Skip to main content

Troubleshoot the Microsoft 365 Unified Audit Logs connector

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Microsoft 365 Unified Audit Logs from the Previews page. See Manage Databricks previews.

Resolve common Microsoft 365 Unified Audit Logs connector errors, including invalid credentials, missing permissions, disabled subscriptions, empty initial pipeline updates, and ingestion gaps.

For general troubleshooting guidance that applies to all managed ingestion pipelines, see Troubleshoot managed ingestion pipelines.

Pipeline fails to authenticate​

Cause: The tenant ID, client ID, or client secret in the Unity Catalog connection is invalid. The client secret might also have expired.

Solution:

  1. In Microsoft Entra ID, confirm that the application is registered in the tenant specified by Tenant ID.
  2. Confirm that Client ID is the application's Application (client) ID.
  3. Confirm that Client secret contains the secret value, not the Secret ID.
  4. If the secret expired, create a new client secret and update the Unity Catalog connection.
  5. Confirm that Subscription plan matches the Microsoft cloud environment that hosts the tenant.

For setup details, see Configure authentication to Microsoft 365 and Create a Microsoft 365 Unified Audit Logs connection.

Microsoft 365 returns a permission error​

Cause: The Microsoft Entra application does not have the required Office 365 Management API application permissions, or an administrator has not granted tenant-wide consent.

Solution:

  1. In Microsoft Entra ID, open the registered application and go to API permissions.
  2. Confirm that ActivityFeed.Read is listed under Office 365 Management APIs as an application permission.
  3. If the pipeline ingests dlp_all, confirm that ActivityFeed.ReadDlp is also listed.
  4. Confirm that the permissions show Granted for your organization. If the status is Not granted, click Grant admin consent for your organization, then run the pipeline again.

Pipeline reports that a subscription is disabled​

Cause: The Management Activity API subscription for the requested content type is disabled, or unified audit logging is disabled for the Microsoft 365 organization.

Solution:

  1. Confirm that unified audit logging is enabled for the organization.
  2. Don't stop or disable the Management Activity API subscription while the pipeline ingests its source table.
  3. Run the pipeline again. The connector attempts to start the subscription for each requested source table.

The first pipeline update ingests no records​

Cause: The connector started a new Management Activity API subscription. Microsoft can take up to 12 hours to make the first content blobs available.

Solution:

Wait for content to become available, then run the pipeline again. Also confirm that unified audit logging is enabled and that the Microsoft 365 tenant has generated events for the selected content type.

Audit events are missing after the pipeline did not run​

Cause: The pipeline did not run for more than seven days. The connector can request Management Activity API content created during only the previous seven days.

Solution:

Schedule the pipeline to run more frequently than every seven days. Events outside the API availability window cannot be recovered through the connector.