Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is an identity-provider log?

An identity-provider log records authentication, token and identity events for applications. It can show how an account gained or continued access, not necessarily who controlled the account or what happened later.

Authentication and application action are separate

Entries may show account, application, address, endpoint, method, result, session, correlation and time for sign-in, MFA, token issue, refresh or risk. Tokens can be reused and sessions continue without another password. Services and delegated administrators can act using earlier identity grants.

Identify the exact identity stage

Record provider, tenant, event type and application and distinguish primary authentication, single sign-on, factor approval, refresh and continuation. Preserve correlation IDs and linked sign-in and audit events.

Use endpoint, management, network, application and communications evidence to attribute the token or session user.

The point to remember

Identity logs establish how account access was issued or continued; application records and context establish later human activity.

Reference: LOG-028Logs, Records & Provider Evidence