Admin Console

eventNameDescriptionSampleRule
anySource-only rules that filter on applicationName 'admin' without specifying an eventName attribute here.NN
ADD_APPLICATIONAn application was added to the Google Workspace domain.NY
ADD_GROUP_MEMBERA user was added to a group.YY
ADD_PRIVILEGEA privilege was added to a role.NY
ADD_TRUSTED_DOMAINSA domain was added to the trusted domains list.NY
ALLOW_STRONG_AUTHENTICATIONThe administrator changed the MFA enforcement setting (allow/require strong authentication).NY
ASSIGN_ROLEAn admin role was assigned to a user or service account.YY
AUTHORIZE_API_CLIENT_ACCESSAn API client was authorized domain-wide access via OAuth.YY
CHANGE_APPLICATION_SETTINGA setting for a Google Workspace application was modified.YY
CHANGE_GMAIL_SETTINGA Gmail routing or mail-flow setting was changed.NY
CREATE_APPLICATION_SETTINGA new application setting was created.NY
CREATE_DATA_TRANSFER_REQUESTAn admin initiated a data transfer (Drive file ownership reassignment) to another user.NY
CREATE_GMAIL_SETTINGA new Gmail routing or mail-flow setting was created.NY
CREATE_ROLEA custom admin role was created.NY
CUSTOMER_TAKEOUT_CREATEDAn admin initiated a Takeout export job for organizational data.NY
DELETE_ROLEAn admin role was permanently deleted.NY
ENFORCE_STRONG_AUTHENTICATIONThe MFA/2SV enforcement policy was changed for the domain or an organizational unit.NY
GRANT_ADMIN_PRIVILEGEAdministrator privileges were granted to a user account.NY
GRANT_DELEGATED_ADMIN_PRIVILEGESDelegated administrator privileges were granted to a user.NY
MOVE_USER_TO_ORG_UNITA user was moved to a different organizational unit.NY
REMOVE_APPLICATIONAn application was removed from the Google Workspace domain.NY
REMOVE_APPLICATION_FROM_WHITELISTAn application was removed from the domain's marketplace allowlist.NY
REMOVE_PRIVILEGEA privilege was removed from a role.NY
RENAME_ROLEAn admin role was renamed.NY
SAML2_SERVICE_PROVIDER_CONFIGA SAML 2.0 service provider configuration was added, modified, or removed.NY
TOGGLE_OUTBOUND_RELAYOutbound email relay routing was enabled or disabled.NY
TURN_OFF_2_STEP_VERIFICATION2-Step Verification was disabled for a user or the domain.NY
UNSUSPEND_USERA suspended user account was reactivated.NY
UPDATE_ROLEAn existing admin role was modified (e.g. description or privileges changed).NY
BLOCK_ALL_THIRD_PARTY_API_ACCESSAn admin blocked all third-party application access to Google Workspace APIs.NN
UNBLOCK_ALL_THIRD_PARTY_API_ACCESSAn admin unblocked third-party application access to Google Workspace APIs.NN
ADD_TO_TRUSTED_OAUTH2_APPSAn OAuth2 application was added to the trusted apps list.NN
ADD_TO_BLOCKED_OAUTH2_APPSAn OAuth2 application was blocked from accessing Google Workspace data.NN
REMOVE_FROM_BLOCKED_OAUTH2_APPSAn OAuth2 application was removed from the blocked apps list.NN
REMOVE_FROM_TRUSTED_OAUTH2_APPSAn OAuth2 application was removed from the trusted apps list.NN
CREATE_USERA new user account was created in the Google Workspace domain.YN
DELETE_USERA user account was deleted from the Google Workspace domain.YN
SUSPEND_USERA user account was suspended by an administrator.NN
RENAME_USERA user's primary email address was changed.YN
CHANGE_PASSWORDAn administrator changed a user's password.YN
REVOKE_ASPAn administrator revoked an application-specific password (ASP) for a user.NN
REVOKE_3LO_TOKENAn administrator revoked an OAuth token for a user.NN
SESSION_CONTROL_SETTINGS_CHANGEWeb session duration or re-authentication settings were changed.NN
WEAK_PROGRAMMATIC_LOGIN_SETTINGS_CHANGEDSettings controlling less-secure app access (LSA/basic auth) were changed.NN
CHANGE_SSO_SETTINGSSAML/SSO settings for the domain were changed.NN
TOGGLE_SSO_ENABLEDSSO (SAML-based single sign-on) was enabled or disabled for the domain.NN
REVOKE_ADMIN_PRIVILEGEAdministrator privileges were revoked from a user account.NN
ALLOW_SERVICE_FOR_OAUTH2_ACCESSA Google service was allowed for OAuth2 API access.NN
DISALLOW_SERVICE_FOR_OAUTH2_ACCESSA Google service was disallowed for OAuth2 API access.NN
TOGGLE_CAA_ENABLEMENTContext-Aware Access was enabled or disabled for the domain.NN
CHANGE_GROUP_SETTINGA setting for a Google Group was changed by an administrator.YN
ADD_APPLICATION_TO_WHITELISTAn application was added to the domain's Google Workspace Marketplace allowlist.NN
CHANGE_TWO_STEP_VERIFICATION_ENROLLMENT_PERIOD_DURATIONThe enrollment period for 2-Step Verification was changed.NN
CHANGE_ALLOWED_TWO_STEP_VERIFICATION_METHODSThe allowed methods for 2-Step Verification were changed.NN
APPLICATION_SETTINGSEvents of this type are returned with type=APPLICATION_SETTINGS .NN
DELETE_APPLICATION_SETTINGFor {APPLICATION_NAME} , {SETTING_NAME} with value {OLD_VALUE} deletedNN
REORDER_GROUP_BASED_POLICIES_EVENTFor {APPLICATION_NAME} , group override priorities for {SETTING_NAME} changed to {GROUP_PRIORITIES} .NN
GPLUS_PREMIUM_FEATURESPremium features for Google+ service for your organization changed to {NEW_VALUE}NN
CREATE_MANAGED_CONFIGURATIONManaged configuration with name {MANAGED_CONFIGURATION_NAME} is created for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} .NN
DELETE_MANAGED_CONFIGURATIONManaged configuration with name {MANAGED_CONFIGURATION_NAME} is deleted for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} .NN
UPDATE_MANAGED_CONFIGURATIONManaged configuration with name {MANAGED_CONFIGURATION_NAME} is updated for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} .NN
FLASHLIGHT_EDU_NON_FEATURED_SERVICES_SELECTED{FLASHLIGHT_EDU_NON_FEATURED_SERVICES_SELECTION} selection was made for Non-Featured Services.NN
UPDATE_SMART_FEATURESSmart features and personalization setting has been updated to {NEW_VALUE}NN
CALENDAR_SETTINGSEvents of this type are returned with type=CALENDAR_SETTINGS .NN
CREATE_BUILDINGBuilding {NEW_VALUE} createdNN
DELETE_BUILDINGBuilding {OLD_VALUE} deletedNN
UPDATE_BUILDINGBuilding {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE}NN
EWS_IN_NEW_CREDENTIALS_GENERATEDShort description for EWS IN credentials generation.NN
EWS_OUT_ENDPOINT_CONFIGURATION_RESETShort description for clearing Calendar Interop Exchange endpoint configuration.NN
EWS_OUT_ENDPOINT_CONFIGURATION_CHANGEDShort description for changing Calendar Interop Exchange endpoint configuration.NN
CREATE_CALENDAR_RESOURCECalendar resource {NEW_VALUE} createdNN
DELETE_CALENDAR_RESOURCECalendar resource {OLD_VALUE} deletedNN
CREATE_CALENDAR_RESOURCE_FEATURECalendar resource feature {NEW_VALUE} createdNN
DELETE_CALENDAR_RESOURCE_FEATURECalendar resource feature {OLD_VALUE} deletedNN
UPDATE_CALENDAR_RESOURCE_FEATURECalendar resource feature {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE}NN
RENAME_CALENDAR_RESOURCECalendar resource {OLD_VALUE} renamed to {NEW_VALUE}NN
UPDATE_CALENDAR_RESOURCECalendar resource {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_CALENDAR_SETTING{SETTING_NAME} for calendar service in your organization changed from {OLD_VALUE} to {NEW_VALUE}NY
CANCEL_CALENDAR_EVENTSEvent cancellation request created for {USER_EMAIL}NN
RELEASE_CALENDAR_RESOURCESRelease resources request created for {USER_EMAIL}NN
CHAT_SETTINGSNote that this page also contains events for Google Hangouts, as well as the previous Google Chat product. Events of this type are returned with type=CHAT_SETTINGS .NN
MEET_INTEROP_CREATE_GATEWAYA Hangouts Meet interoperability gateway was createdNN
MEET_INTEROP_DELETE_GATEWAYA Hangouts Meet interoperability gateway was deletedNN
MEET_INTEROP_MODIFY_GATEWAYA Hangouts Meet interoperability gateway was modifiedNN
CHANGE_CHAT_SETTING{SETTING_NAME} for talk service for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHROME_OS_SETTINGSEvents of this type are returned with type=CHROME_OS_SETTINGS .NN
CHANGE_CHROME_OS_ANDROID_APPLICATION_SETTING{SETTING_NAME} for Android app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_DEVICE_STATEEvent for 'Change device state'.NN
CHANGE_DEVICE_UPGRADEChanged upgrade from {OLD_VALUE} to {NEW_VALUE} for device with serial number {DEVICE_SERIAL_NUMBER} .NN
CHANGE_CHROME_OS_APPLICATION_SETTING{SETTING_NAME} for Chrome app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}NN
SEND_CHROME_OS_DEVICE_COMMANDSent {NEW_VALUE} command to ChromeOS device {DEVICE_SERIAL_NUMBER}NN
CHANGE_CHROME_OS_DEVICE_ANNOTATIONChromeOS device {DEVICE_SERIAL_NUMBER} had its properties updatedNN
CHANGE_CHROME_OS_DEVICE_SETTING{SETTING_NAME} for ChromeOS devices in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_CHROME_OS_DEVICE_STATEState of ChromeOS device {DEVICE_SERIAL_NUMBER} changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_CHROME_OS_PUBLIC_SESSION_SETTING{SETTING_NAME} for ChromeOS managed guest session in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE}NN
INSERT_CHROME_OS_PRINT_SERVERPrint server is added.NN
DELETE_CHROME_OS_PRINT_SERVERExisting print server is deleted.NN
UPDATE_CHROME_OS_PRINT_SERVERExisting print server is updated.NN
INSERT_CHROME_OS_PRINTERPrinter is added.NN
DELETE_CHROME_OS_PRINTERExisting printer is deleted.NN
UPDATE_CHROME_OS_PRINTERExisting printer is updated.NN
CHANGE_CHROME_OS_SETTING{SETTING_NAME} for ChromeOS devices in your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_CHROME_OS_USER_SETTING{SETTING_NAME} for ChromeOS users in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE}NN
CREATE_CHROME_OS_ENROLLMENT_TOKENEvent for 'Create ChromeOS enrollment token'.NN
CHANGE_CHROME_OS_CUSTOM_CONFIGURATIONS_JSON_SETTINGCustom configurations JSON field in the {ORG_UNIT_NAME} organizational unit changed from {OLD_VALUE} to {NEW_VALUE}NN
DELETE_CHROME_OS_DEVICEEvent for 'Delete ChromeOS device'.NN
DELETE_DUPLICATE_CHROME_OS_DEVICEEvent for 'Delete duplicate ChromeOS device'.NN
CHANGE_CHROME_OS_ISOLATED_WEB_APPLICATION_SETTING{SETTING_NAME} for Isolated Web app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}NN
ISSUE_DEVICE_COMMANDEvent for 'Issue device command'.NN
MOVE_DEVICE_TO_ORG_UNIT_DETAILEDEvent for 'Move device to Org Unit'.NN
PRE_PROVISION_CHROME_OS_DEVICEEvent for 'Pre-provision ChromeOS device'.NN
REMOVE_CHROME_OS_APPLICATION_SETTING{APP_TYPE} app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} removedNN
REMOVE_CHROME_OS_APPLICATION_SETTINGSSettings for Chrome app {APP_ID} removedNN
REMOVE_CHROME_OS_WEB_ORIGIN_SETTINGSSettings for web origin {WEB_ORIGIN} for session type {CHROME_OS_SESSION_TYPE} removedNN
REPAIR_CENTER_DEPROVISIONEvent for 'Repair Center deprovision'.NN
REVOKE_CHROME_OS_ENROLLMENT_TOKENEvent for 'Revoke ChromeOS enrollment token'.NN
UPDATE_DEVICEEvent for 'Update device'.NN
CHANGE_CHROME_OS_WEB_APPLICATION_SETTING{SETTING_NAME} for Web app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_CHROME_OS_WEB_PERMISSION_SETTING{SETTING_NAME} for {WEB_ORIGIN} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}NN
CONTACTS_SETTINGSEvents of this type are returned with type=CONTACTS_SETTINGS .NN
CHANGE_CONTACTS_SETTING{SETTING_NAME} for contacts service changed from {OLD_VALUE} to {NEW_VALUE}NN
DOCS_SETTINGSEvents of this type are returned with type=DOCS_SETTINGS .NN
TRANSFER_DOCUMENT_OWNERSHIPOwner of documents changed from {USER_EMAIL} to {NEW_VALUE}NN
DOCS_ORG_BRANDING_PROVISIONINGOrganizational branding provisioning initiated for account {SERVICE_ACCOUNT_EMAIL} and shared drive {SHARED_DRIVE_NAME} with status {ORG_BRANDING_PROVISIONING_STATUS}NN
DOCS_ORG_BRANDING_UPLOADOrganizational branding document upload attempted for document {DOCUMENT_ID} in editor {ORG_BRANDING_EDITOR_TYPE} with status {ORG_BRANDING_UPLOAD_STATUS}NN
DRIVE_DATA_RESTOREDrive data restoration initiated for {USER_EMAIL}NN
CHANGE_DOCS_SETTING{SETTING_NAME} for Drive changed from {OLD_VALUE} to {NEW_VALUE}NN
MOVE_SHARED_DRIVE_TO_ORG_UNITShared drive {SHARED_DRIVE_ID} moved from {ORG_UNIT_NAME} to {NEW_VALUE}NN
DOMAIN_SETTINGSEvents of this type are returned with type=DOMAIN_SETTINGS .NN
CHANGE_ACCOUNT_AUTO_RENEWALAccount automatic renewal changed to {NEW_VALUE} on {DOMAIN_NAME}NN
CHANGE_ADVERTISEMENT_OPTIONAdvertisement option for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CREATE_ALERTAlert {ALERT_NAME} has been createdNN
CHANGE_ALERT_CRITERIAAlert criteria for {ALERT_NAME} has been changedNN
DELETE_ALERTAlert {ALERT_NAME} has been deletedNN
ALERT_RECEIVERS_CHANGEDAlert receivers for {ALERT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
RENAME_ALERTAlert {OLD_VALUE} has been renamed to {NEW_VALUE}NN
ALERT_STATUS_CHANGEDAlert status for {ALERT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
ADD_DOMAIN_ALIASAn unverified {DOMAIN_ALIAS} created as an alias of {DOMAIN_NAME}NN
REMOVE_DOMAIN_ALIAS{DOMAIN_ALIAS} deleted as an alias of {DOMAIN_NAME}NN
SKIP_DOMAIN_ALIAS_MXSkipped MX record setup of alias {DOMAIN_ALIAS} of domain {DOMAIN_NAME}NN
VERIFY_DOMAIN_ALIAS_MXVerified MX record of alias {DOMAIN_ALIAS} of domain {DOMAIN_NAME}NN
VERIFY_DOMAIN_ALIAS{DOMAIN_ALIAS} verified as an alias of {DOMAIN_NAME} using {DOMAIN_VERIFICATION_METHOD}NN
TOGGLE_OAUTH_ACCESS_TO_ALL_APISOAuth access for all APIs changed to {NEW_VALUE} for your organizationNN
TOGGLE_ALLOW_ADMIN_PASSWORD_RESETAllow admin password reset setting changed to {NEW_VALUE}NN
ENABLE_API_ACCESSAPI access for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
REMOVE_API_CLIENT_ACCESSAPI client access to your organization from client {API_CLIENT_NAME} removedNN
CHROME_LICENSES_REDEEMEDLicenses redeemed event name.NN
TOGGLE_AUTO_ADD_NEW_SERVICEAutomatic addition for new services and pre-release features for your organization changed to {NEW_VALUE}NN
CHANGE_PRIMARY_DOMAINPrimary domain name changed from {DOMAIN_NAME} to {NEW_VALUE}NN
CHANGE_WHITELIST_SETTING{SETTING_NAME} changed from {OLD_VALUE} to {NEW_VALUE} for the domainNN
COMMUNICATION_PREFERENCES_SETTING_CHANGE{SETTING_NAME} setting in Communication Preferences changed from {OLD_VALUE} to {NEW_VALUE} (Domain Name : {DOMAIN_NAME} )NN
CHANGE_CONFLICT_ACCOUNT_ACTIONConflict account action for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_CONFLICT_ACCOUNTS_MANAGEMENT_SETTINGSConflict accounts management setting changed to: {CONFLICT_ACCOUNTS_MANAGEMENT_SETTINGS} .NN
ENABLE_FEEDBACK_SOLICITATIONCan contact for feedback setting for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
TOGGLE_CONTACT_SHARINGContact sharing changed to {NEW_VALUE}NN
CREATE_PLAY_FOR_WORK_TOKENMDM vendor enrollment token ( {PLAY_FOR_WORK_TOKEN_ID} ) createdNN
TOGGLE_USE_CUSTOM_LOGOUse custom logo changed to {NEW_VALUE}NN
CHANGE_CUSTOM_LOGONew custom logo uploaded for your organizationNN
CHANGE_DATA_LOCALIZATION_FOR_RUSSIASetting for Data Localization for Russian Federation changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_DATA_LOCALIZATION_SETTINGSetting for Data Localization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_DATA_PROTECTION_OFFICER_CONTACT_INFOPart of an audit log event for contact info update for Data Protection Officer. This is used as an indicator of what kind of event log this message is.NN
DELETE_PLAY_FOR_WORK_TOKENMDM vendor enrollment token ( {PLAY_FOR_WORK_TOKEN_ID} ) deletedNN
VIEW_DNS_LOGIN_DETAILSDNS console login details for {DOMAIN_NAME} viewedNN
CHANGE_DOMAIN_DEFAULT_LOCALEDefault locale for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_DOMAIN_DEFAULT_TIMEZONEDefault time zone for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_DOMAIN_NAMEChange of domain name for {DOMAIN_NAME} to {NEW_VALUE} startedNN
TOGGLE_ENABLE_PRE_RELEASE_FEATURESPre-release features for your organization was set to {NEW_VALUE}NN
CHANGE_DOMAIN_SUPPORT_MESSAGESupport message for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
REMOVE_TRUSTED_DOMAINSDomains {DOMAIN_NAME} removed from Trusted Domains listNY
CHANGE_EDU_TYPEEducational organization type changed from {OLD_VALUE} to {NEW_VALUE}NN
TOGGLE_ENABLE_OAUTH_CONSUMER_KEYEnabling OAuth consumer key changed to {NEW_VALUE} for your organizationNN
TOGGLE_SSLSSL Enforcement changed to {NEW_VALUE} for {DOMAIN_NAME}NN
CHANGE_EU_REPRESENTATIVE_CONTACT_INFOPart of an audit log event for contact info update for EU Representative. This is used as an indicator of what kind of event log this message is.NN
GENERATE_TRANSFER_TOKENTransfer token generatedNN
CHANGE_LOGIN_BACKGROUND_COLORLogin background color for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_LOGIN_BORDER_COLORLogin border color for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_LOGIN_ACTIVITY_TRACEMarketplace Login audit setting in {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
PLAY_FOR_WORK_ENROLLEnrolled for {PLAY_FOR_WORK_MDM_VENDOR_NAME} mobile device management services using token ( {PLAY_FOR_WORK_TOKEN_ID} )NN
PLAY_FOR_WORK_UNENROLLUnenrolled from {PLAY_FOR_WORK_MDM_VENDOR_NAME} mobile device management servicesNN
MX_RECORD_VERIFICATION_CLAIM{USER_EMAIL} claimed to verify the MX record for {DOMAIN_NAME}NN
TOGGLE_NEW_APP_FEATURESNew app features for your organization changed to {NEW_VALUE}NN
TOGGLE_USE_NEXT_GEN_CONTROL_PANELThe setting to enable the new Admin Console changed to {NEW_VALUE} for your organizationNN
UPLOAD_OAUTH_CERTIFICATENew OAuth certificate uploaded for your organizationNN
REGENERATE_OAUTH_CONSUMER_SECRETNew OAuth consumer secret generated for your organizationNN
TOGGLE_OPEN_ID_ENABLEDOpenId federated login for {DOMAIN_NAME} changed to {NEW_VALUE}NN
CHANGE_ORGANIZATION_NAMEOrganization name changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_PASSWORD_MAX_LENGTHPassword maximum length for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_PASSWORD_MIN_LENGTHPassword minimum length for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
UPDATE_DOMAIN_PRIMARY_ADMIN_EMAILPrimary admin for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
ENABLE_SERVICE_OR_FEATURE_NOTIFICATIONSReceive email notification setting for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_RENEW_DOMAIN_REGISTRATIONRenew domain registration setting in {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_RESELLER_ACCESSReseller access changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_RESELLER_ACCESS_FOR_SKUReseller access for {SKU_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
RULE_ACTIONS_CHANGEDRule actions for {RULE_NAME} changedNN
CREATE_RULERule {RULE_NAME} has been createdNN
CHANGE_RULE_CRITERIARule criteria for {RULE_NAME} has been changedNN
DELETE_RULERule {RULE_NAME} has been deletedNN
RENAME_RULERule {OLD_VALUE} has been renamed to {NEW_VALUE}NN
RULE_STATUS_CHANGEDRule status for {RULE_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
ADD_SECONDARY_DOMAINAn unverified {SECONDARY_DOMAIN_NAME} created as a secondary domain of {DOMAIN_NAME}NN
REMOVE_SECONDARY_DOMAIN{SECONDARY_DOMAIN_NAME} deleted as a secondary domain of {DOMAIN_NAME}NN
SKIP_SECONDARY_DOMAIN_MXSkipped MX record setup of secondary domain {SECONDARY_DOMAIN_NAME} of domain {DOMAIN_NAME}NN
VERIFY_SECONDARY_DOMAIN_MXVerified MX records of secondary domain {SECONDARY_DOMAIN_NAME} of domain {DOMAIN_NAME}NN
VERIFY_SECONDARY_DOMAIN{SECONDARY_DOMAIN_NAME} verified as a secondary domain of {DOMAIN_NAME}NN
UPDATE_DOMAIN_SECONDARY_EMAILSecondary email for your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
GENERATE_PINCustomer support PIN generatedNN
UPDATE_RULEUpdate rule event name.NN
EMAIL_SETTINGSEvents of this type are returned with type=EMAIL_SETTINGS .NN
DROP_FROM_QUARANTINEThe title for the event release from quarantine. This title shows the message was dropped from quarantine.NN
EMAIL_LIFE_OF_A_MESSAGEEmail life of a message search is launched.NN
EMAIL_LOG_SEARCHAn email log search is performed for logs from {EMAIL_LOG_SEARCH_START_DATE} to {EMAIL_LOG_SEARCH_END_DATE} with a sender of [ {EMAIL_LOG_SEARCH_SENDER} ], a recipient of [ {EMAIL_LOG_SEARCH_RECIPIENT} ], and an email message id of [ {EMAIL_LOG_SEARCH_MSG_ID} ]NN
EMAIL_UNDELETEEmail restoration from {START_DATE} to {END_DATE} initiated for {USER_EMAIL}NN
CHANGE_EMAIL_SETTING{SETTING_NAME} for email service in your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
DELETE_GMAIL_SETTINGGmail setting {SETTING_NAME} was deletedNY
REJECT_FROM_QUARANTINEThe title for the event release from quarantine. This title shows the message was rejected from quarantine.NN
RELEASE_FROM_QUARANTINEThe title for the event release from quarantine. This title shows the message was released from quarantine.NN
GROUP_SETTINGSEvents of this type are returned with type=GROUP_SETTINGS .NN
WHITELISTED_GROUPS_UPDATEDWhitelisted groups updated event.NN
CREATE_GROUPGroup {GROUP_EMAIL} createdNN
DELETE_GROUPGroup {GROUP_EMAIL} deletedNN
