Retrieve and view detailed user and application sign-in activity for the connected Microsoft 365 tenant.
The information displayed is the same as the data available in the Microsoft Entra sign-in logs. For details about the report, available fields, and retention, see the Microsoft Entra sign-in logs documentation.
You must have a Microsoft Entra ID P1 or P2 license to download sign-in logs through sapio365 because it uses Microsoft Graph API.
Load sign-in activity
-
On the sapio365 Dashboard, in the Tenant section, click Sign-in logs.
-
Set a date range to limit the sign-in records retrieved.
-
Optionally, refine the results further:
-
Select Use advanced filters to apply additional filtering criteria.
-
Set Limit the number of sign-ins returned to retrieve only the most recent entries.
-
-
Add cached user properties to the report. Use the type-ahead search on the right to find properties quickly.
-
Set Limit page size to Yes if you experience frequent timeouts when retrieving a high volume of sign-in records.
Analyze sign-ins
After loading sign-in data, you can update, reorganize, and analyze the results in the GridView.
-
Select Show/Hide columns, or use the Data Viewer pane on the right, to add properties to the GridView.
-
Save the current GridView as a Snapshot or Freeze Point.
-
Reload the sign-in data or adjust the loading options.
-
For the user associated with a selected sign-in activity, retrieve additional information:
-
User Details
-
Group Memberships
-
Licenses
-
Switch to another view
Use the views in the left-side panel to display sign-in data in different ways. sapio365 includes several system views, and you can create and save as many custom views as needed.
Available views include:
-
Risk status info: Groups sign-ins first by Risk Status, then by Username.
-
Successful and failed sign-ins: Groups sign-ins by the Status error column.
-
Users with sign-in errors by city: Filters sign-ins by Username and Status, then groups the results by date and city.
Custom report: Last sign-in activity date per user
Create a summarized GridView that displays the most recent sign-in activity for each user within a category or grouping.
-
In the left-side panel, apply the Successful and failed sign-ins view.
-
Drag the Username column header to the grouping area, placing it to the left of the existing Status error grouping. This groups sign-in entries first by user, then by sign-in status.
-
Display the latest date and time for each group at every grouping level:
-
Open the Grouping tab. Select any cell in the date column to set the column as the active column; its header is highlighted in blue.
-
Select Totals > Maximum. sapio365 displays the latest date and time for each group at every grouping level.
-
-
Expand the groups to the second-to-last level (Level 1 in this example) to display only the grouping levels.
-
Export the summarized report by copying and pasting the GridView data, or click Export in Grid Actions.
-
You can also save the view for use in scheduled reports with Quick GridView.