What is a new-device or unfamiliar-login event?¶
It is a risk or notification event generated when a sign-in differs from the provider's previous observations. It marks activity for attention, not confirmed compromise or a physically new device.
Familiarity is an inference from changing signals¶
Providers may compare browser cookies, device characteristics, IP address, estimated location, application and behaviour. Clearing cookies, changing browser profile, replacing a phone, using private browsing, roaming or connecting through a VPN can make legitimate access appear unfamiliar.
“New device” may therefore mean only that recognition data was absent. An IP-based location may reflect a carrier gateway or VPN exit rather than the user's actual position.
Identify the signal that triggered the event¶
Preserve the linked authentication, session, device and risk records and obtain the provider's definition. Compare characteristics with known devices and examine the account sequence for password resets, MFA challenges, recovery changes and unusual actions.
The event supports that the provider detected a difference under its model. Whether that difference arose from normal change, privacy tooling or another controller depends on corroborating records.
The point to remember
An unfamiliar-login event is a provider risk signal, not proof of compromise, identity or physical location.