Power Pages site activity

OperationDescriptionSampleRule
anyCatch-all for M365-PowerPagesSite rules matching the RecordType but no specific Operation.NN
AnonymousSettingExceptionListChangedThe anonymous access governance control exception list is changed.NN
BootstrapVersionUpdatedThe site's bootstrap version is updated.NN
CDNDisabledThe CDN is disabled for the site.NN
CDNEnabledThe CDN is enabled for the site.NN
ConvertedToProductionA site is converted from trial to production.NN
CustomCertificateUpdatedA custom certificate associated with the site is updated.NN
CustomDomainConnectedA site is connected to a custom domain.NN
CustomDomainDeletedA custom domain is removed from the site.NN
CustomErrorsDisabledCustom errors are disabled for the site.NN
CustomErrorsEnabledCustom errors are enabled for the site.NN
D365URLUpdatedThe Dynamics 365 URL for the site is updated.NN
DataModelVersionUpdatedThe site's data model version is updated.NN
DiagnosticLogsDisabledDiagnostic logs are disabled for the site.NN
DiagnosticLogsEnabledDiagnostic logs are enabled for the site.NN
EarlyUpgradeDisabledEarly upgrade is disabled for the site.NN
EarlyUpgradeEnabledEarly upgrade is enabled for the site.NN
FieldServiceExtensionInstalledThe field service extension is installed on the site.NN
IPRestrictionsAddedA new range of IP addresses is added that can access the site.NN
IPRestrictionsDeletedA range of IP addresses that could access the site is deleted.NN
MaintenanceModeDisabledA site is taken off maintenance mode.NN
MaintenanceModeEnabledA site is put into maintenance mode.NN
MaintenanceModeURLModifiedThe maintenance mode URL is modified.NN
PowerBIEmbeddedServiceDisabledPower BI embedded service is disabled for the site.NN
PowerBIEmbeddedServiceEnabledPower BI embedded service is enabled for the site.NN
PowerBIVisualizationDisabledPower BI visualization is disabled for the site.NN
PowerBIVisualizationEnabledPower BI visualization is enabled for the site.NN
ProjectServiceAutomationExtensionInstalledThe project service automation extension is installed on the site.NN
SharePointIntegrationDisabledSharePoint integration is disabled for the site.NN
SharePointIntegrationEnabledSharePoint integration is enabled for the site.NN
SiteArchivedThe site is archived.NN
SiteCreatedThe site is created.NN
SiteDeletedA site is deleted.NN
SiteNameUpdatedA site name is changed.NN
SiteRestartedA site is restarted.NN
SiteShutDownA site is shut down.NN
SiteSuspendedThe site is suspended.NN
SiteUnarchivedThe site is unarchived.NN
SiteURLUpdatedA site URL is changed.NN
SiteVisibilityPermissionsUpdatedSite visibility permissions, meaning who can change site visibility, are updated.NN
SiteVisibilityUpdatedSite visibility is changed, from private to public or public to private.NN
WAFDisabledAzure Front Door Web Application Firewall protection is disabled for the site.NN
WAFEnabledAzure Front Door Web Application Firewall protection is enabled for the site.NN
WebsiteAuthenticationKeyUpdatedThe website authentication key is updated.NN
WebsiteRecordUpdatedA website record is updated.NN

any: Power Pages site activity (catch-all)

#
RecordType
PowerPagesSite

Description

Catch-all for M365-PowerPagesSite rules matching the RecordType but no specific Operation.

AnonymousSettingExceptionListChanged

#
RecordType
PowerPagesSite

Description

The anonymous access governance control exception list is changed.

BootstrapVersionUpdated

#
RecordType
PowerPagesSite

Description

The site's bootstrap version is updated.

CDNDisabled

#
RecordType
PowerPagesSite

Description

The CDN is disabled for the site.

CDNEnabled

#
RecordType
PowerPagesSite

Description

The CDN is enabled for the site.

ConvertedToProduction

#
RecordType
PowerPagesSite

Description

A site is converted from trial to production.

CustomCertificateUpdated

#
RecordType
PowerPagesSite

Description

A custom certificate associated with the site is updated.

CustomDomainConnected

#
RecordType
PowerPagesSite

Description

A site is connected to a custom domain.

