Session History
Session History is the sign-in record for your business unit. Active Sessions shows who is signed in right now; Session History shows what happened — every sign-in and every refused attempt, with how each session ended. Entries are kept for one year.
Open it from Configuration → Security → Session History in the Admin console. Administrators see every user in the business unit; anyone else who opens it sees only their own sign-ins.
Filter the history
| Filter | Options |
|---|---|
| User | Search for one user by name, or All users |
| Outcome | All attempts, Successful only, Failed only |
| Sign-in source | All sign-in sources, App, Admin, Other / undeclared |
| From / To | A date range, in your own time zone |
Clear filters resets them all. Results are paged; choose how many rows to show per page at the bottom.
What each column shows
| Column | What it tells you |
|---|---|
| User | The email address used. No matching account means someone tried an address that has no account. |
| Outcome | Success, or Failed with the reason — for example Wrong password, Wrong OTP, OTP expired, Wrong PIN, Wrong MFA code, Account locked, Account deactivated, Device not trusted or PIN login unavailable. |
| Method | How they signed in — Password, Email OTP, PIN, PIN unlock, Authenticator app, MFA backup code, Google, Microsoft, Sign-up, Invite accepted, Shared-link OTP or Shared-link PIN. |
| Source | Where the sign-in came from — App, Admin, or Undeclared (for example, a sign-in from an older app version or an integration). |
| Signed in | Date and time of the attempt, in your organisation's date format. |
| Signed out | When the session ended and how: Signed out, Revoked by admin, Password reset, Replaced by a newer sign-in or Expired. A session still running shows Still active and when it expires. |
| Device / Browser | The browser, and the device name and type. Hover for the full details. |
| IP | The IP address the attempt came from. |
When to use it
- A user says they can't sign in — filter to that user and Failed only to see the reason.
- Suspicious activity — look for repeated failures, unfamiliar IP addresses or devices, and then revoke the session in Active Sessions.
- Audits — show who accessed the business unit and when, over any range within the last year.