CHANGE_GROUP_DESCRIPTIONDescription for group {GROUP_EMAIL} changedNN
CHANGE_GROUP_EMAILEmail of group {GROUP_EMAIL} changed to {NEW_VALUE}NN
GROUP_LIST_DOWNLOADGroup list was downloaded as a CSV fileNN
REMOVE_GROUP_MEMBERUser {USER_EMAIL} deleted from group {GROUP_EMAIL}NN
UPDATE_GROUP_MEMBERGroup Setting Change.NN
UPDATE_GROUP_MEMBER_DELIVERY_SETTINGSGroup Member Delivery Settings Change.NN
UPDATE_GROUP_MEMBER_DELIVERY_SETTINGS_CAN_EMAIL_OVERRIDEGroup Member Delivery Settings Email Override Change.NN
GROUP_MEMBER_BULK_UPLOADA total of {GROUP_MEMBER_BULK_UPLOAD_TOTAL_NUMBER} members selected for upload. {GROUP_MEMBER_BULK_UPLOAD_FAILED_NUMBER} out of {GROUP_MEMBER_BULK_UPLOAD_TOTAL_NUMBER} members failed to be uploadedNN
GROUP_MEMBERS_DOWNLOADGroup member list was downloaded as a CSV fileNN
CHANGE_GROUP_NAMEName of group {GROUP_EMAIL} changed to {NEW_VALUE}NN
LICENSES_SETTINGSEvents of this type are returned with type=LICENSES_SETTINGS .NN
CHROME_APP_LICENSES_ENABLEDLicenses enabled or not for a specified group/org unit event name.NN
ORG_USERS_LICENSE_ASSIGNMENTLicenses for {PRODUCT_NAME} product and {NEW_VALUE} sku were assigned to all unassigned users of {ORG_UNIT_NAME}NN
ORG_ALL_USERS_LICENSE_ASSIGNMENTLicenses for {PRODUCT_NAME} product and {NEW_VALUE} sku were assigned to all users of {ORG_UNIT_NAME}NN
SUPPRESSED_LICENSE_ASSIGNMENTA suppressed license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL}NN
TEMPORARY_LICENSE_ASSIGNMENTA temporary license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL}NN
USER_LICENSE_ASSIGNMENTA license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL}NN
CHANGE_LICENSE_AUTO_ASSIGNLicense Auto Assign option changed to {NEW_VALUE} for {PRODUCT_NAME} product and {SKU_NAME} skuNN
SUPPRESSED_TO_ASSIGNED_LICENSE_CONVERSIONSuppressed license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was converted to ActiveNN
TEMPORARY_TO_ASSIGNED_LICENSE_CONVERSIONTemporary license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was converted to ActiveNN
TEMPORARY_TO_SUPPRESSED_LICENSE_CONVERSIONTemporary license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was expired and converted to SuppressedNN
FIRST_TEMPORARY_OR_SUPPRESSED_LICENSE_NOTIFICATIONAudit log event generated when first temporary or suppressed license email notification is sent to the customer.NN
RESELLER_FIRST_TEMPORARY_OR_SUPPRESSED_LICENSE_NOTIFICATIONAudit log event generated when first temporary or suppressed license email notification is sent to the reseller.NN
USER_LICENSE_REASSIGNMENTA license for {PRODUCT_NAME} product and {OLD_VALUE} sku was reassigned for user {USER_EMAIL} to new sku {NEW_VALUE}NN
ORG_LICENSE_REVOKELicenses for {PRODUCT_NAME} product and {OLD_VALUE} sku were removed from assigned users of {ORG_UNIT_NAME}NN
SUPPRESSED_LICENSE_REVOKEA suppressed license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from the user {USER_EMAIL}NN
TEMPORARY_LICENSE_REVOKEA temporary license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from the user {USER_EMAIL}NN
USER_LICENSE_REVOKEA license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from user {USER_EMAIL}NN
TEMPORARY_LICENSES_EXPIRED_NOTIFICATIONAudit log event generated when temporary licenses expired email notification is sent to the customer.NN
RESELLER_TEMPORARY_LICENSES_EXPIRED_NOTIFICATIONAudit log event generated when temporary licenses expired email notification is sent to the reseller.NN
UPDATE_DYNAMIC_LICENSEAuto Licensing settings for {PRODUCT_NAME} product in {ORG_UNIT_NAME} organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHROME_APP_USER_LICENSE_ASSIGNEDShort description to indicate user license is assigned.NN
CHROME_APP_USER_LICENSE_REVOKEDShort description to indicate user license is revoked.NN
MOBILE_SETTINGSEvents of this type are returned with type=MOBILE_SETTINGS .NN
ACTION_CANCELLED{ACTION_TYPE} with id {ACTION_ID} on device type {DEVICE_TYPE} and id {DEVICE_ID} was cancelled by user {USER_EMAIL}NN
ACTION_REQUESTED{ACTION_TYPE} with id {ACTION_ID} on device type {DEVICE_TYPE} and id {DEVICE_ID} was requested by user {USER_EMAIL}NN
ADD_MOBILE_CERTIFICATEMobile certificate {MOBILE_CERTIFICATE_COMMON_NAME} added for mobile devices in your organizationNN
APPLE_DEP_SYNC_TRIGGEREDApple DEP sync triggered by {USER_EMAIL}NN
APPLE_DEP_TOKEN_SETUP_COMPLETEApple Device Enrollment tokens updated by {USER_EMAIL}NN
APPLE_VPP_TOKEN_OPERATIONApple VPP token {TOKEN_OPERATION_NAME} was {TOKEN_OPERATION_STATUS}NN
COMPANY_DEVICES_BULK_CREATIONDetails of {NUMBER_OF_COMPANY_OWNED_DEVICES} company owned device(s) were importedNN
COMPANY_OWNED_DEVICE_BLOCKEDCompany owned device {COMPANY_DEVICE_ID} was blockedNN
COMPANY_DEVICE_DELETIONCompany owned device {COMPANY_DEVICE_ID} was deletedNN
COMPANY_OWNED_DEVICE_UNBLOCKEDCompany owned device {COMPANY_DEVICE_ID} was unblockedNN
COMPANY_OWNED_DEVICE_WIPEDCompany owned device {COMPANY_DEVICE_ID} was wipedNN
CUSTOMER_USER_DEVICE_DELETION_EVENTCustomer user device {COMPANY_DEVICE_ID} was deletedNN
CHANGE_MOBILE_APPLICATION_PERMISSION_GRANTChange in mobile application permission grant.NN
CHANGE_MOBILE_APPLICATION_PRIORITY_ORDERChange in priority order of mobile application.NN
REMOVE_MOBILE_APPLICATION_FROM_WHITELIST{DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} is no longer whitelisted for {DISTRIBUTION_ENTITY_NAME} {DISTRIBUTION_ENTITY_TYPE}NN
CHANGE_MOBILE_APPLICATION_SETTINGSChange in mobile application setting.NN
ADD_MOBILE_APPLICATION_TO_WHITELISTMobile application is added to whitelist.NY
MOBILE_DEVICE_APPROVEMobile device for {USER_EMAIL} approvedNN
MOBILE_DEVICE_BLOCKMobile device for {USER_EMAIL} blockedNN
MOBILE_DEVICE_DELETEMobile device for {USER_EMAIL} deletedNN
MOBILE_DEVICE_WIPEMobile device for {USER_EMAIL} wipedNN
CHANGE_MOBILE_SETTING{SETTING_NAME} for mobile devices in your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_ADMIN_RESTRICTIONS_PINAdministrator restrictions PIN for mobile devices in your organization changedNN
CHANGE_MOBILE_WIRELESS_NETWORKMobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} changed for mobile devices in your organizationNN
ADD_MOBILE_WIRELESS_NETWORKMobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} created for mobile devices in your organizationNN
REMOVE_MOBILE_WIRELESS_NETWORKMobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} deleted for mobile devices in your organizationNN
CHANGE_MOBILE_WIRELESS_NETWORK_PASSWORDPassword changed for mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} in your organizationNN
REMOVE_MOBILE_CERTIFICATEMobile certificate {MOBILE_CERTIFICATE_COMMON_NAME} removed for mobile devices in your organizationNN
ENROLL_FOR_GOOGLE_DEVICE_MANAGEMENTGoogle Device Management is a part of the Google Admin console.NN
USE_GOOGLE_MOBILE_MANAGEMENTYou have selected Google Mobile Management to manage all your mobile devicesNN
USE_GOOGLE_MOBILE_MANAGEMENT_FOR_NON_IOSYou have selected Google Mobile Management to manage your Android and Active Sync devicesNN
USE_GOOGLE_MOBILE_MANAGEMENT_FOR_IOSYou have selected Google Mobile Management to manage your iOS devicesNN
MOBILE_ACCOUNT_WIPEMobile account for {USER_EMAIL} has been wipedNN
MOBILE_DEVICE_CANCEL_WIPE_THEN_APPROVEWipe on mobile device for {USER_EMAIL} was cancelled and the device was approvedNN
MOBILE_DEVICE_CANCEL_WIPE_THEN_BLOCKWipe on mobile device for {USER_EMAIL} was cancelled and the device has been blockedNN
ORG_SETTINGSEvents of this type are returned with type=ORG_SETTINGS .NN
CHROME_LICENSES_ENABLEDLicenses enabled or not at an org unit event name.NN
CHROME_APPLICATION_LICENSE_RESERVATION_CREATEDLicense reservation at an org unit is created.NN
CHROME_APPLICATION_LICENSE_RESERVATION_DELETEDLicense reservation at an org unit is deleted.NN
CHROME_APPLICATION_LICENSE_RESERVATION_UPDATEDLicense reservation at an org unit is updated.NN
CREATE_DEVICE_ENROLLMENT_TOKENEvent for 'Create enrollment token'.NN
ASSIGN_CUSTOM_LOGONew custom logo assigned for org unit {ORG_UNIT_NAME}NN
UNASSIGN_CUSTOM_LOGOCustom logo unassigned for org unit {ORG_UNIT_NAME}NN
CREATE_ENROLLMENT_TOKENA new enrollment token is generated for {ORG_UNIT_NAME}NN
REVOKE_ENROLLMENT_TOKENThe enrollment token of {ORG_UNIT_NAME} has been revokedNN
CHROME_LICENSES_ALLOWEDLicenses allowed or not at an org unit event name.NN
CREATE_ORG_UNITOrg Unit {ORG_UNIT_NAME} createdNN
REMOVE_ORG_UNITOrg Unit {ORG_UNIT_NAME} deletedNN
EDIT_ORG_UNIT_DESCRIPTIONDescription of {ORG_UNIT_NAME} changedNN
MOVE_ORG_UNIT{ORG_UNIT_NAME} moved to parent {NEW_VALUE}NN
EDIT_ORG_UNIT_NAMEName of {ORG_UNIT_NAME} changed to {NEW_VALUE}NN
REVOKE_DEVICE_ENROLLMENT_TOKENEvent for 'Revoke enrollment token'.NN
TOGGLE_SERVICE_ENABLEDService {SERVICE_NAME} changed to {NEW_VALUE} for {ORG_UNIT_NAME} organizational unit in your organizationNN
SECURITY_SETTINGSEvents of this type are returned with type=SECURITY_SETTINGS .NN
CHANGE_CAA_APP_ASSIGNMENTSFor {TARGET_ENTITY_TYPE} [ {TARGET_ENTITY_NAME} ]: Before: Access level [ {CAA_ACCESS_ASSIGNMENTS_OLD} ] applied to {CAA_ENFORCEMENT_ENDPOINTS_OLD} of [ {APPLICATION_NAME} ] in [ {MODE} ] mode. After: Access level [ {CAA_ACCESS_ASSIGNMENTS_NEW} ] applied to {CAA_ENFORCEMENT_ENDPOINTS_NEW} of [ {APPLICATION_NAME} ] in [ {MODE} ] mode.NN
UNDERAGE_BLOCK_ALL_THIRD_PARTY_API_ACCESSAll third party API access blocked for users under 18.NN
UNDERAGE_SIGN_IN_ONLY_THIRD_PARTY_API_ACCESSAllow Google Sign-in only third party API access for users under 18.NN
SIGN_IN_ONLY_THIRD_PARTY_API_ACCESSAllow Google Sign-in only third party API accessNN
CHANGE_APP_ACCESS_SETTINGS_COLLECTION_IDApp Access Settings Collection for the org unit {ORG_UNIT_NAME} has changed from {OLD_VALUE} to {NEW_VALUE}NN
ADD_TO_LIMITED_OAUTH2_APPS{OAUTH2_APP_NAME} added to Limited list for {ORG_UNIT_NAME}NN
ADD_TO_TRUSTED_BY_OAUTH_SCOPE_OAUTH2_APPS{OAUTH2_APP_NAME} added to trusted by OAuth scope list for {ORG_UNIT_NAME}NN
ADD_TO_CAA_EXEMPT_OAUTH2_APPS{OAUTH2_APP_NAME} allowlisted for exemption from API access blocks for {ORG_UNIT_NAME}NN
REMOVE_FROM_CAA_EXEMPT_OAUTH2_APPS{OAUTH2_APP_NAME} removed from allowlist for exemption from API access blocks for {ORG_UNIT_NAME}NN
REMOVE_FROM_LIMITED_OAUTH2_APPS{OAUTH2_APP_NAME} removed from Limited list for {ORG_UNIT_NAME}NN
REMOVE_FROM_TRUSTED_BY_OAUTH_SCOPE_OAUTH2_APPS{OAUTH2_APP_NAME} removed from trusted by OAuth scope list for {ORG_UNIT_NAME}NN
MULTIPLE_ADD_TO_BLOCKED_OAUTH2_APPS{OAUTH2_NUM_APPS} apps added to Blocked list for {ORG_UNIT_NAME}NN
MULTIPLE_ADD_TO_LIMITED_OAUTH2_APPS{OAUTH2_NUM_APPS} apps added to Limited list for {ORG_UNIT_NAME}NN
MULTIPLE_ADD_TO_TRUSTED_BY_OAUTH_SCOPE_OAUTH2_APPS{OAUTH2_NUM_APPS} apps added to Trusted by OAuth Scope list for {ORG_UNIT_NAME}NN
MULTIPLE_ADD_TO_TRUSTED_OAUTH2_APPS{OAUTH2_NUM_APPS} apps added to Trusted list for {ORG_UNIT_NAME}NN
OAUTH_APPS_BULK_UPLOAD{BULK_UPLOAD_SUCCESS_OAUTH_APPS_NUMBER} of {BULK_UPLOAD_TOTAL_OAUTH_APPS_NUMBER} rows successfully uploadedNN
OAUTH_APPS_BULK_UPLOAD_NOTIFICATION_SENTNotification of bulk upload for apps list sent to {USER_EMAIL}NN
BLOCK_ON_DEVICE_ACCESSSummary message to display in the audit log when device access for OAuth2 apps is blocked.NN
CHANGE_TWO_STEP_VERIFICATION_FREQUENCY2-step verification frequency for {ORG_UNIT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_TWO_STEP_VERIFICATION_GRACE_PERIOD_DURATION2-step verification grace period duration for {ORG_UNIT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_TWO_STEP_VERIFICATION_START_DATE2-step verification start date has been changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_CAA_ERROR_MESSAGEError message has been changed to [ {NEW_VALUE} ]. (OrgUnit Name: {ORG_UNIT_NAME} )NN
TOGGLE_CAA_REMEDIATION_ENABLEMENTContext Aware Access Remediation has been {NEW_VALUE} . (OrgUnit Name: {ORG_UNIT_NAME} )NN
EDU_OVER_18_APPROVAL_WORKFLOW_DISABLEDDisabled Edu over 18 users apps requests for {ORG_UNIT_NAME}NN
EDU_DELEGATED_USER_APPROVAL_WORKFLOW_DISABLEDDisabled over 18 users making delegated apps requests for {ORG_UNIT_NAME}NN
UNDERAGE_USER_APPROVAL_WORKFLOW_DISABLEDDisabled under 18 users apps requests for {ORG_UNIT_NAME}NN
USER_APPROVAL_WORKFLOW_DISABLEDDisabled users over 18 to make apps requests for {ORG_UNIT_NAME}NN
UNTRUST_DOMAIN_OWNED_OAUTH2_APPSDomain Owned Apps removed from trusted listNN
TRUST_DOMAIN_OWNED_OAUTH2_APPSDomain Owned Apps added to trusted listNN
ENABLE_NON_ADMIN_USER_PASSWORD_RECOVERYEnable non-admin user password recovery setting in {ORG_UNIT_NAME} organization changed from {OLD_VALUE} to {NEW_VALUE}NN
EDU_OVER_18_APPROVAL_WORKFLOW_ENABLEDEnabled Edu over 18 users apps requests for {ORG_UNIT_NAME}NN
EDU_DELEGATED_USER_APPROVAL_WORKFLOW_ENABLEDEnabled over 18 users making delegated apps requests for {ORG_UNIT_NAME}NN
UNDERAGE_USER_APPROVAL_WORKFLOW_ENABLEDEnabled under 18 users apps requests for {ORG_UNIT_NAME}NN
USER_APPROVAL_WORKFLOW_ENABLEDEnabled users over 18 to make apps requests for {ORG_UNIT_NAME}NN
UPDATE_ERROR_MSG_FOR_RESTRICTED_OAUTH2_APPSSummary message to display in the audit log for Oauth2 scope management settings.NN
CHANGE_SESSION_LENGTHSession length has been changed from {OLD_VALUE} to {NEW_VALUE}NN
UNBLOCK_ON_DEVICE_ACCESSSummary message to display in the audit log when device access for OAuth2 apps is unblocked.NN
DOWNLOAD_PENDING_APP_USER_REQUESTSDownloaded list of users requesting access to {OAUTH2_APP_NAME}NN
SITES_SETTINGSEvents of this type are returned with type=SITES_SETTINGS .NN
ADD_WEB_ADDRESSEvent gets triggered when a web address is added via cpanel.NN
DELETE_WEB_ADDRESSEvent gets triggered when a web address is deleted via cpanel.NN
CHANGE_SITES_SETTING{SETTING_NAME} for sites in your organization changed from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_SITES_WEB_ADDRESS_MAPPING_UPDATESSites web address mapping update.NN
VIEW_SITE_DETAILSAdmin viewed the site details of {SITE_NAME}NN
USER_SETTINGSEvents of this type are returned with type=USER_SETTINGS .NN
DELETE_2SV_SCRATCH_CODES2-step verification scratch codes of the user {USER_EMAIL} deletedNN
GENERATE_2SV_SCRATCH_CODESNew 2-step verification scratch codes generated for the user {USER_EMAIL}NN
REVOKE_3LO_DEVICE_TOKENS3-legged OAuth tokens issued by user {USER_EMAIL} for the device type {DEVICE_TYPE} and id {DEVICE_ID} were revokedNN
ACCEPT_USER_INVITATIONUser invitation accepted for user: {USER_EMAIL}NN
ADD_RECOVERY_EMAILRecovery email added for {USER_EMAIL}NN
ADD_RECOVERY_PHONERecovery phone added for {USER_EMAIL}NN
TOGGLE_AUTOMATIC_CONTACT_SHARINGAutomatic contact sharing for {USER_EMAIL} changed to {NEW_VALUE}NN
BULK_UPLOAD{BULK_UPLOAD_TOTAL_USERS_NUMBER} users selected for upload to your organization. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users were not uploaded.NN
BULK_UPLOAD_NOTIFICATION_SENTNotification of bulk users upload sent to {USER_EMAIL}NN
CANCEL_USER_INVITEInvite to {USER_EMAIL} cancelledNN
CHANGE_USER_CUSTOM_FIELD{USER_CUSTOM_FIELD} changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_USER_EXTERNAL_IDExternal Ids changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_USER_GENDERChange here is a verb. The genders will be customizable, so this should be broader than male vs female.NN
CHANGE_USER_IMIMs changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}NN
ENABLE_USER_IP_WHITELISTIP whitelist changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_USER_KEYWORDKeywords are used on user profiles to help identify a user in searches. Example: find person with name 'Larry' and school 'Stanford'. 'Change' is a verb.NN
CHANGE_USER_LANGUAGECan be a predefined set of more common languages provided by Google or a custom language. 'Change' here is a verb.NN
CHANGE_USER_LOCATIONLocation is different from address in the following ways: (1) Location can be fuzzy. Example: Near Seattle. (2) Hovercards and other short user summaries display location, not address. 'Change' is a verb.NN
CHANGE_USER_ORGANIZATIONOrganizations changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_USER_PHONE_NUMBERPhone Numbers changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_RECOVERY_EMAILRecovery email changed for {USER_EMAIL}NN
CHANGE_RECOVERY_PHONERecovery phone changed for {USER_EMAIL}NN
CHANGE_USER_RELATIONRelations changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}NN
CHANGE_USER_ADDRESSAddresses changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}NN
CREATE_EMAIL_MONITORCreated an email monitor for {USER_EMAIL} to {EMAIL_MONITOR_DEST_EMAIL} that will expire on {END_DATE_TIME}NN
DELETE_ACCOUNT_INFO_DUMPDeleted account and login information dump for {USER_EMAIL} and request ID {REQUEST_ID}NN
DELETE_EMAIL_MONITORDeleted an email monitor for {USER_EMAIL} to {EMAIL_MONITOR_DEST_EMAIL}NN
DELETE_MAILBOX_DUMPDeleted mailbox dump for {USER_EMAIL} and request ID {REQUEST_ID}NN
DELETE_PROFILE_PHOTOProfile photo of {USER_EMAIL} has been deletedNN
ADD_DISPLAY_NAME{USER_DISPLAY_NAME} added as a display name of {USER_EMAIL}NN
CHANGE_DISPLAY_NAMEDisplay name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE}NN
REMOVE_DISPLAY_NAME{USER_DISPLAY_NAME} removed as a display name of {USER_EMAIL}NN
CHANGE_FIRST_NAMEFirst name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE}NN
GMAIL_RESET_USERGmail account of {USER_EMAIL} resetNN
CHANGE_LAST_NAMELast name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE}NN
MAIL_ROUTING_DESTINATION_ADDEDUser {USER_EMAIL} has received the following individual mail routing destination: {NEW_VALUE}NN
MAIL_ROUTING_DESTINATION_REMOVEDUser {USER_EMAIL} has had the following individual mail routing destination removed: {OLD_VALUE}NN
ADD_NICKNAME{USER_NICKNAME} created as a nickname of {USER_EMAIL}NN
REMOVE_NICKNAME{USER_NICKNAME} deleted as a nickname of {USER_EMAIL}NN
PASSKEY_REVOKEDA passkey enrolled for user {USER_EMAIL} was revokedNN
CHANGE_PASSWORD_ON_NEXT_LOGINPassword change requirement for {USER_EMAIL} on next login changed from {OLD_VALUE} to {NEW_VALUE}NN
DOWNLOAD_PENDING_INVITES_LISTPending Invites List was downloaded as a CSV fileNN
UPDATE_PUBLIC_KEY_CERTIFICATE_STATUSPublic key certificate status updated to {PUBLIC_KEY_CERTIFICATE_STATUS} for email {USER_IMPACTED_EMAIL} of user {USER_EMAIL}NN
UPDATE_PUBLIC_KEY_CERTIFICATEPublic key certificate updated for {USER_DISPLAY_NAME} email {USER_EMAIL}NN
REMOVE_RECOVERY_EMAILRecovery email removed for {USER_EMAIL}NN
REMOVE_RECOVERY_PHONERecovery phone removed for {USER_EMAIL}NN
REQUEST_ACCOUNT_INFORequested account and login information for {USER_EMAIL}NN
REQUEST_MAILBOX_DUMPRequested mailbox dump for {USER_EMAIL}NN
RESEND_USER_INVITEInvite email to {USER_EMAIL} resentNN
RESET_SIGNIN_COOKIESCookies reset for {USER_EMAIL} and forced re-loginNN
SECURITY_KEY_REGISTERED_FOR_USERSecurity key registered for {USER_EMAIL}NN
REVOKE_SECURITY_KEYA security key enrolled for user {USER_EMAIL} for 2-step verification was revokedNN
USER_INVITE{USER_EMAIL} invited to join your organizationNN
VIEW_TEMP_PASSWORDTemporary password for user {USER_EMAIL} viewed by the adminNN
UNBLOCK_USER_SESSIONUser {USER_EMAIL} unblocked by temporarily disabling login challengeNN
UNMANAGED_USERS_BULK_UPLOADA total of {BULK_UPLOAD_TOTAL_USERS_NUMBER} unmanaged users selected for upload. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users failed to be uploaded.NN
DOWNLOAD_UNMANAGED_USERS_LISTUnmanaged Users list was downloaded as a CSV fileNN
UPDATE_PROFILE_PHOTOProfile photo of {USER_EMAIL} has been updatedNN
UNENROLL_USER_FROM_TITANIUMUser {USER_EMAIL} unenrolled from Advanced ProtectionNN
ARCHIVE_USER{USER_EMAIL} archivedNN
UPDATE_BIRTHDATEThe birth date for {USER_EMAIL} changed to {BIRTHDATE}NN
USER_CREATED_PASSKEY_REVOKEA user created passkey enrolled for user {USER_EMAIL} was revokedNN
DOWNGRADE_USER_FROM_GPLUS{USER_EMAIL} was downgraded from Google+NN
USER_ENROLLED_IN_TWO_STEP_VERIFICATION{USER_EMAIL} enrolled in 2-step verificationNN
DOWNLOAD_USERLIST_CSVUser list was downloaded as a CSV fileNN
DOWNLOAD_USERLISTUser list was downloaded in {FORMAT}NN
USER_PUT_IN_TWO_STEP_VERIFICATION_GRACE_PERIOD2-step verification grace period has been enabled on {USER_EMAIL} till {NEW_VALUE}NN
UNENROLL_USER_FROM_STRONG_AUTHUser {USER_EMAIL} unenrolled from Strong AuthNY
UNARCHIVE_USER{USER_EMAIL} unarchivedNN
UNDELETE_USER{USER_EMAIL} undeletedNN
UPGRADE_USER_TO_GPLUS{USER_EMAIL} was upgraded to Google+NN
USERS_BULK_UPLOADA total of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users selected for upload. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users failed to be uploaded.NN
USERS_BULK_UPLOAD_NOTIFICATION_SENTNotification of bulk users upload sent to {USER_EMAIL}NN

