Skip to content
Skip to main content
Cloud Services Technical Explainer

What might a cloud login record contain?

A cloud login record describes an authentication event: which identity attempted access, through which client and route, to what resource, when, and with what result. It can establish what the identity system processed; its precise fields depend on whether the event was interactive, federated, token-based or generated by an application.

Read the event type before the fields

At 08:41, Microsoft Entra records Dave's account signing in through Edge to Microsoft 365. Record SIGN-9204 contains tenant and account IDs, application and resource, correlation ID COR-18, public IP address, client and device details, authentication steps, Conditional Access result and overall outcome.

Useful values can include account and tenant IDs, event and session IDs, application, public IP address, browser or device information, authentication and MFA method, identity provider, failure reason and risk indicators.

Location is usually an estimate derived from the connection address. It may be affected by mobile routing, VPNs, proxies and corporate gateways.

Identity evidence may be split

With single sign-on, the cloud application may record that it accepted an assertion while the identity provider holds password, MFA and device detail. Join the events using time and stable correlation or session identifiers where available.

Preserve raw values and outcome

Interfaces may omit fields or display current account names beside historical events. Retain the export, time zone and provider definitions. Next obtain the linked identity-provider event, resource audit event and relevant device record; a successful result establishes accepted authentication at the recorded level, not the person present.

Microsoft Entra sign-in fields - checked 3 September 2026

Microsoft groups sign-in detail around who signed in, how the client connected and what resource was accessed. Its current detail can include application and resource, IP address, browser, operating system, authentication steps, device information, Conditional Access and a correlation ID. Some detail can be incomplete until aggregation finishes, so retain the exported event and collection time.

The point to remember

A login record describes an authentication event and route. Preserve its raw account, session, client, connection and outcome fields before drawing conclusions about the user.

Reference: CLD-104Cloud Services