Account takeover and credential stuffing
Stolen credentials arrive from unfamiliar devices at scale. Passwords alone cannot tell an owner from an attacker who knows the password.
Bind each account to the devices it normally uses. A login from a device the account has never presented is a clean, low-false-positive step-up trigger.