The following list of audit events are supported for “Workplace from Meta”:
| Event Name | Description |
|---|---|
| Admin activate account | An admin has activated an account from the admin panel or via the account management API. |
| Admin create account | An admin has created an account from the admin panel. |
| Admin deactivate | An admin has deactivated an account from the admin panel or via the account management API. |
| Admin force log out | An admin has forced a user logout across all devices from the admin panel. |
| Admin set to unclaimed | An admin has set a user’s account state to unclaimed, from the admin panel or via the account management API. |
| Force password reset | An admin has forced a user to reset their password from the admin panel. |
| Password change | A user’s password has been changed, as a result of completing password recovery or via their account settings. |
| Password reset request | A user’s password recovery flow has been initiated, and a code has been sent to the user’s email address. |
| Password reset success | A user’s password recovery flow has been successfully completed. |
| Password reset wrong code | A user entered an incorrect password reset recovery code. |
| Two factor disabled | A user has disabled two-factor authentication from the settings tab. This does not capture when someone disables two-factor for a particular phone, but indicates that the feature was disabled. |
| Two factor enabled | A user has enabled two-factor authentication from the settings tab. This does not capture when someone confirms a particular phone, but indicates that the feature was enabled. |
| User login | User logs in. |
| User logout | User logs out. |

