Audit log activities

The tables in this article describe the activities recorded in the Microsoft 365 audit log. You can search for these activities by searching the audit log in the Microsoft Purview portal.

Tip

Select one of the links in the In this article list at the top of this article to go directly to a specific product table.

Audit logging is turned on by default for Microsoft 365 organizations. If auditing isn't turned on for your organization, a banner appears that prompts you to start recording user and admin activity. For instructions, see Turn on auditing.

These tables group related activities or the activities from a specific service. The tables include the friendly name that's displayed in the Activities drop-down list (or that are available in PowerShell) and the name of the corresponding operation that appears in the detailed information of an audit record and in the CSV file when you export the search results. For descriptions of the detailed information, see Audit log detailed properties.

Important

Some operation names listed in the Operation column in the following tables contain a period ( . ). You must include the period in the operation name if you specify the operation in a PowerShell command when searching the audit log, creating audit retention policies, creating alert policies, or creating activity alerts. Also be sure to use double quotation marks (" ") to contain the operation name.

Agent 365 activities

The following table lists Agent 365 activities that are logged when an agent is invoked or performs any actions or tool calls.

Friendly name Operation Description
Executed AI tool AIExecuteTool Agent executed a tool call.
Invoked AI agent AIInvokeAgent AI agent is invoked by a user, agent, or event.
Made AI inference call AIInferenceCall AI agent leveraged an AI model to produce an answer or determine next steps.
Applied AI guardrail AIGuardrail A guardrail was applied to an AI agent's request or response to enforce safety or compliance policies.

Application administration activities

The following table lists application admin activities that Microsoft 365 audit logs when an admin adds or changes an application registered in Microsoft Entra ID. You must register any application that relies on Microsoft Entra ID for authentication in the directory.

Friendly name Operation Description
Added credentials to a service principal Add service principal credentials. Credentials were added to a service principal in Microsoft Entra ID. A service principal represents an application in the directory.
Added delegation entry Add delegation entry. An authentication permission was created or granted to an application in Microsoft Entra ID.
Added service principal Add service principal. An application was registered in Microsoft Entra ID. A service principal represents an application in the directory.
Removed a service principal from the directory Remove service principal. An application was deleted or unregistered from Microsoft Entra ID. A service principal represents an application in the directory.
Removed credentials from a service principal Remove service principal credentials. Credentials were removed from a service principal in Microsoft Entra ID. A service principal represents an application in the directory.
Removed delegation entry Remove delegation entry. An authentication permission was removed from an application in Microsoft Entra ID.
Set delegation entry Set delegation entry. An authentication permission was updated for an application in Microsoft Entra ID.

Briefing email activities

The following table lists the activities in Briefing email that the Microsoft 365 audit log records. For more information about Briefing email, see:

Friendly name Operation Description
Updated organization privacy settings UpdatedOrganizationBriefingSettings Admin updates the organization privacy settings for Briefing email.
Updated user privacy settings UpdatedUserBriefingSettings Admin updates the user privacy settings for Briefing email.

Communication compliance activities

The following table lists communication compliance activities that the Microsoft 365 audit log records. For more information, see Learn about Microsoft Purview Communication Compliance.

Note

You can see these activities when you use the Search-UnifiedAuditLog PowerShell cmdlet. You can't see these activities in the Activities drop-down list.

Friendly name Operation Description
Policy match SupervisionRuleMatch A user sent a message that matches a policy's condition.
Policy update SupervisionPolicyCreated, SupervisionPolicyUpdated, SupervisionPolicyDeleted A communication compliance administrator performed a policy update.
Tag applied to messages SupervisoryReviewTag Tags are applied to messages or messages are resolved.

Compliance Manager activities

The following table lists the operations and activities that the audit log records when an admin manages settings in Compliance Manager. For more information, see Learn about Compliance Manager.

Friendly name Operation Description
Roles change ComplianceManagerRolesChange An admin changed the roles for users.
Tenant automation level change ComplianceManagerAutomationLevelChange An admin changed the automation level for the organization across all actions.
Testing source automation change ComplianceManagerAutomationChange An admin changed the testing source automation settings.

Content explorer activities

The following table lists the activities in Content explorer recorded in the Microsoft 365 audit log. You access content explorer on the Data classifications tool in the Microsoft Purview portal. For more information, see Using data classification content explorer.

Friendly name Operation Description
Accessed item LabelContentExplorerAccessedItem An admin (or a user who's a member of the Content Explorer Content Viewer role group) used content explorer to view an email message or SharePoint and OneDrive document.
AccessedAggregates AccessedAggregates An admin used content explorer to navigate between different aggregates.
AccessedContentList AccessedContentList When admin Clicked on any site/user in Content Explorer to get list of items.
AccessedItemDownload AccessedItemDownload An admin used content explorer to download an item.
AccessedItemPreview AccessedItemPreview An admin used content explorer to preview an item.
AccessedSiteList AccessedSiteList An admin used content explorer to navigate to SharePoint and OneDrive to get the site list.
AccessedUserList AccessedUserList An admin used content explorer to navigate to Exchange/Teams workload to get the user list.
SearchedContentList SearchedContentList When admin Searched for a file in Content Explorer.
SearchedSiteList SearchedSiteList An admin used content explorer to search for a site.
SearchedUserList SearchedUserList An admin used content explorer to search for a user.

Data Security Investigations activities

Data Security Investigations provides powerful investigation tools that might require the ability to audit activities to ensure secure and approved use of the solution. To meet these requirements, the unified audit log records Data Security Investigations activities.

The following table lists Data Security Investigations activities that the Microsoft 365 audit log records. For more information, see Learn about Microsoft Purview Data Security Investigations.

Friendly name Operation Description
Canceled DSI sample view DSISampleViewCancelled A user canceled a samples view.
Canceled DSI statistics view DSIStatisticsViewCancelled A user canceled a statistics job.
Created DSI Investigation CreatedDSIInvestigation A user created an investigation.
Deleted Data Security Investigations capacity DSICapacityDeleted A user deleted the Data Security Investigation capacity.
Deleted DSI Investigation DeletedDSIInvestigation A user deleted an investigation.
DSI AI feedback provided DSIAIFeedbackProvided A user provided AI feedback.
DSI investigation list viewed DSIInvestigationListViewed A user viewed the list of investigations.
DSI search added DSIPurviewSearchAdded A user added a search.
DSI search updated DSIPurviewSearchUpdated A user updated a search.
DSIProbeJobResultsViewed DSIProbeJobResultsViewed A user viewed the results of examination.
Get DSI Investigation GetDSIInvestigation A user viewed an investigation.
Get DSI search GetSearchDSIInvestigation A user viewed a search.
Investigation created from Defender XDR DSIInvestigationCreatedFromXDR A user created an investigation from Defender XDR.
Investigation created from Purview IRM DSIInvestigationCreatedFromIRM A user created an investigation from Microsoft Purview Insider Risk Management.
Item added to mitigation DSIItemAddedToMitigation A user added an item to an investigation's mitigation plan.
Item removed from mitigation DSIItemRemovedFromMitigation A user removed an item from an investigation's mitigation plan.
Mitigation plan list viewed DSIMitigationPlanListViewed A user viewed the mitigation plan list.
Started categorization job DSIInvestigationCategorizationJobSubmitted A user started a categorization job.
Started probing job DSIProbeJobSubmitted A user started an examination job.
Started purge job DSIPurgeStarted A user started a purge job.
Started vectorization job DSIInvestigationVectorizationJobSubmitted A user stated a vectorization job.
Submitted DSI search add to evidence set job DSIPurviewSearchAddToEvidenceSetJobSubmitted A user added searched data to an investigation scope.
Submitted DSI search sample job DSIPurviewSearchSampleJobSubmitted A user started a samples job.
Submitted DSI search statistics job DSIPurviewSearchStatisticsJobSubmitted A user started a statistics job.
Updated Data Security Investigations capacity DSICapacityUpdated A user updated the Data Security Investigation capacity.
Updated DSI Investigation UpdatedDSIInvestigation A user updated an investigation.
Updated DSI Investigation members DSIInvestigationMembersUpdated A user updated an investigation's members.
Updated status on item from mitigation plan DSIMitigationItemStatusUpdated A user updated the status of an item on an investigation's mitigation plan.
Uploaded file for DSI search DSIPurviewSearchUploadFile A user uploaded a file to search.
Vector search started DSIVectorSearchStarted A user ran a vector search.
Viewed data processing errors for a DSI evidence set DSIInvestigationSettingsUpdated A user updated investigation settings.
Viewed Data Security Investigations capacity DSICapacityViewed A user viewed the Data Security Investigation capacity.
Viewed default DSI investigation settings DSIInvestigationSettingsDefaultViewed A user viewed investigation settings.
Viewed DSI evidence set document DSIEvidenceSetDocumentViewed A user viewed a document in an investigation.
Viewed DSI investigation settings DSIInvestigationSettingsViewed A user viewed investigation settings.
Viewed DSI sample results DSISampleResultsViewed A user viewed sample results.
Viewed DSI sample status DSISampleStatusViewed A user viewed the status of a samples job.
Viewed DSI statistics results DSIStatisticsResultsViewed A user viewed search statistics.
Viewed individual activity DSISingleActivityViewed A user viewed an activity in an investigation.
Viewed investigation activities list DSIActivitiesViewed A user viewed the investigation activities.
Viewed investigation evidence set DSIEvidenceSetViewed A user viewed the list of items in the investigation.
Viewed item from mitigation plan DSIItemViewedFromMitigation A user viewed an item from an investigation's mitigation plan.

Data Security Posture Agent activities

The following table lists the activities for the Data Security Posture Agent in the Microsoft 365 audit log.

Friendly name Operation Description
Agent Ran AgentRan User ran the Data Security Posture Agent.
Agent re-ran Agent Reran User reran the Data Security Posture Agent.
Agent result viewed AgentResultViewed User viewed the results of a Data Security Posture Agent run.
Agent run cancelled AgentRunCancelled User canceled a run for Data Security Posture Agent.
Agent run deleted AgentRunDeleted User deleted a run for Data Security Posture Agent.

Directory administration activities

The following table lists Microsoft Entra directory and domain-related activities that are logged when an administrator manages their organization in the Microsoft 365 admin center or in the Azure management portal.

