Microsoft 365 Unified Audit Logs connector
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Microsoft 365 Unified Audit Logs from the Previews page. See Manage Databricks previews.
The managed Microsoft 365 Unified Audit Logs connector in Lakeflow Connect ingests unified audit events from Microsoft Entra ID, Exchange, SharePoint, and other Microsoft 365 workloads into Databricks.
The connector uses the Microsoft 365 Management Activity API to ingest append-only audit events. It doesn't ingest Outlook messages or SharePoint files.
Feature availability
Feature | Availability |
|---|---|
UI-based pipeline authoring |
|
API-based pipeline authoring |
|
Declarative Automation Bundles |
|
Incremental ingestion |
|
Unity Catalog governance |
|
Orchestration using Databricks Workflows |
|
API-based column selection and deselection |
|
API-based row filtering |
|
SCD Type 2 |
Microsoft 365 unified audit events are append-only. |
Automated schema evolution: New and deleted columns |
|
Automated schema evolution: Data type changes |
|
Automated schema evolution: Column renames |
Treated as a new column (new name) and deleted column (old name). |
Authentication methods
Authentication method | Availability |
|---|---|
OAuth U2M |
|
OAuth M2M |
A Microsoft Entra application with a client ID, client secret, and Office 365 Management API application permissions. |
Basic authentication (username/password) |
|
What to know before you start
Before starting, review the Databricks user persona, supported interfaces, ingestion frequency, and common patterns.
Start ingesting from Microsoft 365
- Configure Microsoft 365 for ingestion (Microsoft 365 and Entra admins). Enable unified auditing and create a Microsoft Entra application for Databricks.
- Create a Unity Catalog connection (Admins). Create a connection in Catalog Explorer so pipeline authors don't need direct access to the credentials.
- Create an ingestion pipeline (Admins or non-admins). Use Declarative Automation Bundles or a Databricks notebook to create a pipeline from an existing connection.