Skip to content

View the Sign-In Log

Use the Log tab on the Access settings page to audit sign-in activity and provider configuration changes: who signed in (or was denied), which provider was involved, and what an administrator changed.

Permissions

Only users with the Admin role can view the sign-in log. See the Permissions page for details.

What the Log Shows

Each event row shows:

Column Description
Timestamp When the event happened.
Event The event type, such as Successful Sign-in, Account Locked, Invitation Sent, Account Linking Pending Approval, or SSO Verification Failed.
User The user involved, when the event relates to an account.
Provider The type of sign-in provider involved (OpenID Connect, SAML 2.0, or Email & Password).
IP Address Where the request came from.
Outcome Success or Failure.

log-tab-events

The log covers, among others:

  • Sign-in activity: successful and failed sign-ins, account lockouts, and password resets.
  • Denied sign-ins with the reason: an email domain not authorized for the provider, a group restriction, a missing email from the identity provider, or a deactivated account.
  • Provider configuration changes: provider created, updated, or deleted, with the changed properties. Secrets are never shown.
  • Identity linking: link requests created, approved, and rejected.
  • Invitations: invitations sent and accepted.

Filtering and Sorting

  • Filter by Report Date and Timeframe to focus on a period.
  • Use the filter menu to narrow the log by Event type or Provider type.
  • Sort events by timestamp, event type, or outcome.

log-filters

Info

The Log tab covers authentication and sign-in configuration. For the platform-wide activity log of datastores, checks, and other assets, see the Platform Audit documentation.