Glossary
Linkable identifiers (Session ID, Unique token identifier)
Identifiers Microsoft Entra embeds in tokens and surfaces in sign-in and workload logs, linking mailbox and file actions back to the sign-in that issued the token.
Linkable identifiers are values Microsoft Entra places in the tokens it issues and exposes in logs so that activity can be traced to a single authentication. The session ID (sid) is created at interactive sign-in and inherited by every token derived from it; the unique token identifier (uti) identifies one token.
In the Entra sign-in logs they appear as Session ID and Unique token identifier. In Unified Audit Log records for Exchange, SharePoint and Teams they appear as AppAccessContext.AADSessionId (or SessionId for Exchange) and AppAccessContext.UniqueTokenId. Matching them shows which inbox rule, mail read or download came from which sign-in, the core of attributing actions to an attacker's session. Some aggregated or background records lack them.