Sign-in Logs

Retrieve and view detailed user and application sign-in activity for the connected Microsoft 365 tenant.

The information displayed is the same as the data available in the Microsoft Entra sign-in logs. For details about the report, available fields, and retention, see the Microsoft Entra sign-in logs documentation.

You must have a Microsoft Entra ID P1 or P2 license to download sign-in logs through sapio365 because it uses Microsoft Graph API.

sign-ins.jpg


Load sign-in activity

  1. On the sapio365 Dashboard, in the Tenant section, click Sign-in logs.

  2. Set a date range to limit the sign-in records retrieved.

  3. Optionally, refine the results further:

    • Select Use advanced filters to apply additional filtering criteria.

    • Set Limit the number of sign-ins returned to retrieve only the most recent entries.

  4. Add cached user properties to the report. Use the type-ahead search on the right to find properties quickly.

  5. Set Limit page size to Yes if you experience frequent timeouts when retrieving a high volume of sign-in records.

get-sign-ins.jpg

Analyze sign-ins

After loading sign-in data, you can update, reorganize, and analyze the results in the GridView.

  1. Select Show/Hide columns, or use the Data Viewer pane on the right, to add properties to the GridView.

  2. Save the current GridView as a Snapshot or Freeze Point.

  3. Reload the sign-in data or adjust the loading options.

  4. For the user associated with a selected sign-in activity, retrieve additional information:

    • User Details

    • Group Memberships

    • Licenses

default-sign-ins.jpg

Switch to another view

Use the views in the left-side panel to display sign-in data in different ways. sapio365 includes several system views, and you can create and save as many custom views as needed.

Available views include:

  • Risk status info: Groups sign-ins first by Risk Status, then by Username.

  • Successful and failed sign-ins: Groups sign-ins by the Status error column.

  • Users with sign-in errors by city: Filters sign-ins by Username and Status, then groups the results by date and city.

switch-views.jpg

Custom report: Last sign-in activity date per user

Create a summarized GridView that displays the most recent sign-in activity for each user within a category or grouping.

  1. In the left-side panel, apply the Successful and failed sign-ins view.

  2. Drag the Username column header to the grouping area, placing it to the left of the existing Status error grouping. This groups sign-in entries first by user, then by sign-in status.

  3. Display the latest date and time for each group at every grouping level:

    • Open the Grouping tab. Select any cell in the date column to set the column as the active column; its header is highlighted in blue.

    • Select Totals > Maximum. sapio365 displays the latest date and time for each group at every grouping level.

  4. Expand the groups to the second-to-last level (Level 1 in this example) to display only the grouping levels.

  5. custom-view-sign-ins1.jpg

    Export the summarized report by copying and pasting the GridView data, or click Export in Grid Actions.

  6. You can also save the view for use in scheduled reports with Quick GridView.

save-view-sign-ins.jpg