any: Admin Console (any event)

#
ApplicationName
admin

Description

Source-only rules that filter on applicationName 'admin' without specifying an eventName attribute here.

References #

ADD_APPLICATION: Add Application

#
ApplicationName
admin

Description

An application was added to the Google Workspace domain.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Application Added to Google Workspace Domain source high: Detects when an administrator adds a Google Workspace Marketplace application to the domain. Adversaries with administrative access may register a malicious OAuth application to establish long-lived API access to mail, drive, and other Workspace data, maintaining persistence and enabling collection without relying on a single user password alone.T1098, T1098.001

YARA-L #

  • Google Workspace Application Added source high: Identifies when a Marketplace app is added in a Google Workspace organization. Installing certain apps may increase the organization's risk of data exfiltration/leakage and increase its attack surface.

Panther #

References #

ADD_GROUP_MEMBER: Group Member Creation

#
ApplicationName
admin

Description

A user was added to a group.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-08-02T07:23:13.421Z",
    "uniqueQualifier": "-6242204098544478741",
    "applicationName": "admin",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/9oyhwvio4MjL25Tdz-HrTS7DwCc\"",
  "actor": {
    "callerType": "USER",
    "email": "admin@cloud-response.com",
    "profileId": "111440584475724055600"
  },
  "ipAddress": "86.48.11.48",
  "events": [
    {
      "type": "GROUP_SETTINGS",
      "name": "ADD_GROUP_MEMBER",
      "parameters": [
        {
          "name": "USER_EMAIL",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "GROUP_EMAIL",
          "value": "sales@cloud-response.com"
        }
      ]
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

YARA-L #

  • Google Workspace External User Added To Group source medium: Identifies when an external user account is added to a group in Google Workspace. Security teams can monitor for unexpected user accounts being added to Google Workspace groups to prevent unauthorized access to data.T1078

References #

ADD_PRIVILEGE: Add Privilege

#
ApplicationName
admin

Description

A privilege was added to a role.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Google Workspace Role Modified source high: Detects when a custom admin role or its privileges are modified in Google Workspace. Adversaries may add or expand privileges on an existing role to elevate access for assigned users or groups without creating a new role or directly assigning a well-known admin role. Because privilege changes take effect for all principals assigned the role, modifying role permissions can silently expand access across multiple accounts.T1098↳ also matches UPDATE_ROLE: Update Role

References #

ADD_TRUSTED_DOMAINS: Domains added to Trusted Domains

#
ApplicationName
admin

Description

A domain was added to the trusted domains list.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Domain Added to Google Workspace Trusted Domains source high: Detects when an administrator adds a domain to the Google Workspace allowlisted (trusted) domains list. Adversaries with administrative access may onboard a domain they control to relax cross-organization sharing restrictions, enabling data collection and exfiltration through Drive, Chat, and other services that honor the tenant trust boundary.T1484, T1484.002, T1562, T1562.007

YARA-L #

  • Google Workspace New Trusted Domain Added source high: Identifies when a domain is added to the list of trusted domains in Google Workspace. An adversary may attempt to manipulate sharing settings for trusted domains to gain unauthorized access to sensitive files and folders within an organization.T1562

Panther #

References #

ALLOW_STRONG_AUTHENTICATION: Allow 2-Step Verification

#
ApplicationName
admin

Description

The administrator changed the MFA enforcement setting (allow/require strong authentication).

