Failed Logins Review
Failed Logins AI Review (Failed Logins report)
The Failed Logins report includes an AI analysis option for administrators. Unlike the AI Error Diagnoser, which explains one row at a time, this reviews the whole report at once. That difference matters: a single failed sign-in attempt never looks like anything on its own, and the things worth catching — someone working through a stolen list of user names, or repeatedly guessing at one account — are patterns that only appear across many attempts at once.
There are two ways to run it. The Analyze with AI button above the results reviews every attempt matching your current filters. The AI (sparkle) button at the start of each row's action column, next to the View User Location and Block IP Address icons, runs the same analysis narrowed to just that row's IP address, which answers the more useful question of what that address has been doing overall.
Both buttons appear only for users with administrator rights. The Failed Logins report itself can be run by anyone with reporting rights, but the analysis names accounts and recommends administrative actions such as blocking an address, resetting a password or disabling a login, so it is limited to administrators.
The analysis always covers every attempt matching your filters, not just the page shown on screen. Change the date range, user name or IP address filters and re-run the report before analyzing if you want to look at a different window. Because the attempts are summarized before the assistant sees them, the analysis costs the same whether your window contains fifty attempts or fifty thousand.
The result appears in a dialog with a Bottom line telling you whether anything needs your attention, followed by Findings ranked worst first, a Reviewed and cleared section, and What to do next. Each finding is marked Urgent, Worth a look or Minor, and cites the actual counts, names, addresses and times behind it. A Copy button copies the analysis to the clipboard.
Being told that nothing needs your attention is a normal and common result, and is worth as much as any finding. The assistant is deliberately built not to raise an alarm over ordinary activity, because a report that cries wolf gets ignored. It compares the window against your own tenant's recent history rather than against any general expectation, so what counts as unusual is measured against what is normal for you.
The Reviewed and cleared section lists activity the assistant looked at and judged harmless, with the reason. This is there so you can see what has already been ruled out and do not have to re-investigate the same harmless activity next week.
Among the things the analysis looks for: a single address attempting many different user names in a short time, which suggests a stolen list being tried against your tenant; many rapid attempts against one account; attempts spread slowly across many accounts to avoid notice; many different addresses all targeting one account; attempts against user names that do not match any account in your tenant, which is a strong sign the names came from outside; and attempts against accounts that are disabled or have been removed. The most significant thing it checks is whether an address that was failing then went on to sign in successfully, which may mean someone got in rather than merely tried.
Some signals are only ever used as supporting evidence and never raise an alarm on their own, because each has an innocent explanation that is far more common than the guilty one. An account signing in from several addresses is normal for anyone using a mobile network, a VPN or a changing home connection. An address that has not been seen before is normal for any new phone or hotel. Activity outside working hours is normal for shift workers, overseas colleagues and overnight integrations, and the times shown are in UTC rather than your local time.
The analysis pays particular attention to the most common false alarm in this report: a saved password that has gone out of date. A device, mail client or integration still holding an old password will retry steadily and can build up a large number of failed attempts while being completely harmless. The assistant recognizes the steady, evenly spaced pattern this produces, reports it as harmless, and suggests finding the device or integration still using the old password — which is worth doing, because until it is updated it will keep filling this report and may eventually lock the account out.
Where a location is shown for an address it is approximate, reflects the network rather than the person, and is only available for addresses DocMgt has already looked up — through the View User Location icon, for example. Addresses without a stored location are reported as unknown rather than guessed at.
Everything the analysis suggests is limited to things you can do inside DocMgt for your own tenant — blocking an address, resetting a password, disabling a login, requiring multi-factor authentication, asking the person behind an account what they were doing, or tracking down a device holding an old password. The assistant never reports on the infrastructure DocMgt runs on, because that is not something you administer or can act on. Anything that would require that level of access is identified as a DocMgt support item instead.
The analysis is an AI-generated suggestion and should be treated as a helpful starting point rather than a definitive answer. Where the evidence genuinely supports more than one explanation, the assistant says so rather than giving a single false-confident answer.
The AI buttons also require AI to be licensed with an available AI usage allowance. Each analysis counts against the same AI usage allowance used by features such as the Document Summarizer and the AI Error Diagnoser; if the allowance has been reached the assistant reports that instead of running.
To use it: open Reports, run the Failed Logins report with the date range you want to review, then either click Analyze with AI above the results to review the whole window, or click the AI sparkle icon on a row to focus on that address.