Exchange admin activity

OperationDescriptionSampleRule
anyCatch-all for M365-ExchangeAdmin rules matching the RecordType but no specific Operation.NY
Add-FederatedDomainA federated domain was added to the Exchange Online organization, enabling single-sign-on with an external identity provider.YY
Add-MailboxPermissionA mailbox permission (such as FullAccess) was granted to a user, enabling delegate access to another mailbox.YY
Add-RecipientPermissionA SendAs permission was granted on a recipient object, enabling impersonation of that recipient.YY
Add-RoleGroupMemberA role group member was added via the Add-RoleGroupMember Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Disable-AntiPhishRuleAn anti-phishing rule was disabled in Exchange Online Protection, reducing anti-phishing enforcement.YY
Disable-MalwareFilterRuleA malware filter rule was disabled, reducing malware scanning enforcement.YY
Disable-SafeAttachmentRuleA Safe Attachments policy rule was disabled in Microsoft Defender for Office 365, reducing detonation-sandbox coverage.YY
Disable-SafeLinksRuleA Safe Links policy rule was disabled in Microsoft Defender for Office 365, reducing URL-rewriting coverage.YY
Disable-TransportRuleA mail-flow transport rule was disabled, potentially allowing previously blocked or redirected mail to flow unimpeded.YY
New-AcceptedDomainA new accepted domain was added to the Exchange Online organization.NY
New-AntiPhishPolicyAn anti phish policy was created via the New-AntiPhishPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-AppAn Outlook or Exchange add-in (app) was installed into the organization or a mailbox.NN
New-DistributionGroupA distribution group was created via the New-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-DkimSigningConfigA dkim signing config was created via the New-DkimSigningConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-ExoInformationBarrierSegmentAn exo information barrier segment was created via the New-ExoInformationBarrierSegment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-HostedContentFilterPolicyA hosted content filter policy was created via the New-HostedContentFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-InboundConnectorAn inbound connector was created via the New-InboundConnector Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-InboxRuleAn Exchange inbox rule was created via the New-InboxRule cmdlet; first-party capture confirms it logs under ExchangeAdmin (RecordType 1), not the OWA-context UpdateInboxRules operation under ExchangeItem (RecordType 2).YY
New-MailboxA mailbox was created via the New-Mailbox Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-MalwareFilterPolicyA malware filter policy was created via the New-MalwareFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-ManagementRoleAssignmentA new RBAC management role assignment was created, granting administrative permissions in Exchange Online.YY
New-ManagementScopeA management scope was created via the New-ManagementScope Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-MobileDeviceMailboxPolicyA mobile device mailbox policy was created via the New-MobileDeviceMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-OwaMailboxPolicyAn owa mailbox policy was created via the New-OwaMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-RemoteDomainA remote domain was created via the New-RemoteDomain Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-RetentionPolicyA retention policy was created via the New-RetentionPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-RetentionPolicyTagA retention policy tag was created via the New-RetentionPolicyTag Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-RoleGroupA new RBAC role group was created in Exchange Online.YN
New-SafeAttachmentPolicyA safe attachment policy was created via the New-SafeAttachmentPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-SafeAttachmentRuleA Defender for Office 365 Safe Attachments rule was created, binding a Safe Attachments policy to the recipients it applies to. Observed in first-party Unified Audit Log capture. A policy is inert until a rule references it, and a policy cannot be removed while one does.NN
New-SafeLinksPolicyA safe links policy was created via the New-SafeLinksPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-ServicePrincipalA service principal was created via the New-ServicePrincipal Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-SharingPolicyA sharing policy was created via the New-SharingPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-TransportRuleA new mail-flow transport rule was created; adversaries use transport rules to silently copy, redirect, or delete messages.YY
New-UnifiedGroupAn unified group was created via the New-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-AcceptedDomainAn accepted domain was removed from the Exchange Online organization.NY
Remove-AntiPhishPolicyAn anti-phishing policy was deleted.YY
Remove-AntiPhishRuleAn anti-phishing rule was deleted from Exchange Online Protection.YY
Remove-DistributionGroupA distribution group was deleted via the Remove-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-DlpPolicyA Data Loss Prevention policy was deleted from Exchange Online.NY
Remove-ExoInformationBarrierSegmentAn exo information barrier segment was deleted via the Remove-ExoInformationBarrierSegment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-FederatedDomainA federated domain was removed from the Exchange Online organization.NY
Remove-HostedContentFilterPolicyA hosted content filter policy was deleted via the Remove-HostedContentFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-InboundConnectorAn inbound connector was deleted via the Remove-InboundConnector Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-InboxRuleAn inbox rule was deleted via the Remove-InboxRule Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-MailboxA mailbox was deleted via the Remove-Mailbox Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-MailboxPermissionA mailbox permission was removed from a user.YN
Remove-MalwareFilterPolicyA malware filter policy was deleted.YY
Remove-MalwareFilterRuleA malware filter rule was deleted.YY
Remove-ManagementRoleAssignmentA management role assignment was deleted via the Remove-ManagementRoleAssignment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-ManagementScopeA management scope was deleted via the Remove-ManagementScope Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
remove-MobileDeviceMailboxPolicyremove-Mobile Device Mailbox Policy activity in Exchange Online admin, recorded in the Unified Audit Log (observed in first-party capture).YN
Remove-OwaMailboxPolicyAn owa mailbox policy was deleted via the Remove-OwaMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-RecipientPermissionA recipient permission was deleted via the Remove-RecipientPermission Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-RemoteDomainA remote domain was deleted via the Remove-RemoteDomain Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
remove-RetentionPolicyremove-Retention Policy activity in Exchange Online admin, recorded in the Unified Audit Log (observed in first-party capture).YN
Remove-RetentionPolicyTagA retention policy tag was deleted via the Remove-RetentionPolicyTag Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-RoleGroupA role group was deleted via the Remove-RoleGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-SafeAttachmentPolicyA safe attachment policy was deleted via the Remove-SafeAttachmentPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YY
Remove-SafeAttachmentRuleA Defender for Office 365 Safe Attachments rule was deleted, detaching its policy from the recipients it applied to. Observed in first-party Unified Audit Log capture. Deleting the rule leaves the underlying Safe Attachments policy in place but stops it applying to anyone.YY
Remove-SafeLinksPolicyA safe links policy was deleted via the Remove-SafeLinksPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YY
Remove-SharingPolicyA sharing policy was deleted via the Remove-SharingPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-TransportRuleA mail-flow transport rule was deleted.YY
Remove-UnifiedGroupAn unified group was deleted via the Remove-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Set-AcceptedDomainAn accepted domain's configuration was modified.NY
Set-AdminAuditLogConfigThe administrator audit log configuration was changed; adversaries disable audit logging to evade detection.YY
Set-CASMailboxClient-access settings on a mailbox were modified (for example enabling POP, IMAP, or OWA); commonly abused to enable legacy-protocol access.YN
Set-ConditionalAccessPolicyA conditional access policy was modified via the Set-ConditionalAccessPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Set-DistributionGroupA distribution group was modified via the Set-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Set-DkimSigningConfigThe DKIM signing configuration for a domain was modified; disabling DKIM weakens email authentication.YY
Set-InboxRuleAn Exchange inbox rule was modified via the Set-InboxRule cmdlet; first-party capture confirms it logs under ExchangeAdmin (RecordType 1), like New-InboxRule, not the OWA-context UpdateInboxRules operation under ExchangeItem (RecordType 2).YY
Set-MailboxA mailbox configuration was modified; commonly abused to enable forwarding, audit bypass, or delegate access.YY
Set-MailboxAuditBypassAssociationMailbox audit logging was bypassed for a service account, suppressing audit events for that account's actions.YY
Set-MailboxFolderPermissionAn Exchange Online admin cmdlet modified folder-level permissions on a mailbox folder; recorded in the Exchange admin audit log with the Operation set to the cmdlet name (commonly abused to grant a delegate covert folder access).YY
Set-OrganizationConfigAn organization config was modified via the Set-OrganizationConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Set-TransportConfigA transport config was modified via the Set-TransportConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Set-TransportRuleAn existing mail-flow transport rule was modified.YY
Set-UnifiedGroupAn unified group was modified via the Set-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN

any: Exchange admin activity (catch-all)

#
RecordType
ExchangeAdmin

Description

Catch-all for M365-ExchangeAdmin rules matching the RecordType but no specific Operation.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 Email Security Feature Changed source: The following analytic identifies when specific O365 advanced security settings are altered within the Office 365 tenant. If an attacker successfully disables O365 security settings, they can operate within the tenant with reduced risk of…T1685, T1685.002
  • O365 Email Transport Rule Changed source: The following analytic identifies when a user with sufficient access to Exchange Online alters the mail flow/transport rule configuration of the organization. Transport rules are a set of rules that can be used by attackers to modify or…T1114, T1114.003, T1564, T1564.008

References #

Add-FederatedDomain

#
RecordType
ExchangeAdmin

Description

A federated domain was added to the Exchange Online organization, enabling single-sign-on with an external identity provider.

