What can login history show?¶
Login history can show how an account-access attempt was recorded by the provider.
It may tell you that access succeeded, failed or was challenged, and record useful context such as time, source address, client, device or authentication method.
That can be strong evidence about the account event. It is not automatically proof of the person behind it.
What might a sign-in record contain?¶
Depending on the provider and product, a record may include fields such as:
finance@example.orgTime: 2026-08-14 07:48 UTCResult: SuccessSource IP: 203.0.113.24Client: BrowserAuthentication: Password + MFASession ID: S-4812The exact fields vary, but the record may help answer:
- which account was involved;
- when the provider handled the access attempt;
- whether it succeeded;
- what authentication route was accepted;
- what network or client context was recorded; and
- whether a session or device identifier can be carried into later activity.
Read location and device labels carefully¶
An IP-derived location is usually an estimate about the network address, not a GPS fix for the person.
A device name may be user-supplied or reflect a registered device record rather than proving current physical possession.
A successful MFA event means the provider accepted its configured authentication process. It does not by itself explain who controlled every factor.
Those details are still useful — they simply need to be interpreted for what they actually represent.
The important event may happen later¶
Suppose the account signs in at 07:48 and a disputed email is sent at 09:12.
There may be no second login at 09:12.
The account may still be operating through session S-4812, a connected application or delegated access.
What account-access records may exist? shows the wider set of records that can complete that chain.
Compare the login with normal and disputed activity¶
Useful comparisons may include:
- other sign-ins from the same account;
- known devices or browsers;
- session and token history;
- mailbox audit;
- message submission;
- password or recovery changes;
- connected applications; and
- independent evidence about who had the device.
That the provider accepted or rejected access to a particular account in a recorded technical context at a particular time.
Who personally controlled the credential, factor, device or continuing session, or who performed every later mailbox action.
The practical point is: login history is often the start of the account timeline, not the end of the attribution exercise.