Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Chessbot
New Contributor

Users - MFA authenticating logs

Hi all,

I hope you can help with a query I currently have. 

 

I'm looking to see if I can find a way to check whether users of O365 have logged in using MFA or not. Is this parsed by default, or can anyone point me to a way to find this information within logs. 

 

 

TLDR:

Can FortiSIEM report on O365 users who are authenticating with or without MFA

1 REPLY 1
rbraha
Staff
Staff

Hi @Chessbot,

If using any FAC ,most probably imported remote users reside on FAC database and they have token assigned there, you can see them from the logs on FAC when they can authenticate with or without tokens.
Regarding FortiSIEM question you can try to see Raw Event logs from Analytics if something is reported there.

Labels
Top Kudoed Authors