Passwordless sign-in on Azure Sentinel logs

Taiwo Oyewo 21 Reputation points
2022-11-11T10:04:16.767+00:00

I would like to know how to spot in Sentinel sign-in logs the kind of sign-in a user has performed when they login to their account i.e., is it with credentials including password or a passwordless sign in may be through a security key or Microsoft Authenticator/ Azure AD.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,595 questions
0 comments No comments
{count} votes

Accepted answer
  1. Givary-MSFT 28,406 Reputation points Microsoft Employee
    2022-11-14T10:06:38.983+00:00

    @Taiwo Oyewo Just wanted to check if the above mentioned suggestion by our expert has helped or not regarding your issue.

    Also you can review this article https://www.jasonsamuel.com/2020/05/21/how-to-report-on-microsoft-authenticator-password-less-phone-sign-in-fido2-security-key-usage-using-azure-ad-azure-monitor-log-analytics/ talks about similar ask which you are looking for.

    Let me know if you have any further questions.

    Please remember to "Accept Answer" if any of the answer helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Clive Watson 5,716 Reputation points MVP
    2022-11-11T12:30:09.47+00:00
    1 person found this answer helpful.
    0 comments No comments