Microsoft 365 Unified Audit Logs connector FAQ
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Microsoft 365 Unified Audit Logs from the Previews page. See Manage Databricks previews.
The managed Microsoft 365 Unified Audit Logs connector ingests events from five unified audit log source tables. These answers cover subscription plans, supported audit workloads, authentication, and data availability. For FAQs that apply to all managed connectors, see Managed connector FAQs.
Which subscription plan should I select?
Select the plan for the Microsoft cloud environment that hosts your tenant:
- Enterprise for tenants hosted in the commercial Microsoft 365 cloud.
- Government GCC for Microsoft 365 Government Community Cloud tenants.
- Government GCC High for GCC High tenants.
- Government DoD for Department of Defense tenants.
If you don't know your tenant's environment, ask your Microsoft 365 administrator. For the corresponding connection values and API hosts, see Subscription plans.
Does this connector ingest Microsoft Entra ID audit events?
Yes. Select the audit_azure_active_directory source table to ingest the Audit.AzureActiveDirectory content type from the Microsoft 365 Management Activity API. The source table name retains the API's Azure Active Directory terminology.
Does this connector ingest Outlook messages or SharePoint files?
No. The Microsoft 365 Unified Audit Logs connector ingests unified audit events from the Microsoft 365 Management Activity API. Use the Outlook connector to ingest email messages and the SharePoint connector to ingest files and list data.
How far back can the connector ingest data?
The first pipeline update can request content created during the previous seven days. If a pipeline does not run for more than seven days, the connector resumes from seven days before the current time and cannot recover the earlier gap through the Management Activity API.
Why is the first pipeline update empty?
When a pipeline first requests a source table, the connector starts the corresponding Management Activity API subscription. Microsoft states that the first content blobs can take up to 12 hours to become available. Run the pipeline again after content becomes available.
Which authentication method does the connector support?
The connector supports OAuth machine-to-machine authentication with a Microsoft Entra tenant ID, application client ID, and client secret. It doesn't support delegated OAuth or username and password authentication.
Which source tables does the connector support?
The connector supports audit_azure_active_directory, audit_exchange, audit_sharepoint, audit_general, and dlp_all. For details, see Supported source tables.