← Browse all tablesLoading table information…
AADSpnSignInEventsBeta Schema
Table description
| TableSection |
TableType |
TableSectionName |
Description |
| Itp |
Regular |
|
Information about sign-in events initiated by Microsoft Entra ID service principal or managed identities |
Table retention
| HotDays |
ColdDays |
TotalInteractiveDays |
| 30 |
0 |
30 |
Schema
| Name |
Description |
Type |
| Application |
Application that performed the recorded action |
String |
| ApplicationId |
Unique identifier for the application |
String |
| City |
City where the client IP address is geolocated |
String |
| CorrelationId |
Unique identifier of the sign-in event |
String |
| Country |
Country/Region where the account user is located |
String |
| ErrorCode |
Contains the error code if a sign-in error occurs. To find a description of a specific error code, visit https://aka.ms/AADsigninsErrorCodes |
Int32 |
| IPAddress |
IP addresses of the clients on which the activity was performed; can contain multiple Ips if related to Microsoft Defender for Cloud Apps alerts |
String |
| IsConfidentialClient |
Indicates if the sign in was done via confidential client applications |
Boolean |
| IsManagedIdentity |
Indicates whether the sign-in was initiated by a managed identity |
Boolean |
| Latitude |
The north to south coordinates of the sign-in location |
String |
| Longitude |
The east to west coordinates of the sign-in location |
String |
| ReportId |
Unique identifier for the event |
String |
| RequestId |
Unique identifier of the request |
String |
| ResourceDisplayName |
Display name of the resource accessed. The display name can contain any character. |
String |
| ResourceId |
Unique identifier of the resource accessed |
String |
| ResourceTenantId |
Unique identifier of the tenant of the resource accessed |
String |
| ServicePrincipalId |
Unique identifier of the service principal that performed the action |
String |
| ServicePrincipalName |
Name of the service principal that initiated the sign-in |
String |
| State |
State where the sign-in occurred, if available |
String |
| Timestamp |
Date and time when the record was generated |
DateTime |
Schema changes
| Date |
Action |
| 2026-03-08 |
Column IsConfidentialClient added |
| 2026-02-27 |
Column TenantId removed |
| 2026-02-27 |
Column Type removed |
| 2026-02-27 |
Column SourceSystem removed |
| 2026-02-27 |
Column TimeGenerated removed |
| 2026-01-02 |
Table added to tracking |