Friendly name Operation Description
Added a partner to the directory Add partner to company. Added a partner (delegated administrator) to your organization.
Added domain to company Add domain to company. Added a domain to your organization.
Removed a partner from the directory Remove partner from company. Removed a partner (delegated administrator) from your organization.
Removed domain from company Remove domain from company. Removed a domain from your organization.
Set company information Set company information. Updated the company information for your organization. Includes email addresses for subscription-related email that Microsoft 365 sends, and technical notifications about Microsoft 365 services.
Set domain authentication Set domain authentication. Changed the domain authentication setting for your organization.
Set password policy Set password policy. Changed the length and character constraints for user passwords in your organization.
Turned on Microsoft Entra ID Sync Set DirSyncEnabled flag. Set the property that enables a directory for Microsoft Entra ID Sync.
Updated domain Update domain. Updated the settings of a domain in your organization.
Updated the federation settings for a domain Set federation settings on domain. Changed the federation (external sharing) settings for your organization.
Verified domain Verify domain. Verified that your organization was the owner of a domain.
Verified email verified domain Verify email verified domain. Used email verification to verify that your organization is the owner of a domain.

Disposition review activities

The following table lists the activities a disposition reviewer took when an item reached the end of its configured retention period, or when an item automatically moved to the next disposition stage or was permanently deleted as a result of autoapproval.

Friendly name Operation Description
Added reviewers AddReviewer A disposition reviewer added one or more other users to the current disposition review stage.
Approved disposal ApproveDisposal For manual approval: A disposition reviewer approved the disposition of the item to move it to the next disposition stage. If the item was in the only or final stage of disposition review, the disposition approval marked the item as eligible for permanent deletion.

For autoapproval: No manual action was taken within the configured autoapproval time period so the item automatically moved to the next disposition stage. If the item was in the only or final stage of disposition review, the item automatically became eligible for permanent deletion.
Extended retention period ExtendRetention A disposition reviewer extended the retention period of the item.
Relabeled item RelabelItem A disposition reviewer relabeled the retention label.

Dragon Copilot admin activities

The following table lists administrative activities for Dragon Copilot recorded in the Microsoft 365 audit log. These events are logged when an administrator changes Dragon Copilot configuration. These events include changes in environments, products, Electronic Health Record (EHR) connectors, billing plans, groups, role assignments, settings, and extensions. If your organization uses Dragon Copilot, you can search the audit log for these activities by using the Activities picker list. For more information about Dragon Copilot, see the Dragon Copilot documentation.

You can also search for Dragon Copilot admin activities by running the Search-UnifiedAuditLog -RecordType DragonCopilotAdmin command in Exchange Online PowerShell.

Friendly name Operation Description
Accepted terms AcceptedTerms Terms of service were accepted.
Activated subscription ActivatedSubscription A subscription was activated.
Added group member AddedGroupMember A user was added to a group.
Canceled deprovision CanceledDeprovision A previously queued deprovision was cancelled.
Created billing plan CreatedBillingPlan A billing plan was created.
Created child organization CreatedChildOrganization A child organization was created.
Created data export configuration CreatedDataExportConfig A data export configuration was created.
Created EHR connector CreatedEhrConnector An EHR connector was created.
Created EHR instance CreatedEhrInstance An EHR integration instance was created.
Created EHR user CreatedEhrUser An EHR user mapping was created.
Created environment CreatedEnvironment A new Dragon Copilot environment was created.
Created extension CreatedExtension An extension was installed.
Created group CreatedGroup A user group was created.
Created organization role assignment CreatedOrganizationRoleAssignment An organization role assignment was created.
Created role assignment CreatedRoleAssignment A role was assigned to a user.
Deleted billing plan DeletedBillingPlan A billing plan was deleted.
Deleted data export configuration DeletedDataExportConfig A data export configuration was deleted.
Deleted device connector DeletedDeviceConnector A device connector under an EHR connector was deleted.
Deleted EHR instance DeletedEhrInstance An EHR integration instance was removed.
Deleted EHR user DeletedEhrUser An EHR user mapping was deleted.
Deleted environment DeletedEnvironment An environment was deleted.
Deleted group DeletedGroup A user group was deleted.
Deleted organization role assignment DeletedOrganizationRoleAssignment An organization role assignment was deleted.
Deleted role assignment DeletedRoleAssignment A role assignment was removed.
Deleted setting DeletedSetting A configuration setting was deleted.
Deprovisioned product DeprovisionedProduct A product was deprovisioned from an environment.
Installed device connector InstalledDeviceConnector A device connector was installed or upgraded under an EHR connector from a published package.
Installed device connector from package InstalledDeviceConnectorFromPackage A device connector was installed or upgraded under an EHR connector from a sideloaded device package.
Listed billing plans ListedBillingPlans Billing plans were listed.
Listed device connectors ListedDeviceConnectors Device connectors installed under an EHR connector were listed.
Listed EHR instances ListedEhrInstances EHR instances were listed.
Listed environments ListedEnvironments All environments were listed.
Listed extensions ListedExtensions Extensions were listed.
Listed groups ListedGroups User groups were listed.
Listed organizations ListedOrganizations Organizations were listed.
Listed role assignments ListedRoleAssignments Role assignments were listed.
Listed role definitions ListedRoleDefinitions An administrator listed the available role definitions.
Listed settings ListedSettings Configuration settings were listed.
Provisioned product ProvisionedProduct A product was provisioned for an environment.
Queued deprovision QueuedDeprovision An environment was queued for deprovisioning.
Removed group member RemovedGroupMember A user was removed from a group.
Set device connector state SetDeviceConnectorState A device connector under an EHR connector was enabled or disabled.
Updated billing plan UpdatedBillingPlan Billing plan properties were modified.
Updated data export configuration UpdatedDataExportConfig A data export configuration was modified.
Updated device connector configuration UpdatedDeviceConnectorConfiguration The configuration of a device connector under an EHR connector was updated.
Updated EHR connector UpdatedEhrConnector An EHR connector was modified.
Updated EHR instance UpdatedEhrInstance An EHR integration instance was modified.
Updated environment UpdatedEnvironment Environment properties were modified.
Updated extension UpdatedExtension An extension was updated.
Updated group UpdatedGroup Group properties were modified.
Updated organization UpdatedOrganization Organization properties were modified.
Updated setting UpdatedSetting A configuration setting was changed.
Verified device connector package VerifiedDeviceConnectorPackage A sideloaded device package was verified against an EHR connector without being installed.
Viewed billing plan ViewedBillingPlan Billing plan details were viewed.
Viewed data export configuration ViewedDataExportConfig A data export configuration was viewed.
Viewed device connector ViewedDeviceConnector An installed device connector under an EHR connector was viewed.
Viewed EHR connector ViewedEhrConnector An EHR connector was viewed.
Viewed EHR instance ViewedEhrInstance An EHR instance was viewed.
Viewed environment ViewedEnvironment Environment details were viewed.
Viewed extension ViewedExtension Extension details were viewed.
Viewed group ViewedGroup Group details were viewed.
Viewed organization ViewedOrganization Organization details were viewed.
Viewed role assignment ViewedRoleAssignment A role assignment was viewed.
Viewed role definition ViewedRoleDefinition An administrator viewed a role definition.
Viewed setting ViewedSetting A setting value was viewed.

Dragon Copilot Web activities

The following table lists user and application activities for Dragon Copilot Web recorded in the Microsoft 365 audit log. These events capture user access, clinical workflow actions, AI-assisted operations, and session lifecycle events performed within Dragon Copilot Web. Dragon Copilot Web supports clinical documentation workflows including ambient recording, transcript review, AI-assisted note generation, clinical chat, and EHR-integrated experiences.

If your organization uses Dragon Copilot Web, you can search for these activities in Microsoft Purview Audit by selecting the appropriate activity name or by filtering on the Dragon Copilot record types. Audit records are emitted under the following record types:

  • DragonCopilotAccess
  • DragonCopilotClinicalData
  • DragonCopilotSession

You can also search for Dragon Copilot Web audit events by using Search-UnifiedAuditLog and filtering on the corresponding record type.

Dragon Copilot access activities

The following table lists user access and interaction activities for Dragon Copilot recorded in the Microsoft 365 audit log. These events are logged when users access Dragon Copilot or interact with its features and underlying services. These activities include launching Dragon Copilot from an EHR system, accessing Dragon Copilot, and updating patient session data. Events also capture failures related to these operations. If your organization uses Dragon Copilot, you can search the audit log for these activities by using the Activities picker list. For more information about Dragon Copilot, see the Dragon Copilot documentation.

Friendly name Operation Description
Application accessed AppAccessed A user opened the Dragon Copilot web application.
EHR launch completed EhrLaunchCompleted Dragon Copilot launch from EHR completed.
EHR launch failed EhrLaunchFailed Dragon Copilot launch from EHR failed.
Encounter accessed EncounterAccessed A user opened a patient encounter in Dragon Copilot.
License check failed LicenseCheckFailed User doesn't have Dragon Copilot license.
Session data updated SessionDataUpdated Session data updated.
Session data update failed SessionDataUpdateFailed Session data update failed.

Dragon Copilot clinical data activities

Friendly name Operation Description
Transcript viewed TranscriptViewed A user viewed the transcript of an ambient or dictation session.
Clinical chat opened ClinicalChatOpened A user opened the clinical chat interface in Dragon Copilot.
Clinical chat episode viewed ClinicalChatEpisodeViewed A user viewed a previous clinical chat conversation episode.
Clinical chat prompt sent ClinicalChatPromptSent A user sent a message or prompt in the clinical chat interface.
Copilot prompt executed CopilotPromptExecuted A user triggered an AI action such as note summarization, generation, or rewrite.
Note generated NoteGenerated A clinical note was generated by the AI assistant and presented to the user.
Note updated NoteUpdated An AI-generated clinical note was updated with new or revised content and presented to the user.
AI suggested edit presented AiSuggestedEditPresented An AI-suggested edit to a clinical note was presented to the user for review.
AI suggested edit accepted AiSuggestedEditAccepted A user accepted an AI-suggested edit to a clinical note.
AI suggested edit rejected AiSuggestedEditRejected A user rejected an AI-suggested edit to a clinical note.
Clinical chat feedback submitted ClinicalChatFeedbackSubmitted A user submitted feedback on a clinical chat response.

Dragon Copilot session activities

Friendly name Operation Description
Session started SessionStarted A user started a new clinical documentation session in Dragon Copilot.
Session ended SessionEnded A user ended a clinical documentation session in Dragon Copilot.
Recording started RecordingStarted A user started audio recording during a clinical session.
Recording ended RecordingEnded A user stopped audio recording during a clinical session.

eDiscovery activities

The audit log records eDiscovery activities that you perform in the Microsoft Purview portal. It logs events when administrators or eDiscovery managers (or any user assigned eDiscovery permissions) perform the following tasks in the Microsoft Purview portal:

  • Creating and managing eDiscovery cases.
  • Creating and editing searches for eDiscovery cases.
  • Performing search actions, such as generating statistics, creating a sample, and exporting from search.
  • Creating, editing, and removing holds for eDiscovery cases.
  • Creating review sets and performing review activities in eDiscovery cases.

