Skip to content

Get-MgBetaReportServicePrincipalSignInActivity fails #3536

Description

@dmaloney-exelixis

Describe the bug

trying to pull ServicePrincipal Signin Data.

Get-MgBetaReportServicePrincipalSignInActivity

Authenticated as GA and Security Admin. Cannot get powershell query to return results. RAW API query is successful in Graph Explorer

Get-MgBetaReportServicePrincipalSignInActivity_List: User is not in the allowed roles

Status: 403 (Forbidden)
ErrorCode: Authentication_RequestFromUnsupportedUserRole
Date: 2026-02-20T00:29:35

Expected behavior

return proper JSON data for SP Signin activity

"@odata.context": "https://graph.microsoft.com/beta/$metadata#reports/servicePrincipalSignInActivities",
"@odata.nextLink": "https://graph.microsoft.com/beta/reports/servicePrincipalSignInActivities?$skiptoken=3f1d26a74d2c66ee0ffa2bd59ec9229ed6aace91038bc5e1509a55de05c5b150",
"@microsoft.graph.tips": "Use $select to choose only the properties your app needs, as this can lead to performance improvements. For example: GET reports/servicePrincipalSignInActivities?$select=appId,applicationAuthenticationClientSignInActivity",
"value": [
    {
        "id": "MDAwMDAwMDItMDAwMC0wMDAwLWMwMDAtMDAwMDAwMDAwMDAw",
        "appId": "00000002-0000-0000-c000-000000000000",
        "lastSignInActivity": {
            "lastSignInDateTime": "2026-02-19T17:02:22.8258112Z",
            "lastSignInRequestId": "db867493-60ee-4371-898a-8f6597750b00"
        },
        "delegatedClientSignInActivity": {
            "lastSignInDateTime": null,
            "lastSignInRequestId": null
        },
        "delegatedResourceSignInActivity": {
            "lastSignInDateTime": "2026-02-19T17:02:22.8258112Z",
            "lastSignInRequestId": "db867493-60ee-4371-898a-8f6597750b00"
        },
        "applicationAuthenticationClientSignInActivity": {
            "lastSignInDateTime": null,
            "lastSignInRequestId": null
        },
        "applicationAuthenticationResourceSignInActivity": {
            "lastSignInDateTime": "2026-01-21T23:53:34.3439822Z",
            "lastSignInRequestId": "54742ab6-89bd-4ff6-be5c-c42f673c1a00"
        }
    },
    {
        "id": "MzhhYTNiODctYTA2ZC00ODE3LWIyNzUtN2EzMTY5ODhkOTNi",
        "appId": "38aa3b87-a06d-4817-b275-7a316988d93b",
        "lastSignInActivity": {
            "lastSignInDateTime": "2026-02-19T17:02:22.8258112Z",
            "lastSignInRequestId": "db867493-60ee-4371-898a-8f6597750b00"

How to reproduce

Connect-MgGraph -Scopes "AuditLog.Read.all","Directory.Read.All"
Get-MgBetaReportServicePrincipalSignInActivity

SDK Version

No response

Latest version known to work for scenario above?

No response

Known Workarounds

No response

Debug output

Click to expand log ```
</details>


### Configuration

_No response_

### Other information

_No response_

Activity

  1. lramosvea commented on Feb 23, 2026

    @lramosvea
    Contributor

    dmaloney-exelixis please provide the output when you run using the -debug parameter. Do not redact any request ids or timestamps in the output, otherwise we can't trace this.

  2. ToAmins commented on Feb 27, 2026

    @ToAmins

    I got the same error last week. However, it has been working since today without me changing anything. Maybe something has already been fixed in the background?

    Would you mind testing it? dmaloney-exelixis

  3. dmaloney-exelixis commented on Feb 27, 2026

    @dmaloney-exelixis
    Author

    Still happening for me. I am running module version 2.35.1

    Elevated to Global Admin and Security Admin.

    The get-mgbetaserviceprincipal command with the signinActivity proerty does not seem to return results either.
    $spProps = "id,appId,displayName,servicePrincipalType,accountEnabled,createdDateTime,appOwnerOrganizationId,signInActivity"
    $servicePrincipals = Get-MgBetaServicePrincipal -All -Property $spProps

