Godwit AI Labs Talk to us

Home › Free tools › Microsoft 365 sign-in check

Who is really signing in to your Microsoft 365?

Drop in your Entra ID sign-in log. It finds mailboxes still signing in the old way that skips MFA, password-only sign-ins, password sprays, accounts that got in after a run of wrong passwords, sign-ins from unusual countries, and admin accounts reading email. Read in your browser.

Or paste the log
  • The log never leaves this browser
  • No sign-in to your tenant needed
  • Try it offline: it still works
HOW TO GET IT

Download the sign-in log

A Global Reader or Security Reader can download it. Entra keeps 7 days on the free tier and 30 with P1 or P2.

  1. Open the sign-in logsentra.microsoft.com, Identity, Monitoring and health, Sign-in logs.
  2. Pick the periodDate: last 7 days (or 1 month with P1). Keep the default columns.
  3. Download, CSVDownload, then CSV, and drop the interactive sign-ins file here. JSON works too.

What happens to it: it is read in your browser and dropped once the report is drawn. Nothing is uploaded, and nothing signs in to your tenant. Our copy of your details carries only the counts.

QUESTIONS

Asked often

The questions people search for before they run the check.

How do I find out if someone has logged in to my Microsoft 365 account?

Download the sign-in log from the Entra admin centre (Sign-in logs, Download, CSV) and look for sign-ins from unusual countries, a success after many failed passwords, and legacy clients such as IMAP. This check reads the log and points those out.

What is legacy authentication, and why block it?

Older protocols such as IMAP, POP, SMTP AUTH and ActiveSync send a password without any second factor, so they ignore MFA. Attackers use them to get into mailboxes with stolen passwords. Block them with a Conditional Access policy or security defaults.

What does a password spray look like in the sign-in log?

Many failed sign-ins with error 50126 (invalid username or password) from one IP address, spread across many different accounts, often at night. The danger is the one account that then succeeds.

How long does Entra ID keep sign-in logs?

Seven days on the free tier and 30 days with Entra ID P1 or P2. To keep them longer, send them to a Log Analytics workspace or your SIEM; CERT-In expects 180 days of logs.

Is my sign-in log uploaded?

No. It is read in your browser, and nothing signs in to your tenant. If you ask for the report, we keep your details and a one-line summary with the counts.

One stolen password should not be enough

MFA for everyone, the old protocols switched off, admins kept apart, and someone watching the sign-ins: that is what turns a phished password into a non-event.