100% local — nothing ever leaves your browser

Hunt through Entra ID
sign-ins like a pro.

Turn raw sign-in logs into actionable security findings. Drop a log, get an award-winning workspace with detections, pivots, and reports — without a single byte leaving your device.

No account Millions of rows Open & auditable
local://entra-log-inspector/overview
Sign-ins
142,384
+12%
Failures
1,209
-4%
Users
3,842
+2%
Findings
27
high
Sign-in activity · 24h
1h24h7d
HIGH
Password spray
20 users · 1 IP · 3h window
HIGH
Impossible travel
carol.nguyen · US → JP · 30m
Password spray·Brute force·Impossible travel·Legacy auth·Risky sign-ins·MFA fatigue·Off-hours access·Non-compliant device·Conditional access failures·Guest anomalies·Password spray·Brute force·Impossible travel·Legacy auth·Risky sign-ins·MFA fatigue·Off-hours access·Non-compliant device·Conditional access failures·Guest anomalies·
Craft

Everything you need. Nothing you don't.

Airgapped by design
Zero uploads. Zero telemetry.

Files are parsed in a Web Worker inside your tab. There is no backend to leak — the app can run offline.

$ netstat --outboundno active connections
Instant
Millions of rows, still smooth.

Streaming parser, memoized aggregates, virtualized tables.

Detections
14 rules out of the box.

From password spray to impossible travel — tunable thresholds included.

Investigation
Pivot at the speed of thought.

From a suspicious IP to a full user timeline in a click. Then export a self-contained HTML report to share with your team.

ip: 185.220.101.4user: bob.jones@…app: Legacy IMAPcountry: RUrisk: high
How it flows

Three steps. Zero setup.

Try it now
01
Drop your export

CSV or JSON from Entra portal, Graph, or Log Analytics. Multiple files supported.

02
Auto-parse & normalize

A Web Worker streams, deduplicates, and maps columns — no config.

03
Investigate & report

Explore detections, pivot on users and IPs, then export a shareable HTML report.

Privacy, seriously

Your logs.
Your machine.
Full stop.

Entra sign-in data is deeply sensitive. We don't want it, we don't collect it, and we architected the app so we can't — even by accident.

Read the technical explanation
  • No backend
    There is nothing to send data to. The app is static assets.
  • Parsed in a Worker
    Papa Parse streams your file in a Web Worker. It never touches a server.
  • No telemetry SDKs
    No analytics, no error reporters, no third-party fetches at runtime.
  • Works offline
    Load it once, disconnect, and keep working.

Ready when you are.

Load a log, explore the demo, or bring your own export. It really is that fast.