Decoding UserAuthenticationMethod in Microsoft 365 audit logs: the bitfield mapping
ID: d7d822a8-3029-5869-927c-524e1a1736ba
STIX ID: report--d7d822a8-3029-5869-927c-524e1a1736ba
Feed Name: Sekoia.io Blog (archive)
Date Published: 2025-10-21
Date Updated: 2026-04-29
Author: Grégoire Clermont and Sekoia TDR
This report documents Sekoia.io’s findings that Microsoft 365’s `UserAuthenticationMethod` is a bitfield representing primary-capable authentication methods and shows how to decode it by correlating Microsoft 365 audit logs with Microsoft Entra sign-in logs (e.g., mapping values like Password Hash Sync, staged rollout, and passkeys). It provides a correlation-based methodology, an investigation example using Sekoia Operating Language, and a real MFA flow demonstrating bit accumulation, while acknowledging unmapped bits and encouraging community validation and updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
