Short Answer: 'Action' describes the authentication event: 'New device' or 'Recognized device' relate to device recognition; 'Incorrect password' and 'MFA failed' indicate authentication failures.
PreRequisites
- Access the 'Access logs' tab under 'Security'
Steps
-
Open 'Security' → 'Access logs' and locate the 'Action' column.
You can see Action values and their icons for each event. -
Interpret 'New device' as a sign-in from a device not previously associated or recognized for that user.
Row labeled 'New device' indicates a first-time or unrecognized device. -
Interpret 'Recognized device' as a sign-in from a previously seen or trusted device.
Row labeled 'Recognized device' indicates the device was known to the system. -
Interpret 'Incorrect password' as a failed password authentication attempt.
Row labeled 'Incorrect password' indicates the password was rejected. -
Interpret 'MFA failed' as a failed multi-factor authentication challenge.
Row labeled 'MFA failed' indicates the multi-factor check did not succeed.
Troubleshooting
-
A 'New device' event appears that you don’t recognize.
LikelyCause: A new device accessed the account or device recognition data was cleared.
Action: Verify with the user; if unauthorized, follow your organization's account recovery and security procedures e.g., secure account, require password reset, reconfigure MFA. -
You see many 'Incorrect password' entries in quick succession.
LikelyCause: Incorrect credentials entered repeatedly or an automated brute-force attempt.
Action: Confirm whether the user forgot their password; if unauthorized, escalate to security/admin to lock or reset the account per your policy. -
A legitimate user reports 'MFA failed' but they used the correct code.
LikelyCause: User’s MFA device time may be out of sync or their MFA method is misconfigured.
Action: Have the user re-sync their authenticator app or use backup/recovery options according to your organization's MFA procedures.
Note: Use the Action value together with Date, IP address and Location to assess risk.