What is an identity-provider log?¶
An identity-provider log records authentication, token and identity events for applications. It can show how an account gained or continued access, not necessarily who controlled the account or what happened later.
Authentication and application action are separate¶
Entries may show account, application, address, endpoint, method, result, session, correlation and time for sign-in, MFA, token issue, refresh or risk. Tokens can be reused and sessions continue without another password. Services and delegated administrators can act using earlier identity grants.
Identify the exact identity stage¶
Record provider, tenant, event type and application and distinguish primary authentication, single sign-on, factor approval, refresh and continuation. Preserve correlation IDs and linked sign-in and audit events.
Use endpoint, management, network, application and communications evidence to attribute the token or session user.
The point to remember
Identity logs establish how account access was issued or continued; application records and context establish later human activity.