SKIP TO CONTENT
ACCOUNTS AND AUTHENTICATION30 / 36

Entra ID Sign-in Logs

Also called Azure AD sign-in logs, Microsoft 365 sign-in logs, conditional access logs, cloud authentication logs.

PLATFORM
Cloud
CATEGORY
Accounts and Authentication
INDEX
30 of 36
PROVES
4 findings
CANNOT PROVE
5 limits
QUESTIONS
3 answered
WHAT IT IS

Tenant-side records of every authentication to Microsoft 365 and connected applications, with the application, IP address, device state, and conditional-access outcome — retained for days unless exported.

Where it lives

Microsoft Entra ID sign-in logs in the tenant, exportable to a log workspace, storage account, or SIEM

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of entra id sign-in logs” is neither.

What it records

Each authentication produces a record naming the account, the application, the client used, the IP address and the location the service resolved it to, whether the device was registered or compliant, and the result including which conditional-access policies applied. Interactive and non-interactive sign-ins are recorded separately, and non-interactive records — token refreshes and background service authentication — are far more numerous and frequently mistaken for user activity.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That an account authenticated to a named application at a recorded time, and whether it succeeded
  • The IP address the service observed and the device state it evaluated, which can distinguish a managed corporate device from an unknown one
  • Which conditional-access policies applied, and whether multi-factor authentication was satisfied
  • Patterns across accounts and applications, which is how anomalous access is identified in the first place

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • That the account is the person. Cloud logs have the same attribution gap as any other authentication record, and the addition of geolocation makes it look narrower than it is
  • That a location is where the user was. Location is derived from IP address and is wrong routinely — VPNs, corporate egress, mobile carrier routing and address databases that lag reality all produce misleading values
  • That the record still exists. Sign-in log retention in the portal is short and depends on the tenant's licensing, and the figures have changed over time, so the actual window has to be established in the tenant rather than assumed
  • Human activity, from a non-interactive record. Token refreshes and background service authentication generate large volumes of records that no person initiated
  • What the account then did. Sign-in logs record authentication; activity comes from the unified audit log and the workload's own records

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Showing that a geolocation is a derivation from an IP address rather than an observation, and producing an innocent routing explanation
  • Reclassifying records the examiner treated as user sessions as non-interactive token activity
  • Establishing that the retention window closed before preservation, so the produced set is partial and its gaps are not evidence of absence
  • Attacking the account-to-person link where credentials were shared or a device was left signed in

What survives, and for how long

Portal retention is short — measured in days or weeks depending on the tenant's licensing — and the applicable figures have changed across Microsoft's licensing tiers over time. Longer retention exists only where the tenant exported the logs to a workspace, storage account or SIEM beforehand. Confirm the tenant's actual configuration; do not assume a figure.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

How long are Entra ID sign-in logs kept?

Not long, and the exact window depends on the tenant's licensing tier and has changed over time — it is measured in days to a few weeks in the portal. Longer availability exists only where the tenant exported sign-in logs to a log workspace, storage account or SIEM before the events at issue. Establish the tenant's actual configuration rather than relying on a published default.

Does a sign-in log location show where someone actually was?

No. The location field is derived from the IP address the service observed, and it is wrong routinely: VPNs, corporate network egress, mobile carrier routing and stale address databases all produce locations that do not match the user's physical position. Treat it as a lead about network path, not as evidence of where a person was standing.

What is the difference between interactive and non-interactive sign-ins?

Interactive records reflect an authentication a person completed; non-interactive records reflect token refreshes and background service authentication that no one initiated. Non-interactive records are far more numerous, and an examiner who counts them as user sessions will report activity that never happened. Any opinion resting on sign-in volume has to say which category it counted.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the entra id sign-in logsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Cloud forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.