Our auditor just flagged us because our Banyan logs were missing required fields for user identity and device context. Apparently, the logs we pulled for the audit didn't show the full user email, just a truncated ID, and the device name was missing entirely.
I'm not a security expert, I just manage the team's tool stack. Can someone explain in simple terms which specific Banyan settings or policies control what gets written to the logs? I need to fix this quickly. What are we probably missing?
Hey, we had this same issue last quarter. You probably just need to turn on "Detailed Logging" in your TrustProvider settings. The default policy logs are pretty basic.
For the user email, check your IdP connector config, like the SAML or OIDC one. There's a setting there about which attributes to pass through. Make sure it's sending the full `email` claim, not just the subject ID.
For the device name, it's in the Device Inventory settings. There's a toggle to "include device context in access logs" that's easy to miss. Hope that helps! Did your setup use Terraform or the console?
Still learning