Entra keeps a log of every sign-in by people, service principals and managed identities. Admins (Reports Reader or higher) open it under Monitoring & health to work out why sign-ins failed and which Conditional Access policies were applied.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Sign-in logs in context, with comparison tables and the common traps.
Terms in this definition
- Reports Reader
Entra role able to read audit and sign-in reports. Because the administrator SSPR policy does not cover it, those holding it are subject to the ordinary user SSPR policy.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
Related terms
- Correlation ID
An identifier in the sign-in logs that ties together every request from a single sign-in attempt, useful for filtering and troubleshooting.
- Source IP restoration
Keeps the real public IP of a user visible to Microsoft Graph and Microsoft Entra ID even though traffic goes through Global Secure Access, so sign-in logs, risk detections and IP-based Conditional Access aren't broken.