Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is an authentication log?

An authentication log records identity-checking events such as sign-in, failure, factor challenge, token use, session creation or lockout. Success does not necessarily mean a named person entered a password.

Authentication has several mechanisms and stages

Passwords, biometrics, security keys, one-time codes, trusted endpoints, cookies, refresh tokens and single sign-on create different events. A success may be token refresh, service authentication or session continuation. Location is often inferred and address or endpoint fields can be shared or generic.

Resolve method and resulting session

Obtain event definitions and ask whether the row concerns primary login, step-up, token refresh or continuation. Preserve session and correlation IDs and associated application records.

Use endpoint, communications, subscriber and access-pattern evidence to identify who supplied or approved the factor and who performed later activity.

The point to remember

Authentication logs show how an identity check was recorded; they do not alone prove the human controller or later actions.

Reference: LOG-016Logs, Records & Provider Evidence