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
google_workspace.admin.new_value (GWS)eqfalse2 ruleselastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

YARA-L #

References #

ASSIGN_ROLE: Assign Role

#
ApplicationName
admin

Description

An admin role was assigned to a user or service account.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-03-19T22:20:43.530Z",
    "uniqueQualifier": "-7508907472163717949",
    "applicationName": "admin",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/mBEzkDVa6667CpQAnS5-siNE7Q8\"",
  "actor": {
    "callerType": "USER",
    "email": "admin@cloud-response.com",
    "profileId": "111440584475724055600"
  },
  "ipAddress": "80.114.222.200",
  "events": [
    {
      "type": "DELEGATED_ADMIN_SETTINGS",
      "name": "ASSIGN_ROLE",
      "parameters": [
        {
          "name": "ROLE_NAME",
          "value": "_SEED_ADMIN_ROLE"
        },
        {
          "name": "USER_EMAIL",
          "value": "greg@cloud-response.com"
        }
      ]
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
security_result.category_details (Chronicle)eqDELEGATED_ADMIN_SETTINGS1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Google Workspace Admin Role Assigned to a User or Group source high: Assigning an administrative role to a user or group grants elevated privileges within Google Workspace, including access to the Google Admin console and the ability to manage domain resources and applications. Adversaries may assign administrator roles to an existing account or a newly created account/group to establish persistence, facilitate privilege escalation, and enable follow-on actions across the tenant. In particular, users with Super Admin privileges can bypass single sign-on (SSO) if it is enabled in Google Workspace.T1098, T1098.003

YARA-L #

  • Google Workspace Admin Role Assignment source high: Identifies when an administrator role is assigned to a user account in Google Workspace. Security teams can monitor for the malicious or accidental assignment of administrator privileges to prevent unauthorized access to data.T1098

References #

AUTHORIZE_API_CLIENT_ACCESS: API Client Access Authorize

#
ApplicationName
admin

Description

An API client was authorized domain-wide access via OAuth.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-07-19T07:27:14.787Z",
    "uniqueQualifier": "-3655413010083625269",
    "applicationName": "admin",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/d2q8JXudtHXN9ju8y1422NasFeM\"",
  "actor": {
    "email": "admin@cloud-response.com",
    "profileId": "111440584475724055600"
  },
  "events": [
    {
      "type": "DOMAIN_SETTINGS",
      "name": "AUTHORIZE_API_CLIENT_ACCESS",
      "parameters": [
        {
          "name": "DOMAIN_NAME",
          "value": ""
        },
        {
          "name": "API_CLIENT_NAME",
          "value": "106850843410684334493"
        },
        {
          "name": "API_SCOPES",
          "value": "https://www.googleapis.com/auth/admin.reports.audit.readonly"
        }
      ]
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Google Workspace API Access Granted via Domain-Wide Delegation source high: Detects when a super administrator authorizes domain-wide delegation (DWD) API client access for a Google Cloud service account or OAuth client. DWD lets an application impersonate users and access Workspace APIs across the tenant. Adversaries with admin access may register or authorize a malicious client with broad scopes to maintain API-based persistence and access mail, drive, and directory data without relying on a single user's password alone.T1098

Kusto #

References #

CHANGE_APPLICATION_SETTING: Application Setting Change

#
ApplicationName
admin

Description

A setting for a Google Workspace application was modified.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-07-19T06:43:02.250Z",
    "uniqueQualifier": "-6822745075951815011",
    "applicationName": "admin",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/1UHNER-nXmxzm1FTJ6hrJsN1r5w\"",
  "actor": {
    "callerType": "USER",
    "email": "admin@cloud-response.com",
    "profileId": "111440584475724055600"
  },
  "ipAddress": "80.114.222.200",
  "events": [
    {
      "type": "APPLICATION_SETTINGS",
      "name": "CHANGE_APPLICATION_SETTING",
      "parameters": [
        {
          "name": "APPLICATION_NAME",
          "value": "Google Cloud Platform Sharing Options"
        },
        {
          "name": "ORG_UNIT_NAME",
          "value": "cloud-response.com"
        },
        {
          "name": "SETTING_NAME",
          "value": "Data Sharing Settings between GCP and Google Workspace \"Sharing Options\""
        },
        {
          "name": "OLD_VALUE",
          "value": "DISABLED"
        },
        {
          "name": "NEW_VALUE",
          "value": "ENABLED"
        }
      ]
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
google_workspace.admin.application.name (GWS)eqgoogle workspace marketplace2 ruleselastic
parameters.APPLICATION_NAME (panther rule field)eqgmail2 rulespanther
parameters.NEW_VALUE (panther rule field)eqtrue2 rulespanther
security_result.category_details (Chronicle)eqAPPLICATION_SETTINGS2 ruleschronicle
type (panther rule field)eqAPPLICATION_SETTINGS2 rulespanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • Google Workspace Application Access Level Modified source medium: Detects when an access level is changed for a Google workspace application. An access level is part of BeyondCorp Enterprise which is Google Workspace's way of enforcing Zero Trust model. An adversary would be able to remove access levels to gain easier access to Google workspace resources.T1098, T1098.003

Elastic #

YARA-L #

Panther #

References #

CHANGE_GMAIL_SETTING: Gmail Setting Change

#
ApplicationName
admin

Description

A Gmail routing or mail-flow setting was changed.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

References #

CREATE_APPLICATION_SETTING: Application Setting Creation

#
ApplicationName
admin

Description

A new application setting was created.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
security_result.category_details (Chronicle)eqAPPLICATION_SETTINGS1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

YARA-L #

Panther #

References #

CREATE_DATA_TRANSFER_REQUEST: Data transfer request created

#
ApplicationName
admin

Description

An admin initiated a data transfer (Drive file ownership reassignment) to another user.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
security_result.category_details (Chronicle)eqUSER_SETTINGS1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

YARA-L #

References #

CREATE_GMAIL_SETTING: Gmail Setting Creation

#
ApplicationName
admin

Description

A new Gmail routing or mail-flow setting was created.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

References #

CREATE_ROLE: Create Role

#
ApplicationName
admin

Description

A custom admin role was created.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
security_result.category_details (Chronicle)eqDELEGATED_ADMIN_SETTINGS1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Google Workspace Custom Admin Role Created source medium: Detects when a custom administrative role is created in Google Workspace. Unlike prebuilt admin roles, custom roles allow granular selection of privileges across Google services and can be assigned to users or groups. Adversaries may create a custom admin role to craft elevated permissions tailored to their objectives, then assign that role to a compromised or attacker-controlled account to establish persistence and enable follow-on actions such as modifying security controls, granting OAuth access, or changing mail routing.T1098, T1098.003

YARA-L #

  • Google Workspace Custom Admin Role Created source high: Identifies when a custom administrator role is created in Google Workspace. Security teams can monitor for malicious or accidental configuration of administrator privileges to prevent unauthorized access to data.T1098

Panther #

References #

CUSTOMER_TAKEOUT_CREATED: Customer Takeout Created

#
ApplicationName
admin

Description

An admin initiated a Takeout export job for organizational data.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

References #

DELETE_ROLE: Delete Role

#
ApplicationName
admin

Description

An admin role was permanently deleted.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Google Workspace Admin Role Deletion source medium: Detects when a custom administrative role is deleted in Google Workspace. Adversaries may delete a custom admin role to disrupt delegated administration, remove security team access, or hinder incident response. Deleting a role removes the privileges it granted from all assigned users and groups, which can cause operational impact or blind spots during an active investigation.T1484, T1531

References #

ENFORCE_STRONG_AUTHENTICATION: Enforce 2-Step Verification

#
ApplicationName
admin

Description

The MFA/2SV enforcement policy was changed for the domain or an organizational unit.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
google_workspace.admin.new_value (GWS)eqfalse2 ruleselastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

YARA-L #

References #

GRANT_ADMIN_PRIVILEGE: Admin Privileges Grant

#
ApplicationName
admin

Description

Administrator privileges were granted to a user account.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

References #

GRANT_DELEGATED_ADMIN_PRIVILEGES: Delegated Admin Privileges Grant

#
ApplicationName
admin

Description

Delegated administrator privileges were granted to a user.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

MOVE_USER_TO_ORG_UNIT: User OrgUnit Change

#
ApplicationName
admin

Description

A user was moved to a different organizational unit.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
google_workspace.event.type (GWS)equser_settings1 ruleelastic
security_result.category_details (Chronicle)eqUSER_SETTINGS1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Google Workspace User Organizational Unit Changed source low: Users in Google Workspace are typically assigned a specific organizational unit that grants them permissions to certain services and roles that are inherited from this organizational unit. Adversaries may compromise a valid account and change which organizational account the user belongs to which then could allow them to inherit permissions to applications and resources inaccessible prior to.T1098, T1098.003

YARA-L #

References #

REMOVE_APPLICATION: Remove Application

#
ApplicationName
admin

Description

An application was removed from the Google Workspace domain.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

REMOVE_APPLICATION_FROM_WHITELIST: Remove Application from Whitelist

#
ApplicationName
admin

Description

An application was removed from the domain's marketplace allowlist.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

REMOVE_PRIVILEGE: Remove Privilege

#
ApplicationName
admin

Description

A privilege was removed from a role.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

RENAME_ROLE: Rename Role

#
ApplicationName
admin

Description

An admin role was renamed.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

SAML2_SERVICE_PROVIDER_CONFIG: SAML2 Service Provider Config

#
ApplicationName
admin

Description

A SAML 2.0 service provider configuration was added, modified, or removed.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

TOGGLE_OUTBOUND_RELAY: Outbound Relay Change

#
ApplicationName
admin

Description

Outbound email relay routing was enabled or disabled.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

TURN_OFF_2_STEP_VERIFICATION: Turn off 2-step verification

#
ApplicationName
admin

Description

2-Step Verification was disabled for a user or the domain.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

UNSUSPEND_USER: User Unsuspension

#
ApplicationName
admin

Description

A suspended user account was reactivated.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
google_workspace.event.type (GWS)equser_settings1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

YARA-L #

References #

UPDATE_ROLE: Update Role

#
ApplicationName
admin

Description

An existing admin role was modified (e.g. description or privileges changed).

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Google Workspace Role Modified source high: Detects when a custom admin role or its privileges are modified in Google Workspace. Adversaries may add or expand privileges on an existing role to elevate access for assigned users or groups without creating a new role or directly assigning a well-known admin role. Because privilege changes take effect for all principals assigned the role, modifying role permissions can silently expand access across multiple accounts.T1098↳ also matches ADD_PRIVILEGE: Add Privilege

References #

BLOCK_ALL_THIRD_PARTY_API_ACCESS: All third party API access blocked

#
ApplicationName
admin

Description

An admin blocked all third-party application access to Google Workspace APIs.

References #

UNBLOCK_ALL_THIRD_PARTY_API_ACCESS: All third party API access unblocked

#
ApplicationName
admin

Description

An admin unblocked third-party application access to Google Workspace APIs.

References #

ADD_TO_TRUSTED_OAUTH2_APPS: App trusted

#
ApplicationName
admin

Description

An OAuth2 application was added to the trusted apps list.

References #

ADD_TO_BLOCKED_OAUTH2_APPS: App added to Blocked list

#
ApplicationName
admin

Description

An OAuth2 application was blocked from accessing Google Workspace data.

References #

REMOVE_FROM_BLOCKED_OAUTH2_APPS: App removed from Blocked list

#
ApplicationName
admin

Description

An OAuth2 application was removed from the blocked apps list.

References #

REMOVE_FROM_TRUSTED_OAUTH2_APPS: App no longer trusted

#
ApplicationName
admin

Description

An OAuth2 application was removed from the trusted apps list.

References #

CREATE_USER: User Creation

#
ApplicationName
admin

Description

A new user account was created in the Google Workspace domain.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-07-19T10:30:16.448Z",
    "uniqueQualifier": "-6485662965628883717",
    "applicationName": "admin",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/xgZr-1-dUUwmP7cz8G9pXT-7nL8\"",
  "actor": {
    "callerType": "USER",
    "email": "admin@cloud-response.com",
    "profileId": "111440584475724055600"
  },
  "ipAddress": "80.114.222.200",
  "events": [
    {
      "type": "USER_SETTINGS",
      "name": "CREATE_USER",
      "parameters": [
        {
          "name": "USER_EMAIL",
          "value": "suspicious@cloud-response.com"
        }
      ]
    }
  ]
}

References #

DELETE_USER: User Deletion

#
ApplicationName
admin

Description

A user account was deleted from the Google Workspace domain.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-08-11T09:11:04.542Z",
    "uniqueQualifier": "-8365490708529497756",
    "applicationName": "admin",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/PargyQuH7NlMI8Ov8vSZAlDrUEU\"",
  "actor": {
    "callerType": "USER",
    "email": "admin@cloud-response.com",
    "profileId": "111440584475724055600"
  },
  "ipAddress": "145.128.241.109",
  "events": [
    {
      "type": "USER_SETTINGS",
      "name": "DELETE_USER",
      "parameters": [
        {
          "name": "USER_EMAIL",
          "value": "workspace@cloud-response.com"
        }
      ]
    }
  ]
}

References #

SUSPEND_USER: User Suspension

#
ApplicationName
admin

Description

A user account was suspended by an administrator.

References #

RENAME_USER: User Rename

#
ApplicationName
admin

Description

A user's primary email address was changed.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-07-21T13:37:47.057Z",
    "uniqueQualifier": "-6570038635980180654",
    "applicationName": "admin",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/v88-DyEM0pnIGTdGBaEFFudjFic\"",
  "actor": {
    "callerType": "USER",
    "email": "admin@cloud-response.com",
    "profileId": "111440584475724055600"
  },
  "ipAddress": "80.114.222.200",
  "events": [
    {
      "type": "USER_SETTINGS",
      "name": "RENAME_USER",
      "parameters": [
        {
          "name": "USER_EMAIL",
          "value": "suspicious@cloud-response.com"
        },
        {
          "name": "NEW_VALUE",
          "value": "workspace@cloud-response.com"
        }
      ]
    },
    {
      "type": "USER_SETTINGS",
      "name": "CHANGE_FIRST_NAME",
      "parameters": [
        {
          "name": "USER_EMAIL",
          "value": "suspicious@cloud-response.com"
        },
        {
          "name": "OLD_VALUE",
          "value": "Suspicious"
        },
        {
          "name": "NEW_VALUE",
          "value": "Workspace"
        }
      ]
    },
    {
      "type": "USER_SETTINGS",
      "name": "CHANGE_LAST_NAME",
      "parameters": [
        {
          "name": "USER_EMAIL",
          "value": "suspicious@cloud-response.com"
        },
        {
          "name": "OLD_VALUE",
          "value": "account"
        },
        {
          "name": "NEW_VALUE",
          "value": "Admin"
        }
      ]
    }
  ]
}

References #

CHANGE_PASSWORD: Password Change

#
ApplicationName
admin

Description

An administrator changed a user's password.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-07-21T13:38:00.608Z",
    "uniqueQualifier": "-8471045246260126614",
    "applicationName": "admin",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/41AqQRL7AL27pZdLqUiiksMUcEQ\"",
  "actor": {
    "callerType": "USER",
    "email": "admin@cloud-response.com",
    "profileId": "111440584475724055600"
  },
  "ipAddress": "80.114.222.200",
  "events": [
    {
      "type": "USER_SETTINGS",
      "name": "CHANGE_PASSWORD",
      "parameters": [
        {
          "name": "USER_EMAIL",
          "value": "workspace@cloud-response.com"
        }
      ]
    }
  ]
}

References #

REVOKE_ASP: Application Specific Password Revoke

#
ApplicationName
admin

Description

An administrator revoked an application-specific password (ASP) for a user.

References #

REVOKE_3LO_TOKEN: 3-legged OAuth Token Revoke

#
ApplicationName
admin

Description

An administrator revoked an OAuth token for a user.

References #

SESSION_CONTROL_SETTINGS_CHANGE: Session Control Settings Change

#
ApplicationName
admin

Description

Web session duration or re-authentication settings were changed.

References #

WEAK_PROGRAMMATIC_LOGIN_SETTINGS_CHANGED: Less Secure Apps Access setting changed

#
ApplicationName
admin

Description

Settings controlling less-secure app access (LSA/basic auth) were changed.

References #

CHANGE_SSO_SETTINGS: SSO Setting Change

#
ApplicationName
admin

Description

SAML/SSO settings for the domain were changed.