For more information about searching the audit log, the permissions that are required, and exporting search results, see Search the audit log.

How to search for and view eDiscovery activities

The audit log records eDiscovery activities that you perform in the Microsoft Purview portal or in PowerShell. To search for eDiscovery activities, see Search for eDiscovery activities in the audit log.

eDiscovery activity reference

The following table lists the eDiscovery activities that are logged when an administrator or eDiscovery manager performs an eDiscovery-related activity by using the Microsoft Purview portal. Some activities performed in the classic eDiscovery user experience might be returned when you search for activities in this list.

Note

The client IP field is included for all activities performed in the new eDiscovery experience. To distinguish activities performed in the new experience from those in the classic experience, check for the presence of the client IP field in the audit entry. (In the following image, the first entry is eDiscovery case deleted in new modern ux and the other two entries without IP addresses are classic ux).

Friendly name Operation Description
Added favorite FavoriteSet User set a case to favorite.
Added Purview search PurviewSearchAdded A new search was created. This audit activity includes the case name, case ID, and search name that was created.
Added review set ReviewSetAdded User created a review set.
Added saved search for a review set ReviewSetSavedSearchAdded User created saved filters in a review set. The audit activity includes the review set name, saved filters name, and the query used.
Added tag template TagTemplateAdded User created tag template in eDiscovery settings.
Cancelled sample view SampleViewCancelled User canceled sample view. The audit activity includes the canceled search’s name, ID, query, and associated settings.
Cancelled statistics view StatisticsViewCancelled User canceled statistics view. The audit activity includes the canceled search’s name, ID, query, and associated settings.
Changed eDiscovery case CaseUpdated Updated an eDiscovery case.
Changed hold in eDiscovery case HoldUpdated Hold was modified or edited. This audit activity includes the hold name, ID, and the specific data sources and query values that were modified.
Closed eDiscovery case CaseClosed An eDiscovery case was closed.
Copied review set ReviewSetCopied User triggers the “Add to another review set” process.
Created eDiscovery case CaseAdded Added a new eDiscovery case.
Created hold in eDiscovery case HoldCreated A new hold was created. This audit activity includes the case name, case ID, and hold name that was created.
Deleted eDiscovery case CaseRemoved An eDiscovery case was deleted. You must remove any hold associated with the case before you can delete the case.
Deleted file for Purview search PurviewSearchDeleteFile User deleted a file from a search. This audit activity includes the case name, case ID, search name, search ID, and the ID of the file the user deleted.
Deleted hold in eDiscovery case HoldRemoved A hold that is associated with an eDiscovery case was deleted. Deleting a hold releases all of the content locations from the hold.
Deleted Purview search PurviewSearchDeleted A search was deleted. This activity includes the deleted case name, case ID, and search name.
Deleted Purview Search export job PurviewSearchExportJobDeleted An export from search was deleted. This activity includes the deleted export name, the case information in which the export is included, the user, and the deletion timestamp.
Removed favorite FavoriteRemoved User removed a case from favorites.
Removed saved search for a review set ReviewSetSavedSearchRemoved User deleted saved filters in a review set.
Removed tag template TagTemplateRemoved User removed a tag template in eDiscovery settings. The audit activity includes the name and object ID of the tag template removed.
Reopened eDiscovery case CaseReopened An eDiscovery case was reopened.
Retried distribution sync for hold HoldRetryDistributionSync User triggered “retry policy” in a hold.
Retrieved actions for all review sets GetActionsForAllReviewSets User viewed a list of actions associated with all review sets in a case.
Retrieved all action for hold GetActionsForAllHolds User viewed a list of actions associated with all holds in a case. The audit activity includes case name, ID, hold name, ID, and the name of the list of actions.
Retrieved all action for search GetActionsForSearch User viewed a list of actions (such as exports) associated with a search. The audit activity includes case name, ID, search name, ID, and the name of the list of actions.
Retrieved all actions for all exports GetActionsForAllExports User viewed a list of exports in a case. The audit activity includes case name, ID, case settings, and the list of export names viewed.
Retrieved all actions for case GetActionsForCase User viewed a list of actions (such as exports) associated with an eDiscovery case.
Retrieved all actions for hold GetActionsForHold User viewed a list of actions associated with a hold.
Retrieved all actions for review set GetActionsForReviewSet User viewed a list of actions (such as exports) associated with a review set. The audit activity includes case name, ID, review set name, ID, and the name of the list of actions.
Retrieved single action for case GetSingleActionForCase User viewed a single action associated with an eDiscovery case. For example, the user viewed the export process in process manager. The audit activity includes case name, ID, and settings and ID associated with the process.
Retrieved single action for hold GetSingleActionForHold User viewed a single action associated with a hold.
Retrieved single action for review set GetSingleActionForReviewSet User viewed a single action associated with a review set.
Retrieved single action for search GetSingleActionForSearch User viewed a single action associated with a search. For example, the user viewed the export process in the search’s process manager. The audit activity includes case name, ID, and settings and ID associated with the process.
Submitted new algo job AlgoJobSubmitted User ran analytics on the documents in a review set.
Submitted new burn job BurnJobSubmitted User converted all the redacted documents in a review set to PDF files.
Submitted purview search add to review set job PurviewSearchAddToReviewSetJobSubmitted User triggered an “add to review set” process from a search. This audit activity includes the search name, ID, and the specific data sources and query values that were associated to the search. It also includes relevant add to review set process settings used.
Submitted purview search export job PurviewSearchExportJobSubmitted User triggered an “export” process from a search. This audit activity includes the search name, ID, and the specific data sources and query values that were associated to the search. It also includes relevant export process settings used and the export name.
Submitted purview search sample job PurviewSearchSampleJobSubmitted User triggered a “generate sample” process from a search. This audit activity includes the search name, ID, and the specific data sources and query values that were associated to the search. It also includes relevant sample process settings used.
Submitted purview search statistics job PurviewSearchStatisticsJobSubmitted User triggered a “generate statistics” process from a search. This audit activity includes the search name, ID, and the specific data sources and query values that were associated to the search. It also includes relevant statistics process settings used.
Submitted review set export job ReviewSetExportJobSubmitted Exported documents from review set. This audit activity includes the review set name, list of documents IDs being exported and relevant export process settings.
Tagged documents by ID for a review set ReviewSetDocumentsTaggedById User applied tags to specific documents in a review set. The audit activity includes the case name, review set name, and the list of items being tagged.
Tagged documents by query for a review set ReviewSetDocumentsTaggedByQuery User applied tags to specific documents in a review set after filtering by query. The audit activity includes the case name, review set name, and the list of items being tagged.
Updated case members CaseMembersUpdated Case membership was updated. As a member of a case, a user can perform various case-related tasks depending on whether they're assigned the necessary permissions.
Updated case settings CaseSettingsUpdated User modified the settings for a case. Case settings include case information, premium feature access, case permissions, and settings that control search and analytics behavior.
Updated notes for a review set ReviewSetNotesUpdated User updated note for a review set document.
Updated Purview search PurviewSearchUpdated Search was modified or edited. This audit activity includes the search name, ID, and the specific data sources and query values that were modified.
Updated review set ReviewSetUpdated User updated the review set such as review set name and description.
Updated review set annotation ReviewSetAnnotationsUpdated User annotated a document in a review set. This audit activity includes the review set name and other information such as the annotated document ID.
Updated saved search for a review set ReviewSetSavedSearchUpdated User modified saved filters in a review set. The audit activity includes the review set name, saved filters name, and the query used.
Updated tag template TagTemplateUpdated User updated a tag template in eDiscovery settings. The audit activity includes the name and object ID of the tag template updated.
Updated tags TagsUpdated User updated review set tags in a case.
Updated tags for a tag template TagTemplateTagsUpdated User updated tags for a tag template. The audit activity includes the name and ID of the tag template tags updated.
Updated tenant settings TenantSettingsUpdated User updated eDiscovery’s organization settings.
Viewed analytics review set attachments report AlgoGetReviewSetAttachmentsReport User viewed analytics attachment report. This audit activity includes case and review set name and ID.
Viewed analytics review set documents report AlgoGetReviewSetDocumentsReport User viewed analytics document report.
Viewed analytics review set email report AlgoGetReviewSetEmailsReport User viewed analytics email report.
Viewed analytics review set report AlgoGetReviewSetReport User viewed analytics report in a review set. This audit activity includes case and review set name and ID, as well as the report type.
Viewed analytics review set report by file type AlgoGetReviewSetReportByFileType User viewed analytics report graph by file type.
Viewed analytics review set report by source AlgoGetReviewSetReportBySource User viewed analytics document by source. This audit activity includes case and review set name and ID.
Viewed case metadata CaseMetadataViewed Metadata about an eDiscovery case was viewed.
Viewed case settings CaseSettingsViewed User viewed the settings for a case. Case settings include case information, premium feature access, case permissions, and settings that control search and analytics behavior.
Viewed data processing errors for a review set ReviewSetDataProcessingErrorViewed User viewed processing errors in a review set.
Viewed default case settings CaseSettingsDefaultViewed Default case setting viewed.
Viewed eDiscovery case CaseViewed A user viewed an eDiscovery case in the Microsoft Purview portal. The audit record for this event includes the name, case settings, and case ID of the case that was viewed.
Viewed eDiscovery case list CaseListViewed This activity is logged when a user viewed a list of eDiscovery cases. The audit record includes the name and ID of the cases that was viewed in the cases list.
Viewed favorite list FavoriteListViewed User viewed a list of favorite cases.
Viewed hold HoldViewed User viewed a hold inside a case. This audit activity includes the hold name and ID the user viewed. It also includes the specific data sources and query values inside the hold that was viewed by the user.
Viewed hold list HoldListViewed User viewed the holds list inside a case. This audit activity includes the case name, case ID, and the list of holds name and ID the user viewed.
Viewed hold results HoldResultsViewed User viewed hold’s results. The audit activity includes case name, case ID, hold name, and hold ID.
Viewed hold status HoldStatusViewed User viewed hold’s status. The audit activity includes case name, case ID, hold name, and hold ID.
Viewed if analytics settings are changed AlgoIsSettingChanged This audit activity includes case and review set name and ID.
Viewed load count in case LoadCountInCaseViewed User viewed the count of load sets in a case.
Viewed load list LoadListViewed User viewed a list of load sets in review set.
Viewed Purview search PurviewSearchViewed User viewed a specific search. This audit activity includes the search name, ID, and the specific data sources and query values inside the search that was viewed by the user.
Viewed Purview search list PurviewSearchListViewed User viewed the searches list inside a case. This audit activity includes the case name, case ID, and the list of searches name and ID the user viewed.
Viewed query report for a review set ReviewSetQueryReportViewed User viewed query report inside a review set.
Viewed review set document ReviewSetDocumentViewed User viewed a document inside a review set. This audit activity includes the case name, case ID, review set name, review set ID and other information such as the ID of the document viewed.
Viewed review set list ReviewSetListViewed User viewed the list of review sets in a case.
Viewed review set summary ReviewSetSummaryViewed User viewed the Overview of a Review set.
Viewed sample results SampleResultsViewed User viewed search sample results view.
Viewed sample status SampleStatusViewed User viewed search sample view’s status. The audit activity includes search’s name, ID, query, and associated settings.
Viewed saved search list for a review set ReviewSetSavedSearchListViewed User viewed a list of saved filters in a review set. The audit activity includes the review set name and the name of the list of saved filters viewed.
Viewed search count for a review set ReviewSetSearchCountViewed User ran a search within a review set and viewed the count returned. The audit activity includes the case name, review set name and the count of items returned in the search results.
Viewed search options for a review set ReviewSetSearchOptionsViewed User viewed the settings of a review set. The audit activity includes the case name and review set name.
Viewed search results for a review set ReviewSetSearchRun User ran a search within a review set. The audit activity includes the case name, review set name and the list of items returned in the search results.
Viewed statistics results StatisticsResultsViewed User viewed search statistics results.
Viewed statistics status StatisticsStatusViewed User viewed search statistics view’s status. The audit activity includes search’s name, ID, query, and associated settings.
Viewed tag template list TagTemplateListViewed User viewed the list of tag template in eDiscovery settings. The audit activity includes the list of tag templates viewed.
Viewed tags TagsViewed User viewed review set tags in a case.
Viewed tags for a tag template TagTemplateTagsViewed User viewed tags for a tag template. The audit activity includes the name and ID of the tag template tags viewed.
Viewed tenant settings TenantSettingsViewed User viewed eDiscovery’s organization settings. The audit activity contains information on the setting values.

