Microsoft Planner activity
| Operation | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for M365-PlannerTask rules matching the RecordType but no specific Operation. | N | N |
| Task | Task Assigned activity in Microsoft Planner, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Task | Task Created activity in Microsoft Planner, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Task | Task Modified activity in Microsoft Planner, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
any: Microsoft Planner activity (catch-all)
#Description
Catch-all for M365-PlannerTask rules matching the RecordType but no specific Operation.
TaskAssigned
#Description
Task Assigned activity in Microsoft Planner, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"AppAccessContext": {
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"CorrelationId": "4ccaaea8-f00b-4900-b066-6d98f23c5a5a"
},
"ClientIP": "203.0.113.10",
"CreationTime": "2026-07-02T02:10:44Z",
"Id": "62a29bc2-1321-4c63-b4b0-712e1e0fcf66",
"ObjectId": "m6PSKawQ30e4eqgQiOSivmUACu3C",
"Operation": "TaskAssigned",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"PlanId": "vS4pRN0kgU-rJ96he6uvYmUACinM",
"RecordType": 190,
"ResultStatus": "Success",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "11111111-1111-1111-1111-111111111111",
"UserType": 2,
"Workload": "Planner"
}
TaskCreated
#Description
Task Created activity in Microsoft Planner, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"AppAccessContext": {
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"CorrelationId": "4ccaaea8-f00b-4900-b066-6d98f23c5a5a"
},
"ClientIP": "203.0.113.10",
"CreationTime": "2026-07-02T02:10:44Z",
"Id": "ca94dc23-71a4-4753-88d6-383284139cd4",
"ObjectId": "m6PSKawQ30e4eqgQiOSivmUACu3C",
"Operation": "TaskCreated",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"PlanId": "vS4pRN0kgU-rJ96he6uvYmUACinM",
"RecordType": 190,
"ResultStatus": "Success",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "11111111-1111-1111-1111-111111111111",
"UserType": 2,
"Workload": "Planner"
}
TaskModified
#Description
Task Modified activity in Microsoft Planner, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"AppAccessContext": {
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"CorrelationId": "615bb344-a869-4beb-93a6-435e57dcd600"
},
"ClientIP": "203.0.113.10",
"CreationTime": "2026-07-02T02:10:44Z",
"Id": "2ad39c1a-3cff-42e3-ac2d-931b3d64fb5d",
"ObjectId": "m6PSKawQ30e4eqgQiOSivmUACu3C",
"Operation": "TaskModified",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"PlanId": "vS4pRN0kgU-rJ96he6uvYmUACinM",
"RecordType": 190,
"ResultStatus": "Success",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "11111111-1111-1111-1111-111111111111",
"UserType": 2,
"Workload": "Planner"
}
References #
M365 audit records use different field names on each surface #
The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.
- Purview CSV export flattens each record to four columns (
CreationDate,UserIds,Operations,AuditData). The API field names live only inside theAuditDataJSON blob. Expand it withConvertFrom-Json. The wrapper columns are renamed too:CreationDatenotCreationTime,UserIdsnotUserId,OperationsnotOperation. - Sentinel's
OfficeActivitytable renames several fields and turns two integer enum columns into strings. The table below maps them.
| API JSON (event pages) | OfficeActivity column | Note |
|---|---|---|
Id | OfficeId | Renamed. |
Workload | OfficeWorkload | Renamed. |
ObjectId | OfficeObjectId | Renamed. |
CreationTime | TimeGenerated | Renamed. OfficeActivity has no CreationTime column. |
SiteUrl | Site_Url | Renamed (SharePoint family). |
RecordType | RecordType | Same name; the Int32 enum becomes its string enum name. |
UserType | UserType | Same name; the Int32 enum becomes a string. |
ClientIP | ClientIP, Client_IPAddress | Both columns present on OfficeActivity. |
Scope | (none) | No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob. |
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationId | same names | Unchanged. No _s / _d suffixes (a native table, not a custom log). |
Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.