References #

TOGGLE_SSO_ENABLED: Enable SSO Change

#
ApplicationName
admin

Description

SSO (SAML-based single sign-on) was enabled or disabled for the domain.

References #

REVOKE_ADMIN_PRIVILEGE: Admin Privileges Revoke

#
ApplicationName
admin

Description

Administrator privileges were revoked from a user account.

References #

ALLOW_SERVICE_FOR_OAUTH2_ACCESS: API Access Allowed

#
ApplicationName
admin

Description

A Google service was allowed for OAuth2 API access.

References #

DISALLOW_SERVICE_FOR_OAUTH2_ACCESS: API Access Blocked

#
ApplicationName
admin

Description

A Google service was disallowed for OAuth2 API access.

References #

TOGGLE_CAA_ENABLEMENT: Context Aware Access Enablement

#
ApplicationName
admin

Description

Context-Aware Access was enabled or disabled for the domain.

References #

CHANGE_GROUP_SETTING: Group Setting Change

#
ApplicationName
admin

Description

A setting for a Google Group was changed by an administrator.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-08-02T07:23:13.089Z",
    "uniqueQualifier": "-8719895655046965875",
    "applicationName": "admin",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/u50Xc4yaXja3OryKbjY0C8gwceE\"",
  "actor": {
    "callerType": "USER",
    "email": "admin@cloud-response.com",
    "profileId": "111440584475724055600"
  },
  "ipAddress": "86.48.11.48",
  "events": [
    {
      "type": "GROUP_SETTINGS",
      "name": "CHANGE_GROUP_SETTING",
      "parameters": [
        {
          "name": "SETTING_NAME",
          "value": "WHO_CAN_POST_MESSAGE"
        },
        {
          "name": "GROUP_EMAIL",
          "value": "sales@cloud-response.com"
        },
        {
          "name": "OLD_VALUE",
          "value": "ANYONE_CAN_POST"
        },
        {
          "name": "NEW_VALUE",
          "value": "ALL_MEMBERS_CAN_POST"
        }
      ]
    },
    {
      "type": "GROUP_SETTINGS",
      "name": "CHANGE_GROUP_SETTING",
      "parameters": [
        {
          "name": "SETTING_NAME",
          "value": "IS_ARCHIVED"
        },
        {
          "name": "GROUP_EMAIL",
          "value": "sales@cloud-response.com"
        },
        {
          "name": "OLD_VALUE",
          "value": "false"
        },
        {
          "name": "NEW_VALUE",
          "value": "true"
        }
      ]
    }
  ]
}

References #

ADD_APPLICATION_TO_WHITELIST: Add Application to Whitelist

#
ApplicationName
admin

Description

An application was added to the domain's Google Workspace Marketplace allowlist.

References #

CHANGE_TWO_STEP_VERIFICATION_ENROLLMENT_PERIOD_DURATION: Change 2-Step Verification Enrollment Period Duration

#
ApplicationName
admin

Description

The enrollment period for 2-Step Verification was changed.

References #

CHANGE_ALLOWED_TWO_STEP_VERIFICATION_METHODS: Change Allowed 2-step Verification Methods

#
ApplicationName
admin

Description

The allowed methods for 2-Step Verification were changed.

References #

APPLICATION_SETTINGS: Application Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=APPLICATION_SETTINGS .

References #

DELETE_APPLICATION_SETTING: Application Setting Deletion

#
ApplicationName
admin

Description

For {APPLICATION_NAME} , {SETTING_NAME} with value {OLD_VALUE} deleted

References #

REORDER_GROUP_BASED_POLICIES_EVENT: Application Setting Group Priorities Change

#
ApplicationName
admin

Description

For {APPLICATION_NAME} , group override priorities for {SETTING_NAME} changed to {GROUP_PRIORITIES} .

References #

GPLUS_PREMIUM_FEATURES: Google+ Premium Features

#
ApplicationName
admin

Description

Premium features for Google+ service for your organization changed to {NEW_VALUE}

References #

CREATE_MANAGED_CONFIGURATION: Managed configuration is created

#
ApplicationName
admin

Description

Managed configuration with name {MANAGED_CONFIGURATION_NAME} is created for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} .

References #

DELETE_MANAGED_CONFIGURATION: Managed configuration is deleted

#
ApplicationName
admin

Description

Managed configuration with name {MANAGED_CONFIGURATION_NAME} is deleted for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} .

References #

UPDATE_MANAGED_CONFIGURATION: Managed configuration is updated

#
ApplicationName
admin

Description

Managed configuration with name {MANAGED_CONFIGURATION_NAME} is updated for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} .

References #

FLASHLIGHT_EDU_NON_FEATURED_SERVICES_SELECTED: Non-Featured Services Selected

#
ApplicationName
admin

UPDATE_SMART_FEATURES: Update Smart features and personalization

#
ApplicationName
admin

Description

Smart features and personalization setting has been updated to {NEW_VALUE}

References #

CALENDAR_SETTINGS: Calendar Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=CALENDAR_SETTINGS .

References #

CREATE_BUILDING: Building Creation

#
ApplicationName
admin

Description

Building {NEW_VALUE} created

References #

DELETE_BUILDING: Building Deletion

#
ApplicationName
admin

Description

Building {OLD_VALUE} deleted

References #

UPDATE_BUILDING: Building Update

#
ApplicationName
admin

Description

Building {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE}

References #

EWS_IN_NEW_CREDENTIALS_GENERATED: Calendar Interop credentials generated

#
ApplicationName
admin

Description

Short description for EWS IN credentials generation.

References #

EWS_OUT_ENDPOINT_CONFIGURATION_RESET: Calendar Interop Exchange endpoint configuration cleared

#
ApplicationName
admin

Description

Short description for clearing Calendar Interop Exchange endpoint configuration.

References #

EWS_OUT_ENDPOINT_CONFIGURATION_CHANGED: Calendar Interop Exchange endpoint configuration updated

#
ApplicationName
admin

Description

Short description for changing Calendar Interop Exchange endpoint configuration.

References #

CREATE_CALENDAR_RESOURCE: Calendar Resource Creation

#
ApplicationName
admin

Description

Calendar resource {NEW_VALUE} created

References #

DELETE_CALENDAR_RESOURCE: Calendar Resource Deletion

#
ApplicationName
admin

Description

Calendar resource {OLD_VALUE} deleted

References #

CREATE_CALENDAR_RESOURCE_FEATURE: Calendar Resource Feature Creation

#
ApplicationName
admin

Description

Calendar resource feature {NEW_VALUE} created

References #

DELETE_CALENDAR_RESOURCE_FEATURE: Calendar Resource Feature Deletion

#
ApplicationName
admin

Description

Calendar resource feature {OLD_VALUE} deleted

References #

UPDATE_CALENDAR_RESOURCE_FEATURE: Calendar Resource Feature Update

#
ApplicationName
admin

Description

Calendar resource feature {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE}

References #

RENAME_CALENDAR_RESOURCE: Calendar Resource Rename

#
ApplicationName
admin

Description

Calendar resource {OLD_VALUE} renamed to {NEW_VALUE}

References #

UPDATE_CALENDAR_RESOURCE: Calendar Resource Update

#
ApplicationName
admin

Description

Calendar resource {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_CALENDAR_SETTING: Calendar Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for calendar service in your organization changed from {OLD_VALUE} to {NEW_VALUE}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

CANCEL_CALENDAR_EVENTS: Event cancellation request created

#
ApplicationName
admin

Description

Event cancellation request created for {USER_EMAIL}

References #

RELEASE_CALENDAR_RESOURCES: Release resources request created

#
ApplicationName
admin

Description

Release resources request created for {USER_EMAIL}

References #

CHAT_SETTINGS: Talk Settings

#
ApplicationName
admin

Description

Note that this page also contains events for Google Hangouts, as well as the previous Google Chat product. Events of this type are returned with type=CHAT_SETTINGS .

References #

MEET_INTEROP_CREATE_GATEWAY: A Google Meet interoperability gateway was created.

#
ApplicationName
admin

Description

A Hangouts Meet interoperability gateway was created

References #

MEET_INTEROP_DELETE_GATEWAY: A Google Meet interoperability gateway was deleted.

#
ApplicationName
admin

Description

A Hangouts Meet interoperability gateway was deleted

References #

MEET_INTEROP_MODIFY_GATEWAY: A Google Meet interoperability gateway was modified.

#
ApplicationName
admin

Description

A Hangouts Meet interoperability gateway was modified

References #

CHANGE_CHAT_SETTING: Hangouts Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for talk service for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHROME_OS_SETTINGS: ChromeOS Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=CHROME_OS_SETTINGS .

References #

CHANGE_CHROME_OS_ANDROID_APPLICATION_SETTING: Android Application Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for Android app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_DEVICE_STATE: Change device state

#
ApplicationName
admin

Description

Event for 'Change device state'.

References #

CHANGE_DEVICE_UPGRADE: Change Device Upgrade

#
ApplicationName
admin

Description

Changed upgrade from {OLD_VALUE} to {NEW_VALUE} for device with serial number {DEVICE_SERIAL_NUMBER} .

References #

CHANGE_CHROME_OS_APPLICATION_SETTING: Chrome Application Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for Chrome app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}

References #

SEND_CHROME_OS_DEVICE_COMMAND: ChromeOS Device Command

#
ApplicationName
admin

Description

Sent {NEW_VALUE} command to ChromeOS device {DEVICE_SERIAL_NUMBER}

References #

CHANGE_CHROME_OS_DEVICE_ANNOTATION: ChromeOS Device Property Change

#
ApplicationName
admin

Description

ChromeOS device {DEVICE_SERIAL_NUMBER} had its properties updated

References #

CHANGE_CHROME_OS_DEVICE_SETTING: ChromeOS Device Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for ChromeOS devices in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_CHROME_OS_DEVICE_STATE: ChromeOS Device State Change

#
ApplicationName
admin

Description

State of ChromeOS device {DEVICE_SERIAL_NUMBER} changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_CHROME_OS_PUBLIC_SESSION_SETTING: ChromeOS managed guest session setting change

#
ApplicationName
admin

Description

{SETTING_NAME} for ChromeOS managed guest session in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE}

References #

INSERT_CHROME_OS_PRINT_SERVER: ChromeOS Print Server Added

#
ApplicationName
admin

Description

Print server is added.

References #

DELETE_CHROME_OS_PRINT_SERVER: ChromeOS Print Server Deleted

#
ApplicationName
admin

Description

Existing print server is deleted.

References #

UPDATE_CHROME_OS_PRINT_SERVER: ChromeOS Print Server Updated

#
ApplicationName
admin

Description

Existing print server is updated.

References #

INSERT_CHROME_OS_PRINTER: ChromeOS Printer Added

#
ApplicationName
admin

Description

Printer is added.

References #

DELETE_CHROME_OS_PRINTER: ChromeOS Printer Deleted

#
ApplicationName
admin

Description

Existing printer is deleted.

References #

UPDATE_CHROME_OS_PRINTER: ChromeOS Printer Updated

#
ApplicationName
admin

Description

Existing printer is updated.

References #

CHANGE_CHROME_OS_SETTING: ChromeOS Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for ChromeOS devices in your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_CHROME_OS_USER_SETTING: ChromeOS User Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for ChromeOS users in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE}

References #

CREATE_CHROME_OS_ENROLLMENT_TOKEN: Create ChromeOS enrollment token

#
ApplicationName
admin

Description

Event for 'Create ChromeOS enrollment token'.

References #

CHANGE_CHROME_OS_CUSTOM_CONFIGURATIONS_JSON_SETTING: Custom Configurations JSON Setting Change

#
ApplicationName
admin

Description

Custom configurations JSON field in the {ORG_UNIT_NAME} organizational unit changed from {OLD_VALUE} to {NEW_VALUE}

References #

DELETE_CHROME_OS_DEVICE: Delete ChromeOS device

#
ApplicationName
admin

Description

Event for 'Delete ChromeOS device'.

References #

DELETE_DUPLICATE_CHROME_OS_DEVICE: Delete duplicate ChromeOS device

#
ApplicationName
admin

Description

Event for 'Delete duplicate ChromeOS device'.

References #

CHANGE_CHROME_OS_ISOLATED_WEB_APPLICATION_SETTING: Isolated Web Application Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for Isolated Web app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}

References #

ISSUE_DEVICE_COMMAND: Issue device command

#
ApplicationName
admin

Description

Event for 'Issue device command'.

References #

MOVE_DEVICE_TO_ORG_UNIT_DETAILED: Move device to Organizational unit

#
ApplicationName
admin

Description

Event for 'Move device to Org Unit'.

References #

PRE_PROVISION_CHROME_OS_DEVICE: Pre-provision ChromeOS device

#
ApplicationName
admin

Description

Event for 'Pre-provision ChromeOS device'.

References #

REMOVE_CHROME_OS_APPLICATION_SETTING: Remove Application Setting

#
ApplicationName
admin

Description

{APP_TYPE} app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} removed

References #

REMOVE_CHROME_OS_APPLICATION_SETTINGS: Remove Chrome Application Settings

#
ApplicationName
admin

Description

Settings for Chrome app {APP_ID} removed

References #

REMOVE_CHROME_OS_WEB_ORIGIN_SETTINGS: Remove Web Origin Settings

#
ApplicationName
admin

Description

Settings for web origin {WEB_ORIGIN} for session type {CHROME_OS_SESSION_TYPE} removed

References #

REPAIR_CENTER_DEPROVISION: Repair Center deprovision

#
ApplicationName
admin

Description

Event for 'Repair Center deprovision'.

References #

REVOKE_CHROME_OS_ENROLLMENT_TOKEN: Revoke ChromeOS enrollment token

#
ApplicationName
admin

Description

Event for 'Revoke ChromeOS enrollment token'.

References #

UPDATE_DEVICE: Update device

#
ApplicationName
admin

Description

Event for 'Update device'.

References #

CHANGE_CHROME_OS_WEB_APPLICATION_SETTING: Web Application Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for Web app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_CHROME_OS_WEB_PERMISSION_SETTING: Web Permission Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for {WEB_ORIGIN} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}

References #

CONTACTS_SETTINGS: Contacts Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=CONTACTS_SETTINGS .

References #

CHANGE_CONTACTS_SETTING: Contacts Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for contacts service changed from {OLD_VALUE} to {NEW_VALUE}

References #

DOCS_SETTINGS: Drive Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=DOCS_SETTINGS .

References #

TRANSFER_DOCUMENT_OWNERSHIP: Document Ownership Change

#
ApplicationName
admin

Description

Owner of documents changed from {USER_EMAIL} to {NEW_VALUE}

References #

DOCS_ORG_BRANDING_PROVISIONING: Drive and Docs org branding provisioning initiated

#
ApplicationName
admin

Description

Organizational branding provisioning initiated for account {SERVICE_ACCOUNT_EMAIL} and shared drive {SHARED_DRIVE_NAME} with status {ORG_BRANDING_PROVISIONING_STATUS}

References #

DOCS_ORG_BRANDING_UPLOAD: Drive and Docs org branding upload attempt

#
ApplicationName
admin

Description

Organizational branding document upload attempted for document {DOCUMENT_ID} in editor {ORG_BRANDING_EDITOR_TYPE} with status {ORG_BRANDING_UPLOAD_STATUS}

References #

DRIVE_DATA_RESTORE: Drive Data Restore

#
ApplicationName
admin

Description

Drive data restoration initiated for {USER_EMAIL}

References #

CHANGE_DOCS_SETTING: Drive Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for Drive changed from {OLD_VALUE} to {NEW_VALUE}

References #

MOVE_SHARED_DRIVE_TO_ORG_UNIT: Shared Drive Moved

#
ApplicationName
admin

Description

Shared drive {SHARED_DRIVE_ID} moved from {ORG_UNIT_NAME} to {NEW_VALUE}

References #

DOMAIN_SETTINGS: Domain Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=DOMAIN_SETTINGS .

References #

CHANGE_ACCOUNT_AUTO_RENEWAL: Account Automatic Renewal Change

#
ApplicationName
admin

Description

Account automatic renewal changed to {NEW_VALUE} on {DOMAIN_NAME}

References #

CHANGE_ADVERTISEMENT_OPTION: Advertisement Option Change

#
ApplicationName
admin

Description

Advertisement option for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CREATE_ALERT: Alert Creation

#
ApplicationName
admin

Description

Alert {ALERT_NAME} has been created

References #

CHANGE_ALERT_CRITERIA: Alert Criteria Change

#
ApplicationName
admin

Description

Alert criteria for {ALERT_NAME} has been changed

References #

DELETE_ALERT: Alert Deletion

#
ApplicationName
admin

Description

Alert {ALERT_NAME} has been deleted

References #

ALERT_RECEIVERS_CHANGED: Alert Receivers Change

#
ApplicationName
admin

Description

Alert receivers for {ALERT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

RENAME_ALERT: Alert Rename

#
ApplicationName
admin

Description

Alert {OLD_VALUE} has been renamed to {NEW_VALUE}

References #

ALERT_STATUS_CHANGED: Alert Status Change

#
ApplicationName
admin

Description

Alert status for {ALERT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

ADD_DOMAIN_ALIAS: Alias Creation

#
ApplicationName
admin

Description

An unverified {DOMAIN_ALIAS} created as an alias of {DOMAIN_NAME}

References #

REMOVE_DOMAIN_ALIAS: Alias Deletion

#
ApplicationName
admin

Description

{DOMAIN_ALIAS} deleted as an alias of {DOMAIN_NAME}

References #

SKIP_DOMAIN_ALIAS_MX: Alias MX Record Setup Skipped

#
ApplicationName
admin

Description

Skipped MX record setup of alias {DOMAIN_ALIAS} of domain {DOMAIN_NAME}

References #

VERIFY_DOMAIN_ALIAS_MX: Alias MX Record Verification

#
ApplicationName
admin

Description

Verified MX record of alias {DOMAIN_ALIAS} of domain {DOMAIN_NAME}

References #

VERIFY_DOMAIN_ALIAS: Alias Verification

#
ApplicationName
admin

Description

{DOMAIN_ALIAS} verified as an alias of {DOMAIN_NAME} using {DOMAIN_VERIFICATION_METHOD}

References #

TOGGLE_OAUTH_ACCESS_TO_ALL_APIS: All API OAuth Access Change

#
ApplicationName
admin

Description

OAuth access for all APIs changed to {NEW_VALUE} for your organization

References #

TOGGLE_ALLOW_ADMIN_PASSWORD_RESET: Allow Admin Password Reset

#
ApplicationName
admin

Description

Allow admin password reset setting changed to {NEW_VALUE}

References #

ENABLE_API_ACCESS: API Access Change

#
ApplicationName
admin

Description

API access for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

REMOVE_API_CLIENT_ACCESS: API Client Access Remove

#
ApplicationName
admin

Description

API client access to your organization from client {API_CLIENT_NAME} removed

References #

CHROME_LICENSES_REDEEMED: App Licenses Redeemed

#
ApplicationName
admin

Description

Licenses redeemed event name.

