How to Find Authentication Type and MFA Methods in Microsoft 365 Logs
Question details
Administrators need to locate user authentication types and registered multifactor authentication (MFA) methods within Microsoft 365 and Entra ID logs for SIEM integration.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Exporting Microsoft 365 and Entra ID log data to a SIEM system to monitor authentication activities and user security methods.
- Observed behavior
- Authentication types and registered MFA methods are visible in the Entra admin center but appear to be missing from the standard logs forwarded to the SIEM.
Ensure you have Global Administrator, Security Administrator, or Security Reader privileges in Microsoft Entra ID to access detailed sign-in logs and authentication methods.
Review Entra ID Sign-In Logs and Authentication Details
Use the Microsoft Entra admin center to manually inspect authentication details and verify your SIEM export configuration.
Standard Microsoft 365 log exports to SIEM platforms often lack granular MFA details because registered authentication methods are managed separately from basic sign-in events. To retrieve this data, administrators must check the specific authentication details tab or adjust their SIEM data connector.
Log in to the Microsoft Entra admin center (entra.microsoft.com) using an administrator account.
In the left-hand menu, expand 'Identity', go to 'Monitoring & health', and select 'Sign-in logs'.
Click on a specific user's sign-in event. In the pane that opens at the bottom, select the 'Authentication Details' tab to view the authentication method used and the MFA processing results.
Navigate to 'Diagnostic settings' within the Monitoring menu. Ensure that both 'SignInLogs' and 'NonInteractiveUserSignInLogs' are checked for export to your SIEM.
If your SIEM requires registered MFA methods rather than just sign-in events, configure your SIEM connector to query the Microsoft Graph API endpoint: GET /users/{id}/authentication/methods.

Consult Microsoft Entra ID Q&A Community
Leverage Microsoft's dedicated Azure and Entra ID platforms to troubleshoot specific SIEM log parsing limitations.
Manage IT Documentation and Log Exports with WPS Office
While resolving complex Microsoft 365 SIEM integrations, you need a reliable tool to analyze exported log CSV files and draft IT security reports. WPS Office is a free, lightweight suite offering full compatibility with Microsoft Office formats, allowing you to manage your administrative data efficiently.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button.
- 2. Install the Suite: Run the setup file and follow the simple on-screen instructions to install WPS Office on your system.
- 3. Analyze Your Logs: Open WPS Spreadsheet to import and analyze your exported Microsoft 365 and Entra ID log files easily.

Frequently Asked Questions
Why are MFA methods missing from my SIEM logs?
MFA registered methods are stored independently from standard sign-in activity logs in Microsoft Entra ID. Unless your SIEM connector is configured to actively query the Microsoft Graph API for registered authentication methods, this specific data is not ingested by default.
Can I view a user's authentication type directly in Microsoft 365?
Yes. You can view detailed authentication types and MFA responses by navigating to 'Sign-in logs' in the Microsoft Entra admin center and clicking on the 'Authentication Details' tab for any specific sign-in event.
How do I export MFA registration data for all users?
You can export bulk MFA registration details using Microsoft Graph PowerShell (e.g., querying the authentication methods policies) or by downloading reports from the 'Authentication Methods' activity dashboard within the Entra admin center.




