MIND YOUR ATTACK GAPS
GAP:
Authentication Succeeds
SIGN-IN 1/8
Some are real users. Some are attackers with stolen sessions, malicious OAuth grants, or freshly reset MFA. You have 12 seconds per sign-in to APPROVE / DENY.
72 HOURS LATER

Same accounts. Now watch the behavior.

The login told you nothing. Once these accounts are inside, what they do gives them away.
You couldn't decide this at the sign-in. In the behavior after, the attacker can't stay quiet.
GAP: AUTHENTICATION SUCCEEDS
0
of 8 sign-ins called right
"The audit log said yes."