Quickstart: Analyze a sign-in with the Microsoft Graph API
In this Quickstart, you'll use the information in the Microsoft Entra sign-in logs to figure out what happened if a sign-in of a user failed. This quickstart shows you how to access the sign-in log using the Microsoft Graph API.
Prerequisites
To complete the scenario in this quickstart, you need:
- Access to a Microsoft Entra tenant: If you don't have access to a Microsoft Entra tenant, see Create your Azure free account today.
- A test account called Isabella Simonsen: If you don't know how to create a test account, see Add cloud-based users.
- Access to the Microsoft Graph API: If you don't have access yet, see Microsoft Graph authentication and authorization basics.
Perform a failed sign-in
Tip
Steps in this article might vary slightly based on the portal you start from.
The goal of this step is to create a record of a failed sign-in in the Microsoft Entra sign-in log.
Sign in to the Microsoft Entra admin center as Isabella Simonsen using an incorrect password.
Wait for 5 minutes to ensure that you can find a record of the sign-in entry in the logs.
Find the failed sign-in
This section provides the steps to locate the failed sign-in attempt using the Microsoft Graph API.
Sign in to Microsoft Graph Explorer as a user with permissions to run a query.
Select Modify permissions to ensure you have the correct permissions.
Select GET as the HTTP method from the dropdown.
Set the API version to beta.
Select Run query.
Review the query response and locate the status section of the response.
Clean up resources
When no longer needed, delete the test user. If you don't know how to delete a Microsoft Entra user, see Delete users from Microsoft Entra ID.