Audit API - New MFA Audit Events

Description

Added 13 Multi-Factor Authentication (MFA) audit events to the Audit API. These events allow customers to track the full lifecycle of MFA authentication and configuration within their organization.

Configuration events

  • MFA_COMPANY_CONFIGURATION_UPDATED - Company-level MFA configuration was updated (e.g. factor type or mode changed). Includes factorType and mode context.
  • MFA_AUTH_APP_CONFIGURATION_SETUP_SUCCESS - User successfully configured an authenticator app.
  • MFA_AUTH_APP_CONFIGURATION_SETUP_FAILED - A user attempted to configure an authenticator app but the TOTP code verification failed.
  • MFA_AUTH_APP_CONFIGURATION_REMOVED - User removed their authenticator app configuration.
  • MFA_RECOVERY_CODES_GENERATED - New recovery codes were generated for the user.

Login events

  • MFA_LOGIN_STEP_STARTED - An MFA challenge was initiated for the user during login.
  • MFA_OTP_GENERATED - A one-time password was generated and sent to the user. Includes factorType context.
  • MFA_OTP_LOGIN_SUCCESS - User successfully verified a one-time password during login. Includes factorType context.
  • MFA_OTP_LOGIN_FAILED - User failed to verify a one-time password during login. Includes factorType context.
  • MFA_OTP_LOGIN_ATTEMPTS_EXCEEDED - The maximum number of failed OTP verification attempts was reached during login. Includes factorType context.
  • MFA_RECOVERY_CODE_LOGIN_SUCCESS - User successfully verified a recovery code during login.
  • MFA_RECOVERY_CODE_LOGIN_FAILED - User failed to verify a recovery code during login.
  • MFA_RECOVERY_CODE_LOGIN_ATTEMPTS_EXCEEDED - The maximum number of failed recovery code verification attempts was reached during login.

Impact

No breaking changes. Thirteen MFA event types are now available and filterable via the Audit API. Existing integrations are unaffected.

References