Ingest data from Microsoft 365
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Microsoft 365 Unified Audit Logs from the Previews page. See Manage Databricks previews.
Use Declarative Automation Bundles or a Databricks notebook to create a managed Microsoft 365 Unified Audit Logs pipeline for any of the five supported audit log source tables.
Requirements
-
To create an ingestion pipeline, first meet the following requirements:
-
Your workspace must be enabled for Unity Catalog.
-
Serverless compute must be enabled for your workspace. See Serverless compute requirements.
-
To create a new connection, you must have
CREATE CONNECTIONprivileges on the metastore. See Manage privileges in Unity Catalog.If the connector supports UI-based pipeline authoring, an admin can create the connection and the pipeline at the same time by completing the steps on this page. However, if the users who create pipelines use API-based pipeline authoring or are non-admin users, an admin must first create the connection in Catalog Explorer. See Connect to managed ingestion sources.
-
To use an existing connection, you must have
USE CONNECTIONprivileges orALL PRIVILEGESon the connection object. -
You must have
USE CATALOGprivileges on the target catalog. -
You must have
USE SCHEMAandCREATE TABLEprivileges on an existing schema orCREATE SCHEMAprivileges on the target catalog.
-
-
Configure authentication from Databricks and create a connection. See Configure authentication to Microsoft 365 and Create a Microsoft 365 Unified Audit Logs connection.
-
Choose the source objects to ingest. For the supported objects, see Supported source tables.
Connector options
The Microsoft 365 Unified Audit Logs connector doesn't define connector-specific pipeline options. For connection settings, see Connection options.
Create an ingestion pipeline
Create the pipeline with Declarative Automation Bundles or a Databricks notebook. While the connector is in Beta, set the pipeline channel to PREVIEW.
- Declarative Automation Bundles
- Databricks notebook
Use Declarative Automation Bundles to manage Microsoft 365 Unified Audit Logs pipelines as code. Bundles can contain YAML definitions of pipelines and jobs, are managed using the Databricks CLI, and can be shared across development, staging, and production workspaces. For more information, see What are Declarative Automation Bundles?.
-
Create a bundle using the Databricks CLI:
Bashdatabricks bundle init -
Add a pipeline definition file, such as
resources/microsoft_365_pipeline.yml. See pipeline.ingestion_definition and Examples. -
Add a job definition file, such as
resources/microsoft_365_job.yml, to run the pipeline more frequently than every seven days. -
Deploy the pipeline using the Databricks CLI:
Bashdatabricks bundle deploy
-
Import the following notebook into your Databricks workspace:
-
Don't edit the setup cells. Edit only the last cell, which creates the pipeline. See pipeline.ingestion_definition and Examples.
-
Optionally configure advanced pipeline settings. See Common patterns for managed ingestion pipelines.
-
Click Run all.
Examples
The Microsoft 365 Unified Audit Logs connector makes five source tables available in the default source schema. The following examples ingest Entra ID, Exchange, SharePoint, general, and data loss prevention audit events.
- Declarative Automation Bundles
- Databricks notebook
The following pipeline definition file ingests all five source tables:
resources:
pipelines:
microsoft_365_pipeline:
name: microsoft_365_pipeline
channel: PREVIEW
catalog: 'main'
target: 'microsoft_365_data'
ingestion_definition:
connection_name: microsoft_365_connection
objects:
- table:
source_schema: 'default'
source_table: 'audit_azure_active_directory'
destination_catalog: 'main'
destination_schema: 'microsoft_365_data'
destination_table: 'audit_azure_active_directory'
- table:
source_schema: 'default'
source_table: 'audit_exchange'
destination_catalog: 'main'
destination_schema: 'microsoft_365_data'
destination_table: 'audit_exchange'
- table:
source_schema: 'default'
source_table: 'audit_sharepoint'
destination_catalog: 'main'
destination_schema: 'microsoft_365_data'
destination_table: 'audit_sharepoint'
- table:
source_schema: 'default'
source_table: 'audit_general'
destination_catalog: 'main'
destination_schema: 'microsoft_365_data'
destination_table: 'audit_general'
- table:
source_schema: 'default'
source_table: 'dlp_all'
destination_catalog: 'main'
destination_schema: 'microsoft_365_data'
destination_table: 'dlp_all'
The following pipeline specification ingests all five source tables:
pipeline_name = "microsoft_365_pipeline"
connection_name = "<microsoft-365-connection>"
source_tables = [
"audit_azure_active_directory",
"audit_exchange",
"audit_sharepoint",
"audit_general",
"dlp_all",
]
pipeline_spec = {
"name": pipeline_name,
"channel": "PREVIEW",
"catalog": "main",
"schema": "microsoft_365_pipeline",
"ingestion_definition": {
"connection_name": connection_name,
"objects": [
{
"table": {
"source_schema": "default",
"source_table": source_table,
"destination_catalog": "main",
"destination_schema": "microsoft_365_data",
"destination_table": source_table,
}
}
for source_table in source_tables
],
},
}
json_payload = json.dumps(pipeline_spec, indent=2)
create_pipeline(json_payload)
To ingest dlp_all, grant the ActivityFeed.ReadDlp application permission to the Microsoft Entra application. See Configure API permissions.
Declarative Automation Bundles job definition file
The following job definition runs the ingestion pipeline daily. Run the pipeline more frequently than every seven days because Microsoft makes Management Activity API content available for a limited time.
- Declarative Automation Bundles
resources:
jobs:
microsoft_365_job:
name: microsoft_365_job
schedule:
quartz_cron_expression: '0 0 0 * * ?'
timezone_id: 'UTC'
tasks:
- task_key: microsoft_365_ingestion
pipeline_task:
pipeline_id: ${resources.pipelines.microsoft_365_pipeline.id}
Common patterns
For advanced pipeline configurations, see Common patterns for managed ingestion pipelines.
Next steps
Start, schedule, and set alerts on your pipeline. See Common pipeline maintenance tasks.