Sign-in Log guides
Microsoft Entra ID's record of every authentication attempt, with detail on conditions, MFA, and risk. See the glossary entry →
7 guides touch on sign-in log.
- Adding a named location without breaking Conditional Access
How to add or change a named location in Entra without breaking Conditional Access: MFA and risk side effects, the report-only sequence, the egress-IP trap.
- Cleaning up unused enterprise apps in Entra ID
How to find unused service principals in Entra ID — sign-in activity, credentials, assignments — remove them without breaking year-end integrations.
- Compromised Microsoft 365 account response runbook
Compromised Microsoft 365 account runbook: what to run in the first fifteen minutes, what to check in the first hour, and when it is safe to hand it back.
- Investigating a suspicious sign-in with Entra sign-in logs
How to work a suspicious sign-in in the Entra sign-in logs: which log, which columns matter, traveller vs attacker, and when to escalate to compromise.
- Microsoft 365 monitoring and alerts
How to monitor a Microsoft 365 tenant — service health, audit logs, security alerts, and third-party tooling.
- Rotating an app registration secret without downtime
How to rotate an Entra app registration secret or certificate with zero outage: find every consumer, add the new credential alongside the old, switch, remove.
- Testing Conditional Access policies
How to test Conditional Access policies before enforcing them — report-only mode, what-if, and rollout patterns.