Aller au contenu principal

Référence du connecteur Microsoft 365 Unified Audit Logs

info

Bêta

Cette fonctionnalité est en version bêta. Pour l’utiliser, un administrateur du workspace doit activer Lakeflow Connect pour Microsoft 365 Unified Audit Logs à partir de la page Previews . Consultez Gérer les aperçus Databricks.

Le connecteur géré Microsoft 365 Unified Audit Logs prend en charge cinq tables source de Logs unifié. Cette référence répertorie les tables, les schémas de table de destination, les options de connexion, les abonnements et les autorisations Microsoft 365.

Supported source tables​

Le connecteur Microsoft 365 Unified Audit Logs prend en charge les tables sources suivantes dans le schéma source default. Les cinq tables utilisent lw_id comme clé primaire, utilisent une synchronisation incrémentielle et utilisent time comme champ de curseur.

Table source

Clé primaire

Description

Type de contenu de l'API Microsoft Management Activity

Mode de synchronisation

Champ de curseur

audit_azure_active_directory

lw_id

Événements de Microsoft Entra ID, notamment les connexions, l'accès aux applications et les modifications de l'annuaire.

Audit.AzureActiveDirectory

Incrémentiel

time

audit_exchange

lw_id

Événements Exchange, y compris les opérations sur les boîtes aux lettres, les dossiers et les éléments.

Audit.Exchange

Incrémentiel

time

audit_sharepoint

lw_id

Événements SharePoint et OneDrive, y compris les opérations sur les fichiers, les dossiers, le partage et les sites.

Audit.SharePoint

Incrémentiel

time

audit_general

lw_id

Événements d’audit Microsoft 365 qui ne sont pas inclus dans les autres types de contenu spécifiques aux charges de travail.

Audit.General

Incrémentiel

time

dlp_all

lw_id

Événements de prévention de la perte de données sur les charges de travail Microsoft 365 prises en charge.

DLP.All

Incrémentiel

time

Table source

Clé primaire

Description

Type de contenu de l'API Microsoft Management Activity

Mode de synchronisation

Champ de curseur

audit_azure_active_directory

lw_id

Événements de Microsoft Entra ID, notamment les connexions, l'accès aux applications et les modifications de l'annuaire.

Audit.AzureActiveDirectory

Incrémentiel

time

audit_exchange

lw_id

Événements Exchange, y compris les opérations sur les boîtes aux lettres, les dossiers et les éléments.

Audit.Exchange

Incrémentiel

time

audit_sharepoint

lw_id

Événements SharePoint et OneDrive, y compris les opérations sur les fichiers, les dossiers, le partage et les sites.

Audit.SharePoint

Incrémentiel

time

audit_general

lw_id

Événements d’audit Microsoft 365 qui ne sont pas inclus dans les autres types de contenu spécifiques aux charges de travail.

Audit.General

Incrémentiel

time

dlp_all

lw_id

Événements de prévention de la perte de données sur les charges de travail Microsoft 365 prises en charge.

DLP.All

Incrémentiel

time

Pour connaître les définitions de champs et les schémas d’événements spécifiques à une charge de travail, consultez le schéma de l’API Microsoft 365 Management Activity. Microsoft peut ajouter des champs et des types d'événements à ces charges utiles de source.

Utilisez les noms de source suivants dans une définition de pipeline :

YAML
objects:
- table:
source_schema: 'default'
source_table: 'audit_azure_active_directory'
- table:
source_schema: 'default'
source_table: 'audit_exchange'
- table:
source_schema: 'default'
source_table: 'audit_sharepoint'
- table:
source_schema: 'default'
source_table: 'audit_general'
- table:
source_schema: 'default'
source_table: 'dlp_all'

Pour obtenir une définition de pipeline complète, consultez les Exemples.

