User Attempts Audit Report
The User Attempts Audit Report lists the users who have attempted various authentication methods—including MFA, SAML, NTLM authentication, smart card login, and self-service portal access. For each attempt, the report shows the timestamp, the domain name, the total number of attempts, and the attempt type, giving administrators a consolidated view of authentication activity across the organization.
How it works
Each time a user attempts an authentication action—such as performing MFA, signing in through SAML or NTLM, logging in with a smart card, or accessing the self-service portal—ADSelfService Plus records the attempt. The report aggregates these records and displays attempt timestamps, domain names, total attempt counts, and the type of each attempt, along with the success or failure outcome.
Prerequisites
- You must have administrator or operator credentials to access the ADSelfService Plus portal.
- At least one AD domain must be configured in ADSelfService Plus.
Generating the report

To generate the User Attempts Audit Report:
- Log in to the ADSelfService Plus portal with admin or operator credentials.
- Go to Reports > Other Reports > User Attempts Audit Report.
- Use the Period drop-down to select the timeframe: Today, Yesterday, Last 7 days, Last 30 days, This month, or Custom Period.
- Click Generate.
Customizing report columns

- Add or remove columns: Click the Add/Remove Columns [
] icon to modify the displayed fields. Select the fields you want from Available Columns and move them to Selected Columns using the arrow buttons.
- Reorder columns: Select a field and use the Up or Down options to adjust its placement.
Filtering the report
Once the report is generated, narrow the results by clicking the Advanced Filter [
] icon at the far right of the report and using the following parameters:

- User Name — Filter by username using Contains, Does Not Contain, Is, Is Not, Starts With, or Ends With.
- IP Address — Filter by IP address using Contains, Does Not Contain, Equals, Is Not Equal To, Starts With, or Ends With.
- Attempted from — Filter by machine name using comparable conditions.
- Domain Name — Filter by specific domains.
- Policy Name — Filter by policy names.
- CA Rule Name — Filter by conditional access rules.
- Type — Filter by authenticator type using Is or Is Not.
- Status — Filter by Success or Failure outcomes.
Sorting
Click any column header to sort the report entries in ascending or descending order.
Searching
Click the search icon [
] to search for specific entries within the report. You can search by:
- Username
- IP Address — the IP address of the device from which the authentication was attempted
Searches use a contains match. For example, searching for jack in the Username column returns all usernames that contain the sequence jack.
Schedule Reports, Export As, and More
- Schedule Reports — Schedule automatic report generation at set intervals, and email results to administrators or specified addresses.
- Export As — Export the report in CSV, PDF, XLS, XLSX, HTML, or CSVDE format using the option in the top-right corner.
- More — The More menu in the top-right corner provides the following options:
- Printable View: Preview and print the report.
- Send Mail: Email the report to specified addresses.
- Export Settings: Configure a custom report title and header logo to display on each exported page.
The Schedule Reports option at the top-right corner of the page can be used to schedule the generation of reports at specified intervals to set up an automated scheduler. Learn to schedule reports here.