Skip to content
LOG-094 Logs, Records & Provider Evidence

Does an MFA approval prove that the account holder approved it?

No. An MFA approval proves that the system received an approval through the registered method.

It does not automatically prove the account holder personally understood and authorised the login.

Avoid this assumption: That an approved push notification is conclusive proof of the named user’s intent. It is not.

The approval may have been given accidentally, in response to repeated prompts, under social engineering pressure or by another person with access to the device. The device itself may have been compromised or remotely controlled.

Some systems use number matching, biometric confirmation or location details to strengthen the process. Those controls can increase confidence, but they do not eliminate every alternative explanation.

The event may show the account, registered device, approval method, source address, application and timestamp. It can support the proposition that the provider accepted the second factor.

Investigators should obtain the exact MFA method and flow. Ask whether the user saw a number, application name, location or warning. Determine whether the device was shared, unlocked or remotely accessible.

Preserve linked login, session, notification and device records. Communications may also show whether the user was being pressured or deceived at the time.

Use careful language. It may be accurate to state that an MFA request was approved through the registered device while remaining uncertain who made the decision, who physically controlled the device or whether the person understood the consequence.

Operational takeaway

An MFA approval shows that the registered authentication method returned approval, but personal identity, understanding and intent still require supporting evidence.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.