Home Setting Why am I seeing multiple 'Incorrect password' or 'MFA failed' entries for the same user and what should I do?

Why am I seeing multiple 'Incorrect password' or 'MFA failed' entries for the same user and what should I do?

Last updated on Aug 27, 2026

Short Answer: Repeated failures can mean incorrect credentials, MFA issues, or automated attacks — note the Date, IP and Location and follow your security procedures to verify and secure the account.

PreRequisites

  1. Open 'Settings' > 'Security' > 'Access logs'

  2. Ability to contact the affected user or your security/admin team

Steps

  1. Open the 'Access logs' table and locate rows for the affected User with 'Incorrect password' or 'MFA failed'.
    Identify all recent failure rows for the user.

  2. Record the Date, IP address and Location for those rows take screenshots if needed.
    You have timestamps and IPs documented for investigation.

  3. Ask the user whether they attempted to sign in; if yes, guide them to verify credentials and MFA; if not, treat as suspicious.
    You determine whether attempts were legitimate or likely malicious.

  4. If attempts appear malicious, escalate to your security/admin team to secure the account reset password, revoke sessions, investigate IP.
    Account containment measures are initiated by admin per policy.

  5. Keep the Access logs data and timestamps for your incident report or support ticket.
    You have the necessary evidence for follow-up.

Troubleshooting

  1. Failed attempts come from the same IP repeatedly.
    LikelyCause: Automated attack or repeated login attempts from the same source.
    Action: Block or rate-limit the IP at the network/firewall level and notify security/admin to investigate.

  2. A legitimate user cannot pass MFA and shows multiple 'MFA failed' rows.
    LikelyCause: User’s authenticator is out of sync, lost, or misconfigured.
    Action: Have the user reconfigure MFA or use backup codes; involve admin if a recovery is needed.

  3. All failure events show the same exact timestamp or other duplicate data.
    LikelyCause: Log ingestion or display issue.
    Action: Refresh the page and re-check; if duplication persists, collect screenshots and report to technical support.

Note: Follow your organization's incident response playbook for account compromise; Access logs provide evidence timestamp, IP, location.