UserAuthenticationMethod: Understanding M365 Sign-In Logs
Sekoia.io documents the previously undocumented UserAuthenticationMethod field in Microsoft 365 audit logs, revealing it is a bitfield where each bit position maps to a distinct authentication method. Through correlation with Entra ID sign-in logs using shared correlation identifiers, researchers decoded 24 bit positions representing authentication methods ranging from password variants to passkeys and Windows Hello for Business. The field accumulates values during multi-factor authentication flows, capturing both primary and secondary factors in a single numeric value.