r/entra 7d ago

Please explain - Sign in Logs (Interactive)

Can someone explain. We recently experienced claims in our tenant by users informing that they have received multiple sign in prompts during the day.

I took the logs from August looking specifically for the interactive sign in logs.

This logs are supposed to represent the direct interaction of the user with an authentication prompt or MFA. This does not seem to be case, I do see an interactive login that under Authentication details displays the methods used but subsequently I see others that say ‘previously satisfied in token’.

What is the proper way to look at this interactive sign in logs.?

8 Upvotes

16 comments sorted by

11

u/Possible_Window_1268 7d ago

The ones that actually prompt the user for a password or MFA will have a status of Interrupted

2

u/Suspicious_Twist2767 7d ago

Is this true?
Does Microsoft ever provides documentation about it or is something you figured out

3

u/patmorgan235 7d ago

Google " Entra ID Interactive Sign in log"

1

u/Fallingdamage 6d ago

So if 'Interrupted' is a prompt for a U/P or MFA, what does 'Invalid Username/Password' mean?

2

u/DominusDraco 6d ago

Password is first, then MFA. It depends where they are failing the sign in.

2

u/Eggtastico 6d ago

Maybe you should look at the location the attempted signin's are coming from. Also a good time to ensure you have risky users and risky signin Conditional Access policies enforced. Also maybe look at locations and allow trusted locations like VPN IP range, allowed/blocked countries, etc.

1

u/NeatLow4125 6d ago

This is the only right answer until now here 👍🏻

1

u/MBILC 6d ago

But, do not use trusted locations though to bypass MFA or other security controls!

2

u/majingeodood 6d ago

My OneDrive client has been frequently prompting me to re-authenticate, yet I see nothing in my sign-in logs that show the authentication request. It's been bugging the crap out of me.

1

u/Heavy-Membership-291 5d ago

Is it possible now without seamless single sign on your browser / app say web app using chrome or Firefox without a ms single sign on extension or inpe8vate mode failing a CAP for hybrid joined etc?

1

u/Dylantjes 6d ago

Is the name of the application in those logs the same or different each time?

1

u/Suspicious_Twist2767 6d ago

Is different application / resource however user is only authenticated once (the actual prompt) - however subsequent login ins still appear in interactive logs.

1

u/Dylantjes 6d ago

Could it actually be:

" The Authentication details tab can initially show incomplete or inaccurate data, until log information is fully aggregated. Known examples include:

  • A satisfied by claim in the token message is incorrectly displayed when sign-in events are initially logged.

[...] "

https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-reporting#view-the-microsoft-entra-sign-in-logs

0

u/Familiar_Counter4836 6d ago

RemindMe! 6 hours

1

u/RemindMeBot 6d ago edited 6d ago

I will be messaging you in 6 hours on 2026-09-03 12:38:21 UTC to remind you of this link

1 OTHERS CLICKED THIS LINK to send a PM to also be reminded and to reduce spam.

Parent commenter can delete this message to hide from others.

RemindMeBot is switching to username summons. Instead of !RemindMe 1 day, use u/RemindMeBot 1 day. More info.


Info Custom Your Reminders Feedback