Home Setting What do the Action statuses 'New device', 'Recognized device', 'Incorrect password' and 'MFA failed' mean?

What do the Action statuses 'New device', 'Recognized device', 'Incorrect password' and 'MFA failed' mean?

Last updated on Aug 27, 2026

Short Answer: 'Action' describes the authentication event: 'New device' or 'Recognized device' relate to device recognition; 'Incorrect password' and 'MFA failed' indicate authentication failures.

PreRequisites

  1. Access the 'Access logs' tab under 'Security'

Steps

  1. Open 'Security' → 'Access logs' and locate the 'Action' column.
    You can see Action values and their icons for each event.

  2. Interpret 'New device' as a sign-in from a device not previously associated or recognized for that user.
    Row labeled 'New device' indicates a first-time or unrecognized device.

  3. Interpret 'Recognized device' as a sign-in from a previously seen or trusted device.
    Row labeled 'Recognized device' indicates the device was known to the system.

  4. Interpret 'Incorrect password' as a failed password authentication attempt.
    Row labeled 'Incorrect password' indicates the password was rejected.

  5. Interpret 'MFA failed' as a failed multi-factor authentication challenge.
    Row labeled 'MFA failed' indicates the multi-factor check did not succeed.

Troubleshooting

  1. A 'New device' event appears that you don’t recognize.
    LikelyCause: A new device accessed the account or device recognition data was cleared.
    Action: Verify with the user; if unauthorized, follow your organization's account recovery and security procedures e.g., secure account, require password reset, reconfigure MFA.

  2. You see many 'Incorrect password' entries in quick succession.
    LikelyCause: Incorrect credentials entered repeatedly or an automated brute-force attempt.
    Action: Confirm whether the user forgot their password; if unauthorized, escalate to security/admin to lock or reset the account per your policy.

  3. A legitimate user reports 'MFA failed' but they used the correct code.
    LikelyCause: User’s MFA device time may be out of sync or their MFA method is misconfigured.
    Action: Have the user re-sync their authenticator app or use backup/recovery options according to your organization's MFA procedures.

Note: Use the Action value together with Date, IP address and Location to assess risk.