Loading
Salesforce now sends email only from verified domains. Read More
Identify Your Users and Manage Access
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Monitor Identity Verification History

          Monitor Identity Verification History

          Use Identity Verification History to monitor and audit up to 20,000 records of your org users’ identity verification attempts from the past 6 months. For example, when a user successfully provides a time-based, one-time password (TOTP) as proof of identity during multi-factor authentication (MFA), that information is recorded in Identity Verification History.

          Required Editions

          Available in: Essentials, Contact Manager, Group, Professional, Enterprise, Performance, Unlimited, and Developer Editions

          To access Identity Verification History, from Setup, enter Verification History in the Quick Find box, then select Identity Verification History. To view more information, such as the user’s approximate geographic location when verified, create a custom view, and add the columns you want.

          Identity Verification Fields

          The following fields are displayed by default.

          Field Description
          Time The date and time of the identity verification attempt, for example, 7/19/2025, 3:19:13 PM PDT. The time zone is based on GMT.
          Verification Attempt ID of the verification attempt. Verification can involve several attempts and use different verification methods. For example, in a user’s session, a user enters an invalid verification code (first attempt). The user then enters the correct code and successfully verifies identity (second attempt). Both attempts are part of a single verification and, therefore, have the same ID.
          Username The username of the user challenged for identity verification.
          Activity Message

          The text the user sees on the page or in Salesforce Authenticator when prompted to verify identity. For example, if identity verification is required for a user’s login, the user sees “You’re trying to Log In to Salesforce.” In this case, the activity message is “Log In to Salesforce.” If the user activity is “Apex-defined activity,” the activity message can be a custom description passed by an Apex method. If the user is verifying identity using Salesforce Authenticator 2.0 or later, the custom description appears in the app and in Identity Verification History. If the custom description isn’t specified, Identity Verification History shows the name of the Apex method.

          If the user attempted to access a connected app, but the app was renamed or deleted after the verification attempt, this field shows the original connected app name.

          Triggered By

          The identity verification security policy or setting.

          • Apex method—Identity verification made by a verification Apex method.
          • Device activation—Identity verification required for users logging in from an unrecognized device or new IP address. This verification is part of Salesforce’s risk-based authentication.
          • Lightning Login enrollment—Identity verification required for users enrolling in Lightning Login. This verification is triggered when the user attempts to enroll. Users are eligible to enroll if they have the Lightning Login User user permission and the org has enabled Allow Lightning Login in Session Settings.
          • High assurance session required—High assurance session required for resource access. This verification is triggered when the user tries to access a resource, such as a connected app, report, or dashboard, that requires a high-assurance session level.
          • Lightning Login login—Identity verification required for internal users logging in via Lightning Login. This verification is triggered when the enrolled user attempts to log in. Users are eligible to log in if they have the Lightning Login User user permission and have successfully enrolled in Lightning Login. Also, from Session Settings in Setup, Allow Lightning Login must be enabled.
          • Profile session level policy—Session security level required at login. This verification is triggered by the Session security level required at login setting on the user’s profile.
          • Multi-factor authentication required—Multi-factor authentication (formerly called two-factor authentication) required at login. This verification is triggered by the Multi-Factor Authentication for User Interface Logins user permission assigned to a custom profile. Or the user permission is included in a permission set that is assigned to a user.
          Method

          The method by which the user attempted to verify identity in the verification event.

          • Built-in authenticator—A built-in authenticator set up on the user’s device, such as Touch ID or Windows Hello, generated the required credentials.
          • Email message—Salesforce sent an email with a verification code to the address associated with the user’s account.
          • Lightning Login enrollment—Salesforce Authenticator sent a notification to the user’s mobile device to enroll in Lightning Login.
          • One-time password—An authenticator app generated a time-based, one-time password (TOTP) on the user’s mobile device.
          • Lightning Login login—Salesforce Authenticator sent a notification to the user’s mobile device to approve login via Lightning Login.
          • Salesforce Authenticator—Salesforce Authenticator sent a notification to the user’s mobile device to verify account activity.
          • Temporary verification code—A Salesforce admin or a user with the Manage Multi-Factor Authentication in User Interface permission generated a temporary verification code for the user.
          • Text message—Salesforce sent a text message with a verification code to the user’s mobile device. SMS messaging requires a Salesforce add-on license for Identity Verification Credits.
          • U2F security key—A U2F security key generated required credentials for the user.
          Status

          The status of the identity verification attempt.

          • Access denied—The user denied the approval request in the authenticator app, such as Salesforce Authenticator.
          • Access denied: Flagged by user—The user denied the approval request in the authenticator app, such as Salesforce Authenticator, and also flagged the approval request to report to an administrator.
          • Failed: General error—An error caused by something other than an invalid verification code, too many verification attempts, or authenticator app connectivity.
          • Failed: Invalid verification code—The user entered an invalid verification code.
          • Failed: Recoverable error—Salesforce can’t reach the authenticator app to verify identity, but it continues to retry.
          • Failed: Too many attempts—The user attempted to verify identity too many times. For example, the user entered an invalid verification code repeatedly.
          • Succeeded—The user’s identity was verified.
          • Succeeded: Automated response—Salesforce Authenticator approved the request for access because the request came from a trusted location. After users enable location services in Salesforce Authenticator, they can designate trusted locations. When a user trusts a location for a particular activity, such as logging in from a recognized device, that activity is approved from the trusted location for as long as the location is trusted.
          • User challenged; waiting for response—Salesforce challenged the user to verify identity and is waiting for the user to respond or for Salesforce Authenticator to send an automated response.
          Login Time Time of the login attempt, in GMT time zone.
          Source IP The IP address of the machine from which the user attempted the action that requires identity verification. For example, the IP address of the machine from where the user tried to log in or access reports. If it’s a non-login action that required verification, the IP address can be different from the address from where the user logged in. This address can be an IPv4 or IPv6 address.
          Location The country where the user’s IP address is physically located. This value is not localized. Due to the nature of geolocation technology, the accuracy of geolocation fields (for example, country, city, postal code) can vary.

          You can display the following fields by creating a custom view. In the description, the IP address is the address of the machine from which the user attempted the action that requires identity verification. Due to the nature of geolocation technology, the accuracy of geolocation fields (for example, country, city, postal code) can vary.

          Field Description
          City The city where the user’s IP address is physically located. This value isn’t localized.
          Connected App The name and link to the connected app the user attempted to access. If the connected app was renamed since the user’s verification attempt, it shows the new name. If the connected app was deleted since the user’s verification attempt, it shows “Unavailable.”
          Country The country where the user’s IP address is physically located. This value isn’t localized.
          CountryIso The ISO 3166 code for the country where the user’s IP address is physically located. For more information, see Country Codes - ISO 3166.
          Latitude The latitude where the user’s IP address is physically located.
          Login Type The type of login used to access the session.
          Longitude The longitude where the user’s IP address is physically located.
          Postal Code The postal code where the user’s IP address is physically located. This value isn’t localized.
          Subdivision The name of the subdivision where the user’s IP address is physically located. In the United States, this value is usually the state name (for example, Pennsylvania). This value isn’t localized.
          User Activity

          The action the user attempted that requires identity verification.

          • Access a connected app—The user attempted to access a connected app.
          • Access reports—The user attempted to access reports or dashboards.
          • Apex-defined activity—The user attempted to access a Salesforce resource with a verification Apex method.
          • Export and print reports—The user attempted to export or print reports or dashboards.
          • Log in to Salesforce—The user attempted to log in.
           
          Loading
          Salesforce Help | Article