Example Audit Record #

{
  "CreationTime": "2021-01-05T23:39:58",
  "ExternalAccess": false,
  "Id": "93e3dd16-8cf0-4b85-e383-08d8b1d3366c",
  "ObjectId": "Federation",
  "Operation": "Add-FederatedDomain",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "OrganizationName": "rodsoto.onmicrosoft.com",
  "OriginatingServer": "BYAPR14MB2597 (15.20.3721.024)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "rodsoto.onmicrosoft.com"
    },
    {
      "Name": "DomainName",
      "Value": "rodsoto.mail.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "ResultStatus": "True",
  "UserId": "NT AUTHORITY\\SYSTEM (w3wp)",
  "UserKey": "NT AUTHORITY\\SYSTEM (w3wp)",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
status (sigma rule field)eqsuccess1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

References #

Add-MailboxPermission

#
RecordType
ExchangeAdmin

Description

A mailbox permission (such as FullAccess) was granted to a user, enabling delegate access to another mailbox.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:25953",
  "CreationTime": "2026-07-02T15:32:01Z",
  "ExternalAccess": false,
  "Id": "80b3dfc7-5aa6-4c84-c7fa-08ded84f0fc4",
  "ObjectId": "dwshared",
  "Operation": "Add-MailboxPermission",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwshared@example.onmicrosoft.com"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "AccessRights",
      "Value": "FullAccess"
    },
    {
      "Name": "User",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "bf13a316-a199-0ece-6ed0-1d2651c6d663",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
ResultType (kusto rule field)eq01 rulekusto
ResultType (kusto rule field)eq500571 rulekusto
successfulAccountSigninCount (kusto rule field)lt1001 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

Kusto #

References #

Add-RecipientPermission

#
RecordType
ExchangeAdmin

Description

A SendAs permission was granted on a recipient object, enabling impersonation of that recipient.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppId": "fb78d390-0c51-40cd-8e17-fdbfab77341b",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:18751",
  "CreationTime": "2026-07-02T15:32:03Z",
  "ExternalAccess": false,
  "Id": "fcec1905-2018-4d62-e023-08ded84f116c",
  "ObjectId": "dwshared",
  "Operation": "Add-RecipientPermission",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "AccessRights",
      "Value": "SendAs"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwshared@example.onmicrosoft.com"
    },
    {
      "Name": "Trustee",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "8d5b0e61-9a50-1fcb-2603-cc3b8978abdc",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Add-RoleGroupMember

#
RecordType
ExchangeAdmin

Description

A role group member was added via the Add-RoleGroupMember Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-837c-68c5-982d-be027a762ba3",
    "IssuedAtTime": "2026-07-03T04:26:34",
    "UniqueTokenId": "EvPNS22bdEiTvnGJY_ASAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:22290",
  "CreationDate": "2026-07-03T04:31:48",
  "CreationTime": "2026-07-03T04:31:48",
  "ExternalAccess": false,
  "Id": "d1890a7e-2eb0-4d63-32fb-08ded8bbfef1",
  "ObjectId": "Organization Management",
  "Operation": "Add-RoleGroupMember",
  "Operations": "Add-RoleGroupMember",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DM5PR16MB2165 (15.21.0159.018)",
  "Parameters": [
    {
      "Name": "Member",
      "Value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
    },
    {
      "Name": "Identity",
      "Value": "Organization Management"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "2e66f4b8-59d6-0dd2-ba3b-3d35c96f3f0c",
  "ResultStatus": "True",
  "SessionId": "006b4cda-837c-68c5-982d-be027a762ba3",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Disable-AntiPhishRule

#
RecordType
ExchangeAdmin

Description

An anti-phishing rule was disabled in Exchange Online Protection, reducing anti-phishing enforcement.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:29572",
  "CreationTime": "2026-07-02T15:31:26Z",
  "ExternalAccess": false,
  "Id": "eeb1f490-8f1b-4752-ad48-08ded84efb41",
  "ObjectId": "dwapr",
  "Operation": "Disable-AntiPhishRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwapr"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "2df24877-e91d-b347-9673-8d8615b95e63",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Name (elastic rule field)eqexchange1 ruleelastic
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

Disable-MalwareFilterRule

#
RecordType
ExchangeAdmin

Description

A malware filter rule was disabled, reducing malware scanning enforcement.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:27248",
  "CreationTime": "2026-07-02T15:31:30Z",
  "ExternalAccess": false,
  "Id": "df0f7edc-b5e4-40c2-9691-08ded84efda9",
  "ObjectId": "dwmfr",
  "Operation": "Disable-MalwareFilterRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwmfr"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "a6c40dec-7a3d-9ee7-045f-23fd2247f5cb",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Disable-SafeAttachmentRule

#
RecordType
ExchangeAdmin

Description

A Safe Attachments policy rule was disabled in Microsoft Defender for Office 365, reducing detonation-sandbox coverage.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006ea83a-c87c-9d74-7069-3efed03a3197",
    "IssuedAtTime": "2026-07-25T21:14:40",
    "UniqueTokenId": "QvBHGk0zqkKjWpKkIiwiAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:19486",
  "CreationDate": "2026-07-25T21:22:50",
  "CreationTime": "2026-07-25T21:22:50",
  "ExternalAccess": false,
  "Id": "aaa78829-8025-42f5-78fb-08deea92e1ac",
  "ObjectId": "dwharn412a7798-sar",
  "Operation": "Disable-SafeAttachmentRule",
  "Operations": "Disable-SafeAttachmentRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "IA3PR16MB6655 (15.21.0245.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn412a7798-sar"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    }
  ],
  "RecordType": 1,
  "RequestId": "00bf62ab-aa73-899c-bcde-8c0068bf1f1a",
  "ResultStatus": "True",
  "SessionId": "006ea83a-c87c-9d74-7069-3efed03a3197",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange Email Safe Attachment Rule Disabled source low: Identifies when a safe attachment rule is disabled in Microsoft 365. Safe attachment rules can extend malware protections to include routing all messages and attachments without a known malware signature to a special hypervisor environment. An adversary or insider threat may disable a safe attachment rule to exfiltrate data or evade defenses.T1562, T1562.001

Kusto #

References #

Disable-SafeLinksRule

#
RecordType
ExchangeAdmin

Description

A Safe Links policy rule was disabled in Microsoft Defender for Office 365, reducing URL-rewriting coverage.

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2024-02-01T22:21:33",
    "UniqueTokenId": "87Hz6J-5h0K6bJR_NT9QAA"
  },
  "AppId": "80ccca67-54bd-44ab-8625-4b79c4dc7775",
  "AppPoolName": "MSExchangeAdminApiAppPool",
  "ClientIP": "189.135.168.197:14381",
  "CreationTime": "2024-02-01T22:26:34",
  "ExternalAccess": false,
  "Id": "477ed988-73b0-493a-b3a9-08dc2374d903",
  "ObjectId": "Safe-Links Org-Wide",
  "Operation": "Disable-SafeLinksRule",
  "OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "OrganizationName": "attack_range.onmicrosoft.com",
  "OriginatingServer": "BYAPR08MB5704 (15.20.7249.013)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "56216be3-9e84-411a-af36-13f200007341"
    }
  ],
  "RecordType": 1,
  "RequestId": "9f9f2ef1-0861-91d6-68da-af7ccdc0c5a2",
  "ResultStatus": "True",
  "SessionId": "c85d6a46-8c63-449b-9591-c3ab602dac97",
  "UserId": "attacker@attack_range.lan",
  "UserKey": "1003200143005E6B",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Name (elastic rule field)eqexchange1 ruleelastic
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

Disable-TransportRule

#
RecordType
ExchangeAdmin

Description

A mail-flow transport rule was disabled, potentially allowing previously blocked or redirected mail to flow unimpeded.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:24923",
  "CreationTime": "2026-07-02T15:30:56Z",
  "ExternalAccess": false,
  "Id": "b85b63db-add2-4d0e-9cca-08ded84ee8fc",
  "ObjectId": "dwtr",
  "Operation": "Disable-TransportRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwtr"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "d1796c27-76a4-a1c8-71d5-7bb7defa703c",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

New-AcceptedDomain

#
RecordType
ExchangeAdmin

Description

A new accepted domain was added to the Exchange Online organization.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

New-AntiPhishPolicy

#
RecordType
ExchangeAdmin

Description

An anti phish policy was created via the New-AntiPhishPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:21085",
  "CreationTime": "2026-07-02T15:31:24Z",
  "ExternalAccess": false,
  "Id": "0eae10b5-72b2-4178-6e59-08ded84efa23",
  "ObjectId": "example.onmicrosoft.com\\dwap",
  "Operation": "New-AntiPhishPolicy",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Name",
      "Value": "dwap"
    }
  ],
  "RecordType": 1,
  "RequestId": "711769be-29d9-8491-bd32-4caf6eab90f8",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-App

#
RecordType
ExchangeAdmin

Description

An Outlook or Exchange add-in (app) was installed into the organization or a mailbox.

References #

New-DistributionGroup

#
RecordType
ExchangeAdmin

Description

A distribution group was created via the New-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:23717",
  "CreationDate": "2026-07-03T01:55:17",
  "CreationTime": "2026-07-03T01:55:17",
  "ExternalAccess": false,
  "Id": "d258fca2-67d8-4982-6823-08ded8a621ab",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/dwharna9dd06c7-dg",
  "Operation": "New-DistributionGroup",
  "Operations": "New-DistributionGroup",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "BN7PPF175DB1016 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharna9dd06c7-dg"
    },
    {
      "Name": "Type",
      "Value": "Distribution"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "63cfd54f-e2a7-ff76-a7ee-79921cf5daab",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-DkimSigningConfig

#
RecordType
ExchangeAdmin

Description

A dkim signing config was created via the New-DkimSigningConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:16271",
  "CreationDate": "2026-07-03T04:03:10",
  "CreationTime": "2026-07-03T04:03:10",
  "ExternalAccess": false,
  "Id": "8d97ce5e-bb1d-4526-20bc-08ded8b7ff19",
  "ObjectId": "example.onmicrosoft.com\\example.onmicrosoft.com",
  "Operation": "New-DkimSigningConfig",
  "Operations": "New-DkimSigningConfig",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "CH3PR16MB5969 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "DomainName",
      "Value": "example.onmicrosoft.com"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Enabled",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "94fc7691-f72f-629e-d023-868adeb8a8e3",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-ExoInformationBarrierSegment