CustomDomainDeleted

#
RecordType
PowerPagesSite

Description

A custom domain is removed from the site.

CustomErrorsDisabled

#
RecordType
PowerPagesSite

Description

Custom errors are disabled for the site.

CustomErrorsEnabled

#
RecordType
PowerPagesSite

Description

Custom errors are enabled for the site.

D365URLUpdated

#
RecordType
PowerPagesSite

Description

The Dynamics 365 URL for the site is updated.

DataModelVersionUpdated

#
RecordType
PowerPagesSite

Description

The site's data model version is updated.

DiagnosticLogsDisabled

#
RecordType
PowerPagesSite

Description

Diagnostic logs are disabled for the site.

DiagnosticLogsEnabled

#
RecordType
PowerPagesSite

Description

Diagnostic logs are enabled for the site.

EarlyUpgradeDisabled

#
RecordType
PowerPagesSite

Description

Early upgrade is disabled for the site.

EarlyUpgradeEnabled

#
RecordType
PowerPagesSite

Description

Early upgrade is enabled for the site.

FieldServiceExtensionInstalled

#
RecordType
PowerPagesSite

Description

The field service extension is installed on the site.

IPRestrictionsAdded

#
RecordType
PowerPagesSite

Description

A new range of IP addresses is added that can access the site.

IPRestrictionsDeleted

#
RecordType
PowerPagesSite

Description

A range of IP addresses that could access the site is deleted.

MaintenanceModeDisabled

#
RecordType
PowerPagesSite

Description

A site is taken off maintenance mode.

MaintenanceModeEnabled

#
RecordType
PowerPagesSite

Description

A site is put into maintenance mode.

MaintenanceModeURLModified

#
RecordType
PowerPagesSite

Description

The maintenance mode URL is modified.

PowerBIEmbeddedServiceDisabled

#
RecordType
PowerPagesSite

Description

Power BI embedded service is disabled for the site.

PowerBIEmbeddedServiceEnabled

#
RecordType
PowerPagesSite

Description

Power BI embedded service is enabled for the site.

PowerBIVisualizationDisabled

#
RecordType
PowerPagesSite

Description

Power BI visualization is disabled for the site.

PowerBIVisualizationEnabled

#
RecordType
PowerPagesSite

Description

Power BI visualization is enabled for the site.

ProjectServiceAutomationExtensionInstalled

#
RecordType
PowerPagesSite

Description

The project service automation extension is installed on the site.

SharePointIntegrationDisabled

#
RecordType
PowerPagesSite

Description

SharePoint integration is disabled for the site.

SharePointIntegrationEnabled

#
RecordType
PowerPagesSite

Description

SharePoint integration is enabled for the site.

SiteArchived

#
RecordType
PowerPagesSite

Description

The site is archived.

SiteCreated

#
RecordType
PowerPagesSite

Description

The site is created.

SiteDeleted

#
RecordType
PowerPagesSite

Description

A site is deleted.

SiteNameUpdated

#
RecordType
PowerPagesSite

Description

A site name is changed.

SiteRestarted

#
RecordType
PowerPagesSite

Description

A site is restarted.

SiteShutDown

#
RecordType
PowerPagesSite

Description

A site is shut down.

SiteSuspended

#
RecordType
PowerPagesSite

Description

The site is suspended.

SiteUnarchived

#
RecordType
PowerPagesSite

Description

The site is unarchived.

SiteURLUpdated

#
RecordType
PowerPagesSite

Description

A site URL is changed.

SiteVisibilityPermissionsUpdated

#
RecordType
PowerPagesSite

Description

Site visibility permissions, meaning who can change site visibility, are updated.

SiteVisibilityUpdated

#
RecordType
PowerPagesSite

Description

Site visibility is changed, from private to public or public to private.

WAFDisabled

#
RecordType
PowerPagesSite

Description

Azure Front Door Web Application Firewall protection is disabled for the site.

WAFEnabled

#
RecordType
PowerPagesSite

Description

Azure Front Door Web Application Firewall protection is enabled for the site.

WebsiteAuthenticationKeyUpdated

#
RecordType
PowerPagesSite

Description

The website authentication key is updated.

WebsiteRecordUpdated

#
RecordType
PowerPagesSite

Description

A website record is updated.

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.