Detailed properties for eDiscovery activities

The following table lists the properties that the portal shows on the details page for an eDiscovery activity listed in the search results. These properties are also included in the CSV file when you export the audit log search results. An audit log record for an eDiscovery activity doesn't include every detailed property listed in the following table.

Tip

When you export the search results, the CSV file contains a column named AuditData, which contains the detailed properties described in the following table in a multivalue property. You can use the Power Query feature in Excel to split this column into multiple columns so that each property has its own column. This setup lets you sort and filter on one or more of these properties. For more information, see Search the audit log.

Property Description
CaseId The identity (GUID) of the eDiscovery case created, changed, or deleted.
CaseName The name of the eDiscovery case created, changed, or deleted.
ClientApplication eDiscovery cmdlet activities have a value of EMC for this property. This value indicates the activity was performed by using the Microsoft Purview portal GUI or running the cmdlet in PowerShell.
ClientIP The IP address of the device that was used when the activity was logged. The IP address is displayed in either an IPv4 or IPv6 address format.
ClientRequestId For eDiscovery activities, this property is typically blank.
CmdletVersion The build number for the version of the Microsoft Purview portal running in your organization.
CreationTime The creation date and time in Coordinated Universal Time (UTC) for the activity.
DataSources A list of source ID, source name, and location details associated to the activity.
EffectiveOrganization The name of the Microsoft 365 organization.
ExportName Name of the eDiscovery export.
ExtendedProperties Additional properties related to the eDiscovery activity. For example, when case members are updated, this field contains the updated case member information; or when the review set description is updated, this field contains the updated review set description updated by the user.
ID The ID of the report entry. The ID uniquely identifies the audit log entry.
Item The name of the item associated with the activity. For example, this field contains the name of the document viewed when a user views a review set document.
JobId The GUID of the eDiscovery process.
ObjectId The GUID of the object (for example, a search, hold, or review set) created, accessed, or changed, by the activity listed in the Operation property.
ObjectName The name of the object (for example, a search, hold or review set) created, accessed, or changed, by the activity listed in the Operation property.
ObjectType The type of eDiscovery object created, deleted, or modified. For example, a search action (generate sample results or trigger an export from search) are listed as Search in this field.
Operation The name of the operation that corresponds to the eDiscovery activity that was performed.
OrganizationId The GUID for your Microsoft 365 organization.
QueryId The GUID of the query associated with the activity.
QueryText The query text associated with the activity, such as a search statistic process or add to review process.
RecordType The type of operation indicated by the record.
ResultStatus If the action (specified in the Operation property) was successful or not.
Settings Settings applied to the eDiscovery activity.
StartTime The date and time in Coordinated Universal Time (UTC) when the eDiscovery activity was started.
UserCancelled Whether the specific activity was canceled by the user.
UserId The user who performed the activity (specified in the Operation property) that resulted in the record being logged.
UserKey An alternative ID for the user identified in the UserId property. For eDiscovery activities, the value for this property is typically the same as the UserId property.
UserServicePlan The subscription used by your organization. For eDiscovery activities, this property is typically blank.
UserType The type of user that performed the operation. The following values indicate the user type.
0 A regular user. 2 An administrator in your organization. 3 A Microsoft datacenter administrator or datacenter system account. 4 A system account. 5 An application. 6 A service principal.
Version The version number of the activity (identified by the Operation property) that's logged.
Workload The service where the activity occurred.

Encrypted message portal activities

Your organization can access logs for encrypted messages through the encrypted message portal. These logs help you determine when your external recipients read and forward messages. For more information about enabling and using encrypted message portal activity logs, see Encrypted message portal activity log.

Each audit entry for a tracked message contains the following fields:

  • MessageID: Contains the ID of the message being tracked. Use this key identifier to follow a message through the system.
  • Recipient: List of all recipient email addresses.
  • Sender: The originating email address.
  • AuthenticationMethod: Describes the authenticating method for accessing the message, such as OTP, Yahoo, Gmail, or Microsoft.
  • AuthenticationStatus: Contains a value indicating that the authentication succeeded or failed.
  • OperationStatus: Whether the indicated operation succeeded or failed.
  • AttachmentName: Name of the attachment.
  • OperationProperties: A list of optional properties. For example, the number of OTP passcodes sent, or the email subject.

eSignature activities

The following table lists the eSignature activities that the Microsoft 365 audit log records. For more information, see eSignature for Microsoft 365.

Friendly name Operation Description
Cancelled by the requestor ESignatureRequestCanceled The signing request was cancelled by the requestor.
Declined by a signer ESignatureRequestDeclined A signer declined the request.
Document was downloaded ESignatureRequestDownloaded The document was downloaded by a member of the workflow.
Document was viewed ESignatureDocumentViewed The document was viewed by a member of the workflow.
Link to the signed document expired ESignatureRequestExpired The link to the signed document expired.
Request was completed ESignatureRequestCompleted An electronic signature request was completed.
Request was created ESignatureRequestCreated An electronic signature request was created by a member of the organization.
Request was sent ESignatureRequestSent An electronic signature request was sent to recipients.
Request was signed by a user ESignatureDocumentSigned An electronic signature request was signed by a recipient.

Exchange admin activities

Exchange administrator audit logging (which Microsoft 365 enables by default) logs an event in the audit log when an administrator (or a user assigned administrative permissions) makes a change in your Exchange Online organization. The Exchange admin audit log records changes made by using the Exchange admin center or by running a cmdlet in Exchange Online PowerShell. The audit log doesn't record cmdlets that begin with the verbs Get-, Search-, or Test-. For more detailed information about admin audit logging in Exchange, see Administrator audit logging.

Important

Some Exchange Online cmdlets aren't logged in the Exchange admin audit log or in the audit log. Many of these cmdlets relate to maintaining the Exchange Online service and Microsoft datacenter personnel or service accounts run them. These cmdlets aren't logged because they would result in a large number of "noisy" auditing events. If there's an Exchange Online cmdlet that isn't being audited, submit a design change request (DCR) to Microsoft Support.

Use these tips to search for Exchange admin activities when searching the audit log:

  • Use the date range boxes and the Users list to narrow the search results for cmdlets run by a specific Exchange administrator within a specific date range.
  • Select the Activity column to sort the cmdlet names in alphabetical order and display events from the Exchange admin audit log.
  • Select the Download all results option to export the search results and get information about what cmdlet was run, which parameters and parameter values were used, and what objects were affected. For more information, see Export, configure, and view audit log records.
  • Use the Search-UnifiedAuditLog -RecordType ExchangeAdmin command in Exchange Online PowerShell to return only audit records from the Exchange admin audit log. It might take up to 30 minutes after an Exchange cmdlet is run for the corresponding audit log entry to be returned in the search results. For more information, see Search-UnifiedAuditLog. For information about exporting the search results returned by the Search-UnifiedAuditLog cmdlet to a CSV file, see the "Tips for exporting and viewing the audit log" section in Export, configure, and view audit log records.

Exchange mailbox activities

The following table lists the activities recorded in the Microsoft 365 audit log. Mailbox audit logging automatically logs mailbox activities performed by the mailbox owner, a delegated user, or an administrator in the audit log for up to 180 days. An admin can turn off mailbox audit logging for all users in your organization. In this case, no mailbox actions for any user are logged. For more information, see Manage mailbox auditing.

Important

The default retention period for Audit (Standard) changed from 90 days to 180 days. Audit (Standard) logs generated before October 17, 2023, are retained for 90 days. Audit (Standard) logs generated on or after October 17, 2023, follow the new default retention of 180 days.

You can also search for mailbox activities by using the Search-UnifiedAuditLog cmdlet in Exchange Online PowerShell.

