We’re currently using Log Streams and a webhook to react to MFA-related changes in Auth0.
While evaluating Event Streams, I noticed MFA changes seem to surface only as generic user.updated events, so we’d need to detect changes (e.g. multifactor_last_modified) and then call the Management API to determine the actual MFA state. Event Streams appear to be positioned for user lifecycle synchronization, while Log Streams are described as being primarily for monitoring and analytics.
For a production system that needs to keep MFA state synchronized with Auth0, would Auth0 recommend moving from Log Streams to Event Streams? If so, what are the advantages in this scenario? Is the intended pattern to react to user.updated and then query the Management API for current MFA methods?
Thanks!