Tenant Restriction Logs
When a user attempts to sign in to a SaaS application using an account that does not belong to an allowed tenant, a blocking action is triggered by the relevant vendor and a log entry is generated on SASE. These logs help you identify unauthorized access attempts and policy gaps.
Logs are generated automatically. No additional configuration is required.
Logs examples:
-
Microsoft Office 365

-
Google Services

A single log entry is created for each blocked login attempt. Each entry includes:
-
User - The identity that attempted to sign in
-
Application - The SaaS application where the login was attempted
-
Restricted Identifier - The tenant identifier that the user attempted to access
-
Category - The URL category of the login endpoint
-
Policy Rule - The tenant restriction rule that blocked the attempt
-
Action - Blocked
-
Tenant Restriction Logs - Limitations
-
Logs are generated only for failed login attempts.
-
Successful logins to allowed tenants are not logged.