Microsoft 365 Unified Audit Logs connector reference
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Microsoft 365 Unified Audit Logs from the Previews page. See Manage Databricks previews.
The managed Microsoft 365 Unified Audit Logs connector supports five unified audit log source tables. This reference lists the tables, destination table schemas, connection options, subscription plans, and Microsoft 365 permissions.
Supported source tables
The Microsoft 365 Unified Audit Logs connector supports the following source tables in the default source schema. All five tables use lw_id as the primary key, use incremental sync, and use time as the cursor field.
Source table | Primary key | Description | Microsoft Management Activity API content type | Sync mode | Cursor field |
|---|---|---|---|---|---|
|
| Microsoft Entra ID events, including sign-ins, application access, and directory changes. |
| Incremental |
|
|
| Exchange events, including mailbox, folder, and item operations. |
| Incremental |
|
|
| SharePoint and OneDrive events, including file, folder, sharing, and site operations. |
| Incremental |
|
|
| Microsoft 365 audit events that are not included in the other workload-specific content types. |
| Incremental |
|
|
| Data loss prevention events across supported Microsoft 365 workloads. |
| Incremental |
|
For field definitions and workload-specific event schemas, see the Microsoft 365 Management Activity API schema. Microsoft can add fields and event types to these source payloads.
Use the following source names in a pipeline definition:
objects:
- table:
source_schema: 'default'
source_table: 'audit_azure_active_directory'
- table:
source_schema: 'default'
source_table: 'audit_exchange'
- table:
source_schema: 'default'
source_table: 'audit_sharepoint'
- table:
source_schema: 'default'
source_table: 'audit_general'
- table:
source_schema: 'default'
source_table: 'dlp_all'
For a complete pipeline definition, see Examples.
Destination table schemas
All tables use lw_id as the primary key and time as the cursor field. Each destination table also includes the source fields that Microsoft returns for its content type. Microsoft can add fields and event types to these source payloads, so for the complete, authoritative field list, see the Microsoft 365 Management Activity API schema.
audit_azure_active_directory
Primary key: lw_id
Cursor field: time
Field | Data type |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
audit_exchange
Primary key: lw_id
Cursor field: time
Field | Data type |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
audit_sharepoint
Primary key: lw_id
Cursor field: time
Field | Data type |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
audit_general
Primary key: lw_id
Cursor field: time
Field | Data type |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
dlp_all
Primary key: lw_id
Cursor field: time
Field | Data type |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Connection options
Option | Type | Required | Description |
|---|---|---|---|
| String | Yes | The Directory (tenant) ID of the Microsoft Entra tenant. |
| String | Yes | The Application (client) ID of the registered Microsoft Entra application. |
| String | Yes | The client secret value for the registered application. |
| String | Yes | The Microsoft cloud environment for the tenant. Catalog Explorer initially selects |
Subscription plans
Display name | Value | Management Activity API host |
|---|---|---|
Enterprise |
|
|
Government GCC |
|
|
Government GCC High |
|
|
Government DoD |
|
|
Required Microsoft 365 permissions
Permission | Type | Required for |
|---|---|---|
| Application | Reading |
| Application | Reading |
An administrator must grant tenant-wide consent for these permissions. The connector doesn't use delegated permissions.