> For the complete documentation index, see [llms.txt](https://windows.dfirhandbook.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://windows.dfirhandbook.com/windows-artifacts/account-usage/crowdstrike-searches/event-name-ssoapplicationaccess.md).

# Event Name - SsoApplicationAccess

**Description**

**Platforms:** *Public Cloud*

Indicates successful access to an application through an SSO facilitator, which could be either an IDaaS directory, a federation portal, or a combination of both, such as Azure with AD-FS.

**Fields: Public Cloud**

| Field                           | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| ActivityId                      | A globally-unique identifier for the activity event.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ContextTimeStamp                | System time of event creation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| SsoEventSource                  | <p>The source from which the activity data was retrieved. In the case of federated-SSO, this might be either the IDaaS vendor or the federation provider, depending on the retrieval method.</p><p>Values:</p><ul><li>AZURE (1)</li><li>OKTA (2)</li><li>ADFS (100)</li><li>PING\_FEDERATE (101)</li></ul>                                                                                                                                                                                                                           |
| WebSessionIdentifier            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| SourceAccountUserName           | The username associated with this activity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| SourceAccountAzureId            | The unique Azure `userId` value of the user associated with this activity                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| SourceAccountOktaId             | The unique OKTA actor ID of the user associated with this activity                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| SourceAccountObjectSid          | The `objectSid` value of the account bound with this activity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| SourceAccountObjectGuid         | The `objectGUID` value of the account bound with this activity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| SourceEndpointAddressIP4        | <p>The IP address of the endpoint from which this activity originates.</p><p>Mutually exclusive with the <code>SourceEndpointAddressIP6</code> field.</p>                                                                                                                                                                                                                                                                                                                                                                            |
| SourceEndpointAddressIP6        | <p>The IP address of the endpoint from which this activity originates.</p><p>Mutually exclusive with the <code>SourceEndpointAddressIP4</code> field.</p>                                                                                                                                                                                                                                                                                                                                                                            |
| SourceEndpointIpReputation      | <p>The reputation attributes of the source IP (<code>SourceEndpointAddressIP4</code> or <code>SourceEndpointAddressIP6</code>).</p><p>Only set for public addresses.</p><p>Values:</p><ul><li>NONE (0x00)</li><li>ANONYMOUS\_ACTIVE (0x01)</li><li>ANONYMOUS\_SUSPECT (0x02)</li><li>ANONYMOUS\_INACTIVE (0x04)</li><li>ANONYMOUS\_PRIVATE (0x08)</li><li>ASSOCIATED\_WITH\_DICTIONARY\_ATTACK (0x10)</li><li>ASSOCIATED\_WITH\_DDOS\_ATTACK (0x20)</li><li>ASSOCIATED\_WITH\_SPAM (0x40)</li><li>HOSTING\_FACILITY (0x80)</li></ul> |
| SourceEndpointNetworkType       | <p>The network type to which the <code>SourceEndpointAddressIP4</code> or <code>SourceEndpointAddressIP6</code> value belongs, depending on customer configuration.</p><p>Values:</p><ul><li>INTERNAL (0x1)</li><li>VPN (0x2)</li><li>WIRELESS (0x4)</li><li>NAT (0x8)</li><li>PUBLIC (0x10)</li></ul>                                                                                                                                                                                                                               |
| SourceEndpointNetworkTag        | The network tag to which the `SourceEndpointAddressIP4` or `SourceEndpointAddressIP6` value belongs, depending on customer configuration.                                                                                                                                                                                                                                                                                                                                                                                            |
| SourceEndpointHostName          | <p>The hostname of the source endpoint. Might originate either directly from the raw event data or from one of the host association resolution methods.</p><p>When available, either the <code>SourceEndpointAccountObjectSid</code> or <code>SourceEndpointAccountObjectGuid</code> fields are superior for use as foreign keys.</p>                                                                                                                                                                                                |
| SourceEndpointAccountObjectSid  | The `objectSid` value of the source endpoint account.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| SourceEndpointAccountObjectGuid | The `objectGUID` value of the source endpoint account.                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ClientUserAgentString           | The HTTP User-Agent string identified by the client.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ClientIdentifier                | A human readable string identifying the client, if available.                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| LocationLongitudeAsInt          | <p>The location longitude value associated with the event.</p><p>The value is a 4-digit precision fixed-point value (11.1m) represented as a 64-bit integer.</p><p>Divide by 100,000 to get back the fixed-point value</p>                                                                                                                                                                                                                                                                                                           |
| LocationLatitudeAsInt           | <p>The location latitude value associated with the event.</p><p>The value is a 4-digit precision fixed-point value (11.1m) represented as a 64-bit integer.</p><p>Divide by 100,000 to get back the fixed-point value.</p>                                                                                                                                                                                                                                                                                                           |
| LocationAccuracyRadius          | The reported accuracy radius for (`LocationLatitudeAsInt`, `LocationLongitudeAsInt`).                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| LocationCountryCode             | The country-code associated with (`LocationLatitudeAsInt`, `LocationLongitudeAsInt`).                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| LocationStateCode               | The state-code associated with (`LocationLatitudeAsInt`, `LocationLongitudeAsInt`).                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| LocationCityCode                | The city-code associated with (`LocationLatitudeAsInt`, `LocationLongitudeAsInt`) as listed in the *GeoNames* database.                                                                                                                                                                                                                                                                                                                                                                                                              |
| SsoApplicationIdentifier        | <p>The human-readable target application identifier.</p><p>For stronger identification, use either the <code>SsoApplicationUri</code> field, or vendor-specific fields such as <code>AzureApplicationId</code>.</p>                                                                                                                                                                                                                                                                                                                  |
| SsoApplicationUri               | The URL or URN of the target application.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| AzureApplicationId              | The unique Azure `appId` value of the application accessed. Is only available when the `SsoEventSource` field is set to `AZURE`.                                                                                                                                                                                                                                                                                                                                                                                                     |
| OktaApplicationId               | <p>The unique Okta actor ID of the application being accessed.</p><p>Only set if the <code>SsoEventSource</code> field is set to <code>OKTA</code>.</p>                                                                                                                                                                                                                                                                                                                                                                              |
| AppliedDisposition              | A bit mask of the disposition the sensor has applied.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| IdpEntityId                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

<br>
