Some are real users. Some are attackers with stolen sessions, malicious OAuth grants, or freshly
reset MFA. You have 12 seconds per sign-in to APPROVE / DENY.
72 HOURS LATER
Same accounts. Now watch the behavior.
The login told you nothing. Once these accounts are inside, what they do gives them away.
You couldn't decide this at the sign-in. In the behavior after, the attacker can't stay
quiet.