#
RecordType
ExchangeAdmin

Description

An exo information barrier segment was created via the New-ExoInformationBarrierSegment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2026-07-03T05:56:29",
    "UniqueTokenId": "245eff30-bd3a-8dc4-91ce-bd632687c63c"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "[2001:db8::10]:14571",
  "CreationDate": "2026-07-03T06:00:46",
  "CreationTime": "2026-07-03T06:00:46",
  "ExternalAccess": false,
  "Id": "0e4bf4ee-4657-4691-560a-08ded8c86ced",
  "ObjectId": "example.onmicrosoft.com\\2bb8ca5f-c452-48c0-9e0f-99a7603caab7",
  "Operation": "New-ExoInformationBarrierSegment",
  "Operations": "New-ExoInformationBarrierSegment",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SN1PR16MB2397 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "SegmentId",
      "Value": "2bb8ca5f-c452-48c0-9e0f-99a7603caab7"
    },
    {
      "Name": "MembershipFilter",
      "Value": "Department -eq 'zzzdwharn'"
    },
    {
      "Name": "DisplayName",
      "Value": "dwharnee8749b4-seg"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "4b6cbc11-4a4b-1e9c-dbd0-0c4193693c24",
  "ResultStatus": "True",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-HostedContentFilterPolicy

#
RecordType
ExchangeAdmin

Description

A hosted content filter policy was created via the New-HostedContentFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:11876",
  "CreationDate": "2026-07-03T01:55:39",
  "CreationTime": "2026-07-03T01:55:39",
  "ExternalAccess": false,
  "Id": "5393934e-7b70-4bac-00ad-08ded8a62f21",
  "ObjectId": "example.onmicrosoft.com\\dwharna9dd06c7-spam",
  "Operation": "New-HostedContentFilterPolicy",
  "Operations": "New-HostedContentFilterPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DM6PR16MB2668 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharna9dd06c7-spam"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "ae29f3c7-dc66-65f8-b128-ca5f7e13f651",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-InboundConnector

#
RecordType
ExchangeAdmin

Description

An inbound connector was created via the New-InboundConnector Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:46184",
  "CreationDate": "2026-07-03T04:02:39",
  "CreationTime": "2026-07-03T04:02:39",
  "ExternalAccess": false,
  "Id": "b790651e-9258-4c62-1aae-08ded8b7ecba",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-ic",
  "Operation": "New-InboundConnector",
  "Operations": "New-InboundConnector",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "IA6PR16MB6837 (15.21.0159.018)",
  "Parameters": [
    {
      "Name": "ConnectorType",
      "Value": "Partner"
    },
    {
      "Name": "SenderDomains",
      "Value": "smtp:*.example.com;1"
    },
    {
      "Name": "Name",
      "Value": "dwharn867f01-ic"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "8b50e0ca-7ad0-b6f2-514f-96cf0269bc2b",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-InboxRule

#
RecordType
ExchangeAdmin

Description

An Exchange inbox rule was created via the New-InboxRule cmdlet; first-party capture confirms it logs under ExchangeAdmin (RecordType 1), not the OWA-context UpdateInboxRules operation under ExchangeItem (RecordType 2).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:23059",
  "CreationTime": "2026-07-02T15:31:20Z",
  "ExternalAccess": false,
  "Id": "c2d4654f-074e-4ec9-2911-08ded84ef746",
  "ObjectId": "11111111-1111-1111-1111-111111111111\\dwir",
  "Operation": "New-InboxRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "DeleteMessage",
      "Value": "True"
    },
    {
      "Name": "Name",
      "Value": "dwir"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Mailbox",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "SubjectContainsWords",
      "Value": "x"
    }
  ],
  "RecordType": 1,
  "RequestId": "75896e1e-3a27-9b7c-c38b-89c552840b3c",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
m365::Parameterscontainsdeletemessage3 ruleskusto, sigma
m365::Parameters (kusto rule field)containsdeleted items2 ruleskusto
m365::Parameters (kusto rule field)containsjunk email2 ruleskusto
BodyContainsWords (kusto rule field)containsphishing2 ruleskusto
BodyContainsWords (kusto rule field)contains alert1 rulekusto
BodyContainsWords (kusto rule field)contains suspicious1 rulekusto
BodyContainsWords (kusto rule field)containsdo not click1 rulekusto
BodyContainsWords (kusto rule field)containsdo not open1 rulekusto
BodyContainsWords (kusto rule field)containsfake1 rulekusto
BodyContainsWords (kusto rule field)containsfatal1 rulekusto
BodyContainsWords (kusto rule field)containshelpdesk1 rulekusto
EventType (elastic rule field)innew-inboxrule2 ruleselastic
EventType (elastic rule field)inset-inboxrule2 ruleselastic
SubjectContainsWords (kusto rule field)containsphishing2 ruleskusto
SubjectOrBodyContainsWords (kusto rule field)containsphishing2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • M365 Exchange Inbox Forwarding Rule Created source medium: Identifies when a new Inbox forwarding rule is created in Microsoft 365. Inbox rules process messages in the Inbox based on conditions and take actions. In this case, the rules will forward the emails to a defined address. Attackers can abuse Inbox Rules to intercept and exfiltrate email data without making organization-wide configuration changes or having the corresponding privileges.T1114, T1114.003↳ also matches New-TransportRule, Set-InboxRule, Set-Mailbox, Set-TransportRule
  • M365 Exchange Inbox Rule with Obfuscated Name source medium: Identifies when a Microsoft Exchange inbox rule is created or modified with a name composed only of special characters. Adversaries may use obfuscated inbox rule names to evade detection, hide malicious forwarding or deletion rules, or blend in with benign audit noise. The rule name is parsed from "o365.audit.ObjectId", which encodes the mailbox identity and rule name separated by a backslash.T1137, T1137.005, T1564, T1564.008↳ also matches Set-InboxRule
  • M365 Exchange Inbox Phishing Evasion Rule Created source high: Identifies when a user creates a new inbox rule in Microsoft 365 that deletes or moves emails containing suspicious keywords. Adversaries who have compromised accounts often create inbox rules to hide alerts, security notifications, or other sensitive messages by automatically deleting them or moving them to obscure folders. Common destinations include Deleted Items, Junk Email, RSS Feeds, and RSS Subscriptions. This is a New Terms rule that triggers only when the user principal name and associated source IP address have not been observed performing this activity in the past 14 days.T1137, T1137.005, T1564, T1564.008↳ also matches Set-InboxRule

Splunk #

Kusto #

  • Malicious BEC Inbox Rule source medium: 'Often times after the initial compromise in a BEC attack the attackers create inbox rules to delete emails that contain certain keywords related to their BEC attack. This is done so as to limit ability to warn compromised users that they've been compromised.T1078, T1098
  • Malicious Inbox Rule source medium: Often times after the initial compromise the attackers create inbox rules to delete emails that contain certain keywords. This is done so as to limit ability to warn compromised users that they've been compromised. Below is a sample query that tries to detect this. Reference: https://www.reddit.com/r/sysadmin/comments/7kyp0a/recent_phishing_attempts_my_experience_and_what/T1078, T1098
  • High risk Office operation conducted by IP Address that recently attempted to log into a disabled account source medium: It is possible that a disabled user account is compromised and another account on the same IP is used to perform operations that are not typical for that user. The query filters the SigninLogs for entries where ResultType is indicates a disabled account and the TimeGenerated is within a defined time range. It then summarizes these entries by IPAddress and AppId, calculating various statistics such as number of login attempts, distinct UPNs, App IDs etc and joins these results with another set of results from SigninLogs, filtering for entries with less than normal number of successful sign-ins. It then filters out entries where there were no successful sign-ins or where successful sign-ins did not occur within the same lookback period as the failed sign-ins, later projecting relevant fields by the count of login attempts, and expands the set of successful sign-ins into individual events. Finally, it joins these results with entries from OfficeActivity where certain operations deemed rare and high risk have been performed, ensuring their occurrance within a certain time range of the successful sign-ins.T1078, T1098, T1114↳ also matches Add-MailboxPermission, New-ManagementRoleAssignment, Set-InboxRule, Set-Mailbox, Set-TransportRule

References #

New-Mailbox

#
RecordType
ExchangeAdmin

Description

A mailbox was created via the New-Mailbox Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:33:23Z",
    "UniqueTokenId": "puNkY8foYkSQSz011CYOAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28645",
  "CreationTime": "2026-07-02T15:38:34Z",
  "ExternalAccess": false,
  "Id": "3ac8a4c1-bdce-416f-3bf2-08ded84ffa6c",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/dwshared2",
  "Operation": "New-Mailbox",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwshared2"
    },
    {
      "Name": "DisplayName",
      "Value": "dw shared2"
    },
    {
      "Name": "Shared",
      "Value": "True"
    },
    {
      "Name": "PrimarySmtpAddress",
      "Value": "dwshared2@example.onmicrosoft.com"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "WindowsLiveID",
      "Value": "dwshared2@example.onmicrosoft.com"
    },
    {
      "Name": "Password",
      "Value": "<Secure Information Omitted>"
    }
  ],
  "RecordType": 1,
  "RequestId": "304497c0-b535-26fe-bc04-a2912b562a1b",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-MalwareFilterPolicy

#
RecordType
ExchangeAdmin

Description

A malware filter policy was created via the New-MalwareFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:12976",
  "CreationTime": "2026-07-02T15:31:29Z",
  "ExternalAccess": false,
  "Id": "42083e17-4aee-4ee3-442d-08ded84efcc7",
  "ObjectId": "example.onmicrosoft.com\\dwmf",
  "Operation": "New-MalwareFilterPolicy",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Name",
      "Value": "dwmf"
    }
  ],
  "RecordType": 1,
  "RequestId": "25ba1270-d345-238a-71f2-6cfda0ce10bf",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-ManagementRoleAssignment

#
RecordType
ExchangeAdmin

Description

A new RBAC management role assignment was created, granting administrative permissions in Exchange Online.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:26315",
  "CreationTime": "2026-07-02T15:31:32Z",
  "ExternalAccess": false,
  "Id": "155e24be-1cac-44ba-3ee5-08ded84efebf",
  "ObjectId": "example.onmicrosoft.com\\dwmra",
  "Operation": "New-ManagementRoleAssignment",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwmra"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Role",
      "Value": "View-Only Recipients"
    },
    {
      "Name": "User",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "4be42e87-23fa-fe08-4a55-91d29c3e1332",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
ResultType (kusto rule field)eq500571 rulekusto
successfulAccountSigninCount (kusto rule field)lt1001 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

Kusto #

References #

New-ManagementScope

#
RecordType
ExchangeAdmin

Description

A management scope was created via the New-ManagementScope Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:46574",
  "CreationDate": "2026-07-03T04:03:13",
  "CreationTime": "2026-07-03T04:03:13",
  "ExternalAccess": false,
  "Id": "559b6c19-1b1f-4f31-5581-08ded8b800ee",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-ms",
  "Operation": "New-ManagementScope",
  "Operations": "New-ManagementScope",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "BYAPR16MB2949 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "RecipientRestrictionFilter",
      "Value": "Name -like 'zzz*'"
    },
    {
      "Name": "Name",
      "Value": "dwharn867f01-ms"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "bb22ced8-73dc-f6e9-ac46-25a9d18ecff6",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-MobileDeviceMailboxPolicy

#
RecordType
ExchangeAdmin

Description

A mobile device mailbox policy was created via the New-MobileDeviceMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:12012",
  "CreationDate": "2026-07-03T01:55:53",
  "CreationTime": "2026-07-03T01:55:53",
  "ExternalAccess": false,
  "Id": "5413d57f-0d2f-4bad-d807-08ded8a6374a",
  "ObjectId": "example.onmicrosoft.com\\dwharna9dd06c7-mdm",
  "Operation": "New-MobileDeviceMailboxPolicy",
  "Operations": "New-MobileDeviceMailboxPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "LV3PR16MB5882 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharna9dd06c7-mdm"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "e54ce337-e737-9d71-a08e-58483f07e7b6",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-OwaMailboxPolicy

#
RecordType
ExchangeAdmin

Description

An owa mailbox policy was created via the New-OwaMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:16516",
  "CreationDate": "2026-07-03T01:55:49",
  "CreationTime": "2026-07-03T01:55:49",
  "ExternalAccess": false,
  "Id": "a9e9fbd4-f182-4e75-54ae-08ded8a6351f",
  "ObjectId": "example.onmicrosoft.com\\dwharna9dd06c7-owa",
  "Operation": "New-OwaMailboxPolicy",
  "Operations": "New-OwaMailboxPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DS0PR16MB6878 (15.21.0159.007)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharna9dd06c7-owa"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "915f1229-8120-369a-4066-f024d651c3c2",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-RemoteDomain

#
RecordType
ExchangeAdmin

Description

A remote domain was created via the New-RemoteDomain Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:19441",
  "CreationDate": "2026-07-03T04:02:49",
  "CreationTime": "2026-07-03T04:02:49",
  "ExternalAccess": false,
  "Id": "c07a07c6-18be-4b16-4c8c-08ded8b7f2a9",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-rd",
  "Operation": "New-RemoteDomain",
  "Operations": "New-RemoteDomain",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "CH3PR16MB6372 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharn867f01-rd"
    },
    {
      "Name": "DomainName",
      "Value": "dwharn867f01.example.com"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "a90b03a0-e874-f8b5-cda6-175d0e710849",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-RetentionPolicy

#
RecordType
ExchangeAdmin

Description

A retention policy was created via the New-RetentionPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:16484",
  "CreationDate": "2026-07-03T04:02:57",
  "CreationTime": "2026-07-03T04:02:57",
  "ExternalAccess": false,
  "Id": "35cf24ff-101d-4579-38a9-08ded8b7f76e",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-rp",
  "Operation": "New-RetentionPolicy",
  "Operations": "New-RetentionPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA5PPFC5A1786DC (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharn867f01-rp"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "cd045617-e0a9-9752-8964-ee0f0dcdb008",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-RetentionPolicyTag

#
RecordType
ExchangeAdmin

Description

A retention policy tag was created via the New-RetentionPolicyTag Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:14757",
  "CreationDate": "2026-07-03T04:03:02",
  "CreationTime": "2026-07-03T04:03:02",
  "ExternalAccess": false,
  "Id": "eacc3de6-2b4b-4456-3c2b-08ded8b7faa9",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-rpt",
  "Operation": "New-RetentionPolicyTag",
  "Operations": "New-RetentionPolicyTag",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA6PR16MB6695 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Type",
      "Value": "All"
    },
    {
      "Name": "AgeLimitForRetention",
      "Value": "365.00:00:00"
    },
    {
      "Name": "RetentionEnabled",
      "Value": "True"
    },
    {
      "Name": "RetentionAction",
      "Value": "DeleteAndAllowRecovery"
    },
    {
      "Name": "Name",
      "Value": "dwharn867f01-rpt"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "e335dfb8-9fe4-4a9a-9b01-f1db349b82ec",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-RoleGroup

#
RecordType
ExchangeAdmin

Description

A new RBAC role group was created in Exchange Online.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:20325",
  "CreationTime": "2026-07-02T15:31:34Z",
  "ExternalAccess": false,
  "Id": "ac68f239-eb02-4baa-d265-08ded84effec",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/dwrg",
  "Operation": "New-RoleGroup",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Roles",
      "Value": "View-Only Recipients"
    },
    {
      "Name": "Name",
      "Value": "dwrg"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    }
  ],
  "RecordType": 1,
  "RequestId": "137a6d48-09cb-6af0-0c4a-f479dfe1ea63",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-SafeAttachmentPolicy

#
RecordType
ExchangeAdmin

Description

A safe attachment policy was created via the New-SafeAttachmentPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:29457",
  "CreationDate": "2026-07-03T04:02:26",
  "CreationTime": "2026-07-03T04:02:26",
  "ExternalAccess": false,
  "Id": "9032a13c-2a86-4ada-8d51-08ded8b7e50d",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-sa",
  "Operation": "New-SafeAttachmentPolicy",
  "Operations": "New-SafeAttachmentPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DM4PR16MB5419 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Enable",
      "Value": "True"
    },
    {
      "Name": "Name",
      "Value": "dwharn867f01-sa"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "efc477f8-8b01-a528-ceb5-1de23c41fe4c",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-SafeAttachmentRule

#
RecordType
ExchangeAdmin

Description

A Defender for Office 365 Safe Attachments rule was created, binding a Safe Attachments policy to the recipients it applies to. Observed in first-party Unified Audit Log capture. A policy is inert until a rule references it, and a policy cannot be removed while one does.

References #

New-SafeLinksPolicy

#
RecordType
ExchangeAdmin

Description

A safe links policy was created via the New-SafeLinksPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:23168",
  "CreationDate": "2026-07-03T04:02:31",
  "CreationTime": "2026-07-03T04:02:31",
  "ExternalAccess": false,
  "Id": "828a31f2-d960-404e-84ec-08ded8b7e7b5",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-sl",
  "Operation": "New-SafeLinksPolicy",
  "Operations": "New-SafeLinksPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA2PR16MB4186 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharn867f01-sl"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "544b81ea-01ff-79cd-90ca-1bfaecbd0169",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-ServicePrincipal

#
RecordType
ExchangeAdmin

Description

A service principal was created via the New-ServicePrincipal Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-837c-68c5-982d-be027a762ba3",
    "IssuedAtTime": "2026-07-03T04:26:34",
    "UniqueTokenId": "EvPNS22bdEiTvnGJY_ASAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:36904",
  "CreationDate": "2026-07-03T04:31:43",
  "CreationTime": "2026-07-03T04:31:43",
  "ExternalAccess": false,
  "Id": "195b0e02-c074-4daf-5455-08ded8bbfc43",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "Operation": "New-ServicePrincipal",
  "Operations": "New-ServicePrincipal",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SJ2PR16MB6037 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "AppId",
      "Value": "22222222-2222-2222-2222-222222222222"
    },
    {
      "Name": "ServiceId",
      "Value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
    },
    {
      "Name": "DisplayName",
      "Value": "dw-activity-gen"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "014615a2-5ffb-f5ec-8a17-a3580108a7d3",
  "ResultStatus": "True",
  "SessionId": "006b4cda-837c-68c5-982d-be027a762ba3",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-SharingPolicy

#
RecordType
ExchangeAdmin

Description

A sharing policy was created via the New-SharingPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:26833",
  "CreationDate": "2026-07-03T04:02:52",
  "CreationTime": "2026-07-03T04:02:52",
  "ExternalAccess": false,
  "Id": "a863e1e3-e1f0-4647-1f51-08ded8b7f4ba",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-sp",
  "Operation": "New-SharingPolicy",
  "Operations": "New-SharingPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "MW5PR16MB4738 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharn867f01-sp"
    },
    {
      "Name": "Domains",
      "Value": "Anonymous:CalendarSharingFreeBusySimple"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "66c3d910-71d2-351d-509b-f8bc984e62fa",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-TransportRule

#
RecordType
ExchangeAdmin

Description

A new mail-flow transport rule was created; adversaries use transport rules to silently copy, redirect, or delete messages.

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2024-04-05T02:04:16",
    "UniqueTokenId": "MlCqXpE8E0WXmJNhOtNuAA"
  },
  "CreationTime": "2024-04-05T02:09:30",
  "Id": "cae78cca-32a7-4589-8ee8-08dc55156db3",
  "Operation": "New-TransportRule",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 1,
  "ResultStatus": "True",
  "UserKey": "1003BFFD98415B4E",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange",
  "ClientIP": "120.1.121.43:15922",
  "UserId": "user30@splunkresearch.onmicrosoft.com",
  "AppId": "d3590ed6-52b3-4102-aeff-aad2292ab01c",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ExternalAccess": false,
  "OrganizationName": "splunkresearch.onmicrosoft.com",
  "OriginatingServer": "CH0PR18MB4290 (15.20.7409.037)",
  "Parameters": [
    {
      "Name": "Priority",
      "Value": "0"
    },
    {
      "Name": "BlindCopyTo",
      "Value": "attacker@evil.com"
    },
    {
      "Name": "Name",
      "Value": "msInvader mailfow rule"
    }
  ],
  "RequestId": "6864046b-09f3-66e9-8e2a-0e184ff4f19b",
  "SessionId": "3aee2e0a-dbf2-49eb-982c-5ecc93a41c29"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Value (kusto rule field)is_not_null2 ruleskusto
m365::Workload (kusto rule field)eqExchange2 ruleskusto
Provider_Name (elastic rule field)eqExchange1 ruleelastic
match1 (splunk rule field)ge01 rulesplunk
match2 (splunk rule field)ge01 rulesplunk
match3 (splunk rule field)ge01 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

  • O365 New Forwarding Mailflow Rule Created source: The following analytic detects the creation of new mail flow rules in Office 365 that may redirect or copy emails to unauthorized or external addresses. It leverages Office 365 Management Activity logs, specifically querying for the…T1114

Kusto #

References #

New-UnifiedGroup

#
RecordType
ExchangeAdmin

Description

An unified group was created via the New-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppPoolName": "Microsoft.Exchange.DsApi.GRpc.NetCore",
  "CreationTime": "2026-07-04T16:14:05Z",
  "ExternalAccess": false,
  "Id": "957e14b8-9e38-49fa-c659-08ded9e7451d",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/AllCompany.181245214720.zzjydiec_24c1912b67",
  "Operation": "New-UnifiedGroup",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DS4PR16MB7145 (15.21.0159.007)",
  "Parameters": [
    {
      "Name": "IgnoreNamingPolicy",
      "Value": "True"
    },
    {
      "Name": "DomainController",
      "Value": "SJ0PR16A14DC003.NAMPR16A014.PROD.OUTLOOK.COM"
    },
    {
      "Name": "UnifiedGroupAccessType",
      "Value": "Public"
    },
    {
      "Name": "ProvisioningOptions",
      "Value": "YammerProvisioning"
    },
    {
      "Name": "GroupPersonification"
    },
    {
      "Name": "InformationBarrierMode",
      "Value": "Open"
    },
    {
      "Name": "EmailAddresses",
      "Value": "SMTP:AllCompany.181245214720.zzjydiec@example.onmicrosoft.com"
    },
    {
      "Name": "Database",
      "Value": "NAMPR16DG406-db377"
    }
  ],
  "RecordType": 1,
  "RequestId": "3f74cfbf-4aa2-44b9-b757-33e8fed6802b",
  "ResultStatus": "True",
  "UserId": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-AcceptedDomain

#
RecordType
ExchangeAdmin

Description

An accepted domain was removed from the Exchange Online organization.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Remove-AntiPhishPolicy

#
RecordType
ExchangeAdmin

Description

An anti-phishing policy was deleted.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:19711",
  "CreationTime": "2026-07-02T15:31:28Z",
  "ExternalAccess": false,
  "Id": "694337cf-2b6a-4c8c-1a56-08ded84efc34",
  "ObjectId": "dwap",
  "Operation": "Remove-AntiPhishPolicy",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwap"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "a0ec8e4e-882b-0dd7-4296-9ee845a02d23",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Name (elastic rule field)eqexchange1 ruleelastic
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange Anti-Phish Policy Deleted source medium: Identifies the deletion of an anti-phishing policy in Microsoft 365. By default, Microsoft 365 includes built-in features that help protect users from phishing attacks. Anti-phishing polices increase this protection by refining settings to better detect and prevent attacks.T1484, T1562, T1562.001

Kusto #

References #

Remove-AntiPhishRule

#
RecordType
ExchangeAdmin

Description

An anti-phishing rule was deleted from Exchange Online Protection.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:17896",
  "CreationTime": "2026-07-02T15:31:27Z",
  "ExternalAccess": false,
  "Id": "5a3c9793-27fa-45b4-6be2-08ded84efbaf",
  "ObjectId": "dwapr",
  "Operation": "Remove-AntiPhishRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwapr"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "1727cef2-6742-fe9e-8c45-b28696b853df",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Name (elastic rule field)eqexchange1 ruleelastic
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

Remove-DistributionGroup

#
RecordType
ExchangeAdmin

Description

A distribution group was deleted via the Remove-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:18301",
  "CreationDate": "2026-07-03T01:56:31",
  "CreationTime": "2026-07-03T01:56:31",
  "ExternalAccess": false,
  "Id": "e8b2e134-1c36-4de7-2e6e-08ded8a64e15",
  "ObjectId": "dwharna9dd06c7-dg",
  "Operation": "Remove-DistributionGroup",
  "Operations": "Remove-DistributionGroup",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "LV8PR16MB6471 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharna9dd06c7-dg"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "f0010549-9587-4766-b2f6-884ea498a27f",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-DlpPolicy

#
RecordType
ExchangeAdmin

Description

A Data Loss Prevention policy was deleted from Exchange Online.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Name (elastic rule field)eqexchange1 ruleelastic
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

Remove-ExoInformationBarrierSegment

#
RecordType
ExchangeAdmin

Description

An exo information barrier segment was deleted via the Remove-ExoInformationBarrierSegment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2026-07-03T06:00:49",
    "UniqueTokenId": "32437bbd-6d7d-8789-a4d0-45da268ac647"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "[2001:db8::10]:11014",
  "CreationDate": "2026-07-03T06:00:52",
  "CreationTime": "2026-07-03T06:00:52",
  "ExternalAccess": false,
  "Id": "4c717efb-f797-4c04-5133-08ded8c87085",
  "ObjectId": "2bb8ca5f-c452-48c0-9e0f-99a7603caab7",
  "Operation": "Remove-ExoInformationBarrierSegment",
  "Operations": "Remove-ExoInformationBarrierSegment",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "BY1PR16MB6484 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "2bb8ca5f-c452-48c0-9e0f-99a7603caab7"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "d5437e85-06f0-62aa-8baa-1d7456a51fa2",
  "ResultStatus": "True",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-FederatedDomain

#
RecordType
ExchangeAdmin

Description

A federated domain was removed from the Exchange Online organization.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Remove-HostedContentFilterPolicy

#
RecordType
ExchangeAdmin

Description

A hosted content filter policy was deleted via the Remove-HostedContentFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:30226",
  "CreationDate": "2026-07-03T04:11:39",
  "CreationTime": "2026-07-03T04:11:39",
  "ExternalAccess": false,
  "Id": "011645be-efed-45c4-ff42-08ded8b92ee5",
  "ObjectId": "dwharn75efecde-spam",
  "Operation": "Remove-HostedContentFilterPolicy",
  "Operations": "Remove-HostedContentFilterPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "BN7PPF93464F273 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-spam"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "db8700c2-5735-6ca6-22ec-1de5dd0a42bd",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-InboundConnector

#
RecordType
ExchangeAdmin

Description

An inbound connector was deleted via the Remove-InboundConnector Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:22802",
  "CreationDate": "2026-07-03T04:12:01",
  "CreationTime": "2026-07-03T04:12:01",
  "ExternalAccess": false,
  "Id": "79023267-f2e3-47c0-7c6c-08ded8b93bff",
  "ObjectId": "dwharn75efecde-ic",
  "Operation": "Remove-InboundConnector",
  "Operations": "Remove-InboundConnector",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SJ2PR16MB6249 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-ic"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "87468291-f901-c8af-79bb-75799231e1be",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-InboxRule

#
RecordType
ExchangeAdmin

Description

An inbox rule was deleted via the Remove-InboxRule Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:20058",
  "CreationTime": "2026-07-02T15:31:23Z",
  "ExternalAccess": false,
  "Id": "50dac51b-793c-4618-7485-08ded84ef996",
  "ObjectId": "11111111-1111-1111-1111-111111111111\\5819733106155847681",
  "Operation": "Remove-InboxRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwir"
    },
    {
      "Name": "Mailbox",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "05a466ea-54ec-920b-55aa-6b631e49d70d",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-Mailbox

#
RecordType
ExchangeAdmin

Description

A mailbox was deleted via the Remove-Mailbox Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppId": "fb78d390-0c51-40cd-8e17-fdbfab77341b",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28436",
  "CreationTime": "2026-07-02T15:32:12Z",
  "ExternalAccess": false,
  "Id": "a5489d96-ee2c-48cd-4a6b-08ded84f1670",
  "ObjectId": "dwshared",
  "Operation": "Remove-Mailbox",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwshared@example.onmicrosoft.com"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "4226dd1a-be57-b1a1-64a6-7a60d40795d2",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-MailboxPermission

#
RecordType
ExchangeAdmin

Description

A mailbox permission was removed from a user.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppId": "fb78d390-0c51-40cd-8e17-fdbfab77341b",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:20785",
  "CreationTime": "2026-07-02T15:32:06Z",
  "ExternalAccess": false,
  "Id": "8c7509ea-c8d0-48ef-425c-08ded84f12b6",
  "ObjectId": "dwshared",
  "Operation": "Remove-MailboxPermission",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwshared@example.onmicrosoft.com"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "AccessRights",
      "Value": "FullAccess"
    },
    {
      "Name": "User",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "b1128244-ecdc-8a94-2338-739197ff03b9",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-MalwareFilterPolicy

#
RecordType
ExchangeAdmin

Description

A malware filter policy was deleted.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:22692",
  "CreationTime": "2026-07-02T15:31:31Z",
  "ExternalAccess": false,
  "Id": "52ed5062-086c-43d1-bc07-08ded84efe49",
  "ObjectId": "dwmf",
  "Operation": "Remove-MalwareFilterPolicy",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwmf"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "563e6919-ccdc-f0af-0144-4e5a86563674",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange Malware Filter Policy Deleted source medium: Identifies when a malware filter policy has been deleted in Microsoft 365. A malware filter policy is used to alert administrators that an internal user sent a message that contained malware. This may indicate an account or machine compromise that would need to be investigated. Deletion of a malware filter policy may be done to evade detection.T1562, T1562.001

References #

Remove-MalwareFilterRule

#
RecordType
ExchangeAdmin

Description

A malware filter rule was deleted.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:16762",
  "CreationTime": "2026-07-02T15:31:31Z",
  "ExternalAccess": false,
  "Id": "8ab219ca-8333-4b6a-59a7-08ded84efdfa",
  "ObjectId": "dwmfr",
  "Operation": "Remove-MalwareFilterRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwmfr"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "d55abd3b-e7b6-c8b2-05fc-1124a498287b",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Remove-ManagementRoleAssignment

#
RecordType
ExchangeAdmin

Description

A management role assignment was deleted via the Remove-ManagementRoleAssignment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:17489",
  "CreationTime": "2026-07-02T15:31:33Z",
  "ExternalAccess": false,
  "Id": "894082ed-4b20-41bb-0623-08ded84eff3a",
  "ObjectId": "dwmra",
  "Operation": "Remove-ManagementRoleAssignment",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwmra"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "304a0458-313f-8ae1-6b60-bb35fe2abaaa",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-ManagementScope

#
RecordType
ExchangeAdmin

Description

A management scope was deleted via the Remove-ManagementScope Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:26667",
  "CreationDate": "2026-07-03T04:12:37",
  "CreationTime": "2026-07-03T04:12:37",
  "ExternalAccess": false,
  "Id": "3a18d037-f320-45ec-97bc-08ded8b9517e",
  "ObjectId": "dwharn75efecde-ms",
  "Operation": "Remove-ManagementScope",
  "Operations": "Remove-ManagementScope",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "IA2PR16MB6478 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-ms"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "593f7c24-f4ca-46d8-8479-603fedb6909d",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

remove-MobileDeviceMailboxPolicy

#
RecordType
ExchangeAdmin

Description

remove-Mobile Device Mailbox Policy activity in Exchange Online admin, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:29244",
  "CreationDate": "2026-07-03T01:55:59",
  "CreationTime": "2026-07-03T01:55:59",
  "ExternalAccess": false,
  "Id": "87d6f89d-9220-4f6d-65ed-08ded8a63b06",
  "ObjectId": "dwharna9dd06c7-mdm",
  "Operation": "remove-MobileDeviceMailboxPolicy",
  "Operations": "remove-MobileDeviceMailboxPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "MW3PR16MB3771 (15.21.0159.007)",
  "Parameters": [
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "Identity",
      "Value": "dwharna9dd06c7-mdm"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "8bef7c74-782c-8afe-676e-07dd0bbb2a53",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-OwaMailboxPolicy

#
RecordType
ExchangeAdmin

Description

An owa mailbox policy was deleted via the Remove-OwaMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:16056",
  "CreationDate": "2026-07-03T01:59:55",
  "CreationTime": "2026-07-03T01:59:55",
  "ExternalAccess": false,
  "Id": "8090a71e-c3cb-4610-441c-08ded8a6c75c",
  "ObjectId": "dwharna9dd06c7-owa",
  "Operation": "Remove-OwaMailboxPolicy",
  "Operations": "Remove-OwaMailboxPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "CH0PR16MB4563 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharna9dd06c7-owa"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "a910bca7-e8f3-4284-8b15-5ed0bef36491",
  "ResultStatus": "True",
  "SessionId": "006b4cda-5120-b5de-f02d-f24f872aa1a6",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-RecipientPermission

#
RecordType
ExchangeAdmin

Description

A recipient permission was deleted via the Remove-RecipientPermission Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:29692",
  "CreationDate": "2026-07-03T01:55:13",
  "CreationTime": "2026-07-03T01:55:13",
  "ExternalAccess": false,
  "Id": "d8994509-5f5e-4dda-3085-08ded8a61f1f",
  "ObjectId": "aaaaaaaa-0000-0000-0000-000000000001",
  "Operation": "Remove-RecipientPermission",
  "Operations": "Remove-RecipientPermission",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DM4PR16MB5002 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "Identity",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "Trustee",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "AccessRights",
      "Value": "SendAs"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "228d36a9-b32c-4cde-dc62-8ded9e926fcd",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-RemoteDomain

#
RecordType
ExchangeAdmin

Description

A remote domain was deleted via the Remove-RemoteDomain Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:29999",
  "CreationDate": "2026-07-03T04:12:09",
  "CreationTime": "2026-07-03T04:12:09",
  "ExternalAccess": false,
  "Id": "52239b20-6fa0-43cb-086a-08ded8b94055",
  "ObjectId": "dwharn75efecde-rd",
  "Operation": "Remove-RemoteDomain",
  "Operations": "Remove-RemoteDomain",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "LV8PR16MB6758 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-rd"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "1175d96e-b8cd-4637-9ad2-16f24965ac37",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

remove-RetentionPolicy

#
RecordType
ExchangeAdmin

Description

remove-Retention Policy activity in Exchange Online admin, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:22431",
  "CreationDate": "2026-07-03T04:12:18",
  "CreationTime": "2026-07-03T04:12:18",
  "ExternalAccess": false,
  "Id": "eac782db-65a4-46ef-375d-08ded8b94633",
  "ObjectId": "dwharn75efecde-rp",
  "Operation": "remove-RetentionPolicy",
  "Operations": "remove-RetentionPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB7027 (15.21.0159.018)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-rp"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "fd7f8ca7-c3b4-53af-026e-da883d67b5ed",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-RetentionPolicyTag

#
RecordType
ExchangeAdmin

Description

A retention policy tag was deleted via the Remove-RetentionPolicyTag Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:43190",
  "CreationDate": "2026-07-03T04:12:31",
  "CreationTime": "2026-07-03T04:12:31",
  "ExternalAccess": false,
  "Id": "f08cfb42-86d6-4a81-fcaa-08ded8b94d98",
  "ObjectId": "dwharn75efecde-rpt",
  "Operation": "Remove-RetentionPolicyTag",
  "Operations": "Remove-RetentionPolicyTag",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SJ2PR16MB5189 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-rpt"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "4601f706-8f5f-40d1-842f-077da6dbfbf3",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-RoleGroup

#
RecordType
ExchangeAdmin

Description

A role group was deleted via the Remove-RoleGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:30430",
  "CreationTime": "2026-07-02T15:31:35Z",
  "ExternalAccess": false,
  "Id": "a5261a07-db26-4305-8f9f-08ded84f0086",
  "ObjectId": "dwrg",
  "Operation": "Remove-RoleGroup",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwrg"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "b3ef24a6-0fbf-e3ed-592c-57e5690bc64b",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-SafeAttachmentPolicy

#
RecordType
ExchangeAdmin

Description

A safe attachment policy was deleted via the Remove-SafeAttachmentPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:21076",
  "CreationDate": "2026-07-03T04:11:54",
  "CreationTime": "2026-07-03T04:11:54",
  "ExternalAccess": false,
  "Id": "1478534a-75bf-480b-8607-08ded8b937b4",
  "ObjectId": "dwharn75efecde-sa",
  "Operation": "Remove-SafeAttachmentPolicy",
  "Operations": "Remove-SafeAttachmentPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB6812 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-sa"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "241e5166-866a-d10d-b631-289c91ecfc01",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Remove-SafeAttachmentRule

#
RecordType
ExchangeAdmin

Description

A Defender for Office 365 Safe Attachments rule was deleted, detaching its policy from the recipients it applied to. Observed in first-party Unified Audit Log capture. Deleting the rule leaves the underlying Safe Attachments policy in place but stops it applying to anyone.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006ea83a-ea88-19ef-0c5d-d3f2d744c4fe",
    "IssuedAtTime": "2026-07-25T21:05:48",
    "UniqueTokenId": "qtYdrqugs0qgOaLoYW4kAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:19834",
  "CreationDate": "2026-07-25T21:11:00",
  "CreationTime": "2026-07-25T21:11:00",
  "ExternalAccess": false,
  "Id": "4d1fe66b-0ef7-43d6-7bd0-08deea913aa7",
  "ObjectId": "dwharndiag1-sar2",
  "Operation": "Remove-SafeAttachmentRule",
  "Operations": "Remove-SafeAttachmentRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA0PR16MB3773 (15.21.0223.005)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharndiag1-sar2"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "78f515bc-f30b-3cac-22af-eba98e7c9324",
  "ResultStatus": "True",
  "SessionId": "006ea83a-ea88-19ef-0c5d-d3f2d744c4fe",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Remove-SafeLinksPolicy

#
RecordType
ExchangeAdmin

Description

A safe links policy was deleted via the Remove-SafeLinksPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-f544-cad9-543e-871e394fced1",
    "IssuedAtTime": "2026-07-03T03:59:33",
    "UniqueTokenId": "5C9dC0LSzkKNhApry74CAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:54960",
  "CreationDate": "2026-07-03T04:04:46",
  "CreationTime": "2026-07-03T04:04:46",
  "ExternalAccess": false,
  "Id": "0d964f43-ec9d-4ed7-5179-08ded8b83878",
  "ObjectId": "dwharn867f01-sl",
  "Operation": "Remove-SafeLinksPolicy",
  "Operations": "Remove-SafeLinksPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "MW2PR16MB2363 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "Identity",
      "Value": "dwharn867f01-sl"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "090a55cc-b821-07ed-b62a-69042e006491",
  "ResultStatus": "True",
  "SessionId": "006b4cda-f544-cad9-543e-871e394fced1",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Remove-SharingPolicy

#
RecordType
ExchangeAdmin

Description

A sharing policy was deleted via the Remove-SharingPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:12038",
  "CreationDate": "2026-07-03T04:12:14",
  "CreationTime": "2026-07-03T04:12:14",
  "ExternalAccess": false,
  "Id": "80c37e5c-9a0f-4a36-9f33-08ded8b94379",
  "ObjectId": "dwharn75efecde-shp",
  "Operation": "Remove-SharingPolicy",
  "Operations": "Remove-SharingPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DS4PR16MB6922 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-shp"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "d4d9e6ec-f203-626c-558e-6475e2231f86",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-TransportRule

#
RecordType
ExchangeAdmin

Description

A mail-flow transport rule was deleted.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b25ca-8a7e-0c9f-50a5-1338131ca95c",
    "IssuedAtTime": "2026-07-02T00:51:46Z",
    "UniqueTokenId": "Gnv7bm9T4UKndwcLdscpAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28436",
  "CreationTime": "2026-07-02T00:57:31Z",
  "ExternalAccess": false,
  "Id": "8396ca95-334d-4a59-feec-08ded7d4e560",
  "ObjectId": "dw-ual-probe",
  "Operation": "Remove-TransportRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "CH4PR16MB6628 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "SilentlyContinue"
    },
    {
      "Name": "Identity",
      "Value": "dw-ual-probe"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "27c69567-3222-6667-38e5-550c4b08b0d2",
  "ResultStatus": "True",
  "SessionId": "006b25ca-8a7e-0c9f-50a5-1338131ca95c",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Remove-UnifiedGroup

#
RecordType
ExchangeAdmin

Description

An unified group was deleted via the Remove-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppPoolName": "Microsoft.Exchange.DsApi.GRpc.NetCore",
  "CreationDate": "2026-07-03T01:58:05",
  "CreationTime": "2026-07-03T01:58:05",
  "ExternalAccess": false,
  "Id": "ba8e5cc2-8aa2-41d8-fab3-08ded8a685da",
  "ObjectId": "dw-harness-planner-a9dd06c7_1a4adb2a-96c9-4df2-84be-fb5a7f0b1c16",
  "Operation": "Remove-UnifiedGroup",
  "Operations": "Remove-UnifiedGroup",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "DomainController",
      "Value": "SJ0PR16A14DC003.NAMPR16A014.PROD.OUTLOOK.COM"
    },
    {
      "Name": "Identity",
      "Value": "1a4adb2a-96c9-4df2-84be-fb5a7f0b1c16"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "a3c60667-0ac3-4d6a-9d03-cb49f0bc32b0",
  "ResultStatus": "True",
  "UserId": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-AcceptedDomain

#
RecordType
ExchangeAdmin

Description

An accepted domain's configuration was modified.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Set-AdminAuditLogConfig

#
RecordType
ExchangeAdmin

Description

The administrator audit log configuration was changed; adversaries disable audit logging to evade detection.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:60026",
  "CreationDate": "2026-07-03T01:56:19",
  "CreationTime": "2026-07-03T01:56:19",
  "ExternalAccess": false,
  "Id": "f8e09c2a-390e-4274-fbdc-08ded8a646d5",
  "ObjectId": "Admin Audit Log Settings",
  "Operation": "Set-AdminAuditLogConfig",
  "Operations": "Set-AdminAuditLogConfig",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SJ2PR16MB5913 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "UnifiedAuditLogIngestionEnabled",
      "Value": "True"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "488036dc-7381-1174-3746-88a0e8bb85d2",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto
m365::Workload (kusto rule field)eqexchange1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • Exchange AuditLog Disabled source medium: Identifies when the exchange audit logging has been disabled which may be an adversary attempt to evade detection or avoid other defenses.T1562

YARA-L #

References #

Set-CASMailbox

#
RecordType
ExchangeAdmin

Description

Client-access settings on a mailbox were modified (for example enabling POP, IMAP, or OWA); commonly abused to enable legacy-protocol access.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:13434",
  "CreationTime": "2026-07-02T15:31:36Z",
  "ExternalAccess": false,
  "Id": "8d4d327c-cfc9-4128-52b3-08ded84f013a",
  "ObjectId": "11111111-1111-1111-1111-111111111111",
  "Operation": "Set-CASMailbox",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "ImapEnabled",
      "Value": "False"
    },
    {
      "Name": "PopEnabled",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "eb483126-8215-1bb5-56bd-68977780e2c8",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-ConditionalAccessPolicy

#
RecordType
ExchangeAdmin

Description

A conditional access policy was modified via the Set-ConditionalAccessPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2026-07-03T02:37:56",
    "UniqueTokenId": "ecd03fcc-f954-8335-9c1d-3ecc25d48b19"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28300",
  "CreationDate": "2026-07-03T02:37:58",
  "CreationTime": "2026-07-03T02:37:58",
  "ExternalAccess": true,
  "Id": "423111a8-0ada-4da2-9370-08ded8ac1830",
  "ObjectId": "example.onmicrosoft.com\\12b1e3b4-7e38-4b24-a740-186a3e9e8556",
  "Operation": "Set-ConditionalAccessPolicy",
  "Operations": "Set-ConditionalAccessPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SJ2PR16MB5119 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "example.onmicrosoft.com\\12b1e3b4-7e38-4b24-a740-186a3e9e8556"
    },
    {
      "Name": "PolicyDetails",
      "Value": {
        "DummyKnownNetworkPolicy": ""
      }
    },
    {
      "Name": "PolicyLastUpdatedTime",
      "Value": "07/03/2026 02:37:57"
    },
    {
      "Name": "TenantDefaultPolicy",
      "Value": "6"
    },
    {
      "Name": "DisplayName",
      "Value": "Known Networks List"
    },
    {
      "Name": "PolicyIdentifierString",
      "Value": "2026-07-03T01:52:53.8030224Z"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "972156ee-5838-8ed5-9a0d-6fcd9cfe91af",
  "ResultStatus": "True",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserType": "DcAdmin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-DistributionGroup

#
RecordType
ExchangeAdmin

Description

A distribution group was modified via the Set-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:51150",
  "CreationDate": "2026-07-03T04:09:00",
  "CreationTime": "2026-07-03T04:09:00",
  "ExternalAccess": false,
  "Id": "49afcf55-700d-41d7-ce4e-08ded8b8cfa8",
  "ObjectId": "dwharn75efecde-dg",
  "Operation": "Set-DistributionGroup",
  "Operations": "Set-DistributionGroup",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "IA6PR16MB7054 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-dg"
    },
    {
      "Name": "HiddenFromAddressListsEnabled",
      "Value": "True"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "00b49648-7b24-6ab5-4ca8-161717ee817c",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-DkimSigningConfig

#
RecordType
ExchangeAdmin

Description

The DKIM signing configuration for a domain was modified; disabling DKIM weakens email authentication.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006ea83a-48e6-e856-a0c6-63b801badfa7",
    "IssuedAtTime": "2026-07-25T20:58:32",
    "UniqueTokenId": "qUaKtx20zEShctAylTcjAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:17313",
  "CreationDate": "2026-07-25T21:07:40",
  "CreationTime": "2026-07-25T21:07:40",
  "ExternalAccess": false,
  "Id": "9a0ee24b-d391-4f4b-99e3-08deea90c30c",
  "ObjectId": "example.onmicrosoft.com",
  "Operation": "Set-DkimSigningConfig",
  "Operations": "Set-DkimSigningConfig",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DM5PR16MB2230 (15.21.0245.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "example.onmicrosoft.com"
    },
    {
      "Name": "Enabled",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "6e47c62c-f13e-d610-4bda-0c46ecd38230",
  "ResultStatus": "True",
  "SessionId": "006ea83a-48e6-e856-a0c6-63b801badfa7",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Name (elastic rule field)eqexchange1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange DKIM Signing Configuration Disabled source medium: Identifies when a DomainKeys Identified Mail (DKIM) signing configuration is disabled in Microsoft 365. With DKIM in Microsoft 365, messages that are sent from Exchange Online will be cryptographically signed. This will allow the receiving email system to validate that the messages were generated by a server that the organization authorized and were not spoofed.T1484, T1562, T1562.001

References #

Set-InboxRule

#
RecordType
ExchangeAdmin

Description

An Exchange inbox rule was modified via the Set-InboxRule cmdlet; first-party capture confirms it logs under ExchangeAdmin (RecordType 1), like New-InboxRule, not the OWA-context UpdateInboxRules operation under ExchangeItem (RecordType 2).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:20791",
  "CreationTime": "2026-07-02T15:31:21Z",
  "ExternalAccess": false,
  "Id": "9edc78e0-e3bb-4360-3066-08ded84ef84f",
  "ObjectId": "11111111-1111-1111-1111-111111111111\\5819733106155847681",
  "Operation": "set-InboxRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwir"
    },
    {
      "Name": "Mailbox",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "MarkAsRead",
      "Value": "True"
    }
  ],
  "RecordType": 1,
  "RequestId": "d8b1e178-d27b-89ac-a0c6-3813583de487",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)innew-inboxrule2 ruleselastic
EventType (elastic rule field)inset-inboxrule2 ruleselastic
Provider_Name (elastic rule field)eqExchange1 ruleelastic
ResultType (kusto rule field)eq500571 rulekusto
m365::ObjectId (elastic rule field)is_not_null1 ruleelastic
m365::Parameters (sigma rule field)containsdeletemessage1 rulesigma
m365::Parameters (sigma rule field)containsforwardingsmtpaddress1 rulesigma
m365::Parameters (sigma rule field)containsforwardto1 rulesigma
m365::Parameters (sigma rule field)containsredirectto1 rulesigma
match1 (splunk rule field)ge01 rulesplunk
match2 (splunk rule field)ge01 rulesplunk
match3 (splunk rule field)ge01 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • M365 Exchange Inbox Forwarding Rule Created source medium: Identifies when a new Inbox forwarding rule is created in Microsoft 365. Inbox rules process messages in the Inbox based on conditions and take actions. In this case, the rules will forward the emails to a defined address. Attackers can abuse Inbox Rules to intercept and exfiltrate email data without making organization-wide configuration changes or having the corresponding privileges.T1114, T1114.003↳ also matches New-InboxRule, New-TransportRule, Set-Mailbox, Set-TransportRule
  • M365 Exchange Inbox Rule with Obfuscated Name source medium: Identifies when a Microsoft Exchange inbox rule is created or modified with a name composed only of special characters. Adversaries may use obfuscated inbox rule names to evade detection, hide malicious forwarding or deletion rules, or blend in with benign audit noise. The rule name is parsed from "o365.audit.ObjectId", which encodes the mailbox identity and rule name separated by a backslash.T1137, T1137.005, T1564, T1564.008↳ also matches New-InboxRule
  • M365 Exchange Inbox Phishing Evasion Rule Created source high: Identifies when a user creates a new inbox rule in Microsoft 365 that deletes or moves emails containing suspicious keywords. Adversaries who have compromised accounts often create inbox rules to hide alerts, security notifications, or other sensitive messages by automatically deleting them or moving them to obscure folders. Common destinations include Deleted Items, Junk Email, RSS Feeds, and RSS Subscriptions. This is a New Terms rule that triggers only when the user principal name and associated source IP address have not been observed performing this activity in the past 14 days.T1137, T1137.005, T1564, T1564.008↳ also matches New-InboxRule

Splunk #

Kusto #

References #

Set-Mailbox

#
RecordType
ExchangeAdmin

Description

A mailbox configuration was modified; commonly abused to enable forwarding, audit bypass, or delegate access.

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2026-07-03T05:28:29Z",
    "UniqueTokenId": "7e7a831a-e1ff-81fc-8d45-c6142671e9a8"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "[2001:db8::10]:12026",
  "CreationTime": "2026-07-03T05:28:35Z",
  "ExternalAccess": true,
  "Id": "2ae66aa0-ea92-4dab-c281-08ded8c3edcd",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/RecordReview{2b9ab0b1-2e7a-410b-9c30-a873824b4813}",
  "Operation": "Set-Mailbox",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "PH0PR16MB4040 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "RecordReview{2b9ab0b1-2e7a-410b-9c30-a873824b4813}@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "6b1c4f08-79ad-ec5a-382f-e20662066e29",
  "ResultStatus": "True",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserType": 3,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Name (elastic rule field)eqExchange1 ruleelastic
ResultType (kusto rule field)eq500571 rulekusto
m365::Parameters (sigma rule field)containsforwardingsmtpaddress1 rulesigma
m365::Parameters (sigma rule field)containsforwardto1 rulesigma
m365::Parameters (sigma rule field)containsredirectto1 rulesigma
match1 (splunk rule field)ge01 rulesplunk
match2 (splunk rule field)ge01 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Splunk #

  • O365 Mailbox Email Forwarding Enabled source: The following analytic identifies instances where email forwarding has been enabled on mailboxes within an Office 365 environment. It detects this activity by monitoring the Set-Mailbox operation within the o365_management_activity logs,…T1114, T1114.003

Kusto #

References #

Set-MailboxAuditBypassAssociation

#
RecordType
ExchangeAdmin

Description

Mailbox audit logging was bypassed for a service account, suppressing audit events for that account's actions.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:17802",
  "CreationTime": "2026-07-02T15:31:38Z",
  "ExternalAccess": false,
  "Id": "ff4128b0-672e-41f3-b663-08ded84f0233",
  "ObjectId": "11111111-1111-1111-1111-111111111111",
  "Operation": "Set-MailboxAuditBypassAssociation",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "AuditBypassEnabled",
      "Value": "False"
    },
    {
      "Name": "Identity",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    }
  ],
  "RecordType": 1,
  "RequestId": "707b5aeb-749a-801f-b156-8ac44d10fe11",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange Mailbox Audit Logging Bypass Added source medium: Detects the occurrence of mailbox audit bypass associations. The mailbox audit is responsible for logging specified mailbox events (like accessing a folder or a message or permanently deleting a message). However, actions taken by some authorized accounts, such as accounts used by third-party tools or accounts used for lawful monitoring, can create a large number of mailbox audit log entries and may not be of interest to your organization. Because of this, administrators can create bypass associations, allowing certain accounts to perform their tasks without being logged. Attackers can abuse this allowlist mechanism to conceal actions taken, as the mailbox audit will log no activity done by the account.T1098, T1562, T1562.001

References #

Set-MailboxFolderPermission

#
RecordType
ExchangeAdmin

Description

An Exchange Online admin cmdlet modified folder-level permissions on a mailbox folder; recorded in the Exchange admin audit log with the Operation set to the cmdlet name (commonly abused to grant a delegate covert folder access).

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2024-03-28T22:32:11",
    "UniqueTokenId": "HY_070GwA0efL-yHfwALAA"
  },
  "CreationTime": "2024-03-28T22:37:13",
  "Id": "c5062b01-a400-4212-1c0a-08dc4f779cd7",
  "Operation": "Set-MailboxFolderPermission",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 1,
  "ResultStatus": "True",
  "UserKey": "100320030DF47B14",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange",
  "ClientIP": "120.1.121.43:28973",
  "ObjectId": "2d2f9e2c-8350-4d98-852e-3f06daaf7185:\\Inbox",
  "UserId": "victim@splunkresearch.com",
  "AppId": "00b41c95-dab0-4487-9791-b9d2c32c80f2",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ExternalAccess": false,
  "OrganizationName": "splunkresearch.com",
  "OriginatingServer": "MN2PR18MB3053 (15.20.7409.026)",
  "Parameters": [
    {
      "Name": "AccessRights",
      "Value": "Author"
    },
    {
      "Name": "User",
      "Value": "Default"
    },
    {
      "Name": "Identity",
      "Value": "victim@splunkresearch.com:\\Inbox"
    }
  ],
  "RequestId": "f4340c78-7dae-0700-1cdc-829d6eaad5cc",
  "SessionId": "d0e022ae-5d62-48da-aca4-a8d401c128e1"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
isReadRole (splunk rule field)eqtrue1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

Set-OrganizationConfig

#
RecordType
ExchangeAdmin

Description

An organization config was modified via the Set-OrganizationConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-a1b3-9e63-d5b5-a8bb31828c96",
    "IssuedAtTime": "2026-07-03T05:58:00",
    "UniqueTokenId": "b5LCVRhMZk6Y4kZ2fSYUAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:13818",
  "CreationDate": "2026-07-03T06:03:01",
  "CreationTime": "2026-07-03T06:03:01",
  "ExternalAccess": false,
  "Id": "e64f5100-80b3-4497-2802-08ded8c8bd35",
  "ObjectId": "First Organization",
  "Operation": "Set-OrganizationConfig",
  "Operations": "Set-OrganizationConfig",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4804 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "InPlaceHolds",
      "Value": ""
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "d4cd117b-05fa-71ea-084a-14dc3f7286e4",
  "ResultStatus": "True",
  "SessionId": "006b4cda-a1b3-9e63-d5b5-a8bb31828c96",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-TransportConfig

#
RecordType
ExchangeAdmin

Description

A transport config was modified via the Set-TransportConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28876",
  "CreationDate": "2026-07-03T04:11:05",
  "CreationTime": "2026-07-03T04:11:05",
  "ExternalAccess": false,
  "Id": "446af425-d709-4351-fe5b-08ded8b91a12",
  "ObjectId": "Transport Settings",
  "Operation": "Set-TransportConfig",
  "Operations": "Set-TransportConfig",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "BY1PR16MB6382 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ExternalPostmasterAddress",
      "Value": "dwharna9dd06c7@example.com"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "00261cb3-1740-4f59-e94c-ba7278ec5462",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-TransportRule

#
RecordType
ExchangeAdmin

Description

An existing mail-flow transport rule was modified.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28540",
  "CreationTime": "2026-07-02T15:30:36Z",
  "ExternalAccess": false,
  "Id": "1516f079-7c62-4568-da44-08ded84edd10",
  "ObjectId": "dwtr",
  "Operation": "Set-TransportRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwtr"
    },
    {
      "Name": "SubjectContainsWords",
      "Value": "y"
    }
  ],
  "RecordType": 1,
  "RequestId": "45101c08-78b1-ab30-7581-3d1359353099",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Value (kusto rule field)is_not_null2 ruleskusto
m365::Workload (kusto rule field)eqExchange2 ruleskusto
Provider_Name (elastic rule field)eqExchange1 ruleelastic
ResultType (kusto rule field)eq500571 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

Set-UnifiedGroup

#
RecordType
ExchangeAdmin

Description

An unified group was modified via the Set-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppPoolName": "Microsoft.Exchange.DsApi.GRpc.NetCore",
  "CreationTime": "2026-07-02T02:11:04Z",
  "ExternalAccess": false,
  "Id": "23399412-d36e-472e-69f1-08ded7df2ba7",
  "ObjectId": "dw-harness-60974bd7_72ff2416-ca78-4443-8b25-800823d06143",
  "Operation": "Set-UnifiedGroup",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "72ff2416-ca78-4443-8b25-800823d06143"
    },
    {
      "Name": "Notes",
      "Value": "dw harness group (updated) run=60974bd7"
    },
    {
      "Name": "DisplayName",
      "Value": "dw-harness-60974bd7-group"
    },
    {
      "Name": "UnifiedGroupAccessType",
      "Value": "Private"
    }
  ],
  "RecordType": 1,
  "RequestId": "f1e9843c-f7ea-4207-810a-56efd2ea15ea",
  "ResultStatus": "True",
  "UserId": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.