Friendly name Operation Description
Accessed mailbox attachments AttachmentAccess A message attachment was accessed.
Accessed Mailbox folder FolderBind A mailbox folder was accessed. This action is also logged when the admin or delegate opens the mailbox. Audit records for folder bind actions performed by delegates are consolidated. One audit record is generated for individual folder access within a 24-hour period.
Accessed mailbox items MailItemsAccessed Messages were read or accessed in mailbox. Audit records for this activity are triggered in one of two ways: when a mail client (such as Outlook) performs a bind operation on messages or when mail protocols (such as Exchange ActiveSync or IMAP) sync items in a mail folder. Analyzing audit records for this activity is useful when investigating compromised email account.
Accessed message MessageBind A message was viewed in the preview pane or opened by an admin. This value is available only for users without E5/A5/G5 licenses.
Added delegate mailbox permissions Add-MailboxPermission An administrator assigned the FullAccess mailbox permission to a user (known as a delegate) to another person's mailbox. The FullAccess permission allows the delegate to open the other person's mailbox, and read and manage the contents of the mailbox. The audit record for this activity is also generated when a system account in the Microsoft 365 service periodically performs maintenance tasks in behalf of your organization. A common task performed by a system account is updating the permissions for system mailboxes. For more information, see System accounts in Exchange mailbox audit records.
Added or removed user with delegate access to calendar folder UpdateCalendarDelegation A user was added or removed as a delegate to the calendar of another user's mailbox. Calendar delegation gives someone else in the same organization permissions to manage the mailbox owner's calendar.
Added permissions to folder AddFolderPermissions A folder permission was added. Folder permissions control which users in your organization can access folders in a mailbox and the messages located in those folders.
Copied messages to another folder Copy A message was copied to another folder.
Created mailbox item Create An item is created in the Calendar, Contacts, Notes, or Tasks folder in the mailbox. For example, a new meeting request is created. Creating, sending, or receiving a message isn't audited. Also, creating a mailbox folder isn't audited.
Created new inbox rule in Outlook web app New-InboxRule A mailbox owner or other user with access to the mailbox created an inbox rule in the Outlook web app.
Delete priority cleanup label item PriorityCleanupDelete The item with a label of Priority Cleanup type is getting deleted.
Deleted messages from Deleted Items folder SoftDelete A message was permanently deleted or deleted from the Deleted Items folder. These items are moved to the Recoverable Items folder. Messages are also moved to the Recoverable Items folder when a user selects it and presses Shift+Delete.
Label message as a record A user applied a retention label to an email message and that label is configured to mark the item as a record.
Labeled item as a record ApplyRecord An item is labeled as a record.
Labeled message as a record ApplyRecordLabel A message was classified as a record. Occurs when a retention label that classifies content as a record is manually or automatically applied to a message.
Modified folder permission ModifyFolderPermissions A folder permission was changed. Folder permissions control which users in your organization can access mailbox folders and the messages in the folder.
Modified inbox rule from Outlook web app Set-InboxRule A mailbox owner or other user with access to the mailbox modified an inbox rule using the Outlook web app.
Moved messages to another folder Move A message was moved to another folder.
Moved messages to Deleted Items folder MoveToDeletedItems A message was deleted and moved to the Deleted Items folder.
Perform search query SharepointSearchQueryInitiated The user performs a search on SharePoint.
Preserve Mailbox item PreservedMailItemProactively The mail item is proactively preserved. Proactive preservation is a Microsoft Purview Data Lifecycle Management (DLM) feature, where mails deleted by risky users in the tenant are preserved in dumpster.
Priority cleanup label applied ApplyPriorityCleanup The Priority Cleanup label is applied to an item.
Priority cleanup label applied on Exchange item ApplyPriorityCleanup A retention label for priority cleanup is applied to an item on Exchange.
Purged messages from the mailbox HardDelete A message was purged from the Recoverable Items folder (permanently deleted from the mailbox).
Removed delegate mailbox permissions Remove-MailboxPermission An administrator removed the FullAccess permission (that was assigned to a delegate) from a person's mailbox. After the FullAccess permission is removed, the delegate can't open the other person's mailbox or access any content in it.
Removed permissions from folder RemoveFolderPermissions A folder permission was removed. Folder permissions control which users in your organization can access folders in a mailbox and the messages located in those folders.
Search items in a mailbox SearchQueryInitiated A person uses Outlook (Windows, Mac, iOS, Android, or Outlook on the web) or the Mail app for Windows 10 to search for items in a mailbox.
Sent message Send A message was sent, replied to, or forwarded.
Sent message using Send As permissions SendAs A message was sent using the SendAs permission. This means that another user sent the message as though it came from the mailbox owner.
Sent message using Send On Behalf permissions SendOnBehalf A message was sent using the SendOnBehalf permission. This means that another user sent the message on behalf of the mailbox owner. The message the recipient to whom the message was sent on behalf of and who actually sent the message.
Update item label UpdateComplianceTag When the label is applied to an item.
Updated inbox rules from Outlook client UpdateInboxRules A mailbox owner or other user with access to the mailbox created, modified, or removed an inbox rule by using the Outlook client.
Updated message Update A message or its properties was changed.
User signed in to mailbox MailboxLogin The user signed in to their mailbox.

System accounts in Exchange mailbox audit records

In audit records for some mailbox activities, especially Add-MailboxPermissions, you might see the user who performed the activity identified as NT AUTHORITY\SYSTEM or NT SERVICE\MSExchangeAdminApiNetCore(Microsoft.Exchange.AdminApi.NetCore). This system account in the Exchange service in the Microsoft cloud performs scheduled maintenance tasks on behalf of your organization. For example, a common audited activity performed by the NT SERVICE\MSExchangeAdminApiNetCore(Microsoft.Exchange.AdminApi.NetCore) account is updating the permissions on the DiscoverySearchMailbox, which is a system mailbox. This update verifies that the FullAccess permission (which is the default) is assigned to the Discovery Management role group for the DiscoverySearchMailbox. This update ensures that eDiscovery administrators can perform necessary tasks in their organization.

Another system user account that might appear in an audit record for Add-MailboxPermission is Administrator@apcprd03.prod.outlook.com. This service account also appears in mailbox audit records related to verifying and updating the FullAccess permission assigned to the Discovery Management role group for the DiscoverySearchMailbox system mailbox. Specifically, audit records that identify the Administrator@apcprd03.prod.outlook.com account typically trigger when Microsoft support personnel run a role-based access control diagnostic tool on behalf of your organization.

Fabric activities

The following table lists the Microsoft Fabric activities in Power BI that the Microsoft 365 audit log records. You can search the audit log for these activities in Power BI. For information about audit settings, see Audit and usage tenant settings.

Friendly name Operation Description
Applied a PostgreSQL database schema PgSchemaApplied Generated when a user applies (plans and executes) a PostgreSQL database schema through the custom PG schema service (pgschema-based ALM flow). The audit log records caller identity, operation result, and the affected PostgreSQL database artifact.
Assign Warehouse Server Alias AssignWarehouseServerAlias A workspace administrator assigned a server alias to a Fabric Warehouse workspace.
Automatically bound user credentials to Git AutoBoundGitCredentials Automatically bound user credentials to Git.
Branch workspace configuration retrieved BranchWorkspaceConfigurationRetrieved Branch workspace configuration retrieved.
Branch workspace configured GitBranchWorkspaceConfigured Branch workspace configured.
Automatically bound user credentials to Git AutoBoundGitCredentials Automatically bound user credentials to Git.
Branch workspace configuration retrieved BranchWorkspaceConfigurationRetrieved Branch workspace configuration retrieved.
Branch workspace configured GitBranchWorkspaceConfigured Branch workspace configured.
Branched out to a workspace in Git GitBranchedOut Branched out to a workspace in Git.
Browsed PostgreSQL database objects PgSQLDbObjectExplorered Generated when a user browses PostgreSQL database schema objects through Object Explorer. The audit log records caller identity, operation result, and the affected PostgreSQL database artifact.
Cancelled a Digital Operations Ontology Agent conversation DigitalOperationsOntologyAgentConversationCancelled A user canceled a Digital Operations Ontology Agent conversation.
Checked out Git branch GitCheckedOutBranch Checked out Git branch.
Compute Items Sizes ComputeItemsSize Calculated current size of all items for the OneLake item-size report.
Create the cross tenant auth mapping CreateCrossTenantAuthMapping Create a user mapping for the cross tenant auth feature.
Created a Digital Operations Ontology Agent conversation DigitalOperationsOntologyAgentConversationCreated A user created a Digital Operations Ontology Agent conversation.
Created a Fabric Copilot session FabricCopilotSessionCreated A user created a Fabric Copilot session.
Created MirroredStorage CreatedMirroredStorage Generated when a user or service principal creates a Fabric MirroredStorage item, linking an external storage source to a workspace as OneLake shortcuts.
Created workspace relation CreatedWorkspaceRelation Created workspace relation.
Deleted a Fabric Copilot session FabricCopilotSessionDeleted A user deleted a Fabric Copilot session.
Deleted a task flow DeletedTaskFlow Deleted a task flow.
Deleted connection by tenant admin DeletedGatewayClusterDatasourceAsAdmin A tenant admin deleted the connection.
Deleted connection role assignment by tenant admin DeletedGatewayDatasourceByAdmin A tenant admin deleted the connection role assignment.
Deleted workspace relation DeletedWorkspaceRelation Deleted workspace relation.
Downloaded dataflow refresh logs DownloadedDataflowRefreshLogs Downloaded dataflow refresh logs.
Edited Power BI semantic model options EditedSemanticModelOptions A user made a change to their semantic model options. This occurs when changes are made in the model options dialog.
Executed a PostgreSQL database query QueryExecuted Generated when a user executes a SQL query against a Fabric Native PostgreSQL database. The audit log records caller identity, operation result, and the affected PostgreSQL database artifact.
Executed a tenant relocation TenantRelocationExecuted Executed tenant relocation.
Export item definitions ExportItemDefinitions Export multiple item definitions from a workspace.
Exported a PostgreSQL database schema PgSchemaExported Generated when a user dumps a PostgreSQL database schema through the custom PG schema service (pgschema-based ALM flow). The audit log records caller identity, operation result, and the affected PostgreSQL database artifact.
Get Items Sizes GetItemsSize Retrieved cached item sizes for the OneLake item-size report.
Export item definitions ExportItemDefinitions Export multiple item definitions from a workspace.
Exported a PostgreSQL database schema PgSchemaExported Generated when a user dumps a PostgreSQL database schema through the custom PG schema service (pgschema-based ALM flow). The audit log records caller identity, operation result, and the affected PostgreSQL database artifact.
Get Items Sizes GetItemsSize Retrieved cached item sizes for the OneLake item-size report.
Get connection by tenant admin GetGatewayClusterDatasourceAsAdmin A tenant admin retrieved the connection details.
Git connection settings updated GitConnectionSettingsUpdated Git connection settings updated.
Granted consent to tenant relocation TenantRelocationConsentGranted Tenant relocation consent granted.
Import item definitions ImportItemDefinitions Import multiple item definitions into a workspace.
Imported OneLake lifecycle policy ImportedLifecyclePolicy Imported OneLake Lifecycle policy.
Imported PostgreSQL sample data ImportedSampleData Generated when a user imports supported sample data into a Fabric Native PostgreSQL database. The audit log records caller identity, operation result, and the affected PostgreSQL database artifact.
Initialized connection to Git GitConnectionInitialized Initialized connection to Git.
Item definition exported ItemDefinitionExported A Fabric item definition has been exported.
List all of the cross tenant auth mappings ListCrossTenantAuthMappings List cross tenant auth mappings in a tenant.
Logged in to Git provider ConfiguredGitProviderCredentials Logged in to Git provider.
Logged out of Git provider DeletedGitProviderCredentials Logged out of Git provider.
Microsoft Fabric Audit activity to retrieve FMI bindings GetFabricManagedIdentityBindings Microsoft Fabric Audit activity to retrieve FMI bindings.
Migrate Gen1 dataflow MigrateGen1Dataflow A user upgraded a Power BI Gen1 dataflow to a Fabric Gen2.1 dataflow in place by using the Upgrade Wizard.
Modified OneLake default tier ModifiedDefaultTier Modified OneLake default tier.
Planning session upgraded PlanningSessionUpgraded Session type is upgraded in planning workload.
Recover an artifact ArtifactRecovered A user recovered a previously soft-deleted artifact, such as a gateway or gateway cluster member, restoring it to active state.
Retrieved artifact's Logical Id ArtifactLogicalIdRetrieved Retrieved artifact's Logical Id.
Retrieved PostgreSQL SQL audit policy SqlAuditPolicyRetrieved Generated when a user retrieves the SQL audit policy settings for a PostgreSQL database artifact. The audit log records caller identity, operation result, and the affected PostgreSQL database artifact.
Revoked consent to tenant relocation TenantRelocationConsentRevoked Tenant relocation consent revoked.
Sent a Digital Operations Ontology Agent message DigitalOperationsOntologyAgentMessageSent A user sent a message in a Digital Operations Ontology Agent conversation.
Sent a Fabric Copilot message FabricCopilotSessionMessageSent A user sent a message in a Fabric Copilot session.
Set PostgreSQL SQL audit policy SqlAuditPolicySet Generated when a user updates SQL audit policy settings for a PostgreSQL database artifact. The audit log records caller identity, operation result, and the affected PostgreSQL database artifact.
Set Warehouse Connection Mode To Automatic SetWarehouseConnectionModeToAutomatic A workspace administrator set the Fabric Warehouse SQL connection mode to Automatic.
Set Warehouse Connection Mode To Proxy SetWarehouseConnectionModeToProxy A workspace administrator set the Fabric Warehouse SQL connection mode to Proxy.
Set Warehouse Connection Mode To Redirect SetWarehouseConnectionModeToRedirect A workspace administrator set the Fabric Warehouse SQL connection mode to Redirect.
Set Warehouse Hardware Acceleration SetWarehouseHardwarePlatform Changed the current hardware acceleration settings for warehouses in a workspace. 
Soft delete an artifact ArtifactSoftDeleted A user soft deleted an artifact, such as a gateway or gateway cluster member, marking it for deletion while allowing recovery within a retention period.
Switched Git branch GitSwitchedBranch Switched Git branch for workspace.
Updated a Fabric Copilot session FabricCopilotSessionUpdated A user updated a Fabric Copilot session.
Updated a Fabric Copilot session state FabricCopilotSessionStateUpdated A user updated the state of a Fabric Copilot session.
Updated artifact's Logical Id ArtifactLogicalIdUpdated Updated artifact's Logical Id.
Updated authorization setting in GraphQL UpdatedAuthorizationSettingGraphQL Updated authorization setting in GraphQL.
Updated connection role assignment by tenant admin UpdatedGatewayDatasourceByAdmin A tenant admin add or updates the connection role assignment.
Updated git items selection GitItemsSelectionUpdated Updated git items selection.
Updated MirroredStorage definition UpdatedMirroredStorageDefinition Generated when a user or service principal modifies the mirroring scope of an existing MirroredStorage item, changing which external paths are exposed in OneLake.
Unassign Warehouse Server Alias UnassignWarehouseServerAlias A workspace administrator assigned a server alias to a Fabric Warehouse workspace.
Workspace relations retrieved WorkspaceRelationsRetrieved Workspace relations retrieved.

File and page activities

The following table lists the file and page activities in SharePoint and OneDrive that the Microsoft 365 audit log records.

Friendly name Operation Description
(none) FileAccessedExtended This activity is related to the "Accessed file" (FileAccessed) activity. A FileAccessedExtended event is logged when the same person continually accesses a file for an extended period (up to three hours).

The purpose of logging FileAccessedExtended events is to reduce the number of FileAccessed events that are logged when a file is continually accessed. This approach helps reduce the noise of multiple FileAccessed records for what is essentially the same user activity, and lets you focus on the initial (and more important) FileAccessed event.
(none) FileModifiedExtended This activity is related to the "Modified file" (FileModified) activity. A FileModifiedExtended event is logged when the same person continually modifies a file for an extended period (up to three hours).

The purpose of logging FileModifiedExtended events is to reduce the number of FileModified events that are logged when a file is continually modified. This approach helps reduce the noise of multiple FileModified records for what is essentially the same user activity, and lets you focus on the initial (and more important) FileModified event.
(none) FilePreviewed User previews files on a SharePoint or OneDrive site. These events typically occur in high volumes based on a single activity, such as viewing an image gallery.
(none) PagePrefetched A user's client (such as website or mobile app) requests the indicated page to help improve performance if the user browses to it. This event is logged to indicate that the page content is served to the user's client. This event isn't a definitive indication that the user navigated to the page.

When the client renders the page content (as per the user's request), it should generate a ClientViewSignaled event. Not all clients support indicating a prefetch, and therefore some prefetched activities might instead be logged as PageViewed events.
(none) PageViewedExtended This activity is related to the "Viewed page" (PageViewed) activity. A PageViewedExtended event is logged when the same person continually views a web page for an extended period (up to three hours).

The purpose of logging PageViewedExtended events is to reduce the number of PageViewed events that are logged when a page is continually viewed. This approach helps reduce the noise of multiple PageViewed records for what is essentially the same user activity, and lets you focus on the initial (and more important) PageViewed event.
Accessed file FileAccessed User or system account accesses a file. After a user accesses a file, the system doesn't log the FileAccessed event again for the same user and file for the next five minutes.
Changed record status to locked LockRecord The record status of a retention label that classifies a document as a record is locked. This status means the document wasn't modified or deleted. Only users assigned at least the contributor permission for a site can change the record status of a document.
Changed record status to unlocked UnlockRecord The record status of a retention label that classifies a document as a record is unlocked. This status means that the document can be modified or deleted. Only users assigned at least the contributor permission for a site can change the record status of a document.
Changed retention label for a file ComplianceSettingChanged A retention label is applied to or removed from a document. This event is triggered when a retention label is manually or automatically applied to a message.
Checked in file FileCheckedIn User checks in a document that they checked out from a document library.
Checked out file FileCheckedOut User checks out a document located in a document library. Users can check out and make changes to documents that are shared with them.
Copied file FileCopied User copies a document from a site. The copied file can be saved to another folder on the site.
Deleted file FileDeleted User deletes a document from a site.
Deleted file from recycle bin FileDeletedFirstStageRecycleBin User deletes a file from the recycle bin of a site.
Deleted file from second-stage recycle bin FileDeletedSecondStageRecycleBin User deletes a file from the second-stage recycle bin of a site.
Deleted file marked as a record RecordDelete A document or email that was marked as a record is deleted. An item is considered as a record when a retention label that marks items as a record is applied to content.
Detected document sensitivity mismatch DocumentSensitivityMismatchDetected User uploads a document to a site that's protected with a sensitivity label and the document has a higher priority sensitivity label than the sensitivity label applied to the site. For example, a document labeled Confidential is uploaded to a site labeled General.

This event isn't triggered if the document has a lower priority sensitivity label than the sensitivity label applied to the site. For example, a document labeled General is uploaded to a site labeled Confidential. For more information about sensitivity label priority, see Label priority (order matters).
Detected malware in file FileMalwareDetected SharePoint anti-virus engine detects malware in a file.
Discarded file checkout FileCheckOutDiscarded User discards (or undoes) a checked out file. That means any changes they made to the file when it was checked out are discarded, and not saved to the version of the document in the document library.
Downloaded file FileDownloaded User downloads a document from a site.
Modified file FileModified User or system account modifies the content or the properties of a document on a site. The system waits five minutes before it logs another FileModified event when the same user modifies the content or properties of the same document.
Moved file FileMoved User moves a document from its current location on a site to a new location.
Performed search query SearchQueryPerformed User or system account performs a search in SharePoint or OneDrive. Some common scenarios where a service account performs a search query include applying an eDiscovery holds and retention policy to sites and OneDrive accounts, and autoapplying retention or sensitivity labels to site content. To enable logging for this activity, see Get started with auditing solutions.
Priority cleanup move file to recycle bin PriorityCleanupFileRecycled An item is moved to Stage 2 recycle bin by a priority cleanup policy on OneDrive or SharePoint Online.
Priority cleanup permanent delete of file PriorityCleanupFileDeleted An item is permanently deleted by a priority cleanup policy on OneDrive or SharePoint Online.
Recycled a file FileRecycled User moves a file into the SharePoint Recycle Bin.
Recycled a folder FolderRecycled User moves a folder into the SharePoint Recycle Bin.
Recycled all minor versions of file FileVersionsAllMinorsRecycled User deletes all minor versions from the version history of a file. The deleted versions are moved to the site's recycle bin.
Recycled all versions of file FileVersionsAllRecycled User deletes all versions from the version history of a file. The deleted versions are moved to the site's recycle bin.
Recycled version of file FileVersionRecycled User deletes a version from the version history of a file. The deleted version is moved to the site's recycle bin.
Renamed file FileRenamed User renames a document.
Restored file FileRestored User restores a document from the recycle bin of a site.
Started bulk deleting file versions FileVersionBulkDeletionStarted Admin started a bulk deletion of file versions across a SharePoint site or document library to reclaim storage space by permanently removing old versions that exceed the version policy.
Started bulk expiring file versions by using a schedule file FileVersionBulkExpirationByScheduleStarted Admin starts a bulk expiration of file versions using a schedule file on a SharePoint site, applying version expiration according to that schedule.
Started generating file version expiration report FileVersionExpirationReportStarted Admin started generating a file version expiration report for a SharePoint site or document library that includes certain version metadata and expiration information.
Started tenant apply file version policy TenantApplyFileVersionPolicyStarted Admin started applying the tenant-level file version policy across all sites in the organization, which sets version limits or trims existing versions for all document libraries tenant-wide.
Started updating version settings on all document libraries in the site DocumentLibraryVersionPolicyBulkUpdateStarted Admin started a bulk update of version policy settings across all document libraries in a SharePoint site.
Uploaded file FileUploaded User uploads a document to a folder on a site.
View signaled by client ClientViewSignaled A user's client (such as website or mobile app) signals that the indicated page is viewed by the user. This activity is often logged following a PagePrefetched event for a page.

NOTE: Because ClientViewSignaled events are signaled by the client, rather than the server, it's possible the event might not be logged by the server and therefore might not appear in the audit log. It's also possible that information in the audit record might not be trustworthy. However, because the user's identity is validated by the token used to create the signal, the user's identity listed in the corresponding audit record is accurate. The system waits five minutes before it logs the same event when the same user's client signals that the page is viewed again by the user.
Viewed page PageViewed User views a page on a site. This activity doesn't include using a Web browser to view files located in a document library. After a user views a page, the system doesn't log the PageViewed event again for the same user and page for the next five minutes.

Frequently asked questions about FileAccessed and FilePreviewed events

Can non-user activities trigger FilePreviewed audit records that include a user agent like "OneDriveMpc-Transform_Thumbnail"?

There are no known scenarios where non-user actions generate events like these. User actions like opening a user profile card (by selecting their name or email address in a message in Outlook on the web) generate similar events.

Are calls to the OneDriveMpc-Transform_Thumbnail always intentionally triggered by the user?

No. But browser prefetch can result in similar events.

If I see a FilePreviewed event coming from a Microsoft-registered IP address, does that mean the preview shows on the screen of the user's device?

No. Browser prefetch might log the event.

Are there scenarios where a user previewing a document generates FileAccessed events?

Both the FilePreviewed and FileAccessed events indicate that a user's call led to a read of the file (or a read of a thumbnail rendering of the file). While these events are intended to align with preview versus access intention, the event distinction isn't a guarantee of the user's intent.

What causes FileAccessed audit events in Insider Risk Management scenarios?

Creating a case in Insider Risk Management and enabling Content Explorer generates and records a FileAccessed event in the audit log. In this scenario, the event is generated by the Insider Risk Management/Content Explorer workflow rather than by a direct user file-open action, and the same ApplicationId value, 92876b03-76a3-4da8-ad6a-0511ffdf8647, is used for these events. This is important for administrators because it helps distinguish these system-generated FileAccessed events from other FileAccessed activity during an investigation. You can use the ApplicationId field as one of the properties to help identify or filter these specific events when reviewing audit log results.

The app@sharepoint user in audit records

In audit records for some file activities (and other SharePoint-related activities), you might notice the user who performed the activity (identified in the User and UserId fields) is app@sharepoint. This user means that an application performed the activity. In this case, the application was granted permissions in SharePoint to perform organization-wide actions (such as searching a SharePoint site or OneDrive account) on behalf of a user, admin, or service. This process of giving permissions to an application is called SharePoint App-Only access. This user means that an application, instead of a user, presented the authentication to SharePoint to perform an action. This is why the app@sharepoint user is identified in certain audit records. For more information, see Grant access using SharePoint App-Only.

For example, app@sharepoint is often identified as the user for "Performed search query" and "Accessed file" events. That's because an application with SharePoint App-Only access in your organization performs search queries and accesses files when applying retention policies to sites and OneDrive accounts.

Here are a few other scenarios where app@sharepoint might be identified in an audit record as the user who performed an activity:

  • Microsoft 365 Groups. When a user or admin creates a new group, audit records are generated for creating a site collection, updating lists, and adding members to a SharePoint group. An application performs these tasks on behalf of the user who created the group.
  • Microsoft Teams. Similar to Microsoft 365 Groups, audit records are generated for creating a site collection, updating lists, and adding members to a SharePoint group when a team is created.
  • Compliance features. When an admin implements compliance features, such as retention policies, eDiscovery holds, and autoapplying sensitivity labels.

In these and other scenarios, you might also notice that multiple audit records with app@sharepoint as the specified user were created within a short time frame, often within a few seconds of each other. This pattern also means they were probably triggered by the same user-initiated task. Also, the ApplicationDisplayName and EventData fields in the audit record might help you identify the scenario or application that triggered the event.

Folder activities

The following table lists the folder activities in SharePoint and OneDrive recorded in the Microsoft 365 audit log. Audit records for some SharePoint activities indicate the app@sharepoint user performed the activity on behalf of the user or admin who initiated the action. For more information, see The app@sharepoint user in audit records.

Friendly name Operation Description
Copied folder FolderCopied User copies a folder from a site to another location in SharePoint or OneDrive.
Created folder FolderCreated User creates a folder on a site.
Deleted folder FolderDeleted User deletes a folder from a site.
Deleted folder from recycle bin FolderDeletedFirstStageRecycleBin User deletes a folder from the recycle bin on a site.
Deleted folder from second-stage recycle bin FolderDeletedSecondStageRecycleBin User deletes a folder from the second-stage recycle bin on a site.
Modified folder FolderModified User modifies a folder on a site. This action includes changing the folder metadata, such as changing tags and properties.
Moved folder FolderMoved User moves a folder to a different location on a site.
Renamed folder FolderRenamed User renames a folder on a site.
Restored folder FolderRestored User restores a deleted folder from the recycle bin on a site.

Forms activities

The following table lists the user and admin activities in Microsoft Forms that the Microsoft 365 audit log records. Microsoft Forms is a forms, quiz, and survey tool you can use to collect data for analysis. Some operations include additional activity parameters, as noted in the descriptions.

If a coauthor or an anonymous responder performs a Forms activity, the audit log records it slightly differently. For more information, see the Forms activities performed by coauthors and anonymous responders section.

Friendly name Operation Description
Added form coauthor AddFormCoauthor A user uses a collaboration link to help design the form or view responses. This event is logged when a user uses a collaboration URL (not when the collaboration URL is first generated).
Added specific responder AddSpecificResponder Form owner adds a new user or group to the specific responders list.
Allowed share form for copy AllowShareFormForCopy Form owner creates a template link to share the form with other users. This event is logged when the form owner selects to generate the template URL.
Connected to Excel workbook ConnectToExcelWorkbook Connected the form to an Excel workbook.

Property ExcelWorkbookLink:string is the associated Excel workbook ID of the current form.
Created a collection CollectionCreated Form owner created a collection.
Created comment CreateComment Form owner adds comment or score to a quiz.
Created form CreateForm Form owner creates a new form.

Property DataMode:string is the current form is set to sync with a new or existing Excel workbook if the property value equals DataSync. Property ExcelWorkbookLink:string is the associated Excel workbook ID of the current form.
Created response CreateResponse Similar to receiving a new response. A user submitted a response to a form.

Property ResponseId:string and Property ResponderId:string is which result is being viewed.

For an anonymous responder, the ResponderId property is null.
Created summary link GetSummaryLink Form owner creates summary results link to share results.
Deleted all responses DeleteAllResponses Form owner deletes all response data.
Deleted collection from the Recycle Bin CollectionHardDeleted Form owner hard-deleted a collection from the Recycle Bin.
Deleted form DeleteForm Form owner deletes a form. This action includes SoftDelete (delete option used and form moved to recycle bin) and HardDelete (Recycle bin is emptied).
Deleted Response DeleteResponse Form owner deletes one response.

Property ResponseId:string is the response being deleted.
Deleted summary link DeleteSummaryLink Form owner deletes summary results link.
Disabled anyone can respond setting DisallowAnonymousResponse Form owner turns off the setting allowing anyone to respond to the form.
Disabled collaboration DisableCollaboration Form owner turns off the setting of collaboration on the form.
Disabled specific people can respond setting DisableSpecificResponse Form owner turns off the setting allowing only specific people or specific groups in the current organization to respond to the form.
Disallowed share form for copy DisallowShareFormForCopy Form owner deletes template link.
Edited form EditForm Form owner edits a form such as creating, removing, or editing a question. The property EditOperation:string is the edit operation name. The possible operations are:
- CreateQuestion
- CreateQuestionChoice
- DeleteQuestion
- DeleteQuestionChoice
- DeleteFormImage
- DeleteQuestionImage
- UpdateQuestion
- UpdateQuestionChoice
- UploadFormImage/Bing/Onedrive
- UploadQuestionImage
- ChangeTheme

FormImage includes any place within Forms where the user can upload an image, such as in a query or as a background theme.
Enabled anyone can respond setting AllowAnonymousResponse Form owner turns on the setting allowing anyone to respond to the form.
Enabled Office 365 work or school account collaboration EnableWorkOrSchoolCollaboration Form owner turns on the setting allowing users with a Microsoft 365 work or school account to view and edit the form.
Enabled people in my organization collaboration EnableSameOrgCollaboration Form owner turns on the setting allowing users in the current organization to view and edit the form.
Enabled specific people can respond setting EnableSpecificResponse Form owner turns on the setting allowing only specific people or specific groups in the current organization to respond to the form.
Enabled specific people collaboration EnableSpecificCollaboaration Form owner turns on the setting allowing only specific people or specific groups in the current organization to view and edit the form.
Exported form ExportForm Form owner exports results to Excel.

Property ExportFormat:string is if the Excel file is Download or Online.
Listed forms ListForms Form owner is viewing a list of forms.

Property ViewType:string is which view the form owner is looking at: All Forms, Shared with Me, or Group Forms.
Moved a form into collection MovedFormIntoCollection Form owner moved a form into a collection.
Moved a form out of collection MovedFormOutofCollection Form owner moved a form out of a collection.
Moved collection to the Recycle Bin CollectionSoftDeleted Form owner moved a collection to the Recycle Bin.
Moved form MoveForm Form owner moves a form.

Property DestinationUserId:string is the user ID of the person who moved the form. Property NewFormId:string is the new ID for the newly copied form. Property IsDelegateAccess:boolean is the current form move action is performed through the admin delegate page.
Previewed form PreviewForm Form owner previews a form by using the Preview function.
Removed form coauthor RemoveFormCoauthor Form owner deletes a collaboration link.
Removed specific responder RemoveSpecificResponder Form owner removes a user or group from the specific responders list.
Renamed a collection CollectionRenamed Form owner changed the name of a collection.
Sent Forms Pro invitation ProInvitation User selects to activate a Pro trial.
Submitted response SubmitResponse A user submits a response to a form.

Property IsInternalForm:boolean is if the responder is within the same organization as the form owner.
Updated a collection CollectionUpdated Form owner updated a collection property.
Updated form phishing status UpdatePhishingStatus This event is logged whenever the detailed value for the internal security status changes, regardless of whether this change affects the final security state (for example, form is now Closed or Opened). This change might result in duplicate events without a final security state change. The possible status values for this event are:
- Take Down
- Take Down by Admin
- Admin Unblocked
- Auto Blocked
- Auto Unblocked
- Customer Reported
- Reset Customer Reported.
Updated form setting UpdateFormSetting Form owner updates one or multiple form settings.

Property FormSettingName:string is updated sensitive settings' name. Property NewFormSettings:string is updated settings' name and new value. Property thankYouMessageContainsLink:boolean is updated thank-you message contains a URL link.
Updated response UpdateResponse Form owner updated a comment or score on a quiz.

Property ResponseId:string and Property ResponderId:string is which result is being viewed.

For an anonymous responder, the ResponderId property is null.
Updated user phishing status UpdateUserPhishingStatus This event is logged whenever the value for the user security status changes. The value of the user status in the audit record is Confirmed as Phisher when the user created a phishing form that the Microsoft Online safety team took down. If an admin unblocks the user, the value of the user's status is set to Reset as Normal User.
Updated user setting UpdateUserSetting Form owner updates a user setting.

Property UserSettingName:string is the setting's name and new value.
Viewed form (design time) ViewForm Form owner opens an existing form for editing.

Property AccessDenied:boolean is access of current form is denied due to permission check. Property FromSummaryLink:boolean is current request comes from the summary link page.
Viewed response ViewResponse Form owner views a particular response.

Property ResponseId:string and Property ResponderId:string is which result is being viewed.

For an anonymous responder, the ResponderId property is null.
Viewed response page ViewRuntimeForm User opened a response page to view. This event is logged regardless of whether the user submits a response or not.
Viewed responses ViewResponses Form owner views the aggregated list of responses.

Property ViewType:string is whether form owner is viewing Detail or Aggregate.

Forms activities performed by coauthors and anonymous responders

Forms supports collaboration when designing forms and analyzing responses. A form collaborator is known as a coauthor. Coauthors can do everything a form owner can do, except delete or move a form. Forms also allows you to create a form that can be responded to anonymously. This means the responder doesn't have to sign in to your organization to respond to a form.

The following table lists the auditing activities and information recorded in the Microsoft 365 audit log for activities performed by coauthors and anonymous responders.

Activity type Internal or external user User ID that's logged Organization logged in to Forms user type
Coauthoring activities External urn:forms:coauthor#a0b1c2d3@forms.office.com
(The second part of the ID is a hash, which differs for different users)
Form owner's org
Coauthor
Coauthoring activities External UPN
Coauthor's org
Coauthor
Coauthoring activities Internal UPN Form owner's org Coauthor
Response activities Anonymous urn:forms:anonymous#a0b1c2d3@forms.office.com
(The second part of the User ID is a hash, which differs for different users)
Form owner's org Responder
Response activities External urn:forms:external#a0b1c2d3@forms.office.com
(The second part of the User ID is a hash, which differs for different users)
Form owner's org Responder
Response activities External UPN
Responder's org
Responder

Information barriers activities

The following table lists the activities in Information Barriers that the Microsoft 365 audit log records. For more information about Information Barriers, see Learn about Information Barriers in Microsoft 365.

Important

Microsoft recommends that you use roles with the fewest permissions. Minimizing the number of users with the Global Administrator role helps improve security for your organization. Learn more about Microsoft Purview roles and permissions.

Friendly name Operation Description
Applied information barrier mode to site SiteIBModeSet A SharePoint or global administrator applied a mode to the site.
Applied segments to site SiteIBSegmentsSet A SharePoint, global administrator, or site owner added one or more information barriers segments to a site.
Changed AppBypassInformationBarrier setting for the tenant AppBypassInformationBarrier A SharePoint or global administrator changed apps access for SharePoint sites.
Changed information barrier mode of site SiteIBModeChanged A SharePoint or global administrator updated the mode of the site.
Changed segments of site SiteIBSegmentsChanged A SharePoint or global administrator changed one or more information barriers segments for a site.
Disabled information barriers for SharePoint and OneDrive SPOIBIsDisabled A SharePoint or global administrator disabled information barriers for SharePoint and OneDrive in the organization.
Enabled information barriers for SharePoint and OneDrive SPOIBIsEnabled A SharePoint or global administrator disabled information barriers for SharePoint and OneDrive in the organization.
Information barriers insights report completed InformationBarriersInsightsReportCompleted System completes build of the information barriers insights report.
Information barriers insights report OneDrive section queried InformationBarriersInsightsReportOneDriveSectionQueried An administrator queries the information barriers insights report for OneDrive accounts.
Information barriers insights report scheduled InformationBarriersInsightsReportSchedule An administrator schedules the information barriers insights report.
Information barriers insights report SharePoint section queried InformationBarriersInsightsReportSharePointSectionQueried An administrator queries the information barriers insights report for SharePoint sites.
Removed segment from site SiteIBSegmentsRemoved A SharePoint or global administrator removes one or more information barriers segments from a site.

Microsoft 365 Admin Center Agent Management activities

The following table lists Agent Management activities that the Microsoft 365 audit log records. For more information, see Manage Microsoft 365 Copilot agents in the Microsoft 365 admin center.

Friendly name Operation Description
Blocked Agent BlockedAgent An admin blocked an agent. Users in the organization can't use the agent.
Deleted Agent DeletedAgent An admin deleted a shared agent that deletes the underlying files and the agent.
Deployed Agent DeployedAgent An admin deployed an agent. The agent becomes active and usable for specific users, groups, or the entire organization.
Removed Agent RemovedAgent An admin removed a previously installed agent for the whole organization or for specific users and groups.
Unblocked Agent UnblockedAgent An admin unblocked a previously blocked agent.
Updated Agent UpdatedAgent An admin updated a custom agent by uploading the latest manifest file.
Updated Tenant-level Agent Settings UpdatedTenantSettings An admin updated tenant level settings that apply to agents.

Microsoft 365 Apps Admin Services cloud policy activities

The following table lists the activities for policy configuration changes in the Cloud Policy service that the Microsoft 365 audit log records.

Friendly name Operation Description
Created policy configuration CreatedPolicyConfig A new policy configuration was created.
Deleted policy configuration DeletedPolicyConfig A policy configuration was deleted.
Updated policy configuration UpdatedPolicyConfig An existing policy configuration was updated, for example by adding, changing, or removing policy settings, or by changing the policy configuration's name, description, or scope.
Updated policy configuration priority UpdatedPolicyConfigPriority The priority of a policy configuration was changed.

Microsoft 365 Apps Admin Services cloud update activities

The following table lists the activities for configuration changes and triggered actions in the Cloud Update service that the Microsoft 365 audit log records.

Friendly name Operation Description
Device configuration updated updateddeviceconfiguration An action for a device managed by Cloud Update was triggered. This action includes triggering a rollback, resuming a rolled back device, or changing the update channel.
Profile configuration updated updatedprofileconfiguration A Cloud Update profile's configuration changed. This change includes updates to the profile's state, set deadline, Update Validation enablement, and configured waves and wave delay.
Tenant configuration updated updatedtenantconfiguration The Cloud Update's organization-wide configuration changed. This change includes updates to exclusions, exclusion windows, and generating a new Tenant Association Key (TAK).

Microsoft 365 Backup activities

The following table lists the activities in Microsoft 365 Backup that the Microsoft 365 audit log records. Microsoft 365 Backup is designed to ensure your organization's data is always protected and easily recoverable. For more information about Microsoft 365 Backup, see Overview of Microsoft 365 Backup.

Friendly name Operation Description
Activated a Backup Policy BackupPolicyActivated A Microsoft 365 Backup policy is activated from an inactive state.
Activated Draft Restore Task RestoreTaskActivated A draft restore task for Microsoft 365 Backup is activated. This is a long running operation.
Backup Item Created BackupItemAdded One or more backup items are added to a Microsoft 365 Backup policy.
Backup Item Removed BackupItemRemoved One or more backup items are removed from a Microsoft 365 Backup policy.
Browsed Site for Restore SiteBrowsedForRestore A site was browsed in Microsoft 365 Backup to identify and select items for granular restore.
Cancel Offboard Backup Item CancelOffboardBackupItem Offboarding canceled for a backup item.
Completed Granular Restore for Backup Item BackupItemGranularRestoreCompleted A granular restore for one or more backup items is completed in Microsoft 365 Backup.
Completed Granular Restore Session GranularRestoreSessionCompleted A granular restore session is completed in Microsoft 365 Backup.
Completed Restore Task RestoreTaskCompleted A restore task is completed in Microsoft 365 Backup.
Created Draft Restore Task DraftRestoreTaskCreated A restore task is created in Microsoft 365 Backup. By default, the restore task is created as draft.
Created Granular Browse Session GranularBrowseSessionCreated A granular browse session is created in Microsoft 365 Backup to enable browsing of backed-up content for item-level restore.
Created Granular Restore Session GranularRestoreSessionCreated A granular restore session is created in Microsoft 365 Backup.
Created new Backup policy NewBackupPolicyCreated A new Microsoft 365 Backup policy was created by a Global Admin. By default, a backup policy is created in an inactive state.
Deleted a Backup Policy BackupPolicyDeleted A Microsoft 365 Backup policy is deleted.
Deleted Draft Restore Task DraftRestoreTaskDeleted A draft restore task is deleted in Microsoft 365 Backup.
Edited a Backup Policy BackupPolicyEdited A Microsoft 365 Backup policy was updated. You can update a backup policy by performing any of the following actions:

1. Renaming the policy.
2. Add one or more protection units.
3. Removing one or more protection units.
Edited Draft Restore Task DraftRestoreTaskEdited A draft restore task is edited in Microsoft 365 Backup.
Offboard Backup Item OffboardBackupItem Backup item is offboarding.
Paused a Backup Policy BackupPolicyPaused A Microsoft 365 Backup policy is paused from active state.
Programmatically got Backup Item GetBackupItem User requests the protection unit backed up using Microsoft 365 Backup programmatically.
Programmatically got Details of Backup Policy ViewBackupPolicyDetails Details of a Microsoft 365 Backup policy are accessed programmatically.
Programmatically got Details of Restore Task GetRestoreTaskDetails A user requests details of restore task by its identifier in Microsoft 365 Backup.
Programmatically got list of all Backup Policies ListAllBackupPolicies A user programmatically gets the list of all backup policies backed up using Microsoft 365 Backup.
Programmatically got list of Backup Items in Backup Policies ListAllBackupItemsInPolicies A list of all protection units present in a backup policy in Microsoft 365 Backup is requested programmatically.
Programmatically got list of Backup Items in Tenant ListAllBackupItemsInTenant A user programmatically gets list of all protection units in the organization backed up using Microsoft 365 Backup.
Programmatically got list of Backup Items in Workload ListAllBackupItemsInWorkload A user programmatically gets list of all protection units in workload (SharePoint, OneDrive, or Exchange) backed up using Microsoft 365 Backup.
Programmatically got list of Restore Items in Restore Task GetAllRestoreArtifactsInTask A user programmatically gets all artifacts in a restore task in Microsoft 365 Backup.
Programmatically got list of Restore Points ListAllRestorePoints A user programmatically gets all restore points in Microsoft 365 Backup. Restore Points represent the timestamp when an artifact is protected (per Protection Policy). Only Global Admins have access.