Defender-CloudAppEvents

ActionTypeTitleSampleRule
anyCloud app activityYY

any: Cloud app activity

#
Table
CloudAppEvents

Example Event #

{
  "AccountDisplayName": "Admin User",
  "AccountId": "11111111-1111-1111-1111-111111111111",
  "AccountObjectId": "11111111-1111-1111-1111-111111111111",
  "AccountType": "Admin",
  "ActionType": "Add service principal.",
  "ActivityObjects": [
    {
      "Type": "Application",
      "Role": "Parameter",
      "ServiceObjectType": "Azure Service Principal - Object ID"
    },
    {
      "Type": "Application",
      "Role": "Target object",
      "Name": "dw-rt2-delegate"
    },
    {
      "Type": "Application",
      "Role": "Parameter",
      "Id": "Other",
      "ServiceObjectType": "Azure Service Principal - Application ID"
    },
    {
      "Type": "Tenant",
      "Role": "Parameter",
      "Id": "00000000-0000-0000-0000-000000000001"
    },
    {
      "Type": "User",
      "Role": "Actor",
      "Name": "Admin User",
      "Id": "11111111-1111-1111-1111-111111111111",
      "ApplicationId": 11161,
      "ApplicationInstance": 0
    }
  ],
  "ActivityObjects@odata.type": "#Collection(String)",
  "ActivityType": "Add",
  "AdditionalFields": {
    "@odata.type": "#microsoft.graph.security.dynamicColumnValue"
  },
  "AppInstanceId": 0,
  "Application": "Microsoft 365",
  "ApplicationId": 11161,
  "AuditSource": "Defender for Cloud Apps app connector",
  "DeviceType": "Other",
  "IsAdminOperation": 0,
  "IsAdminOperation@odata.type": "#SByte",
  "IsExternalUser": 0,
  "IsExternalUser@odata.type": "#SByte",
  "IsImpersonated": 0,
  "IsImpersonated@odata.type": "#SByte",
  "LastSeenForUser": {
    "@odata.type": "#microsoft.graph.security.dynamicColumnValue",
    "ActionType": 0,
    "ActionType@odata.type": "#Int64",
    "Application": 0,
    "Application@odata.type": "#Int64",
    "OSPlatform": 0,
    "OSPlatform@odata.type": "#Int64",
    "UserAgent": 0,
    "UserAgent@odata.type": "#Int64"
  },
  "OAuthAppId": "5165532d-c344-423b-973e-b4493d5450c5",
  "OSPlatform": "Linux",
  "ObjectName": "dw-rt2-delegate",
  "ObjectType": "Application",
  "RawEventData": {
    "@odata.type": "#microsoft.graph.security.dynamicColumnValue",
    "Actor": [
      {
        "ID": "adminuser@example.onmicrosoft.com",
        "Type": 5
      },
      {
        "ID": "10000000AAAAAAAA",
        "Type": 3
      },
      {
        "ID": "User_11111111-1111-1111-1111-111111111111",
        "Type": 2
      },
      {
        "ID": "11111111-1111-1111-1111-111111111111",
        "Type": 2
      },
      {
        "ID": "User",
        "Type": 2
      },
      {
        "ID": "NotAgentic",
        "Type": 2
      }
    ],
    "Actor@odata.type": "#Collection(String)",
    "ActorContextId": "00000000-0000-0000-0000-000000000001",
    "AzureActiveDirectoryEventType": 1,
    "AzureActiveDirectoryEventType@odata.type": "#Int64",
    "CreationTime": "2026-07-25T21:49:08.0000000Z",
    "ExtendedProperties": [
      {
        "Name": "additionalDetails",
        "Value": {
          "User-Agent": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)",
          "AppId": "5165532d-c344-423b-973e-b4493d5450c5",
          "AppOwnerOrganizationId": "00000000-0000-0000-0000-000000000001",
          "ServicePrincipalProvisioningType": "Other"
        }
      },
      {
        "Name": "extendedAuditEventCategory",
        "Value": "ServicePrincipal"
      }
    ],
    "ExtendedProperties@odata.type": "#Collection(String)",
    "Id": "7943e2c0-acf1-4d0a-ab3f-ee682ed1d93e",
    "InterSystemsId": "d557c366-e388-4fdc-8160-62c183a4bba8",
    "IntraSystemId": "00000000-0000-0000-0000-000000000000",
    "ModifiedProperties": [
      {
        "Name": "AccountEnabled",
