In Azure AD sign In logs, I see logs where the UPN field gives an Object GUID rather than actual UPN of the user.

Acuriouscase-8163 0 Reputation points
2024-08-20T06:24:26.09+00:00

In Azure AD sign In logs, I see logs where the UPN field gives an Object GUID rather than actual UPN of the user. Is there any reason why this is so? And for analysis using signIn logs can we exclude this data?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,065 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 32,986 Reputation points Microsoft Employee
    2024-08-21T09:41:34.74+00:00

    @Acuriouscase-8163 Thank you for reaching out to us, As I understand you would like to know why the User field is showing as Object ID or GUID instead of the user principal name.

    Here are the few common reasons why user field is showing as object id or GUID in the sign-in report instead of the user's UPN:

    1. When a user is unauthenticated and is not yet signed in, interrupt user flow - error 50058 - UserInformationNotProvided - Session information isn't sufficient for single-sign-on. This means that a user isn't signed in. This is a common error that's expected when a user is unauthenticated and hasn't yet signed in. - AADSTS50058
    2. If the User is showing as "00000000-0000-0000-0000-000000000000", then it could be due to Tenant Restrictions.
    3. If the sign-in has not been fully aggregated with MFA data. If looking at the sign-in within a few minutes of sign-in, there could be an incremental state where we have not resolved the user DisplayName. Waiting a few minutes should show the correct results. The data should be fully aggregated within few hours, although it typically happens much quicker than that. This may be seen for 50074 interrupt events.
    4. When a user tried to initiate a connection from Windows laptop, but purposely cancelled from his mobile by choosing “No, It’s not me” option, sign-in log would show the username as object ID. When our service is unable to resolve the UPN of a user due to an interrupted or failed sign in, it may display an object ID instead.

    Hope the above reasons answers your query, let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.