> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/successful-access-from-a-previously-only-failing-ip.md).

# Successful Access from a Previously Only Failing IP

Detects successful logins from an IP address that has only produced failed login attempts against accounts in your org over the last 30 days. A user will fail this check if a successful login occurs within the last 7 days from an IP that was previously associated only with failures. IP addresses are assessed using a risk-based scoring model that weighs both the volume and behavioral pattern of failed attempts.<br>

**Recommended Actions**

Contact the end user to verify whether they recognize the successful login. If it cannot be confirmed as legitimate, revoke all active sessions, reset the account credentials, and review recent activity for unauthorized actions.

\
**Compatibility**

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)

[Okta](/integrations/okta-data-integration.md)

[Duo](/integrations/duo-security-integration.md)

[Google Workspace](/integrations/google-workspace-integration.md)

<figure><img src="/files/bBMadoOZLjFCc7w9qWVr" alt=""><figcaption></figcaption></figure>
