Why this matters
Sign-in activity shows when, where and from what device an account was used. Unexpected locations or failed sign-ins can be the first sign of a compromised account. Checking regularly helps you catch problems before they turn into fraud.
What you'll need
- Your Microsoft 365 account
- For organisation-wide logs: an admin role such as Security Reader or Global Reader
Step-by-step instructions
Step 1
Users: open My Sign-ins
Go to mysignins.microsoft.com and select "Recent activity".
Step 2
Users: review each sign-in
Expand entries to see the location, device, browser and whether it succeeded. Select "Looks good" or "This wasn’t me" for unusual entries.
Step 3
Admins: open the Entra sign-in logs
Go to entra.microsoft.com, then Identity, Monitoring & health, Sign-in logs.
Step 4
Admins: filter the results
Filter by user, date range, status (failure) or location. Look for sign-ins from overseas, unfamiliar apps or many failures in a short time.
Step 5
Admins: check risky sign-ins
If you have Microsoft Entra ID P1/P2 (included in Business Premium for P1), review the Risky sign-ins and Risky users reports.
Step 6
Act on anything suspicious
Reset the password, revoke sessions and check mailbox rules for any account with unexplained sign-ins.
Summary
A quick monthly review of sign-in activity, and an immediate check when something feels wrong, helps you spot compromised accounts early.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.