Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To track authentication-method registration in Microsoft Entra ID, query Microsoft Graph’s v1.0 userRegistrationDetails report. Use the collection endpoint for a tenant-wide inventory or add a user’s Entra object ID to retrieve one record. The report shows registration and capability state; it is not a real-time log of each registration action.

Choose the tenant-wide report or a single-user lookup

Both requests use the Microsoft Graph v1.0 reports API. For a delegated request, send a bearer token in the Authorization header.

Use case Request What to know
Tenant-wide inventory GET https://graph.microsoft.com/v1.0/reports/authenticationMethods/userRegistrationDetails The collection endpoint supports documented filters and returns a collection.
One user GET https://graph.microsoft.com/v1.0/reports/authenticationMethods/userRegistrationDetails/{userId} Replace {userId} with the Entra user object ID. This operation does not support OData query parameters.

For endpoint details, see Microsoft’s list user registration details and get user registration details references.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set permissions and confirm licensing

Microsoft documents AuditLog.Read.All as the least-privileged permission for both operations, for application access and delegated work or school account access. For delegated access, the signed-in user also needs an appropriate directory role or custom role. The documented roles for these v1.0 operations include Reports Reader, Security Reader, Security Administrator, and Global Reader. Personal Microsoft accounts are not supported.

Microsoft’s authentication methods usage report overview says access to authentication methods usage and insights reports requires Microsoft Entra ID P1 or P2. Check that the tenant and workload are appropriately licensed before rollout. See the Microsoft Graph usage and insights overview.

Filter a tenant-wide inventory

The collection endpoint supports filters on documented identity and registration properties, including isMfaCapable, isMfaRegistered, isSsprEnabled, isSsprRegistered, methodsRegistered, userDisplayName, and userPrincipalName. For example, this filter selects records where MFA is registered:

GET https://graph.microsoft.com/v1.0/reports/authenticationMethods/userRegistrationDetails?$filter=isMfaRegistered%20eq%20true

To select records whose registered methods include email, the documented expression is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
GET https://graph.microsoft.com/v1.0/reports/authenticationMethods/userRegistrationDetails?$filter=methodsRegistered/any(x:x%20eq%20'email')

Supported operators vary by field. Check Microsoft’s list operation reference before relying on more complex expressions. The single-user operation does not accept OData filters.

Interpret the fields without confusing registration and capability

A userRegistrationDetails record contains identity fields such as id, userDisplayName, userPrincipalName, and userType; an administrator indicator; MFA and self-service password reset (SSPR) registration and capability indicators; passwordless capability; registered methods; preferred-method fields; and lastUpdatedDateTime. The resource’s field definitions are in Microsoft’s userRegistrationDetails reference.

  • isMfaRegistered indicates that the user has registered an MFA method.
  • isMfaCapable indicates whether the user has an allowed method and is therefore capable of performing MFA under the authentication methods policy. Registration alone does not mean a method is allowed by policy.
  • methodsRegistered lists registered methods. Examples include mobilePhone, email, and passKeyDeviceBound; the set can evolve, so consult the current resource reference for the full list.
  • lastUpdatedDateTime is the UTC time when the report record was last updated. It is not the timestamp of a particular method-registration event.

Account for report freshness and omissions

Microsoft’s authentication methods activity guidance says the details report updates for most users within 36 hours, with rare cases taking longer. Treat it as a periodically updated report rather than a real-time feed. Disabled users and recently deleted (soft-deleted) users are omitted; Microsoft also says the list API does not work for disabled users. See Authentication methods activity for the report guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use the current API, not the retired credential report

For production work, use the v1.0 userRegistrationDetails endpoint. Microsoft’s documentation for the older credentialUserRegistrationDetails API says it is deprecated and stopped returning data on June 30, 2024; the replacement is the current user registration details API. See the deprecated resource notice.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.