Two logins. Same credentials. Same application. Same organisation.
The first: 9:15 AM, known workstation, corporate network, normal working hours, familiar location.
The second: 2:47 AM, unrecognised device, residential IP in a different city, application not normally accessed by this user.
A static authentication system sees both as identical, valid credentials presented, access granted. A context-aware authentication system sees them as categorically different events and responds accordingly.
That difference between treating every login as the same and treating every login as a unique event with its own risk profile, is what context-aware authentication is about. Not just adding a second factor, but making the authentication decision based on the full picture of what is happening around the login attempt.