logo
search
Account Security Problems

Why Azure AD Sign-In Logs Show an Object GUID Instead of a UPN

Maira MehtabMaira Mehtab Sep 24, 2026 869 views

Question details

The user wants to understand why Microsoft Entra ID (formerly Azure AD) sign-in logs sometimes display an object GUID in the UPN field instead of the actual User Principal Name, and whether these entries can be excluded from analysis.

Product
Microsoft Entra ID (Azure AD)
Device & OS
not provided
Scenario
Reviewing and auditing account security and sign-in logs in the Microsoft Entra admin center.
Observed behavior
The sign-in logs show a system-generated Object GUID in the User Principal Name (UPN) field instead of a human-readable email format.
Before you start

Ensure you have at least a Security Reader or Reports Reader role assigned in Microsoft Entra ID to access and filter the tenant's sign-in logs.

Solution 1Recommended

Identify the Source of the Object GUID and Apply Log Filters

Determine if the GUID belongs to a deleted user, service principal, or managed identity, and use Entra ID filters to exclude them from standard user audits.

In Microsoft Entra ID, an Object GUID appears instead of a UPN when the system cannot resolve the principal's human-readable name. This typically occurs for deleted user accounts, managed identities, service principals, or external guest users whose UPNs are not fully provisioned in the directory.

If these entries interfere with your routine security analysis, you can easily filter them out using the built-in diagnostic tools.

1
Access Microsoft Entra admin center

Log in to the Microsoft Entra admin center, expand the 'Identity' menu, and navigate to 'Monitoring & health' > 'Sign-in logs'.

2
Investigate the Object GUID

Copy the Object GUID from the UPN field. Navigate to 'Users' or 'Enterprise applications' and paste the GUID into the search bar to identify whether it belongs to a deleted user account or an automated app.

3
Apply Log Filters

Click 'Add filters' at the top of the Sign-in logs view. Select 'User Principal Name', set the condition to 'Does not start with', and input the GUID format, or simply switch tabs to isolate 'Service principal sign-ins' from 'Interactive user sign-ins'.

Deleted Accounts Retention: When a user account is deleted, their UPN is immediately stripped from the active directory. However, their historical sign-in logs remain for up to 30 days and will permanently display their Object GUID instead.
Free Microsoft Office alternative

Looking for a Secure, Lightweight Office Suite?

While you manage complex IT infrastructure and account security in Entra ID, your daily document tasks shouldn't be a hassle. WPS Office provides a lightweight, highly compatible, and secure alternative for enterprise productivity.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installation package for Windows, macOS, or Linux.
  2. 2. Install WPS Office: Run the downloaded installer and follow the quick on-screen instructions to complete the setup.
  3. 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Word, Excel, or PowerPoint files without losing any formatting.
Seamlessly compatible with Microsoft Office formats (.docx, .xlsx, .pptx)Advanced document encryption and account security features to keep sensitive files safeLightweight installation with incredibly fast loading speedsFamiliar tabbed interface requiring zero learning curve for users
microsoft office alternative - wps office

Frequently Asked Questions

Can I permanently convert the Object GUID back to a UPN in Azure AD logs?

No. If the original UPN was removed from the directory (e.g., the user was permanently deleted), the sign-in log will permanently display the Object GUID. You can only cross-reference this GUID with historical audit logs to find the original user identity.

Do managed identities generate sign-in logs with a standard UPN?

No. Managed identities and service principals authenticate using their Object ID or Application ID. Since they do not have a standard email-style User Principal Name, you will see a GUID in the UPN field.

How do I completely exclude service principal sign-ins from my analysis?

In the Entra admin center 'Sign-in logs' section, utilize the tabs at the top. Switching from the 'Interactive user sign-ins' tab to the 'Service principal sign-ins' tab naturally separates machine-generated logs from human user activities.