References #

TOGGLE_AUTO_ADD_NEW_SERVICE: Automatic Addition Update

#
ApplicationName
admin

Description

Automatic addition for new services and pre-release features for your organization changed to {NEW_VALUE}

References #

CHANGE_PRIMARY_DOMAIN: Change Primary Domain Name

#
ApplicationName
admin

Description

Primary domain name changed from {DOMAIN_NAME} to {NEW_VALUE}

References #

CHANGE_WHITELIST_SETTING: Change Whitelist Setting

#
ApplicationName
admin

Description

{SETTING_NAME} changed from {OLD_VALUE} to {NEW_VALUE} for the domain

References #

COMMUNICATION_PREFERENCES_SETTING_CHANGE: Communication Preferences Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} setting in Communication Preferences changed from {OLD_VALUE} to {NEW_VALUE} (Domain Name : {DOMAIN_NAME} )

References #

CHANGE_CONFLICT_ACCOUNT_ACTION: Conflict Account Action Change

#
ApplicationName
admin

Description

Conflict account action for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_CONFLICT_ACCOUNTS_MANAGEMENT_SETTINGS: Conflict accounts management settings change

#
ApplicationName
admin

Description

Conflict accounts management setting changed to: {CONFLICT_ACCOUNTS_MANAGEMENT_SETTINGS} .

References #

ENABLE_FEEDBACK_SOLICITATION: Contact for Feedback Setting Change

#
ApplicationName
admin

Description

Can contact for feedback setting for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

TOGGLE_CONTACT_SHARING: Contact Sharing Change

#
ApplicationName
admin

Description

Contact sharing changed to {NEW_VALUE}

References #

CREATE_PLAY_FOR_WORK_TOKEN: Create MDM vendor enrollment token

#
ApplicationName
admin

Description

MDM vendor enrollment token ( {PLAY_FOR_WORK_TOKEN_ID} ) created

References #

CHANGE_DATA_LOCALIZATION_FOR_RUSSIA: Data Localization For Russian Federation Change

#
ApplicationName
admin

Description

Setting for Data Localization for Russian Federation changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_DATA_LOCALIZATION_SETTING: Data Localization Setting Change

#
ApplicationName
admin

Description

Setting for Data Localization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_DATA_PROTECTION_OFFICER_CONTACT_INFO: Data Protection Officer Contact Information Change

#
ApplicationName
admin

Description

Part of an audit log event for contact info update for Data Protection Officer. This is used as an indicator of what kind of event log this message is.

References #

DELETE_PLAY_FOR_WORK_TOKEN: Delete MDM vendor enrollment token

#
ApplicationName
admin

Description

MDM vendor enrollment token ( {PLAY_FOR_WORK_TOKEN_ID} ) deleted

References #

VIEW_DNS_LOGIN_DETAILS: DNS console login details viewed

#
ApplicationName
admin

Description

DNS console login details for {DOMAIN_NAME} viewed

References #

CHANGE_DOMAIN_DEFAULT_LOCALE: Domain Default Locale Change

#
ApplicationName
admin

Description

Default locale for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_DOMAIN_DEFAULT_TIMEZONE: Domain Default Timezone Change

#
ApplicationName
admin

Description

Default time zone for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_DOMAIN_NAME: Domain Name Change

#
ApplicationName
admin

Description

Change of domain name for {DOMAIN_NAME} to {NEW_VALUE} started

References #

TOGGLE_ENABLE_PRE_RELEASE_FEATURES: Domain Pre-release Setting Change

#
ApplicationName
admin

Description

Pre-release features for your organization was set to {NEW_VALUE}

References #

CHANGE_DOMAIN_SUPPORT_MESSAGE: Domain Support Message Change

#
ApplicationName
admin

Description

Support message for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

REMOVE_TRUSTED_DOMAINS: Domains removed from Trusted Domains

#
ApplicationName
admin

Description

Domains {DOMAIN_NAME} removed from Trusted Domains list

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

CHANGE_EDU_TYPE: Education Organization Type Change

#
ApplicationName
admin

Description

Educational organization type changed from {OLD_VALUE} to {NEW_VALUE}

References #

TOGGLE_ENABLE_OAUTH_CONSUMER_KEY: Enable OAuth Consumer Key

#
ApplicationName
admin

Description

Enabling OAuth consumer key changed to {NEW_VALUE} for your organization

References #

TOGGLE_SSL: Enforce SSL Change

#
ApplicationName
admin

Description

SSL Enforcement changed to {NEW_VALUE} for {DOMAIN_NAME}

References #

CHANGE_EU_REPRESENTATIVE_CONTACT_INFO: EU Representative Contact Information Change

#
ApplicationName
admin

Description

Part of an audit log event for contact info update for EU Representative. This is used as an indicator of what kind of event log this message is.

References #

GENERATE_TRANSFER_TOKEN: Generate Transfer Token

#
ApplicationName
admin

Description

Transfer token generated

References #

CHANGE_LOGIN_BACKGROUND_COLOR: Login Background Color Change

#
ApplicationName
admin

Description

Login background color for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_LOGIN_BORDER_COLOR: Login Border Color Change

#
ApplicationName
admin

Description

Login border color for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_LOGIN_ACTIVITY_TRACE: Marketplace Login Audit Change

#
ApplicationName
admin

Description

Marketplace Login audit setting in {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

PLAY_FOR_WORK_ENROLL: MDM vendor enrollment

#
ApplicationName
admin

Description

Enrolled for {PLAY_FOR_WORK_MDM_VENDOR_NAME} mobile device management services using token ( {PLAY_FOR_WORK_TOKEN_ID} )

References #

PLAY_FOR_WORK_UNENROLL: MDM vendor unenrollment

#
ApplicationName
admin

Description

Unenrolled from {PLAY_FOR_WORK_MDM_VENDOR_NAME} mobile device management services

References #

MX_RECORD_VERIFICATION_CLAIM: MX Record Verification Claim

#
ApplicationName
admin

Description

{USER_EMAIL} claimed to verify the MX record for {DOMAIN_NAME}

References #

TOGGLE_NEW_APP_FEATURES: New App Features Update

#
ApplicationName
admin

Description

New app features for your organization changed to {NEW_VALUE}

References #

TOGGLE_USE_NEXT_GEN_CONTROL_PANEL: Next Generation CPanel Setting Change

#
ApplicationName
admin

Description

The setting to enable the new Admin Console changed to {NEW_VALUE} for your organization

References #

UPLOAD_OAUTH_CERTIFICATE: OAuth Certificate Upload

#
ApplicationName
admin

Description

New OAuth certificate uploaded for your organization

References #

REGENERATE_OAUTH_CONSUMER_SECRET: OAuth Consumer Secret Regenerate

#
ApplicationName
admin

Description

New OAuth consumer secret generated for your organization

References #

TOGGLE_OPEN_ID_ENABLED: OpenId Change

#
ApplicationName
admin

Description

OpenId federated login for {DOMAIN_NAME} changed to {NEW_VALUE}

References #

CHANGE_ORGANIZATION_NAME: Organization Name Change

#
ApplicationName
admin

Description

Organization name changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_PASSWORD_MAX_LENGTH: Password Maximum Length Change

#
ApplicationName
admin

Description

Password maximum length for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_PASSWORD_MIN_LENGTH: Password Minimum Length Change

#
ApplicationName
admin

Description

Password minimum length for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

UPDATE_DOMAIN_PRIMARY_ADMIN_EMAIL: Primary Admin Change

#
ApplicationName
admin

Description

Primary admin for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

ENABLE_SERVICE_OR_FEATURE_NOTIFICATIONS: Receive Email Notification Setting Change

#
ApplicationName
admin

Description

Receive email notification setting for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_RENEW_DOMAIN_REGISTRATION: Renew Domain Registration Setting Change

#
ApplicationName
admin

Description

Renew domain registration setting in {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_RESELLER_ACCESS: Reseller Access Change

#
ApplicationName
admin

Description

Reseller access changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_RESELLER_ACCESS_FOR_SKU: Reseller Access Change for SKU

#
ApplicationName
admin

Description

Reseller access for {SKU_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

RULE_ACTIONS_CHANGED: Rule Actions Change

#
ApplicationName
admin

Description

Rule actions for {RULE_NAME} changed

References #

CREATE_RULE: Rule Creation

#
ApplicationName
admin

Description

Rule {RULE_NAME} has been created

References #

CHANGE_RULE_CRITERIA: Rule Criteria Change

#
ApplicationName
admin

Description

Rule criteria for {RULE_NAME} has been changed

References #

DELETE_RULE: Rule Deletion

#
ApplicationName
admin

Description

Rule {RULE_NAME} has been deleted

References #

RENAME_RULE: Rule Rename

#
ApplicationName
admin

Description

Rule {OLD_VALUE} has been renamed to {NEW_VALUE}

References #

RULE_STATUS_CHANGED: Rule Status Change

#
ApplicationName
admin

Description

Rule status for {RULE_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

ADD_SECONDARY_DOMAIN: Secondary Domain Creation

#
ApplicationName
admin

Description

An unverified {SECONDARY_DOMAIN_NAME} created as a secondary domain of {DOMAIN_NAME}

References #

REMOVE_SECONDARY_DOMAIN: Secondary Domain Deletion

#
ApplicationName
admin

Description

{SECONDARY_DOMAIN_NAME} deleted as a secondary domain of {DOMAIN_NAME}

References #

SKIP_SECONDARY_DOMAIN_MX: Secondary Domain MX Record Setup Skipped

#
ApplicationName
admin

Description

Skipped MX record setup of secondary domain {SECONDARY_DOMAIN_NAME} of domain {DOMAIN_NAME}

References #

VERIFY_SECONDARY_DOMAIN_MX: Secondary Domain MX Verification

#
ApplicationName
admin

Description

Verified MX records of secondary domain {SECONDARY_DOMAIN_NAME} of domain {DOMAIN_NAME}

References #

VERIFY_SECONDARY_DOMAIN: Secondary Domain Verification

#
ApplicationName
admin

Description

{SECONDARY_DOMAIN_NAME} verified as a secondary domain of {DOMAIN_NAME}

References #

UPDATE_DOMAIN_SECONDARY_EMAIL: Secondary Email Change

#
ApplicationName
admin

Description

Secondary email for your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

GENERATE_PIN: Support PIN Generation

#
ApplicationName
admin

Description

Customer support PIN generated

References #

UPDATE_RULE: Update rule

#
ApplicationName
admin

Description

Update rule event name.

References #

EMAIL_SETTINGS: Email Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=EMAIL_SETTINGS .

References #

DROP_FROM_QUARANTINE: Drop from Quarantine

#
ApplicationName
admin

Description

The title for the event release from quarantine. This title shows the message was dropped from quarantine.

References #

EMAIL_LIFE_OF_A_MESSAGE: Email life of a message search

#
ApplicationName
admin

Description

Email life of a message search is launched.

References #

EMAIL_LOG_SEARCH: Email Log Search

#
ApplicationName
admin

Description

An email log search is performed for logs from {EMAIL_LOG_SEARCH_START_DATE} to {EMAIL_LOG_SEARCH_END_DATE} with a sender of [ {EMAIL_LOG_SEARCH_SENDER} ], a recipient of [ {EMAIL_LOG_SEARCH_RECIPIENT} ], and an email message id of [ {EMAIL_LOG_SEARCH_MSG_ID} ]

References #

EMAIL_UNDELETE: Email Restore

#
ApplicationName
admin

Description

Email restoration from {START_DATE} to {END_DATE} initiated for {USER_EMAIL}

References #

CHANGE_EMAIL_SETTING: Email Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for email service in your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

DELETE_GMAIL_SETTING: Gmail Setting Deletion

#
ApplicationName
admin

Description

Gmail setting {SETTING_NAME} was deleted

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

REJECT_FROM_QUARANTINE: Reject from Quarantine

#
ApplicationName
admin

Description

The title for the event release from quarantine. This title shows the message was rejected from quarantine.

References #

RELEASE_FROM_QUARANTINE: Release from Quarantine

#
ApplicationName
admin

Description

The title for the event release from quarantine. This title shows the message was released from quarantine.

References #

GROUP_SETTINGS: Group Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=GROUP_SETTINGS .

References #

WHITELISTED_GROUPS_UPDATED: Filtering groups updated

#
ApplicationName
admin

Description

Whitelisted groups updated event.

References #

CREATE_GROUP: Group Creation

#
ApplicationName
admin

Description

Group {GROUP_EMAIL} created

References #

DELETE_GROUP: Group Deletion

#
ApplicationName
admin

Description

Group {GROUP_EMAIL} deleted

References #

CHANGE_GROUP_DESCRIPTION: Group Description Change

#
ApplicationName
admin

Description

Description for group {GROUP_EMAIL} changed

References #

CHANGE_GROUP_EMAIL: Group Email Change

#
ApplicationName
admin

Description

Email of group {GROUP_EMAIL} changed to {NEW_VALUE}

References #

GROUP_LIST_DOWNLOAD: Group List Download

#
ApplicationName
admin

Description

Group list was downloaded as a CSV file

References #

REMOVE_GROUP_MEMBER: Group Member Deletion

#
ApplicationName
admin

Description

User {USER_EMAIL} deleted from group {GROUP_EMAIL}

References #

UPDATE_GROUP_MEMBER: Group Member Update

#
ApplicationName
admin

Description

Group Setting Change.

References #

UPDATE_GROUP_MEMBER_DELIVERY_SETTINGS: Group Member Update

#
ApplicationName
admin

Description

Group Member Delivery Settings Change.

References #

UPDATE_GROUP_MEMBER_DELIVERY_SETTINGS_CAN_EMAIL_OVERRIDE: Group Member Update

#
ApplicationName
admin

Description

Group Member Delivery Settings Email Override Change.

References #

GROUP_MEMBER_BULK_UPLOAD: Group Members Bulk Upload

#
ApplicationName
admin

Description

A total of {GROUP_MEMBER_BULK_UPLOAD_TOTAL_NUMBER} members selected for upload. {GROUP_MEMBER_BULK_UPLOAD_FAILED_NUMBER} out of {GROUP_MEMBER_BULK_UPLOAD_TOTAL_NUMBER} members failed to be uploaded

References #

GROUP_MEMBERS_DOWNLOAD: Group Members Download

#
ApplicationName
admin

Description

Group member list was downloaded as a CSV file

References #

CHANGE_GROUP_NAME: Group Name Change

#
ApplicationName
admin

Description

Name of group {GROUP_EMAIL} changed to {NEW_VALUE}

References #

LICENSES_SETTINGS: Licenses Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=LICENSES_SETTINGS .

References #

CHROME_APP_LICENSES_ENABLED: App License Policy Setting Changed

#
ApplicationName
admin

Description

Licenses enabled or not for a specified group/org unit event name.

References #

ORG_USERS_LICENSE_ASSIGNMENT: Assign Licenses to All Unassigned Users

#
ApplicationName
admin

Description

Licenses for {PRODUCT_NAME} product and {NEW_VALUE} sku were assigned to all unassigned users of {ORG_UNIT_NAME}

References #

ORG_ALL_USERS_LICENSE_ASSIGNMENT: Assign Licenses to All Users

#
ApplicationName
admin

Description

Licenses for {PRODUCT_NAME} product and {NEW_VALUE} sku were assigned to all users of {ORG_UNIT_NAME}

References #

SUPPRESSED_LICENSE_ASSIGNMENT: Assign Suppressed License

#
ApplicationName
admin

Description

A suppressed license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL}

References #

TEMPORARY_LICENSE_ASSIGNMENT: Assign Temporary License

#
ApplicationName
admin

Description

A temporary license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL}

References #

USER_LICENSE_ASSIGNMENT: Assign User License

#
ApplicationName
admin

Description

A license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL}

References #

CHANGE_LICENSE_AUTO_ASSIGN: Auto Assign Licenses

#
ApplicationName
admin

Description

License Auto Assign option changed to {NEW_VALUE} for {PRODUCT_NAME} product and {SKU_NAME} sku

References #

SUPPRESSED_TO_ASSIGNED_LICENSE_CONVERSION: Convert user's Suppressed License to Active

#
ApplicationName
admin

Description

Suppressed license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was converted to Active

References #

TEMPORARY_TO_ASSIGNED_LICENSE_CONVERSION: Convert user's Temporary License to Active

#
ApplicationName
admin

Description

Temporary license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was converted to Active

References #

TEMPORARY_TO_SUPPRESSED_LICENSE_CONVERSION: Convert user's Temporary License to Suppressed

#
ApplicationName
admin

Description

Temporary license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was expired and converted to Suppressed

References #

FIRST_TEMPORARY_OR_SUPPRESSED_LICENSE_NOTIFICATION: First Temporary or Suppressed License Email Sent

#
ApplicationName
admin

Description

Audit log event generated when first temporary or suppressed license email notification is sent to the customer.

References #

RESELLER_FIRST_TEMPORARY_OR_SUPPRESSED_LICENSE_NOTIFICATION: First Temporary or Suppressed License Email Sent for a User

#
ApplicationName
admin

Description

Audit log event generated when first temporary or suppressed license email notification is sent to the reseller.

References #

USER_LICENSE_REASSIGNMENT: Reassign User License

#
ApplicationName
admin

Description

A license for {PRODUCT_NAME} product and {OLD_VALUE} sku was reassigned for user {USER_EMAIL} to new sku {NEW_VALUE}

References #

ORG_LICENSE_REVOKE: Revoke Licenses to All Users

#
ApplicationName
admin

Description

Licenses for {PRODUCT_NAME} product and {OLD_VALUE} sku were removed from assigned users of {ORG_UNIT_NAME}

References #

SUPPRESSED_LICENSE_REVOKE: Revoke Suppressed License

#
ApplicationName
admin

Description

A suppressed license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from the user {USER_EMAIL}

References #

TEMPORARY_LICENSE_REVOKE: Revoke Temporary License

#
ApplicationName
admin

Description

A temporary license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from the user {USER_EMAIL}

References #

USER_LICENSE_REVOKE: Revoke User License

#
ApplicationName
admin

Description

A license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from user {USER_EMAIL}

References #

TEMPORARY_LICENSES_EXPIRED_NOTIFICATION: Temporary Licenses Expiration Email Notification Sent

#
ApplicationName
admin

Description

Audit log event generated when temporary licenses expired email notification is sent to the customer.

References #

RESELLER_TEMPORARY_LICENSES_EXPIRED_NOTIFICATION: Temporary Licenses Expiration Email Notification Sent for a User

#
ApplicationName
admin

Description

Audit log event generated when temporary licenses expired email notification is sent to the reseller.

References #

UPDATE_DYNAMIC_LICENSE: Update Auto Licensing

#
ApplicationName
admin

Description

Auto Licensing settings for {PRODUCT_NAME} product in {ORG_UNIT_NAME} organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHROME_APP_USER_LICENSE_ASSIGNED: User license is assigned

#
ApplicationName
admin

Description

Short description to indicate user license is assigned.

References #

CHROME_APP_USER_LICENSE_REVOKED: User license is revoked

#
ApplicationName
admin

Description

Short description to indicate user license is revoked.

References #

MOBILE_SETTINGS: Mobile Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=MOBILE_SETTINGS .

References #

ACTION_CANCELLED: Action Cancelled On Device

#
ApplicationName
admin

Description

{ACTION_TYPE} with id {ACTION_ID} on device type {DEVICE_TYPE} and id {DEVICE_ID} was cancelled by user {USER_EMAIL}

References #

ACTION_REQUESTED: Action Requested On Device

#
ApplicationName
admin

Description

{ACTION_TYPE} with id {ACTION_ID} on device type {DEVICE_TYPE} and id {DEVICE_ID} was requested by user {USER_EMAIL}

References #

ADD_MOBILE_CERTIFICATE: Add Mobile certificate

#
ApplicationName
admin

Description

Mobile certificate {MOBILE_CERTIFICATE_COMMON_NAME} added for mobile devices in your organization

References #

APPLE_DEP_SYNC_TRIGGERED: Apple DEP sync triggered by admin

#
ApplicationName
admin

Description

Apple DEP sync triggered by {USER_EMAIL}

References #

APPLE_DEP_TOKEN_SETUP_COMPLETE: Apple DEP token setup complete for customer

#
ApplicationName
admin

Description

Apple Device Enrollment tokens updated by {USER_EMAIL}

References #

APPLE_VPP_TOKEN_OPERATION: Apple VPP token operation

#
ApplicationName
admin

Description

Apple VPP token {TOKEN_OPERATION_NAME} was {TOKEN_OPERATION_STATUS}

References #

COMPANY_DEVICES_BULK_CREATION: Bulk import of company owned devices

#
ApplicationName
admin

Description

Details of {NUMBER_OF_COMPANY_OWNED_DEVICES} company owned device(s) were imported

References #

COMPANY_OWNED_DEVICE_BLOCKED: Company owned device blocked

#
ApplicationName
admin

Description

Company owned device {COMPANY_DEVICE_ID} was blocked

References #

COMPANY_DEVICE_DELETION: Company owned device deleted

#
ApplicationName
admin

Description

Company owned device {COMPANY_DEVICE_ID} was deleted

References #

COMPANY_OWNED_DEVICE_UNBLOCKED: Company owned device unblocked

#
ApplicationName
admin

Description

Company owned device {COMPANY_DEVICE_ID} was unblocked

References #

COMPANY_OWNED_DEVICE_WIPED: Company owned device wiped

#
ApplicationName
admin

Description

Company owned device {COMPANY_DEVICE_ID} was wiped

References #

CUSTOMER_USER_DEVICE_DELETION_EVENT: Customer user device deleted

#
ApplicationName
admin

Description

Customer user device {COMPANY_DEVICE_ID} was deleted

References #

CHANGE_MOBILE_APPLICATION_PERMISSION_GRANT: Mobile application permission grant change

#
ApplicationName
admin

Description

Change in mobile application permission grant.

References #

CHANGE_MOBILE_APPLICATION_PRIORITY_ORDER: Mobile application priority order change

#
ApplicationName
admin

Description

Change in priority order of mobile application.

References #

REMOVE_MOBILE_APPLICATION_FROM_WHITELIST: Mobile application removed from whitelist

#
ApplicationName
admin

Description

{DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} is no longer whitelisted for {DISTRIBUTION_ENTITY_NAME} {DISTRIBUTION_ENTITY_TYPE}

References #

CHANGE_MOBILE_APPLICATION_SETTINGS: Mobile application setting change

#
ApplicationName
admin

Description

Change in mobile application setting.

References #

ADD_MOBILE_APPLICATION_TO_WHITELIST: Mobile application whitelisted

#
ApplicationName
admin

Description

Mobile application is added to whitelist.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

MOBILE_DEVICE_APPROVE: Mobile Device Approve

#
ApplicationName
admin

Description

Mobile device for {USER_EMAIL} approved

References #

MOBILE_DEVICE_BLOCK: Mobile Device Block

#
ApplicationName
admin

Description

Mobile device for {USER_EMAIL} blocked

References #

MOBILE_DEVICE_DELETE: Mobile Device Deletion

#
ApplicationName
admin

Description

Mobile device for {USER_EMAIL} deleted

References #

MOBILE_DEVICE_WIPE: Mobile Device Wipe

#
ApplicationName
admin

Description

Mobile device for {USER_EMAIL} wiped

References #

CHANGE_MOBILE_SETTING: Mobile Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for mobile devices in your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_ADMIN_RESTRICTIONS_PIN: Mobile Setting Change: Administrator Restrictions Pin

#
ApplicationName
admin

Description

Administrator restrictions PIN for mobile devices in your organization changed

References #

CHANGE_MOBILE_WIRELESS_NETWORK: Mobile Wireless Network Change

#
ApplicationName
admin

Description

Mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} changed for mobile devices in your organization

References #

ADD_MOBILE_WIRELESS_NETWORK: Mobile Wireless Network Creation

#
ApplicationName
admin

Description

Mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} created for mobile devices in your organization

References #

REMOVE_MOBILE_WIRELESS_NETWORK: Mobile Wireless Network Deletion

#
ApplicationName
admin

Description

Mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} deleted for mobile devices in your organization

References #

CHANGE_MOBILE_WIRELESS_NETWORK_PASSWORD: Mobile Wireless Network Password Change

#
ApplicationName
admin

Description

Password changed for mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} in your organization

References #

REMOVE_MOBILE_CERTIFICATE: Remove Mobile certificate

#
ApplicationName
admin

Description

Mobile certificate {MOBILE_CERTIFICATE_COMMON_NAME} removed for mobile devices in your organization

References #

ENROLL_FOR_GOOGLE_DEVICE_MANAGEMENT: Use Google Device Management

#
ApplicationName
admin

Description

Google Device Management is a part of the Google Admin console.

References #

USE_GOOGLE_MOBILE_MANAGEMENT: Use Google Mobile Management

#
ApplicationName
admin

Description

You have selected Google Mobile Management to manage all your mobile devices

References #

USE_GOOGLE_MOBILE_MANAGEMENT_FOR_NON_IOS: Use Google Mobile Management for Android and Active Sync devices

#
ApplicationName
admin

Description

You have selected Google Mobile Management to manage your Android and Active Sync devices

References #

USE_GOOGLE_MOBILE_MANAGEMENT_FOR_IOS: Use Google Mobile Management for iOS devices

#
ApplicationName
admin

Description

You have selected Google Mobile Management to manage your iOS devices

References #

MOBILE_ACCOUNT_WIPE: Wipe Mobile Account

#
ApplicationName
admin

Description

Mobile account for {USER_EMAIL} has been wiped

References #

MOBILE_DEVICE_CANCEL_WIPE_THEN_APPROVE: Wipe On Mobile Cancel And Approve Device

#
ApplicationName
admin

Description

Wipe on mobile device for {USER_EMAIL} was cancelled and the device was approved

References #

MOBILE_DEVICE_CANCEL_WIPE_THEN_BLOCK: Wipe On Mobile Cancel And Block Device

#
ApplicationName
admin

Description

Wipe on mobile device for {USER_EMAIL} was cancelled and the device has been blocked

References #

ORG_SETTINGS: Organization Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=ORG_SETTINGS .

References #

CHROME_LICENSES_ENABLED: App License Policy Changed

#
ApplicationName
admin

Description

Licenses enabled or not at an org unit event name.

References #

CHROME_APPLICATION_LICENSE_RESERVATION_CREATED: App License Reservation Created

#
ApplicationName
admin

Description

License reservation at an org unit is created.

References #

CHROME_APPLICATION_LICENSE_RESERVATION_DELETED: App License Reservation Deleted

#
ApplicationName
admin

Description

License reservation at an org unit is deleted.

References #

CHROME_APPLICATION_LICENSE_RESERVATION_UPDATED: App License Reservation Updated

#
ApplicationName
admin

Description

License reservation at an org unit is updated.

References #

CREATE_DEVICE_ENROLLMENT_TOKEN: Create enrollment token

#
ApplicationName
admin

Description

Event for 'Create enrollment token'.

References #

CREATE_ENROLLMENT_TOKEN: Enrollment Token Creation

#
ApplicationName
admin

Description

A new enrollment token is generated for {ORG_UNIT_NAME}

References #

REVOKE_ENROLLMENT_TOKEN: Enrollment Token Revocation

#
ApplicationName
admin

Description

The enrollment token of {ORG_UNIT_NAME} has been revoked

References #

CHROME_LICENSES_ALLOWED: Licenses allowed or not at an org unit

#
ApplicationName
admin

Description

Licenses allowed or not at an org unit event name.

References #

CREATE_ORG_UNIT: OrgUnit Creation

#
ApplicationName
admin

Description

Org Unit {ORG_UNIT_NAME} created

References #

REMOVE_ORG_UNIT: OrgUnit Deletion

#
ApplicationName
admin

Description

Org Unit {ORG_UNIT_NAME} deleted

References #

EDIT_ORG_UNIT_DESCRIPTION: OrgUnit Description Change

#
ApplicationName
admin

Description

Description of {ORG_UNIT_NAME} changed

References #

MOVE_ORG_UNIT: OrgUnit Move

#
ApplicationName
admin

Description

{ORG_UNIT_NAME} moved to parent {NEW_VALUE}

References #

EDIT_ORG_UNIT_NAME: OrgUnit Name Change

#
ApplicationName
admin

Description

Name of {ORG_UNIT_NAME} changed to {NEW_VALUE}

References #

REVOKE_DEVICE_ENROLLMENT_TOKEN: Revoke enrollment token

#
ApplicationName
admin

Description

Event for 'Revoke enrollment token'.

References #

TOGGLE_SERVICE_ENABLED: Service Change

#
ApplicationName
admin

Description

Service {SERVICE_NAME} changed to {NEW_VALUE} for {ORG_UNIT_NAME} organizational unit in your organization

References #

SECURITY_SETTINGS: Security Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=SECURITY_SETTINGS .

References #

CHANGE_CAA_APP_ASSIGNMENTS: (Context-aware access) Access level assignment changed for an app

#
ApplicationName
admin

Description

For {TARGET_ENTITY_TYPE} [ {TARGET_ENTITY_NAME} ]: Before: Access level [ {CAA_ACCESS_ASSIGNMENTS_OLD} ] applied to {CAA_ENFORCEMENT_ENDPOINTS_OLD} of [ {APPLICATION_NAME} ] in [ {MODE} ] mode. After: Access level [ {CAA_ACCESS_ASSIGNMENTS_NEW} ] applied to {CAA_ENFORCEMENT_ENDPOINTS_NEW} of [ {APPLICATION_NAME} ] in [ {MODE} ] mode.

References #

UNDERAGE_BLOCK_ALL_THIRD_PARTY_API_ACCESS: All access to unconfigured third-party apps blocked for users under 18

#
ApplicationName
admin

Description

All third party API access blocked for users under 18.

References #

UNDERAGE_SIGN_IN_ONLY_THIRD_PARTY_API_ACCESS: Allow Google Sign-in only access to unconfigured third-party apps for users under 18

#
ApplicationName
admin

Description

Allow Google Sign-in only third party API access for users under 18.

References #

SIGN_IN_ONLY_THIRD_PARTY_API_ACCESS: Allow Google Sign-in only third party API access

#

CHANGE_APP_ACCESS_SETTINGS_COLLECTION_ID: app access settings collection id change.

#
ApplicationName
admin

Description

App Access Settings Collection for the org unit {ORG_UNIT_NAME} has changed from {OLD_VALUE} to {NEW_VALUE}

References #

ADD_TO_LIMITED_OAUTH2_APPS: App added to Limited list

#
ApplicationName
admin

Description

{OAUTH2_APP_NAME} added to Limited list for {ORG_UNIT_NAME}

References #

ADD_TO_TRUSTED_BY_OAUTH_SCOPE_OAUTH2_APPS: App added to Trusted by OAuth Scope list

#
ApplicationName
admin

Description

{OAUTH2_APP_NAME} added to trusted by OAuth scope list for {ORG_UNIT_NAME}

References #

ADD_TO_CAA_EXEMPT_OAUTH2_APPS: App allowlisted for exemption from API access blocks

#
ApplicationName
admin

Description

{OAUTH2_APP_NAME} allowlisted for exemption from API access blocks for {ORG_UNIT_NAME}

References #

REMOVE_FROM_CAA_EXEMPT_OAUTH2_APPS: App no longer allowlisted for exemption from API access blocks

#
ApplicationName
admin

Description

{OAUTH2_APP_NAME} removed from allowlist for exemption from API access blocks for {ORG_UNIT_NAME}

References #

REMOVE_FROM_LIMITED_OAUTH2_APPS: App removed from Limited list

#
ApplicationName
admin

Description

{OAUTH2_APP_NAME} removed from Limited list for {ORG_UNIT_NAME}

References #

REMOVE_FROM_TRUSTED_BY_OAUTH_SCOPE_OAUTH2_APPS: App removed from Trusted by OAuth Scope list

#
ApplicationName
admin

Description

{OAUTH2_APP_NAME} removed from trusted by OAuth scope list for {ORG_UNIT_NAME}

References #

MULTIPLE_ADD_TO_BLOCKED_OAUTH2_APPS: Apps added to Blocked list

#
ApplicationName
admin

Description

{OAUTH2_NUM_APPS} apps added to Blocked list for {ORG_UNIT_NAME}

References #

MULTIPLE_ADD_TO_LIMITED_OAUTH2_APPS: Apps added to Limited list

#
ApplicationName
admin

Description

{OAUTH2_NUM_APPS} apps added to Limited list for {ORG_UNIT_NAME}

References #

MULTIPLE_ADD_TO_TRUSTED_BY_OAUTH_SCOPE_OAUTH2_APPS: Apps added to Trusted by OAuth Scope list

#
ApplicationName
admin

Description

{OAUTH2_NUM_APPS} apps added to Trusted by OAuth Scope list for {ORG_UNIT_NAME}

References #

MULTIPLE_ADD_TO_TRUSTED_OAUTH2_APPS: Apps added to Trusted list

#
ApplicationName
admin

Description

{OAUTH2_NUM_APPS} apps added to Trusted list for {ORG_UNIT_NAME}

References #

OAUTH_APPS_BULK_UPLOAD: Apps lists bulk upload

#
ApplicationName
admin

Description

{BULK_UPLOAD_SUCCESS_OAUTH_APPS_NUMBER} of {BULK_UPLOAD_TOTAL_OAUTH_APPS_NUMBER} rows successfully uploaded

References #

OAUTH_APPS_BULK_UPLOAD_NOTIFICATION_SENT: Apps lists bulk upload notification

#
ApplicationName
admin

Description

Notification of bulk upload for apps list sent to {USER_EMAIL}

References #

BLOCK_ON_DEVICE_ACCESS: Block On Device Access

#
ApplicationName
admin

Description

Summary message to display in the audit log when device access for OAuth2 apps is blocked.

References #

CHANGE_TWO_STEP_VERIFICATION_FREQUENCY: Change 2-Step Verification Frequency

#
ApplicationName
admin

Description

2-step verification frequency for {ORG_UNIT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_TWO_STEP_VERIFICATION_GRACE_PERIOD_DURATION: Change 2-Step Verification Grace Period Duration

#
ApplicationName
admin

Description

2-step verification grace period duration for {ORG_UNIT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_TWO_STEP_VERIFICATION_START_DATE: Change 2-Step Verification Start Date

#
ApplicationName
admin

Description

2-step verification start date has been changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_CAA_ERROR_MESSAGE: Context Aware Access Error Message Change

#
ApplicationName
admin

Description

Error message has been changed to [ {NEW_VALUE} ]. (OrgUnit Name: {ORG_UNIT_NAME} )

References #

TOGGLE_CAA_REMEDIATION_ENABLEMENT: Context Aware Access Remediation Enablement

#
ApplicationName
admin

Description

Context Aware Access Remediation has been {NEW_VALUE} . (OrgUnit Name: {ORG_UNIT_NAME} )

References #

EDU_OVER_18_APPROVAL_WORKFLOW_DISABLED: Disabled Edu over 18 users apps requests

#
ApplicationName
admin

Description

Disabled Edu over 18 users apps requests for {ORG_UNIT_NAME}

References #

EDU_DELEGATED_USER_APPROVAL_WORKFLOW_DISABLED: Disabled over 18 users making delegated apps requests

#
ApplicationName
admin

Description

Disabled over 18 users making delegated apps requests for {ORG_UNIT_NAME}

References #

UNDERAGE_USER_APPROVAL_WORKFLOW_DISABLED: Disabled under 18 users apps requests

#
ApplicationName
admin

Description

Disabled under 18 users apps requests for {ORG_UNIT_NAME}

References #

USER_APPROVAL_WORKFLOW_DISABLED: Disabled users over 18 to make apps requests

#
ApplicationName
admin

Description

Disabled users over 18 to make apps requests for {ORG_UNIT_NAME}

References #

UNTRUST_DOMAIN_OWNED_OAUTH2_APPS: Domain Owned Apps not trusted

#
ApplicationName
admin

Description

Domain Owned Apps removed from trusted list

References #

TRUST_DOMAIN_OWNED_OAUTH2_APPS: Domain Owned Apps trusted

#
ApplicationName
admin

Description

Domain Owned Apps added to trusted list

References #

ENABLE_NON_ADMIN_USER_PASSWORD_RECOVERY: Enable Non-Admin User Password Recovery

#
ApplicationName
admin

Description

Enable non-admin user password recovery setting in {ORG_UNIT_NAME} organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

EDU_OVER_18_APPROVAL_WORKFLOW_ENABLED: Enabled Edu over 18 users apps requests

#
ApplicationName
admin

Description

Enabled Edu over 18 users apps requests for {ORG_UNIT_NAME}

References #

EDU_DELEGATED_USER_APPROVAL_WORKFLOW_ENABLED: Enabled over 18 users making delegated apps requests

#
ApplicationName
admin

Description

Enabled over 18 users making delegated apps requests for {ORG_UNIT_NAME}

References #

UNDERAGE_USER_APPROVAL_WORKFLOW_ENABLED: Enabled under 18 users apps requests

#
ApplicationName
admin

Description

Enabled under 18 users apps requests for {ORG_UNIT_NAME}

References #

USER_APPROVAL_WORKFLOW_ENABLED: Enabled users over 18 to make apps requests

#
ApplicationName
admin

Description

Enabled users over 18 to make apps requests for {ORG_UNIT_NAME}

References #

UPDATE_ERROR_MSG_FOR_RESTRICTED_OAUTH2_APPS: Error message for restricted OAuth2 apps updated

#
ApplicationName
admin

Description

Summary message to display in the audit log for Oauth2 scope management settings.

References #

CHANGE_SESSION_LENGTH: Session length changed

#
ApplicationName
admin

Description

Session length has been changed from {OLD_VALUE} to {NEW_VALUE}

References #

UNBLOCK_ON_DEVICE_ACCESS: Unblock on Device Access

#
ApplicationName
admin

Description

Summary message to display in the audit log when device access for OAuth2 apps is unblocked.

References #

DOWNLOAD_PENDING_APP_USER_REQUESTS: Users requesting access list download

#
ApplicationName
admin

Description

Downloaded list of users requesting access to {OAUTH2_APP_NAME}

References #

SITES_SETTINGS: Sites Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=SITES_SETTINGS .

References #

ADD_WEB_ADDRESS: Add Web Address

#
ApplicationName
admin

Description

Event gets triggered when a web address is added via cpanel.

References #

DELETE_WEB_ADDRESS: Delete Web Address

#
ApplicationName
admin

Description

Event gets triggered when a web address is deleted via cpanel.

References #

CHANGE_SITES_SETTING: Sites Setting Change

#
ApplicationName
admin

Description

{SETTING_NAME} for sites in your organization changed from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_SITES_WEB_ADDRESS_MAPPING_UPDATES: Sites web address mapping change

#
ApplicationName
admin

Description

Sites web address mapping update.

References #

VIEW_SITE_DETAILS: Viewed Google Site details

#
ApplicationName
admin

Description

Admin viewed the site details of {SITE_NAME}

References #

USER_SETTINGS: User Settings

#
ApplicationName
admin

Description

Events of this type are returned with type=USER_SETTINGS .

References #

DELETE_2SV_SCRATCH_CODES: 2-step Verification Scratch Codes Deletion

#
ApplicationName
admin

Description

2-step verification scratch codes of the user {USER_EMAIL} deleted

References #

GENERATE_2SV_SCRATCH_CODES: 2-step Verification Scratch Codes Generate

#
ApplicationName
admin

Description

New 2-step verification scratch codes generated for the user {USER_EMAIL}

References #

REVOKE_3LO_DEVICE_TOKENS: 3-legged OAuth Device Tokens Revoke

#
ApplicationName
admin

Description

3-legged OAuth tokens issued by user {USER_EMAIL} for the device type {DEVICE_TYPE} and id {DEVICE_ID} were revoked

References #

ACCEPT_USER_INVITATION: Accept User Invite

#
ApplicationName
admin

Description

User invitation accepted for user: {USER_EMAIL}

References #

ADD_RECOVERY_EMAIL: Add Recovery Email

#
ApplicationName
admin

Description

Recovery email added for {USER_EMAIL}

References #

ADD_RECOVERY_PHONE: Add Recovery Phone

#
ApplicationName
admin

Description

Recovery phone added for {USER_EMAIL}

References #

TOGGLE_AUTOMATIC_CONTACT_SHARING: Automatic Contact Share Change

#
ApplicationName
admin

Description

Automatic contact sharing for {USER_EMAIL} changed to {NEW_VALUE}

References #

BULK_UPLOAD: Bulk Upload

#
ApplicationName
admin

Description

{BULK_UPLOAD_TOTAL_USERS_NUMBER} users selected for upload to your organization. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users were not uploaded.

References #

BULK_UPLOAD_NOTIFICATION_SENT: Bulk Upload Notification

#
ApplicationName
admin

Description

Notification of bulk users upload sent to {USER_EMAIL}

References #

CANCEL_USER_INVITE: Cancel User Invite

#
ApplicationName
admin

Description

Invite to {USER_EMAIL} cancelled

References #

CHANGE_USER_CUSTOM_FIELD: Change Custom Attribute

#
ApplicationName
admin

Description

{USER_CUSTOM_FIELD} changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_USER_EXTERNAL_ID: Change External Id

#
ApplicationName
admin

Description

External Ids changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_USER_GENDER: Change Gender

#
ApplicationName
admin

Description

Change here is a verb. The genders will be customizable, so this should be broader than male vs female.

References #

CHANGE_USER_IM: Change IM

#
ApplicationName
admin

Description

IMs changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}

References #

ENABLE_USER_IP_WHITELIST: Change IP Whitelist

#
ApplicationName
admin

Description

IP whitelist changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_USER_KEYWORD: Change Keyword

#
ApplicationName
admin

Description

Keywords are used on user profiles to help identify a user in searches. Example: find person with name 'Larry' and school 'Stanford'. 'Change' is a verb.

References #

CHANGE_USER_LANGUAGE: Change Language

#
ApplicationName
admin

Description

Can be a predefined set of more common languages provided by Google or a custom language. 'Change' here is a verb.

References #

CHANGE_USER_LOCATION: Change Location

#
ApplicationName
admin

Description

Location is different from address in the following ways: (1) Location can be fuzzy. Example: Near Seattle. (2) Hovercards and other short user summaries display location, not address. 'Change' is a verb.

References #

CHANGE_USER_ORGANIZATION: Change Organization

#
ApplicationName
admin

Description

Organizations changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_USER_PHONE_NUMBER: Change Phone Numbers

#
ApplicationName
admin

Description

Phone Numbers changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_RECOVERY_EMAIL: Change Recovery Email

#
ApplicationName
admin

Description

Recovery email changed for {USER_EMAIL}

References #

CHANGE_RECOVERY_PHONE: Change Recovery Phone

#
ApplicationName
admin

Description

Recovery phone changed for {USER_EMAIL}

References #

CHANGE_USER_RELATION: Change Relation

#
ApplicationName
admin

Description

Relations changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}

References #

CHANGE_USER_ADDRESS: Change User Address

#
ApplicationName
admin

Description

Addresses changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}

References #

CREATE_EMAIL_MONITOR: Create an email monitor

#
ApplicationName
admin

Description

Created an email monitor for {USER_EMAIL} to {EMAIL_MONITOR_DEST_EMAIL} that will expire on {END_DATE_TIME}

References #

DELETE_ACCOUNT_INFO_DUMP: Delete account information dump

#
ApplicationName
admin

Description

Deleted account and login information dump for {USER_EMAIL} and request ID {REQUEST_ID}

References #

DELETE_EMAIL_MONITOR: Delete an email monitor

#
ApplicationName
admin

Description

Deleted an email monitor for {USER_EMAIL} to {EMAIL_MONITOR_DEST_EMAIL}

References #

DELETE_MAILBOX_DUMP: Delete mailbox dump

#
ApplicationName
admin

Description

Deleted mailbox dump for {USER_EMAIL} and request ID {REQUEST_ID}

References #

DELETE_PROFILE_PHOTO: Delete Profile Photo

#
ApplicationName
admin

Description

Profile photo of {USER_EMAIL} has been deleted

References #

ADD_DISPLAY_NAME: Display Name Added

#
ApplicationName
admin

Description

{USER_DISPLAY_NAME} added as a display name of {USER_EMAIL}

References #

CHANGE_DISPLAY_NAME: Display Name Change

#
ApplicationName
admin

Description

Display name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE}

References #

REMOVE_DISPLAY_NAME: Display Name Removed

#
ApplicationName
admin

Description

{USER_DISPLAY_NAME} removed as a display name of {USER_EMAIL}

References #

CHANGE_FIRST_NAME: First Name Change

#
ApplicationName
admin

Description

First name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE}

References #

GMAIL_RESET_USER: Gmail Account Reset

#
ApplicationName
admin

Description

Gmail account of {USER_EMAIL} reset

References #

CHANGE_LAST_NAME: Last Name Change

#
ApplicationName
admin

Description

Last name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE}

References #

MAIL_ROUTING_DESTINATION_ADDED: Mail Routing Destination Creation

#
ApplicationName
admin

Description

User {USER_EMAIL} has received the following individual mail routing destination: {NEW_VALUE}

References #

MAIL_ROUTING_DESTINATION_REMOVED: Mail Routing Destination Deletion

#
ApplicationName
admin

Description

User {USER_EMAIL} has had the following individual mail routing destination removed: {OLD_VALUE}

References #

ADD_NICKNAME: Nickname Creation

#
ApplicationName
admin

Description

{USER_NICKNAME} created as a nickname of {USER_EMAIL}

References #

REMOVE_NICKNAME: Nickname Deletion

#
ApplicationName
admin

Description

{USER_NICKNAME} deleted as a nickname of {USER_EMAIL}

References #

PASSKEY_REVOKED: Passkey revoked

#
ApplicationName
admin

Description

A passkey enrolled for user {USER_EMAIL} was revoked

References #

CHANGE_PASSWORD_ON_NEXT_LOGIN: Password Change on Next Login

#
ApplicationName
admin

Description

Password change requirement for {USER_EMAIL} on next login changed from {OLD_VALUE} to {NEW_VALUE}

References #

DOWNLOAD_PENDING_INVITES_LIST: Pending Invites List Download

#
ApplicationName
admin

Description

Pending Invites List was downloaded as a CSV file

References #

UPDATE_PUBLIC_KEY_CERTIFICATE_STATUS: Public Key Certificate Status Updated

#
ApplicationName
admin

Description

Public key certificate status updated to {PUBLIC_KEY_CERTIFICATE_STATUS} for email {USER_IMPACTED_EMAIL} of user {USER_EMAIL}

References #

UPDATE_PUBLIC_KEY_CERTIFICATE: Public Key Certificate Updated

#
ApplicationName
admin

Description

Public key certificate updated for {USER_DISPLAY_NAME} email {USER_EMAIL}

References #

REMOVE_RECOVERY_EMAIL: Remove Recovery Email

#
ApplicationName
admin

Description

Recovery email removed for {USER_EMAIL}

References #

REMOVE_RECOVERY_PHONE: Remove Recovery Phone

#
ApplicationName
admin

Description

Recovery phone removed for {USER_EMAIL}

References #

REQUEST_ACCOUNT_INFO: Request account information

#
ApplicationName
admin

Description

Requested account and login information for {USER_EMAIL}

References #

REQUEST_MAILBOX_DUMP: Request mailbox dump

#
ApplicationName
admin

Description

Requested mailbox dump for {USER_EMAIL}

References #

RESEND_USER_INVITE: Resend User Invite

#
ApplicationName
admin

Description

Invite email to {USER_EMAIL} resent

References #

RESET_SIGNIN_COOKIES: Reset Cookies and Forced Relogin

#
ApplicationName
admin

Description

Cookies reset for {USER_EMAIL} and forced re-login

References #

SECURITY_KEY_REGISTERED_FOR_USER: Security Key Registered For User

#
ApplicationName
admin

Description

Security key registered for {USER_EMAIL}

References #

REVOKE_SECURITY_KEY: Security Key Revoke

#
ApplicationName
admin

Description

A security key enrolled for user {USER_EMAIL} for 2-step verification was revoked

References #

USER_INVITE: Send User Invite

#
ApplicationName
admin

Description

{USER_EMAIL} invited to join your organization

References #

VIEW_TEMP_PASSWORD: Temporary Password Viewed

#
ApplicationName
admin

Description

Temporary password for user {USER_EMAIL} viewed by the admin

References #

UNBLOCK_USER_SESSION: Unblock User Session

#
ApplicationName
admin

Description

User {USER_EMAIL} unblocked by temporarily disabling login challenge

References #

UNMANAGED_USERS_BULK_UPLOAD: Unmanaged Users Bulk Upload

#
ApplicationName
admin

Description

A total of {BULK_UPLOAD_TOTAL_USERS_NUMBER} unmanaged users selected for upload. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users failed to be uploaded.

References #

DOWNLOAD_UNMANAGED_USERS_LIST: Unmanaged Users List Download

#
ApplicationName
admin

Description

Unmanaged Users list was downloaded as a CSV file

References #

UPDATE_PROFILE_PHOTO: Update Profile Photo

#
ApplicationName
admin

Description

Profile photo of {USER_EMAIL} has been updated

References #

UNENROLL_USER_FROM_TITANIUM: User Advanced Protection Unenroll

#
ApplicationName
admin

Description

User {USER_EMAIL} unenrolled from Advanced Protection

References #

ARCHIVE_USER: User Archival

#
ApplicationName
admin

Description

{USER_EMAIL} archived

References #

UPDATE_BIRTHDATE: User BirthDate Change

#
ApplicationName
admin

Description

The birth date for {USER_EMAIL} changed to {BIRTHDATE}

References #

USER_CREATED_PASSKEY_REVOKE: User created passkey revoked

#
ApplicationName
admin

Description

A user created passkey enrolled for user {USER_EMAIL} was revoked

References #

DOWNGRADE_USER_FROM_GPLUS: User Downgrade From Google+

#
ApplicationName
admin

Description

{USER_EMAIL} was downgraded from Google+

References #

USER_ENROLLED_IN_TWO_STEP_VERIFICATION: User Enrolled In 2-Step Verification

#
ApplicationName
admin

Description

{USER_EMAIL} enrolled in 2-step verification

References #

DOWNLOAD_USERLIST_CSV: User List Download

#
ApplicationName
admin

Description

User list was downloaded as a CSV file

References #

DOWNLOAD_USERLIST: User List Download

#
ApplicationName
admin

Description

User list was downloaded in {FORMAT}

References #

USER_PUT_IN_TWO_STEP_VERIFICATION_GRACE_PERIOD: User Put In 2-Step Verification Grace Period

#
ApplicationName
admin

Description

2-step verification grace period has been enabled on {USER_EMAIL} till {NEW_VALUE}

References #

UNENROLL_USER_FROM_STRONG_AUTH: User Strong Auth Unenroll

#
ApplicationName
admin

Description

User {USER_EMAIL} unenrolled from Strong Auth

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

UNARCHIVE_USER: User Unarchival

#
ApplicationName
admin

Description

{USER_EMAIL} unarchived

References #

UNDELETE_USER: User Undeletion

#
ApplicationName
admin

Description

{USER_EMAIL} undeleted

References #

UPGRADE_USER_TO_GPLUS: User Upgrade To Google+

#
ApplicationName
admin

Description

{USER_EMAIL} was upgraded to Google+

References #

USERS_BULK_UPLOAD: Users Bulk Upload

#
ApplicationName
admin

Description

A total of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users selected for upload. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users failed to be uploaded.

References #

USERS_BULK_UPLOAD_NOTIFICATION_SENT: Users Bulk Upload Notification

#
ApplicationName
admin

Description

Notification of bulk users upload sent to {USER_EMAIL}

References #