
xbpam (xbpam) asked a question.
When viewing System Log, how do you tell what factor was used to login?
I'm trying to investigate a potentially compromised account but the events don't seem to indicate how they got through MFA, just that they were challenged and succeeded. Which factor was used? Why doesn't it say?

Hmm. I'm looking at my own MFA access in System Logs and when I expand into the following section:
Event > System > DebugContext > DebugData > Factor
It shows the method I did MFA. Is this what you're looking for?