Glossary
Non-interactive sign-in
An Entra ID sign-in performed by a client with an existing token, without user input; the log where token use and token replay become visible.
A non-interactive sign-in is recorded by Microsoft Entra ID when a client application obtains or refreshes tokens on the user's behalf without the user providing a factor, for example by redeeming a refresh token. Interactive sign-ins are the ones where the user types a password, approves MFA or uses a passkey.
Non-interactive sign-ins are far more numerous and are downloaded separately in the Entra admin center. They matter in investigations because a stolen session is replayed without any user input: token replay shows up as non-interactive sign-ins with the victim's Session ID from the attacker's IP. In Graph they are identified by isInteractive = false or signInEventTypes containing nonInteractiveUser.
See how to export sign-in logs and Entra ID sign-in logs analysis.