<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Jan 20, 2016 at 7:05 AM, Marvin Addison <span dir="ltr"><<a href="mailto:marvin.addison@gmail.com" target="_blank">marvin.addison@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">It seems like there ought to be a straightforward way to determine from audit logs whether a profile execution results in a new authentication or reuse of an existing one (i.e. SSO). Is there a way to do this out of the box?</blockquote></div><br>As a proxy for my security folks, I added AuthenticationInstant to my audit logs.  Comparing that to the event time was enough to give them most of what they wanted, which was mostly to determine if an SSO session was used.  (An actual indicator would be better still, though.)</div><div class="gmail_extra"><br></div><div class="gmail_extra">Greg</div></div>