Skip to main content

Microsoft 365 Unified Audit Logs connector

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Microsoft 365 Unified Audit Logs from the Previews page. See Manage Databricks previews.

The managed Microsoft 365 Unified Audit Logs connector in Lakeflow Connect ingests unified audit events from Microsoft Entra ID, Exchange, SharePoint, and other Microsoft 365 workloads into Databricks.

The connector uses the Microsoft 365 Management Activity API to ingest append-only audit events. It doesn't ingest Outlook messages or SharePoint files.

Feature availability​

Feature

Availability

UI-based pipeline authoring

Red X icon Not supported

API-based pipeline authoring

Green check icon Supported

Declarative Automation Bundles

Green check icon Supported

Incremental ingestion

Green check icon Supported

Unity Catalog governance

Green check icon Supported

Orchestration using Databricks Workflows

Green check icon Supported

API-based column selection and deselection

Green check icon Supported

API-based row filtering

Red X icon Not supported

SCD Type 2

Red X icon Not supported

Microsoft 365 unified audit events are append-only.

Automated schema evolution: New and deleted columns

Green check icon Supported

Automated schema evolution: Data type changes

Red X icon Not supported

Automated schema evolution: Column renames

Green check icon Supported

Treated as a new column (new name) and deleted column (old name).

Feature

Availability

UI-based pipeline authoring

Red X icon Not supported

API-based pipeline authoring

Green check icon Supported

Declarative Automation Bundles

Green check icon Supported

Incremental ingestion

Green check icon Supported

Unity Catalog governance

Green check icon Supported

Orchestration using Databricks Workflows

Green check icon Supported

API-based column selection and deselection

Green check icon Supported

API-based row filtering

Red X icon Not supported

SCD Type 2

Red X icon Not supported

Microsoft 365 unified audit events are append-only.

Automated schema evolution: New and deleted columns

Green check icon Supported

Automated schema evolution: Data type changes

Red X icon Not supported

Automated schema evolution: Column renames

Green check icon Supported

Treated as a new column (new name) and deleted column (old name).

Authentication methods​

Authentication method

Availability

OAuth U2M

Red X icon Not supported

OAuth M2M

Green check icon Supported

A Microsoft Entra application with a client ID, client secret, and Office 365 Management API application permissions.

Basic authentication (username/password)

Red X icon Not supported

Authentication method

Availability

OAuth U2M

Red X icon Not supported

OAuth M2M

Green check icon Supported

A Microsoft Entra application with a client ID, client secret, and Office 365 Management API application permissions.

Basic authentication (username/password)

Red X icon Not supported

What to know before you start​

Start ingesting from Microsoft 365​

  1. Configure Microsoft 365 for ingestion (Microsoft 365 and Entra admins). Enable unified auditing and create a Microsoft Entra application for Databricks.
  2. Create a Unity Catalog connection (Admins). Create a connection in Catalog Explorer so pipeline authors don't need direct access to the credentials.
  3. Create an ingestion pipeline (Admins or non-admins). Use Declarative Automation Bundles or a Databricks notebook to create a pipeline from an existing connection.