cipp_list_user_signin_logs
Lists one user's recent Entra ID sign-ins to diagnose failed logins, unexpected locations, and whether MFA or Conditional Access applied. Returns time, app, IP, status, error, and device details.
Instructions
List one user's most recent interactive Entra ID sign-ins, newest first. Each row gives the time, app and resource, IP address, location, success/failure with the error code and failure reason, client app, Conditional Access status and the policies that evaluated, authentication requirement (whether MFA was required) and the authentication methods/steps Graph recorded, first factor included, device, and risk when flagged — plus a summary of failures, distinct IPs and countries. Answers "why can't this user sign in", "was this account used from somewhere unexpected", and "did MFA/CA apply". Accepts a UPN or Entra object id; a UPN is resolved to the object id first, because the upstream filter matches object ids only. One tenant and one user per call. Requires Entra ID P1/P2 in the tenant. For tenant-wide sign-ins this is the wrong tool — use CIPP's Sign-Ins report (ListSignIns).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| top | No | Number of most recent sign-ins to return (default 50, maximum 1000). A result that fills the limit carries a warning that older sign-ins may exist. | |
| userId | Yes | The user's Entra object ID or User Principal Name (e.g. alice@contoso.com). | |
| tenantFilter | Yes | Tenant domain name or ID that owns the user. 'allTenants' is not supported — the upstream endpoint reads one tenant. |