Additional Microsoft Entra services and features related to identity, access, and network security
It seems unusual that you are not seeing any records of login failures from outside the US in your Entra sign-in logs for January 2026, especially given the history of hacking attempts from various locations over the past three years. Here are a few things to consider:
- Filtering Issues: Double-check your filters in the sign-in logs to ensure they are set correctly. Sometimes, filters might inadvertently exclude certain records. Make sure you are not filtering out locations or statuses that could include the login failures you are looking for.
- Log Retention Policies: It's possible that log retention policies may have affected the availability of records. Ensure that your logs are retained for the required duration and that you are querying the correct time frame.
- Conditional Access Policies: Review the Conditional Access policies that might be in place. If there are strict policies that block access from certain regions, it might result in fewer recorded failures from those areas.
- System Updates or Changes: Consider whether there have been any updates or changes to the logging system or security configurations that might affect how logs are recorded or displayed.
- Monitoring Tools: If you are using any monitoring tools or SIEMs, check if they are capturing and reporting the sign-in failures correctly. Sometimes, external tools may have their own filtering or reporting issues.
If none of these considerations resolve the issue, it may be worthwhile to reach out to Microsoft support for further investigation into the sign-in logs for your tenant.
References: