iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
An identity-provider sign-in log can show how a user authenticated and which identity policies were evaluated, but it may not explain the full access decision. In Microsoft Entra, start with the event’s Conditional Access and Authentication Details, then check policy-change records and—if needed—the application’s own authorization logs.
What an IdP sign-in log can—and cannot—tell you
A sign-in event is evidence about an authentication attempt and, depending on the identity provider (IdP), the policies evaluated during it. It is not necessarily a complete record of every decision between the user and the feature or data they tried to reach.
Keep three decision layers distinct:
- Authentication: Did the IdP verify the user, and by which method or sequence?
- Identity-provider policy: Which access policies were in scope, and what outcomes did they record?
- Application or resource authorization: After authentication, did the application or resource permit the requested action?
A successful IdP event therefore does not, by itself, establish why a particular application function was allowed—or why it was denied. For example, AWS documents a separate policy evaluation after authentication for console access; that is an example of a downstream decision, not a universal description of all services. AWS: Enabling SAML 2.0 federated users to access the AWS Management Console
How to investigate a Microsoft Entra sign-in
The following workflow applies to Microsoft Entra. Other IdPs may use different fields, terminology, retention settings, and diagnostic tools. Access to logs and policy views depends on the roles and permissions assigned to your account; consult the relevant Entra documentation for the required access. Microsoft: Sign-in logs in Microsoft Entra ID Microsoft: Audit logs in Microsoft Entra ID
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Find and identify the event. In the Microsoft Entra admin center, open Identity > Monitoring & health > Sign-in logs. Confirm the account, client application, target resource, and event time. Use the event’s correlation information when connecting related requests. The portal displays sign-in time in the administrator’s local time zone; in Log Analytics, ingestion time may differ from the event time. Microsoft: Sign-in logs in Microsoft Entra ID
- Inspect the authentication sequence. Open the event’s Authentication Details and review the methods and steps recorded. Check whether a requirement was satisfied by a claim from a prior token instead of a new prompt: a sign-in event does not always mean the user just interacted with an authentication prompt. Microsoft: Sign-in logs in Microsoft Entra ID Microsoft: Authentication strengths
- Read the Conditional Access results policy by policy. Open the event’s Conditional Access tab. Check which policies targeted the user and resource, and distinguish applied policies from excluded, disabled, or report-only policies. Interpret each result in context rather than treating the overall sign-in status as a verdict on every control. Microsoft: Troubleshoot Conditional Access
- Check whether the policy changed. In Identity > Monitoring & health > Audit logs, filter for Conditional Access activity near the event time. Open relevant additions, updates, or deletions and review Modified properties. Compare those changes with the policy outcome recorded on the sign-in. Microsoft: Audit logs in Microsoft Entra ID Microsoft: Troubleshoot Conditional Access policy changes using audit logs
- Use diagnostics if the event still does not make sense. Open the sign-in’s diagnostics and review the analysis and recommendations. For unfamiliar authentication-flow behavior, Microsoft suggests using report-only evaluation or filtering sign-in logs for the relevant flow. Microsoft: Troubleshoot Conditional Access Microsoft: Conditional Access report-only mode
- Continue in the application or resource logs when necessary. If the IdP records successful authentication but the user could not reach a function—or could reach something unexpected—check the application’s or resource’s authorization records for the requested action.
Read Conditional Access outcomes precisely
Microsoft describes Conditional Access policies as “if-then statements: if a user wants to access a resource, then they must complete an action.” Whether a policy appears in a sign-in result depends on its scope and evaluation; the event status alone does not explain every condition or downstream decision. Microsoft: Conditional Access: Zero Trust Policy Engine
- Success is not proof that every policy condition was satisfied. Microsoft notes that one or more policies may have applied or been evaluated without every other condition being satisfied. Read the per-policy results and controls alongside the overall sign-in status. Microsoft: Troubleshoot Conditional Access
- Failure has to be read against the specific evaluation. Check the failed policy, condition, or control shown for the event instead of inferring a cause from the word “Failure” alone. Microsoft: Troubleshoot Conditional Access
- Not Applied does not necessarily indicate a broken policy. A policy may not apply because its conditions did not match, or because a documented exception or bootstrap scenario was involved. Verify the targeted users, resources, and conditions. Conditional Access governs access to cloud resources; it does not protect the local Windows sign-in itself. Microsoft: Troubleshoot Conditional Access Microsoft: Cloud apps, actions, and authentication context
- Disabled and report-only policies are different from enforced policies. A disabled policy is not enforcing its controls; a report-only policy records what its evaluation would do without applying those controls. Check the policy state when interpreting an event. Microsoft: Conditional Access report-only mode
Check log retention before relying on history
Microsoft says Entra audit-log data is retained for 30 days by default. This is an Entra audit-log default, not a universal retention period for all IdPs, log types, or tenant configurations. For a longer history, organizations can configure export to Log Analytics, a storage account, Event Hubs, or a partner solution. If the event or policy change is older than the available history, check whether records were exported before they expired. Microsoft: How long Microsoft Entra ID stores reporting data
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Build an explanation from the right evidence
When deciding why access was allowed or denied, compare evidence from the layer that made the decision:
Recommended Free Tools
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Authentication evidence: Which methods were recorded, in what sequence, and whether a prior token claim satisfied a requirement.
- Policy scope and outcome: Which policies applied, were evaluated, were excluded, or were disabled or report-only; whether their conditions and controls were met.
- Change history: Whether a policy was created, updated, or deleted near the event, and which properties changed.
- Decision layer: Whether the question is about authentication, IdP policy evaluation, or a later application or resource authorization decision.
- Time coverage: Whether the relevant records remain available or were exported to another logging destination.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

