Scenario
A user contacts support stating that they were unable to sign in to an application and are unsure what went wrong. An administrator needs to review the user’s login activity to understand what happened during the sign-in attempt, identify where the authentication flow stopped, and determine whether the issue was related to the password, multi-factor authentication (MFA), one-time password (OTP), authenticator, passkey, or the application itself. This investigation is performed using audit visibility only, without making any configuration changes.