Microsoft Defender XDR
General

EntraIdSpnSignInEvents

In brief

The replacement date for AADSpnSignInEventsBeta moved to October 19, 2026. Queries will migrate automatically, custom detections need no changes, and several fields are now documented.

What Defender admins need to know

No administrator action is required. Note the updated migration date and review the newly documented fields for hunting queries.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

EntraIdSpnSignInEvents

|Longitude|string|The east to west coordinates of the sign-in location| |RequestId|string|Unique identifier of the request| |ReportId|string|Unique identifier for the event| |IsConfidentialClient|boolean|Indicates whether the sign-in was performed by a confidential client application| |GatewayJA4|string|JA4 fingerprint derived from the TLS Client Hello request that identifies the client's TLS configuration| |SessionId|string|Unique number assigned to a user by a website's server for the duration of the visit or session| |UserAgent|string|User agent information from the web browser or other client application| |TenantId|string|Unique identifier representing the organization's instance of Microsoft Entra ID| |Type|string|Name of the table| |SourceSystem|string|Source system for the record| |TimeGenerated|datetime|Date and time when the record was generated| |UniqueTokenId|string|Unique identifier for the token passed during sign-in, used to correlate the sign-in with the token request|

Related articles