Access to authentication data is strictly limited to staff with a legitimate security need, and all access is logged.
The following information can be seen for any authentication method (SMS, voice, authenticator app, hardware key, etc.):
- Date and time of the last successful authentication
- Authentication logs for the last 30 days only, including success or failure and the IP address of the attempt (used to identify suspicious patterns in log activity)
- The application or service the user attempted to access
Additional information visible when using Microsoft Authenticator with a JJC account:
- Confirmation that the Microsoft Authenticator app was registered for the account
- Device type (such as iPhone or Android)
- Operating system version of the device
What Cannot Be Seen
- Personal data on the device, including photos, files, messages, browsing history, phone calls, text messages, or other apps and services
- One time codes or the content of push notifications
- Real time location or movements
- Any activity related to personal accounts or any non college use of the app
Bottom line: Only authentication metadata required for security is visible. The college does not have access to device contents or personal activities.