Audit log innacuracies

Anonymous
2018-09-17T11:41:47+00:00

Hi all, 

Is there a reason why audit logs display a "resultstatus:succeeded" for "userloggedin" events when later on the in the individual log it states "logonerror": "temporaryRedirect"?

Then in the azure ad sign-in logs the same event is considered a failed event.

If this event is really a failed event, why is it referred to as a temporary redirect not referred to as a failed login/event? 

Additionally,  

why is the action successful if the event failed?

Microsoft 365 and Office | Subscription, account, billing | For home | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

Anonymous
2018-09-20T13:18:08+00:00

Hi Joshua Smith,

As per your concerns, if the ResultStatus shows succeeded, then it indicate that this user logged in successfully, which means, ResultStatus property shows whether the log in was successful or not.

As for redirect values, we think that is because when a user tries to login, Office 365 will firstly redirect him to authenticate with Azure Ad, as Office 365 uses Azure Active Directory (Azure AD) to manage user identities behind the scenes, user identity and authentication are handled completely in the cloud by Azure AD. Here’s the article about relationship between Office 365 and Azure AD: Understanding Office 365 identity and Azure Active Directory.

About Azure Ad sign-in log, we tried to check the screenshot you provided, however, we have no permission to further analyze this kind of log, to better help you, I suggest you to contact our dedicated Teams Support and let him help check your sign-in logs: https://azure.microsoft.com/en-us/support/community/ .

Thanks,

Anna

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

7 additional answers

Sort by: Most helpful
  1. Anonymous
    2018-09-18T15:15:10+00:00

    Hello Joshua Smith,

    Thanks for the information you provided.

    The result in Office 365 Audit log should be consistent with Azure Ad Sign-in log for a same event. When checking user sign-in event, I suggest admin refers to the information Azure ad reported.

    For Office 365 Audit log, it can take up to 30 minutes or up to 24 hours after an event occurs for the corresponding audit log entry to be displayed in the search results. here’s the article for your reference: https://docs.microsoft.com/en-us/office365/securitycompliance/search-the-audit-log-in-security-and-compliance.

    As per your concerns, user attempts to login via Azure Ad on July 31th, and you can only find a fail attempt on August 17th. If anything misunderstood, please feel free to let me know.

    In the screenshot you provided, it has Failure reason, which indicate that this user inputted wrong username and password, and then been recorded to the log.

    I’d like to confirm if that loggedin activity which show ResultStatus as Succeeded in Office 365 audit log also occurs on date August 17th? Whether they are the same event?

    Thanks,

    Anna

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-09-17T15:00:06+00:00

    Hello Joshua Smith,

    Yes, I have sent one Private Messages to you, please check it: https://answers.microsoft.com/en-us/privatemessage/inbox.

    Thanks,

    Anna

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-09-17T14:12:34+00:00
    1. I have no idea, it seems like I got 3 different results from the log in. 
    2. can this be sent in a PM of some sort?
    3. refer to 2, I can provide more context as well.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-09-17T13:10:14+00:00

    Hello Joshua Smith,

    According to my test, if I login in Office 365 online service successfully, in audit log, UserLoggedIn activity event will show ResultStatus as Succeeded. To better understand your issue, I’d like to confirm the following information:

    1. When you check this user login event, whether this user failed to login Office 365?
    2. the Userloggedin event in individual log states “logerrror”, is it also occurs on Office 365 Audit logs, would you please provide a detailed step about how you create this individual logs so that I can check it on my side?
    3. About Azure ad signed in logs, as I can’t repro your issue, please share a screenshot of that failed event information in signed in logs as well as a screenshot of the same event in Office 365 audit log for comparison.

    Thanks,

    Anna

    Was this answer helpful?

    0 comments No comments