

A user provides username and password in the Microsoft Entra sign-in screen.This log also includes federated sign-ins from identity providers that are federated to Microsoft Entra ID. Users can provide passwords, responses to MFA challenges, biometric factors, or QR codes to Microsoft Entra ID or to a helper app. That authentication factor could also interact with a helper app, such as the Microsoft Authenticator app. They provide an authentication factor to Microsoft Entra ID. Interactive sign-ins are performed by a user. The classic sign-in logs only include interactive user sign-ins.Įntries in the sign-in logs are system generated and can't be changed or deleted. There are four types of logs in the sign-in logs preview: What – The target (Resource) accessed by the identity.How – The client (Application) used for the sign-in.Who – The identity (User) performing the sign-in.You can also describe the activity associated with a sign-in request by identifying the following details: Which of my Azure resources are being accessed by managed identities and service principals?.Are users signing in from specific browsers or operating systems?.How many failed sign-in attempts have occurred in the last 24 hours?.How many users have signed into a particular application this week?.You can use the sign-in logs to answer questions such as: Provisioning – Activities performed by a provisioning service, such as the creation of a group in ServiceNow or a user imported from Workday.Audit – Information about changes applied to your tenant, such as users and group management or updates applied to your tenant’s resources.Two other activity logs are also available to help monitor the health of your tenant: You can still view the classic sign-in logs, which only include interactive sign-ins. The preview view of the sign-in logs includes interactive and non-interactive user sign-ins as well as service principal and managed identity sign-ins.
#CHECK MICROSOFT OFFICE LOGIN HOW TO#
This article explains how to access and utilize the sign-in logs.

The sign-in logs provided by Microsoft Entra ID are a powerful type of activity log that you can analyze. Reviewing sign-in errors and patterns provides valuable insight into how your users access applications and services. As an IT administrator, you need to know what the values in the sign-in logs mean, so that you can interpret the log values correctly. Microsoft Entra ID logs all sign-ins into an Azure tenant, which includes your internal apps and resources.
