What is a multi-factor authentication event?¶
A multi-factor authentication event records one stage in a process that uses more than one authentication factor. Its exact event type determines whether a challenge was issued, answered, verified or followed by access.
MFA produces several distinct records¶
A flow may combine a password with an authenticator approval, one-time code, security key, biometric or trusted-device check. Logs can separately record challenge creation, delivery, approval, denial, timeout and final sign-in.
An approved factor is not necessarily a completed login. Risk-based or remembered-device flows may also satisfy policy without displaying a new prompt, so “MFA completed” should be used only when the linked records support it.
Establish method, stage and result¶
Preserve the account, application, method, registered device, source, transaction or session ID and provider result. Link the factor event to the primary sign-in and resulting session. Product definitions explain whether a success field means a valid response or final access.
Number matching, device details and additional confirmation can strengthen an attribution, but do not eliminate shared devices, remote control or deception. State what the provider verified before inferring who responded.
The point to remember
An MFA event must be interpreted by its method and stage; a successful factor is not automatically successful account access.