Get-MgAuditLogSignIn
SafeSign-in logs
Get-MgAuditLogSignIn -Filter "userPrincipalName eq '<upn>'" -Top 20
Queries sign-in history with failure reasons, IPs and apps — the core of suspicious-login triage.
Examples
Get-MgAuditLogSignIn -Filter "status/errorCode ne 0" -Top 20Recent failed sign-ins
Syntax
Get-MgAuditLogSignIn [-Filter odata] [-Top N]
Before you run it
Read only.
Used when you see
Related commands
- Search-UnifiedAuditLogAudit log search
- Revoke-MgUserSignInSessionRevoke sign-ins
The same reference, with no signal at all
Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.
Get it free on the App Store