Schémas de table de destination​

Toutes les tables utilisent lw_id comme clé primaire et time comme champ de curseur. Chaque table de destination inclut également les champs sources renvoyés par Microsoft pour son type de contenu. Microsoft peut ajouter des champs et des types d’événements à ces charges utiles sources. Pour consulter la liste complète et officielle des champs, reportez-vous au schéma de l’API Microsoft 365 Management Activity.

audit_azure_active_directory​

Clé principale : lw_id Champ de curseur : time

Champ

Type de données

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

AzureActiveDirectoryEventType

INT

ExtendedProperties

ARRAY<STRUCT<Name: STRING, Value: STRING>>

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

DeviceProperties

ARRAY<STRUCT<Name: STRING, Value: STRING>>

Application

STRING

Client

STRING

LoginStatus

INT

UserDomain

STRING

Actor

ARRAY<STRUCT<ID: STRING, Type: INT>>

ActorContextId

STRING

ActorIpAddress

STRING

InterSystemsId

STRING

IntraSystemId

STRING

SupportTicketId

STRING

Target

ARRAY<STRUCT<ID: STRING, Type: INT>>

TargetContextId

STRING

ApplicationId

STRING

ErrorNumber

STRING

LogonError

STRING

Champ

Type de données

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

AzureActiveDirectoryEventType

INT

ExtendedProperties

ARRAY<STRUCT<Name: STRING, Value: STRING>>

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

DeviceProperties

ARRAY<STRUCT<Name: STRING, Value: STRING>>

Application

STRING

Client

STRING

LoginStatus

INT

UserDomain

STRING

Actor

ARRAY<STRUCT<ID: STRING, Type: INT>>

ActorContextId

STRING

ActorIpAddress

STRING

InterSystemsId

STRING

IntraSystemId

STRING

SupportTicketId

STRING

Target

ARRAY<STRUCT<ID: STRING, Type: INT>>

TargetContextId

STRING

ApplicationId

STRING

ErrorNumber

STRING

LogonError

STRING

audit_exchange​

Clé principale : lw_id Champ de curseur : time

Champ

Type de données

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

ModifiedObjectResolvedName

STRING

Parameters

ARRAY<STRUCT<Name: STRING, Value: STRING>>

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

ExternalAccess

BOOLEAN

OriginatingServer

STRING

OrganizationName

STRING

LogonType

INT

InternalLogonType

INT

MailboxGuid

STRING

MailboxOwnerUPN

STRING

MailboxOwnerSid

STRING

MailboxOwnerMasterAccountSid

STRING

LogonUserSid

STRING

LogonUserDisplayName

STRING

ClientInfoString

STRING

ClientIPAddress

STRING

ClientMachineName

STRING

ClientProcessName

STRING

ClientVersion

STRING

Folder

STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>

CrossMailboxOperations

BOOLEAN

DestMailboxId

STRING

DestMailboxOwnerUPN

STRING

DestMailboxOwnerSid

STRING

DestMailboxOwnerMasterAccountSid

STRING

DestFolder

STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>

Folders

ARRAY<STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>>

AffectedItems

ARRAY<STRUCT<Id: STRING, Subject: STRING, ParentFolder: STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>, Attachments: STRING>>

Item

STRUCT<Id: STRING, Subject: STRING, ParentFolder: STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>, Attachments: STRING>

SendAsUserSmtp

STRING

SendAsUserMailboxGuid

STRING

SendOnBehalfOfUserSmtp

STRING

SendOnBehalfOfUserMailboxGuid

STRING

Champ

Type de données

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

ModifiedObjectResolvedName

STRING

Parameters

ARRAY<STRUCT<Name: STRING, Value: STRING>>

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

ExternalAccess

BOOLEAN

OriginatingServer

STRING

OrganizationName

STRING

LogonType

INT

InternalLogonType

INT

MailboxGuid

STRING

MailboxOwnerUPN

STRING

MailboxOwnerSid

STRING

MailboxOwnerMasterAccountSid

STRING

LogonUserSid

STRING

LogonUserDisplayName

STRING

ClientInfoString

STRING

ClientIPAddress

STRING

ClientMachineName

STRING

ClientProcessName

STRING

ClientVersion

STRING

Folder

STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>

CrossMailboxOperations

BOOLEAN

DestMailboxId

STRING

DestMailboxOwnerUPN

STRING

DestMailboxOwnerSid

STRING

DestMailboxOwnerMasterAccountSid

STRING

DestFolder

STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>

Folders

ARRAY<STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>>

AffectedItems

ARRAY<STRUCT<Id: STRING, Subject: STRING, ParentFolder: STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>, Attachments: STRING>>

