Skip to main content

Microsoft 365 Unified Audit Logs connector reference

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Microsoft 365 Unified Audit Logs from the Previews page. See Manage Databricks previews.

The managed Microsoft 365 Unified Audit Logs connector supports five unified audit log source tables. This reference lists the tables, destination table schemas, connection options, subscription plans, and Microsoft 365 permissions.

Supported source tables​

The Microsoft 365 Unified Audit Logs connector supports the following source tables in the default source schema. All five tables use lw_id as the primary key, use incremental sync, and use time as the cursor field.

Source table

Primary key

Description

Microsoft Management Activity API content type

Sync mode

Cursor field

audit_azure_active_directory

lw_id

Microsoft Entra ID events, including sign-ins, application access, and directory changes.

Audit.AzureActiveDirectory

Incremental

time

audit_exchange

lw_id

Exchange events, including mailbox, folder, and item operations.

Audit.Exchange

Incremental

time

audit_sharepoint

lw_id

SharePoint and OneDrive events, including file, folder, sharing, and site operations.

Audit.SharePoint

Incremental

time

audit_general

lw_id

Microsoft 365 audit events that are not included in the other workload-specific content types.

Audit.General

Incremental

time

dlp_all

lw_id

Data loss prevention events across supported Microsoft 365 workloads.

DLP.All

Incremental

time

Source table

Primary key

Description

Microsoft Management Activity API content type

Sync mode

Cursor field

audit_azure_active_directory

lw_id

Microsoft Entra ID events, including sign-ins, application access, and directory changes.

Audit.AzureActiveDirectory

Incremental

time

audit_exchange

lw_id

Exchange events, including mailbox, folder, and item operations.

Audit.Exchange

Incremental

time

audit_sharepoint

lw_id

SharePoint and OneDrive events, including file, folder, sharing, and site operations.

Audit.SharePoint

Incremental

time

audit_general

lw_id

Microsoft 365 audit events that are not included in the other workload-specific content types.

Audit.General

Incremental

time

dlp_all

lw_id

Data loss prevention events across supported Microsoft 365 workloads.

DLP.All

Incremental

time

For field definitions and workload-specific event schemas, see the Microsoft 365 Management Activity API schema. Microsoft can add fields and event types to these source payloads.

Use the following source names in a pipeline definition:

YAML
objects:
- table:
source_schema: 'default'
source_table: 'audit_azure_active_directory'
- table:
source_schema: 'default'
source_table: 'audit_exchange'
- table:
source_schema: 'default'
source_table: 'audit_sharepoint'
- table:
source_schema: 'default'
source_table: 'audit_general'
- table:
source_schema: 'default'
source_table: 'dlp_all'

For a complete pipeline definition, see Examples.

Destination table schemas​

All tables use lw_id as the primary key and time as the cursor field. Each destination table also includes the source fields that Microsoft returns for its content type. Microsoft can add fields and event types to these source payloads, so for the complete, authoritative field list, see the Microsoft 365 Management Activity API schema.

audit_azure_active_directory​

Primary key: lw_id Cursor field: time

Field

Data type

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

AzureActiveDirectoryEventType

INT

ExtendedProperties

ARRAY<STRUCT<Name: STRING, Value: STRING>>

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

DeviceProperties

ARRAY<STRUCT<Name: STRING, Value: STRING>>

Application

STRING

Client

STRING

LoginStatus

INT

UserDomain

STRING

Actor

ARRAY<STRUCT<ID: STRING, Type: INT>>

ActorContextId

STRING

ActorIpAddress

STRING

InterSystemsId

STRING

IntraSystemId

STRING

SupportTicketId

STRING

Target

ARRAY<STRUCT<ID: STRING, Type: INT>>

TargetContextId

STRING

ApplicationId

STRING

ErrorNumber

STRING

LogonError

STRING

Field

Data type

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

AzureActiveDirectoryEventType

INT

ExtendedProperties

ARRAY<STRUCT<Name: STRING, Value: STRING>>

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

DeviceProperties

ARRAY<STRUCT<Name: STRING, Value: STRING>>

Application

STRING

Client

STRING

LoginStatus

INT

UserDomain

STRING

Actor

ARRAY<STRUCT<ID: STRING, Type: INT>>

ActorContextId

STRING

ActorIpAddress

STRING

InterSystemsId

STRING

IntraSystemId

STRING

SupportTicketId

STRING

Target

ARRAY<STRUCT<ID: STRING, Type: INT>>

TargetContextId

STRING

ApplicationId

STRING

ErrorNumber

STRING

LogonError

STRING

audit_exchange​

Primary key: lw_id Cursor field: time

Field

Data type

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

ModifiedObjectResolvedName

STRING

Parameters

ARRAY<STRUCT<Name: STRING, Value: STRING>>

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

ExternalAccess

BOOLEAN

OriginatingServer

STRING

OrganizationName

STRING

LogonType

INT

InternalLogonType

INT

MailboxGuid

STRING

MailboxOwnerUPN

STRING

MailboxOwnerSid

STRING

MailboxOwnerMasterAccountSid

STRING

LogonUserSid

STRING

LogonUserDisplayName

STRING

ClientInfoString

STRING

ClientIPAddress

STRING

ClientMachineName

STRING

ClientProcessName

STRING

ClientVersion

STRING

Folder

STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>

CrossMailboxOperations

BOOLEAN

DestMailboxId

STRING

DestMailboxOwnerUPN

STRING

DestMailboxOwnerSid

STRING

DestMailboxOwnerMasterAccountSid

STRING

DestFolder

STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>

Folders

ARRAY<STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>>

AffectedItems

ARRAY<STRUCT<Id: STRING, Subject: STRING, ParentFolder: STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>, Attachments: STRING>>

Item

STRUCT<Id: STRING, Subject: STRING, ParentFolder: STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>, Attachments: STRING>

SendAsUserSmtp

STRING

SendAsUserMailboxGuid

STRING

SendOnBehalfOfUserSmtp

STRING

SendOnBehalfOfUserMailboxGuid

STRING

Field

Data type

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

ModifiedObjectResolvedName

STRING

Parameters

ARRAY<STRUCT<Name: STRING, Value: STRING>>

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

ExternalAccess

BOOLEAN

OriginatingServer

STRING

OrganizationName

STRING

LogonType

INT

InternalLogonType

INT

MailboxGuid

STRING

MailboxOwnerUPN

STRING

MailboxOwnerSid

STRING

MailboxOwnerMasterAccountSid

STRING

LogonUserSid

STRING

LogonUserDisplayName

STRING

ClientInfoString

STRING

ClientIPAddress

STRING

ClientMachineName

STRING

ClientProcessName

STRING

ClientVersion

STRING

Folder

STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>

CrossMailboxOperations

BOOLEAN

DestMailboxId

STRING

DestMailboxOwnerUPN

STRING

DestMailboxOwnerSid

STRING

DestMailboxOwnerMasterAccountSid

STRING

DestFolder

STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>

Folders

ARRAY<STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>>

AffectedItems

ARRAY<STRUCT<Id: STRING, Subject: STRING, ParentFolder: STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>, Attachments: STRING>>

Item

STRUCT<Id: STRING, Subject: STRING, ParentFolder: STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>, Attachments: STRING>

SendAsUserSmtp

STRING

SendAsUserMailboxGuid

STRING

SendOnBehalfOfUserSmtp

STRING

SendOnBehalfOfUserMailboxGuid

STRING

audit_sharepoint​

Primary key: lw_id Cursor field: time

Field

Data type

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

Site

STRING

ItemType

STRING

EventSource

STRING

SourceName

STRING

UserAgent

STRING

MachineDomainInfo

STRING

MachineId

STRING

ListItemUniqueId

STRING

ListId

STRING

ApplicationId

STRING

ApplicationDisplayName

STRING

IsWorkflow

BOOLEAN

SiteUrl

STRING

SourceRelativeUrl

STRING

SourceFileName

STRING

SourceFileExtension

STRING

DestinationRelativeUrl

STRING

DestinationFileName

STRING

DestinationFileExtension

STRING

UserSharedWith

STRING

SharingType

STRING

SourceLabel

STRING

DestinationLabel

STRING

SensitivityLabelOwnerEmail

STRING

SensitivityLabelId

STRING

ListTitle

STRING

ListName

STRING

ListUrl

STRING

ListBaseType

STRING

ListBaseTemplateType

STRING

IsHiddenList

BOOLEAN

IsDocLib

BOOLEAN

TargetUserOrGroupName

STRING

TargetUserOrGroupType

STRING

UniqueSharingId

STRING

CustomEvent

STRING

EventData

STRING

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

Field

Data type

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

Site

STRING

ItemType

STRING

EventSource

STRING

SourceName

STRING

UserAgent

STRING

MachineDomainInfo

STRING

MachineId

STRING

ListItemUniqueId

STRING

ListId

STRING

ApplicationId

STRING

ApplicationDisplayName

STRING

IsWorkflow

BOOLEAN

SiteUrl

STRING

SourceRelativeUrl

STRING

SourceFileName

STRING

SourceFileExtension

STRING

DestinationRelativeUrl

STRING

DestinationFileName

STRING

DestinationFileExtension

STRING

UserSharedWith

STRING

SharingType

STRING

SourceLabel

STRING

DestinationLabel

STRING

SensitivityLabelOwnerEmail

STRING

SensitivityLabelId

STRING

ListTitle

STRING

ListName

STRING

ListUrl

STRING

ListBaseType

STRING

ListBaseTemplateType

STRING

IsHiddenList

BOOLEAN

IsDocLib

BOOLEAN

TargetUserOrGroupName

STRING

TargetUserOrGroupType

STRING

UniqueSharingId

STRING

CustomEvent

STRING

EventData

STRING

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

audit_general​

Primary key: lw_id Cursor field: time

Field

Data type

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

payload

VARIANT

Field

Data type

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

payload

VARIANT

dlp_all​

Primary key: lw_id Cursor field: time

Field

Data type

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

SharePointMetaData

STRUCT<From: STRING, itemCreationTime: TIMESTAMP, SiteCollectionGuid: STRING, SiteCollectionUrl: STRING, FileName: STRING, FileOwner: STRING, FilePathUrl: STRING, DocumentLastModifier: STRING, DocumentSharer: STRING, UniqueId: STRING, LastModifiedTime: TIMESTAMP, IsViewableByExternalUsers: BOOLEAN>

ExchangeMetaData

STRUCT<MessageID: STRING, From: STRING, To: ARRAY<STRING>, CC: ARRAY<STRING>, BCC: ARRAY<STRING>, Subject: STRING, Sent: TIMESTAMP, RecipientCount: INT>

EndPointMetaData

STRUCT<SensitiveInformation: ARRAY<STRUCT<Confidence: INT, Count: INT, Location: STRING, SensitiveType: STRING, SensitiveInformationDetections: STRUCT<DetectedValues: ARRAY<STRUCT<Name: STRING, Value: STRING>>, ResultsTruncated: BOOLEAN>, SensitiveInformationDetailedClassificationAttributes: ARRAY<STRUCT<Confidence: INT, Count: INT, IsMatch: BOOLEAN>>, SensitiveInformationTypeName: STRING, UniqueCount: INT>>, EnforcementMode: STRING, FileExtension: STRING, FileType: STRING, DeviceName: STRING>

ExceptionInfo

STRING

PolicyDetails

ARRAY<STRUCT<PolicyId: STRING, PolicyName: STRING, Rules: ARRAY<STRUCT<RuleId: STRING, RuleName: STRING, Actions: ARRAY<STRING>, OverriddenActions: ARRAY<STRING>, Severity: STRING, RuleMode: STRING, ConditionsMatched: STRUCT<SensitiveInformation: ARRAY<STRUCT<Confidence: INT, Count: INT, Location: STRING, SensitiveType: STRING, SensitiveInformationDetections: STRUCT<DetectedValues: ARRAY<STRUCT<Name: STRING, Value: STRING>>, ResultsTruncated: BOOLEAN>, SensitiveInformationDetailedClassificationAttributes: ARRAY<STRUCT<Confidence: INT, Count: INT, IsMatch: BOOLEAN>>, SensitiveInformationTypeName: STRING, UniqueCount: INT>>, DocumentProperties: ARRAY<STRUCT<Name: STRING, Value: STRING>>, OtherConditions: ARRAY<STRUCT<Name: STRING, Value: STRING>>>>>>>

SensitiveInfoDetectionIsIncluded

BOOLEAN

Field

Data type

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

SharePointMetaData

STRUCT<From: STRING, itemCreationTime: TIMESTAMP, SiteCollectionGuid: STRING, SiteCollectionUrl: STRING, FileName: STRING, FileOwner: STRING, FilePathUrl: STRING, DocumentLastModifier: STRING, DocumentSharer: STRING, UniqueId: STRING, LastModifiedTime: TIMESTAMP, IsViewableByExternalUsers: BOOLEAN>

ExchangeMetaData

STRUCT<MessageID: STRING, From: STRING, To: ARRAY<STRING>, CC: ARRAY<STRING>, BCC: ARRAY<STRING>, Subject: STRING, Sent: TIMESTAMP, RecipientCount: INT>

EndPointMetaData

STRUCT<SensitiveInformation: ARRAY<STRUCT<Confidence: INT, Count: INT, Location: STRING, SensitiveType: STRING, SensitiveInformationDetections: STRUCT<DetectedValues: ARRAY<STRUCT<Name: STRING, Value: STRING>>, ResultsTruncated: BOOLEAN>, SensitiveInformationDetailedClassificationAttributes: ARRAY<STRUCT<Confidence: INT, Count: INT, IsMatch: BOOLEAN>>, SensitiveInformationTypeName: STRING, UniqueCount: INT>>, EnforcementMode: STRING, FileExtension: STRING, FileType: STRING, DeviceName: STRING>

ExceptionInfo

STRING

PolicyDetails

ARRAY<STRUCT<PolicyId: STRING, PolicyName: STRING, Rules: ARRAY<STRUCT<RuleId: STRING, RuleName: STRING, Actions: ARRAY<STRING>, OverriddenActions: ARRAY<STRING>, Severity: STRING, RuleMode: STRING, ConditionsMatched: STRUCT<SensitiveInformation: ARRAY<STRUCT<Confidence: INT, Count: INT, Location: STRING, SensitiveType: STRING, SensitiveInformationDetections: STRUCT<DetectedValues: ARRAY<STRUCT<Name: STRING, Value: STRING>>, ResultsTruncated: BOOLEAN>, SensitiveInformationDetailedClassificationAttributes: ARRAY<STRUCT<Confidence: INT, Count: INT, IsMatch: BOOLEAN>>, SensitiveInformationTypeName: STRING, UniqueCount: INT>>, DocumentProperties: ARRAY<STRUCT<Name: STRING, Value: STRING>>, OtherConditions: ARRAY<STRUCT<Name: STRING, Value: STRING>>>>>>>

SensitiveInfoDetectionIsIncluded

BOOLEAN

Connection options​

Option

Type

Required

Description

tenant_id

String

Yes

The Directory (tenant) ID of the Microsoft Entra tenant.

client_id

String

Yes

The Application (client) ID of the registered Microsoft Entra application.

client_secret

String

Yes

The client secret value for the registered application.

subscription_plan

String

Yes

The Microsoft cloud environment for the tenant. Catalog Explorer initially selects enterprise.

Option

Type

Required

Description

tenant_id

String

Yes

The Directory (tenant) ID of the Microsoft Entra tenant.

client_id

String

Yes

The Application (client) ID of the registered Microsoft Entra application.

client_secret

String

Yes

The client secret value for the registered application.

subscription_plan

String

Yes

The Microsoft cloud environment for the tenant. Catalog Explorer initially selects enterprise.

Subscription plans​

Display name

Value

Management Activity API host

Enterprise

enterprise

manage.office.com

Government GCC

gcc

manage-gcc.office.com

Government GCC High

gcc_high

manage.office365.us

Government DoD

dod

manage.protection.apps.mil

Display name

Value

Management Activity API host

Enterprise

enterprise

manage.office.com

Government GCC

gcc

manage-gcc.office.com

Government GCC High

gcc_high

manage.office365.us

Government DoD

dod

manage.protection.apps.mil

Required Microsoft 365 permissions​

Permission

Type

Required for

ActivityFeed.Read

Application

Reading Audit.AzureActiveDirectory, Audit.Exchange, Audit.SharePoint, and Audit.General content.

ActivityFeed.ReadDlp

Application

Reading DLP.All content for the dlp_all source table.

Permission

Type

Required for

ActivityFeed.Read

Application

Reading Audit.AzureActiveDirectory, Audit.Exchange, Audit.SharePoint, and Audit.General content.

ActivityFeed.ReadDlp

Application

Reading DLP.All content for the dlp_all source table.

An administrator must grant tenant-wide consent for these permissions. The connector doesn't use delegated permissions.