Common support scenario: signed in but cannot access a resource
A frequent support case is a user who successfully signs in but cannot access a resource. This can appear confusing because authentication succeeded — the user’s identity was verified — yet authorization fails.
- Authentication = verifies who the user is.
- Authorization = determines what the authenticated identity is allowed to access.
Authentication confirms who the user is. Authorization checks what the user is allowed to do. When sign-in succeeds but access fails, investigate authorization controls first (Conditional Access, device compliance, application permissions).
Two pillars of effective troubleshooting
- Technical knowledge — Know how identities, authentication flows, Conditional Access, device management, and application permissions interact.
- Active investigation — Use evidence from logs, policy configurations, and telemetry to find the root cause.
Tools for troubleshooting and monitoring identity security
Microsoft provides several complementary tools for investigation and continuous monitoring. Use them together to determine whether an access problem stems from identity configuration, device posture, application permissions, or a security incident.
Where possible, correlate signals across these tools (for example, a blocked sign-in in Entra ID with a device risk alert from Defender for Endpoint) to rapidly identify root causes.
Third-party applications and governance
External apps connected to Microsoft 365 increase productivity but also introduce risk if they’re unmanaged or over-permissioned. Uncontrolled apps may request excessive scopes, store credentials insecurely, or access sensitive data without oversight.
- Control authentication methods and redirect URIs
- Define and restrict permissions (apply least privilege)
- Manage consent settings and require admin consent where appropriate
- Apply Conditional Access or access reviews to application access
Unmanaged or poorly configured third-party apps are a common attack vector. Enforce app registration, review permissions regularly, and use app consent policies to limit exposure.
Application registration and secure integration flow
Registering applications in Entra ID ensures they follow organizational policies and apply governance from the start. Registered apps can be restricted to the minimum required permissions, authenticated securely, and included in Conditional Access rules or access reviews.
- Register every production app in Entra ID.
- Apply least privilege to scopes and API permissions.
- Use managed identities or certificate-based authentication where possible.
- Periodically review app permissions and consent history.
Summary — what to focus on for the exam and in practice
Identity security is more than signing users in. Administrators should:- Monitor and collect logs: sign-ins, audit events, provisioning logs, and device reports.
- Investigate incidents using logs and telemetry from Entra ID, Intune, and Defender for Endpoint.
- Secure device posture and verify compliance state.
- Govern and periodically review third-party application access.
- Continuously evaluate risk signals and Conditional Access outcomes.
Where to find relevant logs in the Entra portal
In the Microsoft Entra admin center you can access the primary logs and insights needed for troubleshooting:- Monitoring section: sign-in logs, audit logs, provisioning logs, and Conditional Access insights.
- Sign-in logs: show who signed in, which application was used, IP address, resource, device information, and which Conditional Access policies were applied. Open a sign-in record to view location, device, authentication details, and policy evaluation results.
- Audit logs: record administrative operations such as user or group changes and configuration updates.

Quick reference and links
- Microsoft Entra ID (Azure AD) sign-in and audit logs — https://learn.microsoft.com/azure/active-directory/
- Conditional Access overview — https://learn.microsoft.com/azure/active-directory/conditional-access/
- Microsoft Intune documentation — https://learn.microsoft.com/mem/
- Microsoft Defender for Endpoint docs — https://learn.microsoft.com/microsoft-365/security/defender-endpoint/
- Microsoft Sentinel (SIEM) overview — https://learn.microsoft.com/azure/sentinel/