Item

STRUCT<Id: STRING, Subject: STRING, ParentFolder: STRUCT<Id: STRING, Path: STRING, FolderItems: ARRAY<STRUCT<Id: STRING, ImmutableId: STRING, InternetMessageId: STRING, CreationTime: TIMESTAMP, Subject: STRING, SizeInBytes: BIGINT, Sensitivity: STRING, ClientRequestId: STRING, Teams: VARIANT>>>, Attachments: STRING>

SendAsUserSmtp

STRING

SendAsUserMailboxGuid

STRING

SendOnBehalfOfUserSmtp

STRING

SendOnBehalfOfUserMailboxGuid

STRING

audit_sharepoint​

Clé principale : lw_id Champ de curseur : time

Champ

Type de données

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

Site

STRING

ItemType

STRING

EventSource

STRING

SourceName

STRING

UserAgent

STRING

MachineDomainInfo

STRING

MachineId

STRING

ListItemUniqueId

STRING

ListId

STRING

ApplicationId

STRING

ApplicationDisplayName

STRING

IsWorkflow

BOOLEAN

SiteUrl

STRING

SourceRelativeUrl

STRING

SourceFileName

STRING

SourceFileExtension

STRING

DestinationRelativeUrl

STRING

DestinationFileName

STRING

DestinationFileExtension

STRING

UserSharedWith

STRING

SharingType

STRING

SourceLabel

STRING

DestinationLabel

STRING

SensitivityLabelOwnerEmail

STRING

SensitivityLabelId

STRING

ListTitle

STRING

ListName

STRING

ListUrl

STRING

ListBaseType

STRING

ListBaseTemplateType

STRING

IsHiddenList

BOOLEAN

IsDocLib

BOOLEAN

TargetUserOrGroupName

STRING

TargetUserOrGroupType

STRING

UniqueSharingId

STRING

CustomEvent

STRING

EventData

STRING

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

Champ

Type de données

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

Site

STRING

ItemType

STRING

EventSource

STRING

SourceName

STRING

UserAgent

STRING

MachineDomainInfo

STRING

MachineId

STRING

ListItemUniqueId

STRING

ListId

STRING

ApplicationId

STRING

ApplicationDisplayName

STRING

IsWorkflow

BOOLEAN

SiteUrl

STRING

SourceRelativeUrl

STRING

SourceFileName

STRING

SourceFileExtension

STRING

DestinationRelativeUrl

STRING

DestinationFileName

STRING

DestinationFileExtension

STRING

UserSharedWith

STRING

SharingType

STRING

SourceLabel

STRING

DestinationLabel

STRING

SensitivityLabelOwnerEmail

STRING

SensitivityLabelId

STRING

ListTitle

STRING

ListName

STRING

ListUrl

STRING

ListBaseType

STRING

ListBaseTemplateType

STRING

IsHiddenList

BOOLEAN

IsDocLib

BOOLEAN

TargetUserOrGroupName

STRING

TargetUserOrGroupType

STRING

UniqueSharingId

STRING

CustomEvent

STRING

EventData

STRING

ModifiedProperties

ARRAY<MAP<STRING, VARIANT>>

audit_general​

Clé principale : lw_id Champ de curseur : time

Champ

Type de données

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

payload

VARIANT

Champ

Type de données

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

payload

VARIANT

dlp_all​

Clé principale : lw_id Champ de curseur : time

Champ

Type de données

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

SharePointMetaData

STRUCT<From: STRING, itemCreationTime: TIMESTAMP, SiteCollectionGuid: STRING, SiteCollectionUrl: STRING, FileName: STRING, FileOwner: STRING, FilePathUrl: STRING, DocumentLastModifier: STRING, DocumentSharer: STRING, UniqueId: STRING, LastModifiedTime: TIMESTAMP, IsViewableByExternalUsers: BOOLEAN>

