Actions129
- Calendar Permission Actions
- CIPP Administration Actions
- Execute API Client (GET)
- Execute Auto Backup
- Execute Extension Mapping (GET)
- Execute Extension Mapping (POST)
- Execute Extension Sync
- Execute Extensions Config
- Execute Password Config (POST)
- Execute Restore Backup
- Execute Run Backup
- List Custom Roles
- List Extension Sync
- List Logs
- List Scheduled Items
- Remove Scheduled Item
- Execute API Client (POST)
- Execute Extension Test
- Execute Password Config (GET)
- List Backups
- List Function Parameters
- Group Actions
- Intune Actions
- Add MSP App
- Add Office App
- Add Policy
- Add Store App
- Assign App
- Assign Autopilot Device
- Device Action
- Get Recovery Key
- List Applications
- List Application Queue
- List Autopilot Config
- List Devices
- List Intune Scripts
- List Intune Templates
- Remove Autopilot Device
- Remove Policy
- Remove Queued App
- Add Choco App
- Add WinGet App
- Assign Policy
- Get Local Admin Password
- List Autopilot Devices
- List Intune Policies
- Remove App
- Remove Intune Script
- Sync Autopilot Devices
- License Actions
- Security & Compliance Actions
- Teams & SharePoint Actions
- Tenant Actions
- Add Alert
- Clear Tenant Cache
- Execute CA Exclusion
- Execute Named Location
- Get Tenant
- List Alerts Queue
- List Azure AD Connect Status
- List Conditional Access Policies
- List Named Locations
- List Shared Mailbox Statistics
- List Standards
- List Tenants
- Remove Standard Template
- Add Named Location
- Edit Tenant
- Execute Standards Run
- List Audit Logs
- List CSP Licenses
- List Roles
- List Standard Templates
- Tool Actions
- User Actions
- Add User
- Exec Restore Deleted User
- List User
- List User Conditional Access Policies
- List User Groups
- Clear Immutable ID
- Create Temporary Access Password
- Delete User Device
- Dismiss Risky User
- List Deleted Items
- List Inactive Accounts
- List Sign-Ins
- Remove User
- Reset MFA
- Restore Deleted Item
- Revoke Sessions
- Set Email Forward
- Set Per-User MFA
- List All Users
- List User Counts
- List User Devices
- Convert Mailbox
- Disable User
- Enable Archive
- List MFA Users
- Offboard User
- Reset Password
- Send MFA Push
- Set Out of Office
Overview
This node interacts with the CIPP API to list user sign-in activities within a specified tenant. It is useful for monitoring user sign-in events, especially for security auditing or troubleshooting access issues. For example, an administrator can use this node to retrieve all sign-in attempts for a tenant, optionally filtering to show only failed sign-ins to identify potential unauthorized access attempts.
Use Case Examples
- List all sign-ins for a tenant to monitor user activity.
- Retrieve only failed sign-ins to investigate security incidents.
Properties
| Name | Meaning |
|---|---|
| Tenant Filter | The tenant ID or domain name to filter the sign-in data for a specific tenant. |
| Failures Only | A boolean flag to indicate whether to show only failed sign-in attempts. |
| Request Options | Additional request settings such as batching, SSL certificate validation, proxy configuration, and timeout settings to control how the API requests are made. |
Output
JSON
signIns- An array of sign-in records retrieved from the tenant, each containing details about individual sign-in events such as user information, timestamps, and status.
Dependencies
- Requires an API key credential for authenticating with the CIPP API.
Troubleshooting
- Ensure the tenant ID or domain name is correctly specified to avoid empty or incorrect results.
- If the node returns SSL certificate errors, consider enabling the 'Ignore SSL Issues' option if appropriate for your environment.
- Timeout errors may occur if the server is slow to respond; increase the timeout setting if needed.
- Batching settings should be adjusted carefully to avoid overwhelming the API or hitting rate limits.