        "NewValue": [
          true
        ],
        "OldValue": []
      },
      {
        "Name": "AppPrincipalId",
        "NewValue": [
          "5165532d-c344-423b-973e-b4493d5450c5"
        ],
        "OldValue": []
      },
      {
        "Name": "DisplayName",
        "NewValue": [
          "dw-rt2-delegate"
        ],
        "OldValue": []
      },
      {
        "Name": "ServicePrincipalName",
        "NewValue": [
          "5165532d-c344-423b-973e-b4493d5450c5"
        ],
        "OldValue": []
      },
      {
        "Name": "Credential",
        "NewValue": [
          {
            "CredentialType": 2,
            "KeyStoreId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c",
            "KeyGroupId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c"
          }
        ],
        "OldValue": []
      },
      {
        "Name": "Included Updated Properties",
        "NewValue": "AccountEnabled, AppPrincipalId, DisplayName, ServicePrincipalName, Credential",
        "OldValue": ""
      }
    ],
    "ModifiedProperties@odata.type": "#Collection(String)",
    "ObjectId": "5165532d-c344-423b-973e-b4493d5450c5",
    "Operation": "Add service principal.",
    "OrganizationId": "00000000-0000-0000-0000-000000000001",
    "RecordType": 8,
    "RecordType@odata.type": "#Int64",
    "ResultStatus": "Success",
    "SupportTicketId": "",
    "Target": [
      {
        "ID": "ServicePrincipal_3ce33562-8f77-4735-afa3-eb60a90c3377",
        "Type": 2
      },
      {
        "ID": "3ce33562-8f77-4735-afa3-eb60a90c3377",
        "Type": 2
      },
      {
        "ID": "ServicePrincipal",
        "Type": 2
      },
      {
        "ID": "NotAgentic",
        "Type": 2
      },
      {
        "ID": "dw-rt2-delegate",
        "Type": 1
      },
      {
        "ID": "5165532d-c344-423b-973e-b4493d5450c5",
        "Type": 2
      },
      {
        "ID": "5165532d-c344-423b-973e-b4493d5450c5",
        "Type": 4
      },
      {
        "ID": "00000000-0000-0000-0000-000000000001",
        "Type": 2
      },
      {
        "ID": "Other",
        "Type": 2
      }
    ],
    "Target@odata.type": "#Collection(String)",
    "TargetContextId": "00000000-0000-0000-0000-000000000001",
    "UserId": "adminuser@example.onmicrosoft.com",
    "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
    "UserType": 0,
    "UserType@odata.type": "#Int64",
    "Version": 1,
    "Version@odata.type": "#Int64",
    "Workload": "AzureActiveDirectory"
  },
  "ReportId": "75768946_11161_7943e2c0-acf1-4d0a-ab3f-ee682ed1d93e",
  "Timestamp": "2026-07-25T21:49:08Z",
  "UncommonForUser@odata.type": "#Collection(String)",
  "UserAgent": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Active (kusto rule field)eqtrue4 ruleskusto
ValidUntil (kusto rule field)is_null4 ruleskusto
CloudAppEvents_TimeGenerated (kusto rule field)cross_field_compareExpirationDateTime3 ruleskusto
CloudAppEvents_TimeGenerated (kusto rule field)cross_field_compareValidUntil3 ruleskusto
ActionType (kusto rule field)eqUsbDriveMounted1 rulekusto
ActionType (kusto rule field)inExecuteToolByGateway2 ruleskusto
ActionType (kusto rule field)inExecuteToolByMCPServer2 ruleskusto
ActionType (kusto rule field)inExecuteToolBySDK2 ruleskusto
ActionType (kusto rule field)inInferenceCall2 ruleskusto
ActionType (kusto rule field)inInvokeAgent2 ruleskusto
ActionType (kusto rule field)inFileCreated1 rulekusto
Image (kusto rule field)is_not_null2 ruleskusto
User_Id (kusto rule field)is_not_null2 ruleskusto
User_Id (kusto rule field)regex_match^[a-zA-Z0-9_.+-]+@[a-zA-Z0-9-]+\.[a-zA-Z0-9-.]+$2 ruleskusto
AccountObjectId (kusto rule field)is_not_null1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #