Intune-Application

any: Application (catch-all)

#

Description

Synthetic aggregation for Intune audit rules that filter the Application category without a specific activityType. Not a distinct audit record.

Fields #

NameDescription
activity Edm.StringFriendly name of the activity.
activityDateTime Edm.DateTimeOffsetThe date time in UTC when the activity was performed.
activityOperationType Edm.StringThe HTTP operation type of the activity.
activityResult Edm.StringThe result of the activity.
activityType Edm.StringThe type of activity that was being performed.
actor graph.auditActorAAD user and application that are associated with the audit event.
category Edm.StringAudit category.
componentName Edm.StringComponent name.
correlationId Edm.GuidThe client request Id that is used to correlate activity within the system.
displayName Edm.StringEvent display name.
resources Collection(graph.auditResource)Resources being modified.

Create IntuneBrandingProfile

#

Description

Create a group targeted branding profile.

Fields #

NameDescription
activity Edm.StringFriendly name of the activity.
activityDateTime Edm.DateTimeOffsetThe date time in UTC when the activity was performed.
activityOperationType Edm.StringThe HTTP operation type of the activity.
activityResult Edm.StringThe result of the activity.
activityType Edm.StringThe type of activity that was being performed.
actor graph.auditActorAAD user and application that are associated with the audit event.
category Edm.StringAudit category.
componentName Edm.StringComponent name.
correlationId Edm.GuidThe client request Id that is used to correlate activity within the system.
displayName Edm.StringEvent display name.
resources Collection(graph.auditResource)Resources being modified.

Example Audit Record #

{
  "id": "b6620a32-3129-430a-b468-e39aad1e4743",
  "displayName": "Create a group targeted branding profile.",
  "componentName": "MobileApp",
  "activity": null,
  "activityDateTime": "2026-07-04T18:40:39.1454313Z",
  "activityType": "Create IntuneBrandingProfile",
  "activityOperationType": "Create",
  "activityResult": "Success",
  "correlationId": "50d15e86-5d98-454a-9890-ab9d93ce0ff5",
  "category": "Application",
  "actor": {
    "auditActorType": "ItPro",
    "userPermissions": [
      "*"
    ],
    "applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
    "applicationDisplayName": "Microsoft Graph Command Line Tools",
    "userPrincipalName": "adminuser@example.onmicrosoft.com",
    "servicePrincipalName": null,
    "ipAddress": null,
    "userId": "33333333-3333-3333-3333-333333333333"
  },
  "resources": [
    {
      "displayName": "dwharn-2d37281a",
      "auditResourceType": "IntuneBrandingProfile",
      "resourceId": "06d17e54-0dac-41a3-bbad-e5307220e21f",
      "modifiedProperties": [
        {
          "displayName": "ProfileName",
          "oldValue": null,
          "newValue": "dwharn-2d37281a"
        },
        {
          "displayName": "ThemeColor",
          "oldValue": null,
          "newValue": "R=0, G=114, B=198"
        },
        {
          "displayName": "ShowLogo",
          "oldValue": null,
          "newValue": "False"
        },
        {
          "displayName": "ShowDisplayNameNextToLogo",
          "oldValue": null,
          "newValue": "False"
        },
        {
          "displayName": "SendDeviceOwnershipChangePushNotification",
          "oldValue": null,
          "newValue": "True"
        },
        {
          "displayName": "EnrollmentAvailability",
          "oldValue": null,
          "newValue": "AvailableWithPrompts"
        },
        {
          "displayName": "DisableDeviceCategorySelection",
          "oldValue": null,
          "newValue": "False"
        },
        {
          "displayName": "ShowAzureADEnterpriseApps",
          "oldValue": null,
          "newValue": "False"
        },
        {
          "displayName": "ShowOfficeWebApps",
          "oldValue": null,
          "newValue": "False"
        },
        {
          "displayName": "ShowConfigurationManagerApps",
          "oldValue": null,
          "newValue": "False"
        },
        {
          "displayName": "DisableClientTelemetry",
          "oldValue": null,
          "newValue": "False"
        },
        {
          "displayName": "RoleScopeTagIds",
          "oldValue": null,
          "newValue": "Default"
        },
        {
          "displayName": "CompanyPortalBlockedActions",
          "oldValue": null,
          "newValue": "6,1,1"
        },
        {
          "displayName": "DeviceManagementAPIVersion",
          "oldValue": null,
          "newValue": "5025-09-30"
        }
      ]
    }
  ]
}

Create ManagedDeviceMobileAppConfiguration

#

Description

Create iOS app configuration policy

Fields #

NameDescription
activity Edm.StringFriendly name of the activity.
activityDateTime Edm.DateTimeOffsetThe date time in UTC when the activity was performed.
activityOperationType Edm.StringThe HTTP operation type of the activity.
activityResult Edm.StringThe result of the activity.
activityType Edm.StringThe type of activity that was being performed.
actor graph.auditActorAAD user and application that are associated with the audit event.
category Edm.StringAudit category.
componentName Edm.StringComponent name.
correlationId Edm.GuidThe client request Id that is used to correlate activity within the system.
displayName Edm.StringEvent display name.
resources Collection(graph.auditResource)Resources being modified.

Example Audit Record #

{
  "id": "e63f5afa-8875-4423-8bc2-e78cc2f21e34",
  "displayName": "Create iOS app configuration policy",
  "componentName": "MobileAppConfiguration",
  "activity": null,
  "activityDateTime": "2026-07-04T18:40:33.0108931Z",
  "activityType": "Create ManagedDeviceMobileAppConfiguration",
  "activityOperationType": "Create",
  "activityResult": "Success",
  "correlationId": "7a01a6ee-92db-40bb-a5d7-57db80b94e16",
  "category": "Application",
  "actor": {
    "auditActorType": "ItPro",
    "userPermissions": [
      "*"
    ],
    "applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
    "applicationDisplayName": "Microsoft Graph Command Line Tools",
    "userPrincipalName": "adminuser@example.onmicrosoft.com",
    "servicePrincipalName": null,
    "ipAddress": null,
    "userId": "33333333-3333-3333-3333-333333333333"
  },
  "resources": [
    {
      "displayName": "dwharn-2d37281a",
      "auditResourceType": "IOSMobileAppConfiguration",
      "resourceId": "5cb8b1d0-8e2d-4d65-8b5d-15f66d582582",
      "modifiedProperties": [
        {
          "displayName": "TargetedMobileApps",
          "oldValue": null,
          "newValue": []
        },
        {
          "displayName": "EncodedSettingXml",
          "oldValue": null,
          "newValue": "PGRpY3QgLz4="
        },
        {
          "displayName": "SettingXml",
          "oldValue": null,
          "newValue": "<dict />"
        },
        {
          "displayName": "Id",
          "oldValue": null,
          "newValue": "5cb8b1d0-8e2d-4d65-8b5d-15f66d582582"
        },
        {
          "displayName": "CreatedDateTime",
          "oldValue": null,
          "newValue": "7/4/2026 6:40:32 PM"
        },
        {
          "displayName": "Description",
          "oldValue": null,
          "newValue": "<null>"
        },
        {
          "displayName": "LastModifiedDateTime",
          "oldValue": null,
          "newValue": "7/4/2026 6:40:32 PM"
        },
        {
          "displayName": "Version",
          "oldValue": null,
          "newValue": "1"
        },
        {
          "displayName": "DeviceManagementAPIVersion",
          "oldValue": null,
          "newValue": "5026-04-26"
        },
        {
          "displayName": "$Collection.RoleScopeTagIds[0]",
          "oldValue": null,
          "newValue": "Default"
        }
      ]
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

Create MobileApp

#

Description

Create application.

Fields #

NameDescription
activity Edm.StringFriendly name of the activity.
activityDateTime Edm.DateTimeOffsetThe date time in UTC when the activity was performed.
activityOperationType Edm.StringThe HTTP operation type of the activity.
activityResult Edm.StringThe result of the activity.
activityType Edm.StringThe type of activity that was being performed.
actor graph.auditActorAAD user and application that are associated with the audit event.
category Edm.StringAudit category.
componentName Edm.StringComponent name.
correlationId Edm.GuidThe client request Id that is used to correlate activity within the system.
displayName Edm.StringEvent display name.
resources Collection(graph.auditResource)Resources being modified.

Example Audit Record #

{
  "id": "525a7b6a-751f-42e4-8d22-fab160caf8b8",
  "displayName": "Create application.",
  "componentName": "MobileApp",
  "activity": null,
  "activityDateTime": "2026-07-04T18:40:30.311818Z",
  "activityType": "Create MobileApp",
  "activityOperationType": "Create",
  "activityResult": "Success",
  "correlationId": "637f03b6-1d5e-425c-bc94-746f37b1e1c0",
  "category": "Application",
  "actor": {
    "auditActorType": "ItPro",
    "userPermissions": [
      "*"
    ],
    "applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
    "applicationDisplayName": "Microsoft Graph Command Line Tools",
    "userPrincipalName": "adminuser@example.onmicrosoft.com",
    "servicePrincipalName": null,
    "ipAddress": null,
    "userId": "33333333-3333-3333-3333-333333333333"
  },
  "resources": [
    {
      "displayName": "dwharn-2d37281a",
      "auditResourceType": "WebApp",
      "resourceId": "a7b6cdb3-02a9-4853-990f-a4608a83a32d",
      "modifiedProperties": [
        {
          "displayName": "AppUrl",
          "oldValue": null,
          "newValue": "https://example.com"
        },
        {
          "displayName": "UseManagedBrowser",
          "oldValue": null,
          "newValue": "False"
        },
        {
          "displayName": "Id",
          "oldValue": null,
          "newValue": "a7b6cdb3-02a9-4853-990f-a4608a83a32d"
        },
        {
          "displayName": "Description",
          "oldValue": null,
          "newValue": "<null>"
        },
        {
          "displayName": "Publisher",
          "oldValue": null,
          "newValue": "detection.wiki"
        },
        {
          "displayName": "CreatedDateTime",
          "oldValue": null,
          "newValue": "7/4/2026 6:40:29 PM"
        },
        {
          "displayName": "LastModifiedDateTime",
          "oldValue": null,
          "newValue": "7/4/2026 6:40:29 PM"
        },
        {
          "displayName": "IsFeatured",
          "oldValue": null,
          "newValue": "False"
        },
        {
          "displayName": "PrivacyInformationUrl",
          "oldValue": null,
          "newValue": "<null>"
        },
        {
          "displayName": "InformationUrl",
          "oldValue": null,
          "newValue": "<null>"
        },
        {
          "displayName": "Owner",
          "oldValue": null,
          "newValue": "<null>"
        },
        {
          "displayName": "Developer",
          "oldValue": null,
          "newValue": "<null>"
        },
        {
          "displayName": "Notes",
          "oldValue": null,
          "newValue": "<null>"
        },
        {
          "displayName": "PublishingState",
          "oldValue": null,
          "newValue": "Published"
        },
        {
          "displayName": "DeviceManagementAPIVersion",
          "oldValue": null,
          "newValue": "2025-07-02"
        }
      ]
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

Panther #

  • Intune Create or Modify Client App source medium: Microsoft Intune allows administrators to deploy applications to devices as a means of remote management and configuration. This functionality can be abused by adversaries to deploy malicious executables to devices, thereby allowing adversaries to pivot from compromised accounts to endpoints. This detection identifies the creation of or changes to apps that are deployed to devices.T1021.007, T1072, T1202

Create MobileAppCategory

#

Description

Create application category.

Fields #

NameDescription
activity Edm.StringFriendly name of the activity.
activityDateTime Edm.DateTimeOffsetThe date time in UTC when the activity was performed.
activityOperationType Edm.StringThe HTTP operation type of the activity.
activityResult Edm.StringThe result of the activity.
activityType Edm.StringThe type of activity that was being performed.
actor graph.auditActorAAD user and application that are associated with the audit event.
category Edm.StringAudit category.
componentName Edm.StringComponent name.
correlationId Edm.GuidThe client request Id that is used to correlate activity within the system.
displayName Edm.StringEvent display name.
resources Collection(graph.auditResource)Resources being modified.

Example Audit Record #

{
  "id": "a9964589-db0d-4961-bafa-2c2574097ad0",
  "displayName": "Create application category.",
  "componentName": "MobileApp",
  "activity": null,
  "activityDateTime": "2026-07-04T18:40:31.6472294Z",
  "activityType": "Create MobileAppCategory",
  "activityOperationType": "Create",
  "activityResult": "Success",
  "correlationId": "2b3b7d22-aea0-4781-b9e9-800f9eacbe2b",
  "category": "Application",
  "actor": {
    "auditActorType": "ItPro",
    "userPermissions": [
      "*"
    ],
    "applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
    "applicationDisplayName": "Microsoft Graph Command Line Tools",
    "userPrincipalName": "adminuser@example.onmicrosoft.com",
    "servicePrincipalName": null,
    "ipAddress": null,
    "userId": "33333333-3333-3333-3333-333333333333"
  },
  "resources": [
    {
      "displayName": "dwharn-2d37281a",
      "auditResourceType": "MobileAppCategory",
      "resourceId": "1e52293f-5e1e-4319-842b-7a88608c37bd",
      "modifiedProperties": [
        {
          "displayName": "Id",
          "oldValue": null,
          "newValue": "1e52293f-5e1e-4319-842b-7a88608c37bd"
        },
        {
          "displayName": "LastModifiedDateTime",
          "oldValue": null,
          "newValue": "1/1/0001 12:00:00 AM"
        },
        {
          "displayName": "DeviceManagementAPIVersion",
          "oldValue": null,
          "newValue": "2025-07-02"
        }
      ]
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

Delete IntuneBrandingProfile

#

Description

Delete a BrandingProfile.

Fields #

NameDescription
activity Edm.StringFriendly name of the activity.
activityDateTime Edm.DateTimeOffsetThe date time in UTC when the activity was performed.
activityOperationType Edm.StringThe HTTP operation type of the activity.
activityResult Edm.StringThe result of the activity.
activityType Edm.StringThe type of activity that was being performed.
actor graph.auditActorAAD user and application that are associated with the audit event.
category Edm.StringAudit category.
componentName Edm.StringComponent name.
correlationId Edm.GuidThe client request Id that is used to correlate activity within the system.
displayName Edm.StringEvent display name.
resources Collection(graph.auditResource)Resources being modified.

Example Audit Record #

{
  "id": "e079417e-e8cb-4418-ac6c-0fa7ad3cfe64",
  "displayName": "Delete a BrandingProfile.",
  "componentName": "MobileApp",
  "activity": null,
  "activityDateTime": "2026-07-04T18:40:39.7806243Z",
  "activityType": "Delete IntuneBrandingProfile",
  "activityOperationType": "Delete",
  "activityResult": "Success",
  "correlationId": "db6fa3c1-e03a-4b13-b887-3e20ac7b5b59",
  "category": "Application",
  "actor": {
    "auditActorType": "ItPro",
    "userPermissions": [
      "*"
    ],
    "applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
    "applicationDisplayName": "Microsoft Graph Command Line Tools",
    "userPrincipalName": "adminuser@example.onmicrosoft.com",
    "servicePrincipalName": null,
    "ipAddress": null,
    "userId": "33333333-3333-3333-3333-333333333333"
  },
  "resources": [
    {
      "displayName": null,
      "auditResourceType": "Microsoft.Management.Services.BrandingProfileCommon.BrandingProfile",
      "resourceId": "06d17e54-0dac-41a3-bbad-e5307220e21f",
      "modifiedProperties": [
        {
          "displayName": "DeviceManagementAPIVersion",
          "oldValue": null,
          "newValue": "5025-09-30"
        }
      ]
    }
  ]
}

Delete ManagedDeviceMobileAppConfiguration

#

Description

Delete iOS app configuration policy

Fields #

NameDescription
activity Edm.StringFriendly name of the activity.
activityDateTime Edm.DateTimeOffsetThe date time in UTC when the activity was performed.
activityOperationType Edm.StringThe HTTP operation type of the activity.
activityResult Edm.StringThe result of the activity.
activityType Edm.StringThe type of activity that was being performed.
actor graph.auditActorAAD user and application that are associated with the audit event.
category Edm.StringAudit category.
componentName Edm.StringComponent name.
correlationId Edm.GuidThe client request Id that is used to correlate activity within the system.
displayName Edm.StringEvent display name.
resources Collection(graph.auditResource)Resources being modified.

Example Audit Record #

{
  "id": "4251011f-f438-4bfa-81e9-991d558082d9",
  "displayName": "Delete iOS app configuration policy",
  "componentName": "MobileAppConfiguration",
  "activity": null,
  "activityDateTime": "2026-07-04T18:40:33.8215619Z",
  "activityType": "Delete ManagedDeviceMobileAppConfiguration",
  "activityOperationType": "Delete",
  "activityResult": "Success",
  "correlationId": "c7a190ec-f76e-4759-881b-84a9391d973d",
  "category": "Application",
  "actor": {
    "auditActorType": "ItPro",
    "userPermissions": [
      "*"
    ],
    "applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
    "applicationDisplayName": "Microsoft Graph Command Line Tools",
    "userPrincipalName": "adminuser@example.onmicrosoft.com",
    "servicePrincipalName": null,
    "ipAddress": null,
    "userId": "33333333-3333-3333-3333-333333333333"
  },
  "resources": [
    {
      "displayName": "dwharn-2d37281a",
      "auditResourceType": "IOSMobileAppConfiguration",
      "resourceId": "5cb8b1d0-8e2d-4d65-8b5d-15f66d582582",
      "modifiedProperties": [
        {
          "displayName": "Id",
          "oldValue": "5cb8b1d0-8e2d-4d65-8b5d-15f66d582582",
          "newValue": "<null>"
        },
        {
          "displayName": "CreatedDateTime",
          "oldValue": "7/4/2026 6:40:32 PM",
          "newValue": "<null>"
        },
        {
          "displayName": "Description",
          "oldValue": "<null>",
          "newValue": "<null>"
        },
        {
          "displayName": "LastModifiedDateTime",
          "oldValue": "7/4/2026 6:40:32 PM",
          "newValue": "<null>"
        },
        {
          "displayName": "Version",
          "oldValue": "1",
          "newValue": "<null>"
        },
        {
          "displayName": "DeviceManagementAPIVersion",
          "oldValue": null,
          "newValue": "5026-04-26"
        },
        {
          "displayName": "$Collection.RoleScopeTagIds[0]",
          "oldValue": null,
          "newValue": "<null>"
        },
        {
          "displayName": "$Collection.RoleScopeTagIds[1]",
          "oldValue": "Default",
          "newValue": null
        }
      ]
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

Delete MobileApp

#

Description

Delete application.

Fields #

NameDescription
activity Edm.StringFriendly name of the activity.
activityDateTime Edm.DateTimeOffsetThe date time in UTC when the activity was performed.
activityOperationType Edm.StringThe HTTP operation type of the activity.
activityResult Edm.StringThe result of the activity.
activityType Edm.StringThe type of activity that was being performed.
actor graph.auditActorAAD user and application that are associated with the audit event.
category Edm.StringAudit category.
componentName Edm.StringComponent name.
correlationId Edm.GuidThe client request Id that is used to correlate activity within the system.
displayName Edm.StringEvent display name.
resources Collection(graph.auditResource)Resources being modified.

Example Audit Record #

{
  "id": "a7e8f80d-3cb9-4dba-bb62-5a1876e929b6",
  "displayName": "Delete application.",
  "componentName": "MobileApp",
  "activity": null,
  "activityDateTime": "2026-07-04T18:40:31.0792541Z",
  "activityType": "Delete MobileApp",
  "activityOperationType": "Delete",
  "activityResult": "Success",
  "correlationId": "111ebe68-c46d-4e1b-9d72-54d7bb8c5e92",
  "category": "Application",
  "actor": {
    "auditActorType": "ItPro",
    "userPermissions": [
      "*"
    ],
    "applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
    "applicationDisplayName": "Microsoft Graph Command Line Tools",
    "userPrincipalName": "adminuser@example.onmicrosoft.com",
    "servicePrincipalName": null,
    "ipAddress": null,
    "userId": "33333333-3333-3333-3333-333333333333"
  },
  "resources": [
    {
      "displayName": "dwharn-2d37281a",
      "auditResourceType": "WebApp",
      "resourceId": "a7b6cdb3-02a9-4853-990f-a4608a83a32d",
      "modifiedProperties": [
        {
          "displayName": "AppUrl",
          "oldValue": "https://example.com",
          "newValue": "<null>"
        },
        {
          "displayName": "UseManagedBrowser",
          "oldValue": "False",
          "newValue": "<null>"
        },
        {
          "displayName": "Id",
          "oldValue": "a7b6cdb3-02a9-4853-990f-a4608a83a32d",
          "newValue": "<null>"
        },
        {
          "displayName": "Description",
          "oldValue": "<null>",
          "newValue": "<null>"
        },
        {
          "displayName": "Publisher",
          "oldValue": "detection.wiki",
          "newValue": "<null>"
        },
        {
          "displayName": "CreatedDateTime",
          "oldValue": "7/4/2026 6:40:29 PM",
          "newValue": "<null>"
        },
        {
          "displayName": "LastModifiedDateTime",
          "oldValue": "7/4/2026 6:40:29 PM",
          "newValue": "<null>"
        },
        {
          "displayName": "IsFeatured",
          "oldValue": "False",
          "newValue": "<null>"
        },
        {
          "displayName": "PrivacyInformationUrl",
          "oldValue": "<null>",
          "newValue": "<null>"
        },
        {
          "displayName": "InformationUrl",
          "oldValue": "<null>",
          "newValue": "<null>"
        },
        {
          "displayName": "Owner",
          "oldValue": "<null>",
          "newValue": "<null>"
        },
        {
          "displayName": "Developer",
          "oldValue": "<null>",
          "newValue": "<null>"
        },
        {
          "displayName": "Notes",
          "oldValue": "<null>",
          "newValue": "<null>"
        },
        {
          "displayName": "PublishingState",
          "oldValue": "Published",
          "newValue": "<null>"
        },
        {
          "displayName": "DeviceManagementAPIVersion",
          "oldValue": null,
          "newValue": "2025-07-02"
        }
      ]
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

Delete MobileAppCategory

#

Description

Delete application category.

Fields #

NameDescription
activity Edm.StringFriendly name of the activity.
activityDateTime Edm.DateTimeOffsetThe date time in UTC when the activity was performed.
activityOperationType Edm.StringThe HTTP operation type of the activity.
activityResult Edm.StringThe result of the activity.
activityType Edm.StringThe type of activity that was being performed.
actor graph.auditActorAAD user and application that are associated with the audit event.
category Edm.StringAudit category.
componentName Edm.StringComponent name.
correlationId Edm.GuidThe client request Id that is used to correlate activity within the system.
displayName Edm.StringEvent display name.
resources Collection(graph.auditResource)Resources being modified.

Example Audit Record #

{
  "id": "25bcd1a9-5b4d-46a1-b532-fc569b74b64e",
  "displayName": "Delete application category.",
  "componentName": "MobileApp",
  "activity": null,
  "activityDateTime": "2026-07-04T18:40:32.1982613Z",
  "activityType": "Delete MobileAppCategory",
  "activityOperationType": "Delete",
  "activityResult": "Success",
  "correlationId": "b43f8a01-3138-4572-b23d-172a1a892b26",
  "category": "Application",
  "actor": {
    "auditActorType": "ItPro",
    "userPermissions": [
      "*"
    ],
    "applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
    "applicationDisplayName": "Microsoft Graph Command Line Tools",
    "userPrincipalName": "adminuser@example.onmicrosoft.com",
    "servicePrincipalName": null,
    "ipAddress": null,
    "userId": "33333333-3333-3333-3333-333333333333"
  },
  "resources": [
    {
      "displayName": null,
      "auditResourceType": "MobileAppCategory",
      "resourceId": "1e52293f-5e1e-4319-842b-7a88608c37bd",
      "modifiedProperties": [
        {
          "displayName": "DeviceManagementAPIVersion",
          "oldValue": null,
          "newValue": "2025-07-02"
        }
      ]
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #