch to the opt-in webhook instead, since it isn't subject to the same polling rate limit.

Licensing​

REALTIME_EVENTS is a Pro/Enterprise feature — see Licensing.