logo
search
MFA Security Issues

How to Find Authentication Type and MFA Methods in Microsoft 365 Logs

Natalie TaylorNatalie Taylor Sep 28, 2026 869 views

Question details

Administrators need to locate user authentication types and registered multifactor authentication (MFA) methods within Microsoft 365 and Entra ID logs for SIEM integration.

How to Find Authentication Type and MFA Methods in Microsoft 365 Logs
Product
Microsoft 365
Device & OS
not provided
Scenario
Exporting Microsoft 365 and Entra ID log data to a SIEM system to monitor authentication activities and user security methods.
Observed behavior
Authentication types and registered MFA methods are visible in the Entra admin center but appear to be missing from the standard logs forwarded to the SIEM.
Before you start

Ensure you have Global Administrator, Security Administrator, or Security Reader privileges in Microsoft Entra ID to access detailed sign-in logs and authentication methods.

Solution 1Recommended

Review Entra ID Sign-In Logs and Authentication Details

Use the Microsoft Entra admin center to manually inspect authentication details and verify your SIEM export configuration.

Standard Microsoft 365 log exports to SIEM platforms often lack granular MFA details because registered authentication methods are managed separately from basic sign-in events. To retrieve this data, administrators must check the specific authentication details tab or adjust their SIEM data connector.

1
Access Entra Admin Center

Log in to the Microsoft Entra admin center (entra.microsoft.com) using an administrator account.

2
Navigate to Sign-in Logs

In the left-hand menu, expand 'Identity', go to 'Monitoring & health', and select 'Sign-in logs'.

3
View Authentication Details

Click on a specific user's sign-in event. In the pane that opens at the bottom, select the 'Authentication Details' tab to view the authentication method used and the MFA processing results.

4
Check SIEM Diagnostic Settings

Navigate to 'Diagnostic settings' within the Monitoring menu. Ensure that both 'SignInLogs' and 'NonInteractiveUserSignInLogs' are checked for export to your SIEM.

5
Query Microsoft Graph (Advanced)

If your SIEM requires registered MFA methods rather than just sign-in events, configure your SIEM connector to query the Microsoft Graph API endpoint: GET /users/{id}/authentication/methods.

Review Entra ID Sign-In Logs and Authentication Details
SIEM Schema Limitations: If MFA fields are still missing in your SIEM, verify your SIEM provider's log parsing schema to ensure it is configured to extract Microsoft Entra authentication detail arrays.
Free Microsoft Office alternative

Manage IT Documentation and Log Exports with WPS Office

While resolving complex Microsoft 365 SIEM integrations, you need a reliable tool to analyze exported log CSV files and draft IT security reports. WPS Office is a free, lightweight suite offering full compatibility with Microsoft Office formats, allowing you to manage your administrative data efficiently.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button.
  2. 2. Install the Suite: Run the setup file and follow the simple on-screen instructions to install WPS Office on your system.
  3. 3. Analyze Your Logs: Open WPS Spreadsheet to import and analyze your exported Microsoft 365 and Entra ID log files easily.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Easily open, filter, and analyze large exported SIEM log CSV files using WPS Spreadsheet.Lightweight installation with zero complex cloud-sync requirements.Familiar user interface that requires no learning curve for IT professionals.
microsoft office alternative - wps office

Frequently Asked Questions

Why are MFA methods missing from my SIEM logs?

MFA registered methods are stored independently from standard sign-in activity logs in Microsoft Entra ID. Unless your SIEM connector is configured to actively query the Microsoft Graph API for registered authentication methods, this specific data is not ingested by default.

Can I view a user's authentication type directly in Microsoft 365?

Yes. You can view detailed authentication types and MFA responses by navigating to 'Sign-in logs' in the Microsoft Entra admin center and clicking on the 'Authentication Details' tab for any specific sign-in event.

How do I export MFA registration data for all users?

You can export bulk MFA registration details using Microsoft Graph PowerShell (e.g., querying the authentication methods policies) or by downloading reports from the 'Authentication Methods' activity dashboard within the Entra admin center.