Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: Label

OperationNameDescriptionSampleRule
Add labelA sensitivity label was applied to a Microsoft Entra (Microsoft 365) group.NN
Delete labelDeletes a sensitivity/classification label synchronized to Entra ID for Microsoft 365 groups and sites.NN
Update labelUpdate to a label definition stored in the Microsoft Entra (Core Directory).NN

Add label

#
Source
Microsoft Entra ID audit log
Audit Category
Label

Description

A sensitivity label was applied to a Microsoft Entra group. In Entra ID, published Microsoft Purview sensitivity labels can be applied to Microsoft 365 groups, where they enforce the group's connected-workspace settings such as privacy and guest access.

References #

Delete label

#
Source
Microsoft Entra ID audit log
Audit Category
Label

Description

Records deletion of a sensitivity (classification) label from the directory, the labels synchronized to Microsoft Entra ID and applied to Microsoft 365 groups, Teams, and SharePoint sites. Removing a label can relax container-level protections on those workspaces.

References #

Update label

#
Source
Microsoft Entra ID audit log
Audit Category
Label

Description

Records an update to a label definition stored in the Microsoft Entra Core Directory. The specific label type cannot be determined from the operation name, category, and service alone.

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.