question

JasonBarden-7061 avatar image
0 Votes"
JasonBarden-7061 asked JamesTran-MSFT answered

Sign-in logs older than the 30 day limit

I have a user that fell for a phishing scam, the investigating party is wanting sign in information from the incident but was about 100 days ago. is there anyway to gain access to those logs for legal investigation purposes?
Specifically i am looking for the User sign-in logs in the Azure AD.
Thanks for any help!!

azure-active-directoryazure-ad-sign-in-logs
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

michev avatar image
3 Votes"
michev answered JasonBarden-7061 edited

Not unless you're exporting them somewhere. If you are using Office 365, you can use the Unified audit log, which ingests events from Azure AD as well: https://docs.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=o365-worldwide

As detailed in the article, depending on the license you can get events from up to 90 days/1 year back.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

We are using office 365 and it looks like this would have worked if i had enabled the logging. it was not enabled by default.

Thanks for that answer, any other ideas by chance?

1 Vote 1 ·
JamesTran-MSFT avatar image
0 Votes"
JamesTran-MSFT answered

@JasonBarden-7061
Unfortunately, Azure AD does not store any activity data past 30 days.

10354-signindata.jpg

Link: https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/reference-reports-data-retention#how-long-does-azure-ad-store-the-data



Please let us know if any reply/answer helped resolve your question. If so, please remember to "mark as answer" so that others in the community facing similar issues can easily find a solution.



signindata.jpg (29.1 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.