JAEN

Microsoft 365

Get-MgAuditLogSignIn

SafeSign-in logs

Get-MgAuditLogSignIn -Filter "userPrincipalName eq '<upn>'" -Top 20

Queries sign-in history with failure reasons, IPs and apps — the core of suspicious-login triage.

Examples

  • Get-MgAuditLogSignIn -Filter "status/errorCode ne 0" -Top 20Recent failed sign-ins

Syntax

Get-MgAuditLogSignIn [-Filter odata] [-Top N]

Before you run it

Read only.

Used when you see

New phone broke MFA sign-in
3
Check sign-in logs for suspicious attempts
See the whole flow →

Related commands

The same reference, with no signal at all

Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.

Get it free on the App Store