Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

Non-interactive sign-in

An Entra ID sign-in performed by a client with an existing token, without user input; the log where token use and token replay become visible.

A non-interactive sign-in is recorded by Microsoft Entra ID when a client application obtains or refreshes tokens on the user's behalf without the user providing a factor, for example by redeeming a refresh token. Interactive sign-ins are the ones where the user types a password, approves MFA or uses a passkey.

Non-interactive sign-ins are far more numerous and are downloaded separately in the Entra admin center. They matter in investigations because a stolen session is replayed without any user input: token replay shows up as non-interactive sign-ins with the victim's Session ID from the attacker's IP. In Graph they are identified by isInteractive = false or signInEventTypes containing nonInteractiveUser.

See how to export sign-in logs and Entra ID sign-in logs analysis.