Short Answer: Repeated failures can mean incorrect credentials, MFA issues, or automated attacks — note the Date, IP and Location and follow your security procedures to verify and secure the account.
PreRequisites
-
Open 'Settings' > 'Security' > 'Access logs'
-
Ability to contact the affected user or your security/admin team
Steps
-
Open the 'Access logs' table and locate rows for the affected User with 'Incorrect password' or 'MFA failed'.
Identify all recent failure rows for the user. -
Record the Date, IP address and Location for those rows take screenshots if needed.
You have timestamps and IPs documented for investigation. -
Ask the user whether they attempted to sign in; if yes, guide them to verify credentials and MFA; if not, treat as suspicious.
You determine whether attempts were legitimate or likely malicious. -
If attempts appear malicious, escalate to your security/admin team to secure the account reset password, revoke sessions, investigate IP.
Account containment measures are initiated by admin per policy. -
Keep the Access logs data and timestamps for your incident report or support ticket.
You have the necessary evidence for follow-up.
Troubleshooting
-
Failed attempts come from the same IP repeatedly.
LikelyCause: Automated attack or repeated login attempts from the same source.
Action: Block or rate-limit the IP at the network/firewall level and notify security/admin to investigate. -
A legitimate user cannot pass MFA and shows multiple 'MFA failed' rows.
LikelyCause: User’s authenticator is out of sync, lost, or misconfigured.
Action: Have the user reconfigure MFA or use backup codes; involve admin if a recovery is needed. -
All failure events show the same exact timestamp or other duplicate data.
LikelyCause: Log ingestion or display issue.
Action: Refresh the page and re-check; if duplication persists, collect screenshots and report to technical support.
Note: Follow your organization's incident response playbook for account compromise; Access logs provide evidence timestamp, IP, location.