When running the report and filtering as instructed in the article with output to a excel format for 24h period, 94% of the entries are appDisplayName as "Windows Azure Active Directory" and only 6% with appDisplayName as "Office 365 Exchange Online or Office 365 SharePoint Online".
What could those "Windows Azure Active Directory" be using basic auth?
Another question is if anyone have tip how to collect and aggregate the data.
Its hard to run and export reports larger than 24h when yuo get approx 30000 entries. But filter out the unique entires are very time consuming, some accounts could have hundreds of entries and other just a single entry.
Running one time 24h report its of course not enough to catch all possible account using basic auth so I need to run the report randomly, but my problem is how to create master file from the randomly reports without havinga a lots of manually work. any tip?