loading
Preparing LoginRadius developer resources
Mission: Help enterprises accelerate digital transformation with our fully-managed Customer IAM technology.
Skip to main content

Security Analytics

A dedicated view for authentication-event health — successful and failed logins, the reasons behind failures, password-reset activity, MFA outcomes, and account-protection signals. Use it to spot abuse patterns, weak factor configurations, and infrastructure regressions before they reach the helpdesk.

Access: Admin Console → Insights → Security Analytics. If the feature is not enabled on your tenant, contact support@loginradius.com.


Modules

Pick a module to drill into one slice of authentication health. Each tab shows the headline counts on top and a trend chart below — successful events in green, failures in red.

Total login volume split into Successful and Failed. Filter by Login factor (Email, Passkey, Social Login) to isolate one channel.
210
Total
199(94.76%)
Successful
11(5.24%)
Failed
806040200Jun 2Jun 4Jun 6Jun 8Jun 9

Failed Login Reasons

11
Total failures
4(36.4%)
Username or password wrong
4(36.4%)
User id locked
2(18.1%)
OAuth invalid grant
1(9.1%)
Provider required error
43210Jun 2Jun 4Jun 6Jun 8Jun 9

Protections

Background guards that block abusive sign-in attempts before they reach your application. Each tab shows the daily count of events the guard intercepted — a flat-zero baseline is the expected state.

Repeated authentication attempts from the same credential, IP, or account that exceeded the configured threshold are blocked at the gate.
6420Jun 2Jun 5Jun 9

Controls & Actions

Two controls scope what the page shows and produce a shareable snapshot: Date Range bounds every chart on the page, and Export downloads the current view as a PDF.

The date range at the top of the page bounds every chart in Security Analytics. Click either input to open the picker.
Minimum
15 minutes
Maximum
7 days
Timezone
Account-configured
2026-06-02 00:002026-06-09 00:00
Two date-time inputs separated by an arrow. Click either to open the picker.

Best practices

Watch the failure ratio, not just the count

A small absolute number of failures on a low-traffic day can still be alarming if the ratio crosses 5–10%. Always compare Successful vs Failed proportionally.

Cross-reference with Platform Analytics

If failed logins spike, switch to Platform Analytics → Top 5 by IP in the same window to identify the offending clients.

Tune MFA factor mix on real outcomes

Compare failure rates across MFA factors before rolling out a default. Email OTP failures dominated by "expired" suggest tightening the TTL is wrong — users need more time, not less.

Treat protection spikes as signal, not noise

Brute Force or Breached Password spikes are often the first sign of a coordinated attack. Investigate IPs immediately and consider tightening thresholds for the duration.