Why Azure AD Sign-In Logs Show an Object GUID Instead of a UPN
Question details
The user wants to understand why Microsoft Entra ID (formerly Azure AD) sign-in logs sometimes display an object GUID in the UPN field instead of the actual User Principal Name, and whether these entries can be excluded from analysis.
- Product
- Microsoft Entra ID (Azure AD)
- Device & OS
- not provided
- Scenario
- Reviewing and auditing account security and sign-in logs in the Microsoft Entra admin center.
- Observed behavior
- The sign-in logs show a system-generated Object GUID in the User Principal Name (UPN) field instead of a human-readable email format.
Ensure you have at least a Security Reader or Reports Reader role assigned in Microsoft Entra ID to access and filter the tenant's sign-in logs.
Identify the Source of the Object GUID and Apply Log Filters
Determine if the GUID belongs to a deleted user, service principal, or managed identity, and use Entra ID filters to exclude them from standard user audits.
In Microsoft Entra ID, an Object GUID appears instead of a UPN when the system cannot resolve the principal's human-readable name. This typically occurs for deleted user accounts, managed identities, service principals, or external guest users whose UPNs are not fully provisioned in the directory.
If these entries interfere with your routine security analysis, you can easily filter them out using the built-in diagnostic tools.
Log in to the Microsoft Entra admin center, expand the 'Identity' menu, and navigate to 'Monitoring & health' > 'Sign-in logs'.
Copy the Object GUID from the UPN field. Navigate to 'Users' or 'Enterprise applications' and paste the GUID into the search bar to identify whether it belongs to a deleted user account or an automated app.
Click 'Add filters' at the top of the Sign-in logs view. Select 'User Principal Name', set the condition to 'Does not start with', and input the GUID format, or simply switch tabs to isolate 'Service principal sign-ins' from 'Interactive user sign-ins'.
Looking for a Secure, Lightweight Office Suite?
While you manage complex IT infrastructure and account security in Entra ID, your daily document tasks shouldn't be a hassle. WPS Office provides a lightweight, highly compatible, and secure alternative for enterprise productivity.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for Windows, macOS, or Linux.
- 2. Install WPS Office: Run the downloaded installer and follow the quick on-screen instructions to complete the setup.
- 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Word, Excel, or PowerPoint files without losing any formatting.

Frequently Asked Questions
Can I permanently convert the Object GUID back to a UPN in Azure AD logs?
No. If the original UPN was removed from the directory (e.g., the user was permanently deleted), the sign-in log will permanently display the Object GUID. You can only cross-reference this GUID with historical audit logs to find the original user identity.
Do managed identities generate sign-in logs with a standard UPN?
No. Managed identities and service principals authenticate using their Object ID or Application ID. Since they do not have a standard email-style User Principal Name, you will see a GUID in the UPN field.
How do I completely exclude service principal sign-ins from my analysis?
In the Entra admin center 'Sign-in logs' section, utilize the tabs at the top. Switching from the 'Interactive user sign-ins' tab to the 'Service principal sign-ins' tab naturally separates machine-generated logs from human user activities.




