What is authentication?¶
Authentication is the check a service performs before it accepts that an account, device or session is allowed to continue.
That might involve a password, an app approval, a security key, a trusted device or an existing authenticated session.
For an investigator, the useful question is what did the service actually accept?
“Login” can hide several different mechanisms¶
A service may grant access after:
- a password;
- a PIN;
- a one-time code;
- an authenticator-app approval;
- a security key;
- trusted-device recognition;
- a session token;
- single sign-on; or
- account recovery.
So a record labelled successful login does not always mean somebody typed a password at that moment.
Read the authentication record carefully¶
A provider event might contain:
S-4812That tells you what the service accepted and which session followed.
It still leaves a human attribution question.
Authentication proves the check, not the person¶
Credentials can be shared.
A saved password can fill automatically.
A trusted device may continue access without a fresh challenge.
A token can maintain an earlier authenticated state.
So separate:
- what the service checked;
- what credential or factor satisfied the check;
- which device or client was involved;
- which session was created; and
- who controlled that device or credential.
Multi-factor authentication adds more than one factor, while successful login records deal with what an access event can actually prove.
The practical point is: authentication tells you which security check succeeded. Use the method, device and resulting session to work out what that means for the investigation.