ExchangeMetaData

STRUCT<MessageID: STRING, From: STRING, To: ARRAY<STRING>, CC: ARRAY<STRING>, BCC: ARRAY<STRING>, Subject: STRING, Sent: TIMESTAMP, RecipientCount: INT>

EndPointMetaData

STRUCT<SensitiveInformation: ARRAY<STRUCT<Confidence: INT, Count: INT, Location: STRING, SensitiveType: STRING, SensitiveInformationDetections: STRUCT<DetectedValues: ARRAY<STRUCT<Name: STRING, Value: STRING>>, ResultsTruncated: BOOLEAN>, SensitiveInformationDetailedClassificationAttributes: ARRAY<STRUCT<Confidence: INT, Count: INT, IsMatch: BOOLEAN>>, SensitiveInformationTypeName: STRING, UniqueCount: INT>>, EnforcementMode: STRING, FileExtension: STRING, FileType: STRING, DeviceName: STRING>

ExceptionInfo

STRING

PolicyDetails

ARRAY<STRUCT<PolicyId: STRING, PolicyName: STRING, Rules: ARRAY<STRUCT<RuleId: STRING, RuleName: STRING, Actions: ARRAY<STRING>, OverriddenActions: ARRAY<STRING>, Severity: STRING, RuleMode: STRING, ConditionsMatched: STRUCT<SensitiveInformation: ARRAY<STRUCT<Confidence: INT, Count: INT, Location: STRING, SensitiveType: STRING, SensitiveInformationDetections: STRUCT<DetectedValues: ARRAY<STRUCT<Name: STRING, Value: STRING>>, ResultsTruncated: BOOLEAN>, SensitiveInformationDetailedClassificationAttributes: ARRAY<STRUCT<Confidence: INT, Count: INT, IsMatch: BOOLEAN>>, SensitiveInformationTypeName: STRING, UniqueCount: INT>>, DocumentProperties: ARRAY<STRUCT<Name: STRING, Value: STRING>>, OtherConditions: ARRAY<STRUCT<Name: STRING, Value: STRING>>>>>>>

SensitiveInfoDetectionIsIncluded

BOOLEAN

Champ

Type de données

lw_id

STRING

time

TIMESTAMP

Id

STRING

RecordType

INT

CreationTime

TIMESTAMP

Operation

STRING

OrganizationId

STRING

UserType

INT

UserKey

STRING

Workload

STRING

Version

INT

ResultStatus

STRING

ObjectId

STRING

UserId

STRING

ClientIP

STRING

Scope

STRING

AppAccessContext

STRUCT<AADSessionId: STRING, APIId: STRING, ClientAppId: STRING, ClientAppName: STRING, CorrelationId: STRING>

SharePointMetaData

STRUCT<From: STRING, itemCreationTime: TIMESTAMP, SiteCollectionGuid: STRING, SiteCollectionUrl: STRING, FileName: STRING, FileOwner: STRING, FilePathUrl: STRING, DocumentLastModifier: STRING, DocumentSharer: STRING, UniqueId: STRING, LastModifiedTime: TIMESTAMP, IsViewableByExternalUsers: BOOLEAN>

ExchangeMetaData

STRUCT<MessageID: STRING, From: STRING, To: ARRAY<STRING>, CC: ARRAY<STRING>, BCC: ARRAY<STRING>, Subject: STRING, Sent: TIMESTAMP, RecipientCount: INT>

EndPointMetaData

STRUCT<SensitiveInformation: ARRAY<STRUCT<Confidence: INT, Count: INT, Location: STRING, SensitiveType: STRING, SensitiveInformationDetections: STRUCT<DetectedValues: ARRAY<STRUCT<Name: STRING, Value: STRING>>, ResultsTruncated: BOOLEAN>, SensitiveInformationDetailedClassificationAttributes: ARRAY<STRUCT<Confidence: INT, Count: INT, IsMatch: BOOLEAN>>, SensitiveInformationTypeName: STRING, UniqueCount: INT>>, EnforcementMode: STRING, FileExtension: STRING, FileType: STRING, DeviceName: STRING>

ExceptionInfo

STRING

PolicyDetails

ARRAY<STRUCT<PolicyId: STRING, PolicyName: STRING, Rules: ARRAY<STRUCT<RuleId: STRING, RuleName: STRING, Actions: ARRAY<STRING>, OverriddenActions: ARRAY<STRING>, Severity: STRING, RuleMode: STRING, ConditionsMatched: STRUCT<SensitiveInformation: ARRAY<STRUCT<Confidence: INT, Count: INT, Location: STRING, SensitiveType: STRING, SensitiveInformationDetections: STRUCT<DetectedValues: ARRAY<STRUCT<Name: STRING, Value: STRING>>, ResultsTruncated: BOOLEAN>, SensitiveInformationDetailedClassificationAttributes: ARRAY<STRUCT<Confidence: INT, Count: INT, IsMatch: BOOLEAN>>, SensitiveInformationTypeName: STRING, UniqueCount: INT>>, DocumentProperties: ARRAY<STRUCT<Name: STRING, Value: STRING>>, OtherConditions: ARRAY<STRUCT<Name: STRING, Value: STRING>>>>>>>

SensitiveInfoDetectionIsIncluded

BOOLEAN

Options de connexion​

Option

Type

Obligatoire

Description

tenant_id

Chaîne

Oui

ID du répertoire (tenant) du tenant Microsoft Entra.

client_id

Chaîne

Oui

L’ID d’application (client) de l’application Microsoft Entra enregistrée.

client_secret

Chaîne

Oui

La valeur du secret du client pour l’application enregistrée.

subscription_plan

Chaîne

Oui

L’environnement cloud Microsoft pour le tenant. L’Explorateur de catalogue sélectionne initialement enterprise.

Option

Type

Obligatoire

Description

tenant_id

Chaîne

Oui

ID du répertoire (tenant) du tenant Microsoft Entra.

client_id

Chaîne

Oui

L’ID d’application (client) de l’application Microsoft Entra enregistrée.

client_secret

Chaîne

Oui

La valeur du secret du client pour l’application enregistrée.

subscription_plan

Chaîne

Oui

L’environnement cloud Microsoft pour le tenant. L’Explorateur de catalogue sélectionne initialement enterprise.

Forfaits d'abonnement​

Nom d’affichage

Valeur

Hôte de l'API Management Activity

Entreprise

enterprise

manage.office.com

Government GCC

gcc

manage-gcc.office.com

Government GCC High

gcc_high

manage.office365.us

Government DoD

dod

manage.protection.apps.mil

Nom d’affichage

Valeur

Hôte de l'API Management Activity

Entreprise

enterprise

manage.office.com

Government GCC

gcc

manage-gcc.office.com

Government GCC High

gcc_high

manage.office365.us

Government DoD

dod

manage.protection.apps.mil

Autorisations Microsoft 365 requises​

Autorisation

Type

Obligatoire pour

ActivityFeed.Read

Application

Lecture du contenu Audit.AzureActiveDirectory, Audit.Exchange, Audit.SharePoint et Audit.General.

ActivityFeed.ReadDlp

Application

Lecture du contenu de DLP.All pour la table source dlp_all.

Autorisation

Type

Obligatoire pour

ActivityFeed.Read

Application

Lecture du contenu Audit.AzureActiveDirectory, Audit.Exchange, Audit.SharePoint et Audit.General.

ActivityFeed.ReadDlp

Application

Lecture du contenu de DLP.All pour la table source dlp_all.

Un administrateur doit accorder le consentement à l'échelle du tenant pour ces autorisations. Le connecteur n'utilise pas d'autorisations déléguées.