signin_by_ip
Investigate sign-in activity from a specific IP address: identify successful and failed logins per account, with timestamps, for security triage after suspicious IP detection.
Instructions
Every sign-in from one source IP: who got in from it, who was tried, and when.
The follow-up to a spray_suspects or shared_ips hit: Graph can
filter sign-ins on ipAddress server-side, so this is one cheap
query, not a log walk. users summarises the IP per account
(successes, failures, first/last seen, up to 50 accounts) over every row
fetched; events lists the newest top entries that match
result ("all" by default, or "success" / "failure"), each carrying
the account name and the same AADSTS annotation as signin_logs.
capped=true means the page budget or the deadline ran out before the
window was fully read; events_truncated=true means more matching
rows were read than top returns (the users summary still counts
them).
Read-only (AuditLog.Read.All application permission, or -- for azure-cli auth -- the Reports Reader directory role).
Args: ip: The source IPv4 or IPv6 address, exactly as the sign-in log shows it. hours: How far back to look, clamped to [1, 720] (30 days). result: "all" (default), "success", or "failure" -- which events to list. top: Maximum events to return, clamped to [1, 500]. max_pages: Page budget (default: ENTRAADM_MAX_PAGES_DEFAULT).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ip | Yes | ||
| top | No | ||
| hours | No | ||
| result | No | all | |
| max_pages | No |