Recent sign-ins
Applies to: identity 0.27 · Checked: 26.09.2026
Recent sign-ins
In the /me portal, the Security tab has a Recent sign-ins card: this account's
sign-ins over the last 30 days, at most 50 entries. For each one it shows:
- when;
- how: password, password and code, recovery code, passkey (with or without PIN or biometric verification), company sign-in (ADFS or another provider), LDAP directory password, an LDAP bind from an application, an app password for mail;
- into what: the application signed into, or the messenger, mail, LDAP;
- from: the address the sign-in came from;
- result: signed in, refused with a reason (wrong password, wrong code, account locked, address blocked and so on) or failed (directory unavailable).
The list is read from identity's security event log — the same one exported to the SIEM. A person sees only their own sign-ins. Error texts and secrets never reach the portal, only the class of the reason.
Next to the Sign out everywhere button it says: "Not you? Sign out everywhere and change your password."
The address is shown when whoever checks the sign-in passes it on: identity's sign-in page and LDAP server know it themselves, the coordinator passes it with a password check, mail with an app-password check.
Who may act for a person
Identity grants no access to another person's mailbox or calendar. Mail and the calendar decide that themselves: access to a mailbox or a calendar is given to people and groups in their own settings.