    Get-MgBetaReportServicePrincipalSignInActivity -debug
    DEBUG: [CmdletBeginProcessing]: - Get-MgBetaReportServicePrincipalSignInActivity begin processing with parameterSet 'List'.
    DEBUG: [Authentication]: - AuthType: 'Delegated', TokenCredentialType: 'InteractiveBrowser', ContextScope: 'CurrentUser', AppName: 'Microsoft Graph Command Line Tools'.
    DEBUG: [Authentication]: - Scopes: [Agreement.Read.All, Agreement.ReadWrite.All, Application.Read.All, Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All, AuditLog.Read.All, Channel.ReadBasic.All, ChannelMessage.Read.All, CloudPC.ReadWrite.All, CrossTenantInformation.ReadBasic.All, DelegatedPermissionGrant.Read.All, Device.Read.All, Device.ReadWrite.All, DeviceManagementApps.Read.All, DeviceManagementApps.ReadWrite.All, DeviceManagementConfiguration.Read.All, DeviceManagementConfiguration.ReadWrite.All, DeviceManagementManagedDevices.Read.All, DeviceManagementManagedDevices.ReadWrite.All, DeviceManagementRBAC.Read.All, DeviceManagementRBAC.ReadWrite.All, DeviceManagementScripts.ReadWrite.All, DeviceManagementServiceConfig.Read.All, DeviceManagementServiceConfig.ReadWrite.All, Directory.Read.All, Directory.ReadWrite.All, DirectoryRecommendations.Read.All, Domain.Read.All, Domain.ReadWrite.All, email, EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All, Files.Read.All, Files.ReadWrite.All, Group.Read.All, Group.ReadWrite.All, GroupMember.ReadWrite.All, IdentityRiskEvent.Read.All, IdentityRiskyUser.Read.All, Mail.Read, Mail.ReadWrite, Mail.Send, openid, Organization.Read.All, Organization.ReadWrite.All, Policy.Read.All, Policy.Read.ConditionalAccess, Policy.Read.PermissionGrant, Policy.ReadWrite.ApplicationConfiguration, Policy.ReadWrite.ConditionalAccess, PrivilegedAccess.Read.AzureAD, PrivilegedEligibilitySchedule.Read.AzureADGroup, profile, Reports.Read.All, ReportSettings.Read.All, ReportSettings.ReadWrite.All, RoleAssignmentSchedule.Read.Directory, RoleAssignmentSchedule.ReadWrite.Directory, RoleEligibilitySchedule.Read.Directory, RoleEligibilitySchedule.ReadWrite.Directory, RoleManagement.Read.All, RoleManagement.Read.Directory, RoleManagement.ReadWrite.Directory, SecurityIdentitiesHealth.Read.All, SecurityIdentitiesSensors.Read.All, SharePointTenantSettings.Read.All, Sites.FullControl.All, Sites.Read.All, Sites.ReadWrite.All, Sites.Selected, Team.ReadBasic.All, TeamMember.Read.All, ThreatHunting.Read.All, User.Read, User.Read.All, User.ReadWrite.All, UserAuthenticationMethod.Read.All, UserAuthenticationMethod.ReadWrite.All].
    DEBUG: ============================ HTTP REQUEST ============================
    
    HTTP Method:
    GET
    
    Absolute Uri:
    https://graph.microsoft.com/beta/reports/servicePrincipalSignInActivities
    
    Headers:
    FeatureFlag                   : 00000003
    Cache-Control                 : no-store, no-cache
    User-Agent                    : Mozilla/5.0,(Windows NT 10.0; Microsoft Windows 10.0.20348; en-US),PowerShell/2025.4.0
    SdkVersion                    : graph-powershell-beta/2.35.1
    client-request-id             : 6b02263d-fbd7-4648-97f9-ce3f62c28226
    Accept-Encoding               : gzip,deflate,br
    
    Body:
    
    
    
    DEBUG: ============================ HTTP RESPONSE ============================
    
    Status Code:
    Forbidden
    
    Headers:
    Vary                          : Accept-Encoding
    Strict-Transport-Security     : max-age=31536000
    request-id                    : 7acddd60-1dfb-402e-b3a2-810f4c4d83d9
    client-request-id             : 6b02263d-fbd7-4648-97f9-ce3f62c28226
    x-ms-ags-diagnostic           : {"ServerInfo":{"DataCenter":"West US 2","Slice":"E","Ring":"4","ScaleUnit":"000","RoleInstance":"CO1PEPF0001343C"}}
    Date                          : Fri, 27 Feb 2026 18:56:29 GMT
    
    Body:
    {
      "error": {
        "code": "Authentication_RequestFromUnsupportedUserRole",
        "message": "User is not in the allowed roles",
        "innerError": {
          "date": "2026-02-27T18:56:30",
          "request-id": "7acddd60-1dfb-402e-b3a2-810f4c4d83d9",
          "client-request-id": "6b02263d-fbd7-4648-97f9-ce3f62c28226"
        }
      }
    }
    
    
    Get-MgBetaReportServicePrincipalSignInActivity_List: User is not in the allowed roles
    
    Status: 403 (Forbidden)
    ErrorCode: Authentication_RequestFromUnsupportedUserRole
    Date: 2026-02-27T18:56:30
    
    Headers:
    Vary                          : Accept-Encoding
    Strict-Transport-Security     : max-age=31536000
    request-id                    : 7acddd60-1dfb-402e-b3a2-810f4c4d83d9
    client-request-id             : 6b02263d-fbd7-4648-97f9-ce3f62c28226
    x-ms-ags-diagnostic           : {"ServerInfo":{"DataCenter":"West US 2","Slice":"E","Ring":"4","ScaleUnit":"000","RoleInstance":"CO1PEPF0001343C"}}
    Date                          : Fri, 27 Feb 2026 18:56:29 GMT
    
    
      Recommendation: See service error codes: https://learn.microsoft.com/graph/errors
    DEBUG: [CmdletEndProcessing]: - Get-MgBetaReportServicePrincipalSignInActivity end processing.
    
  4. gavinbarron commented on Mar 3, 2026

    @gavinbarron
    Member

    Thanks for that data dmaloney-exelixis

    I can see that you have both of the permissions that allow access to this API based on the documentation https://learn.microsoft.com/en-us/graph/api/reportroot-list-serviceprincipalsigninactivities?view=graph-rest-beta&tabs=http#permissions

    I've escalated internally with IcM 756386760

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions