Power Platform administrator activity

OperationDescriptionSampleRule
anyCatch-all for M365-PowerPlatformAdministratorActivity rules matching the RecordType but no specific Operation.NY
AIPluginOperationCreateAn AI plugin is created for an agent in Copilot Studio.NN
AIPluginOperationDeleteAn AI plugin is removed from an agent in Copilot Studio.NN
AIPluginOperationUpdateAn AI plugin is updated for an agent in Copilot Studio.NN
ApplyAdminRoleA tenant admin requests the system administrator role in Dataverse in the environment.NN
AssignLicenseAutoClaimA license is assigned to a user automatically through an auto-claim policy.NN
AssignLicenseAutoClaimPolicyCreateA new license auto-claim policy is created.NN
AssignLicenseToUserA trial license is assigned to a user.NN
Backed up environmentThe environment was backed up.NN
BillingPolicyCreateA new billing policy is created.NN
BillingPolicyDeleteA billing policy is deleted.NN
BillingPolicyUpdateThe environments linked to a billing policy change, added or removed.NN
BotAppInsightsUpdateAn agent's App Insights logging configuration is updated in Copilot Studio.NN
BotComponentCollectionCreateA component collection is created for an agent in Copilot Studio.NN
BotComponentCollectionDeleteA component collection is deleted for an agent in Copilot Studio.NN
BotComponentCollectionUpdateA component collection is updated for an agent in Copilot Studio.NN
BotComponentCreateA component such as a topic or skill is created for an agent in Copilot Studio.NN
BotComponentDeleteA component such as a topic or skill is deleted for an agent in Copilot Studio.NN
BotComponentUpdateA component such as a topic or skill is updated for an agent in Copilot Studio.NN
BotCreateA new agent is created in Copilot Studio.NN
BotDeleteAn agent is deleted in Copilot Studio.NN
BotDeleteCleanupDependencies are cleaned up after an agent is deleted in Copilot Studio.NN
BotUpdateOperation-BotAuthUpdateAn agent's authentication settings are updated in Copilot Studio.NN
BotUpdateOperation-BotIconUpdateAn agent's icon is updated in Copilot Studio.NN
BotUpdateOperation-BotNameUpdateAn agent's name is updated in Copilot Studio.NN
BotUpdateOperation-BotPublishAn agent is published in Copilot Studio.NN
BotUpdateOperation-BotShareAn agent is shared to other users in Copilot Studio.NN
Changed property on environmentA property on the environment changed, such as display name, domain name, security group ID, admin mode, or background operations state.NN
CMK-Renewed environmentThe customer-managed key (CMK) was renewed on the environment.NN
CMK-Reverted environmentThe environment was removed from its enterprise policy and encryption reverted to a Microsoft-managed key.NN
Converted environment typeThe environment was converted to a different environment type, such as production or sandbox.NN
Copied environmentThe environment, including application data, users, customizations, and schemas, was copied.NN
CopilotInteractionA user interacts with a Copilot Studio agent, for example asking a question or viewing a response. The audit row carries only the transcript thread ID, not the transcript text.NN
Create connector blocking policyA new connector blocking policy is created.NN
Create Connector ConfigurationsA connector configuration is created for a data policy.NN
Create Custom Connector PatternsA new custom connector URL pattern is created for a data policy.NN
Create Data PolicyA new data loss prevention (DLP) policy is created.NN
Create Exempt Resources (Deprecated)An exempt resources list is created for a data policy. Marked deprecated in the source doc.NN
CreateRuleBasedPolicyAssignmentOperationA rule-based policy assignment is added to an environment group for the first time.NN
CreateRuleBasedPolicyOperationA rule-based policy is added to an environment group for the first time.NN
CreateRuleSetOperationA rule is added to an environment group for the first time.NN
CurrencyEnvironmentAllocateA currency add-on is allocated or deallocated to an environment.NN
Delete connector blocking policyA connector blocking policy is deleted.NN
Delete Connector ConfigurationsA connector configuration is deleted from a data policy.NN
Delete Custom Connector PatternsA custom connector URL pattern is deleted from a data policy.NN
Delete Data PolicyA data loss prevention (DLP) policy is deleted.NN
Delete Exempt Resources (Deprecated)An exempt resources list is deleted from a data policy. Marked deprecated in the source doc.NN
DeleteConnectionA Power Apps/Power Automate connection was deleted. Observed in first-party Unified Audit Log capture landing on RecordType 256 (PowerPlatformAdministratorActivity) rather than RecordType 79 (PowerAppsResource), where the Purview activity-logging article documents this event under the human-readable label "Connection deleted". See PutConnection for the RT256-consolidation note.YN
Deleted environmentThe environment was deleted.NN
DeleteEnvironmentGroupAn environment group is deleted.NN
DeleteRuleBasedPolicyAssignmentOperationA rule-based policy assignment on an environment group is deleted.NN
DeleteRuleBasedPolicyOperationA rule-based policy on an environment group is deleted.NN
DeleteRuleSetOperationA rule set on an environment group is deleted.NN
EnvironmentAddedToEnvironmentGroupAn environment is added to an environment group.NN
EnvironmentDisabledByMiserAn environment is automatically disabled because of insufficient database capacity.NN
EnvironmentRemovedFromEnvironmentGroupAn environment is removed from an environment group.NN
EnvironmentVariableCreateAn environment variable is created for an agent in Copilot Studio.NN
EnvironmentVariableDeleteAn environment variable is deleted for an agent in Copilot Studio.NN
EnvironmentVariableUpdateAn environment variable is updated for an agent in Copilot Studio.NN
GovernanceApiPolicyOperationA tenant-wide Power Platform DLP (data loss prevention) policy was created, updated, or deleted via the Power Platform Governance API. Observed in first-party Unified Audit Log capture (a policy-create action) landing on RecordType 256 (PowerPlatformAdministratorActivity) with this literal Operation token, confirming the RecordType 187 (PowerPlatformAdminDlp) entry's documented note that current Power Platform admin activity-logging covers DLP policy events under GovernanceApiPolicyOperation on RT256 rather than RT187. The specific action (create/update/delete) is carried in a nested PropertyCollection/JsonPropertiesCollection field, powerplatform.analytics.resource.tenant.governance.api_policy.operation_name (observed value CreateDlpPolicy for this capture), not in the top-level Operation field.YY
Hard-deleted environmentThe environment was hard deleted.NN
IsvContractConsentA tenant admin consents to an ISV contract.NN
LockboxRequestOperationA lockbox request is created, approved or denied, or expires/ends access. All lockbox activities are logged under this single activity name.NN
Moved environmentThe environment was moved to a different tenant.NN
NewEnvironmentGroupA new environment group is created.NN
Provisioned environmentThe environment was created.NN
PutConnectionA Power Apps/Power Automate connection was created or updated. Observed in first-party Unified Audit Log capture landing on RecordType 256 (PowerPlatformAdministratorActivity) rather than RecordType 79 (PowerAppsResource), where the Purview activity-logging article documents connection lifecycle events under the human-readable label "Connection created or edited". Current live telemetry consolidates Power Apps connection events onto RT256 under a distinct Put/Delete-prefixed operation-name convention not covered by that article.YY
Recovered environmentAn environment that was deleted was recovered within seven days.NN
Reset environmentA sandbox environment was reset.NN
Restored environmentThe environment was restored from a backup.NN
TrialConvertToProductionA trial plan is converted to a production plan.NN
TrialEnforceA customer attempts to provision environments beyond the trial limit.NN
TrialProvisionA new trial plan is provisioned.NN
TrialSignUpEligibilityCheckPrior to trial provisioning, a check occurs to determine trial eligibility.NN
TrialViralConsentA tenant changes their consented plan types, reflecting the new state.NN
Update connector blocking policyA connector blocking policy is updated.NN
Update Connector ConfigurationsA connector configuration is updated for a data policy.NN
Update Custom Connector PatternsA custom connector URL pattern is updated for a data policy.NN
Update Data PolicyA data loss prevention (DLP) policy is updated.NN
Update Exempt Resources (Deprecated)An exempt resources list is updated for a data policy. Marked deprecated in the source doc.NN
UpdateEnvironmentGroupAn environment group's name or description is updated.NN
UpdateRuleBasedPolicyOperationA rule-based policy is added, edited, or removed from an environment group.NN
UpdateRuleSetOperationA rule is edited in an environment group.NN
Upgraded environmentA component of the environment was upgraded to a new version.NN

any: Power Platform administrator activity (catch-all)

#
RecordType
PowerPlatformAdministratorActivity

Description

Catch-all for M365-PowerPlatformAdministratorActivity rules matching the RecordType but no specific Operation.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Tactics (kusto rule field)containsexfiltration1 rulekusto
Value (kusto rule field)eqFalse1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

AIPluginOperationCreate

#
RecordType
PowerPlatformAdministratorActivity

Description

An AI plugin is created for an agent in Copilot Studio.

AIPluginOperationDelete

#
RecordType
PowerPlatformAdministratorActivity

Description

An AI plugin is removed from an agent in Copilot Studio.

AIPluginOperationUpdate

#
RecordType
PowerPlatformAdministratorActivity

Description

An AI plugin is updated for an agent in Copilot Studio.

ApplyAdminRole

#
RecordType
PowerPlatformAdministratorActivity

Description

A tenant admin requests the system administrator role in Dataverse in the environment.

AssignLicenseAutoClaim

#
RecordType
PowerPlatformAdministratorActivity

Description

A license is assigned to a user automatically through an auto-claim policy.

AssignLicenseAutoClaimPolicyCreate

#
RecordType
PowerPlatformAdministratorActivity

Description

A new license auto-claim policy is created.

AssignLicenseToUser

#
RecordType
PowerPlatformAdministratorActivity

Description

A trial license is assigned to a user.

Backed up environment

#
RecordType
PowerPlatformAdministratorActivity

Description

The environment was backed up.

BillingPolicyCreate

#
RecordType
PowerPlatformAdministratorActivity

Description

A new billing policy is created.

BillingPolicyDelete

#
RecordType
PowerPlatformAdministratorActivity

Description

A billing policy is deleted.

BillingPolicyUpdate

#
RecordType
PowerPlatformAdministratorActivity

Description

The environments linked to a billing policy change, added or removed.

BotAppInsightsUpdate

#
RecordType
PowerPlatformAdministratorActivity

Description

An agent's App Insights logging configuration is updated in Copilot Studio.

BotComponentCollectionCreate

#
RecordType
PowerPlatformAdministratorActivity

Description

A component collection is created for an agent in Copilot Studio.

BotComponentCollectionDelete

#
RecordType
PowerPlatformAdministratorActivity

Description

A component collection is deleted for an agent in Copilot Studio.

BotComponentCollectionUpdate

#
RecordType
PowerPlatformAdministratorActivity

Description

A component collection is updated for an agent in Copilot Studio.

BotComponentCreate

#
RecordType
PowerPlatformAdministratorActivity

Description

A component such as a topic or skill is created for an agent in Copilot Studio.

BotComponentDelete

#
RecordType
PowerPlatformAdministratorActivity

Description

A component such as a topic or skill is deleted for an agent in Copilot Studio.

BotComponentUpdate

#
RecordType
PowerPlatformAdministratorActivity

Description

A component such as a topic or skill is updated for an agent in Copilot Studio.

BotCreate

#
RecordType
PowerPlatformAdministratorActivity

Description

A new agent is created in Copilot Studio.

BotDelete

#
RecordType
PowerPlatformAdministratorActivity

Description

An agent is deleted in Copilot Studio.

BotDeleteCleanup

#
RecordType
PowerPlatformAdministratorActivity

Description

Dependencies are cleaned up after an agent is deleted in Copilot Studio.

BotUpdateOperation-BotAuthUpdate

#
RecordType
PowerPlatformAdministratorActivity

Description

An agent's authentication settings are updated in Copilot Studio.

BotUpdateOperation-BotIconUpdate

#
RecordType
PowerPlatformAdministratorActivity

Description

An agent's icon is updated in Copilot Studio.

BotUpdateOperation-BotNameUpdate

#
RecordType
PowerPlatformAdministratorActivity

Description

An agent's name is updated in Copilot Studio.

BotUpdateOperation-BotPublish

#
RecordType
PowerPlatformAdministratorActivity

Description

An agent is published in Copilot Studio.

BotUpdateOperation-BotShare

#
RecordType
PowerPlatformAdministratorActivity

Description

An agent is shared to other users in Copilot Studio.

Changed property on environment

#
RecordType
PowerPlatformAdministratorActivity

Description

A property on the environment changed, such as display name, domain name, security group ID, admin mode, or background operations state.

CMK-Renewed environment

#
RecordType
PowerPlatformAdministratorActivity

Description

The customer-managed key (CMK) was renewed on the environment.

CMK-Reverted environment

#
RecordType
PowerPlatformAdministratorActivity

Description

The environment was removed from its enterprise policy and encryption reverted to a Microsoft-managed key.

Converted environment type

#
RecordType
PowerPlatformAdministratorActivity

Description

The environment was converted to a different environment type, such as production or sandbox.

Copied environment

#
RecordType
PowerPlatformAdministratorActivity

Description

The environment, including application data, users, customizations, and schemas, was copied.

CopilotInteraction

#
RecordType
PowerPlatformAdministratorActivity

Description

A user interacts with a Copilot Studio agent, for example asking a question or viewing a response. The audit row carries only the transcript thread ID, not the transcript text.

Create connector blocking policy

#
RecordType
PowerPlatformAdministratorActivity

Description

A new connector blocking policy is created.

Create Connector Configurations

#
RecordType
PowerPlatformAdministratorActivity

Description

A connector configuration is created for a data policy.

Create Custom Connector Patterns

#
RecordType
PowerPlatformAdministratorActivity

Description

A new custom connector URL pattern is created for a data policy.

Create Data Policy

#
RecordType
PowerPlatformAdministratorActivity

Description

A new data loss prevention (DLP) policy is created.

Create Exempt Resources (Deprecated)

#
RecordType
PowerPlatformAdministratorActivity

Description

An exempt resources list is created for a data policy. Marked deprecated in the source doc.

CreateRuleBasedPolicyAssignmentOperation

#
RecordType
PowerPlatformAdministratorActivity

Description

A rule-based policy assignment is added to an environment group for the first time.

CreateRuleBasedPolicyOperation

#
RecordType
PowerPlatformAdministratorActivity

Description

A rule-based policy is added to an environment group for the first time.

CreateRuleSetOperation

#
RecordType
PowerPlatformAdministratorActivity

Description

A rule is added to an environment group for the first time.

CurrencyEnvironmentAllocate

#
RecordType
PowerPlatformAdministratorActivity

Description

A currency add-on is allocated or deallocated to an environment.

Delete connector blocking policy

#
RecordType
PowerPlatformAdministratorActivity

Description

A connector blocking policy is deleted.

Delete Connector Configurations

#
RecordType
PowerPlatformAdministratorActivity

Description

A connector configuration is deleted from a data policy.

Delete Custom Connector Patterns

#
RecordType
PowerPlatformAdministratorActivity

Description

A custom connector URL pattern is deleted from a data policy.

Delete Data Policy

#
RecordType
PowerPlatformAdministratorActivity

Description

A data loss prevention (DLP) policy is deleted.

Delete Exempt Resources (Deprecated)

#
RecordType
PowerPlatformAdministratorActivity

Description

An exempt resources list is deleted from a data policy. Marked deprecated in the source doc.

DeleteConnection

#
RecordType
PowerPlatformAdministratorActivity

Description

A Power Apps/Power Automate connection was deleted. Observed in first-party Unified Audit Log capture landing on RecordType 256 (PowerPlatformAdministratorActivity) rather than RecordType 79 (PowerAppsResource), where the Purview activity-logging article documents this event under the human-readable label "Connection deleted". See PutConnection for the RT256-consolidation note.

Example Audit Record #

{
  "ClientIP": "::ffff:203.0.113.10",
  "CreationTime": "2026-07-04T19:16:06Z",
  "EnvironmentId": "Default-00000000-0000-0000-0000-000000000001",
  "Id": "c48229f5-e421-4285-a7d6-a4708c40cf0b",
  "JsonPropertiesCollection": {
    "powerplatform.analytics.resource.connector.name": "shared_rss",
    "powerplatform.analytics.resource.connection.action_name": "DELETE/PROVIDERS/MICROSOFT.POWERAPPS/APIS/CONNECTIONS/.User",
    "powerplatform.analytics.resource.connection.id": "dwharn1f3b4980",
    "powerplatform.analytics.operation.is_successful": "True",
    "powerplatform.analytics.correlation.id": "d4ac6e36-dc99-4829-9b5f-f79068949a7f",
    "enduser.ip_address": "::ffff:203.0.113.10",
    "user_agent.original": "python-requests/2.34.2",
    "powerplatform.analytics.resource.type": "Connection",
    "version": "1.0",
    "type": "PowerPlatformAdministratorActivityRecord",
    "powerplatform.analytics.activity.name": "DeleteConnection",
    "powerplatform.analytics.activity.id": "c48229f5-e421-4285-a7d6-a4708c40cf0b",
    "enduser.id": "11111111-1111-1111-1111-111111111111",
    "powerplatform.analytics.resource.tenant.id": "00000000-0000-0000-0000-000000000001",
    "enduser.role": "Admin",
    "powerplatform.analytics.resource.environment.id": "Default-00000000-0000-0000-0000-000000000001",
    "enduser.principal_name": "adminuser@example.onmicrosoft.com"
  },
  "Operation": "DeleteConnection",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "PropertyCollection": [
    {
      "Name": "powerplatform.analytics.resource.connector.name",
      "Value": "shared_rss"
    },
    {
      "Name": "powerplatform.analytics.resource.connection.action_name",
      "Value": "DELETE/PROVIDERS/MICROSOFT.POWERAPPS/APIS/CONNECTIONS/.User"
    },
    {
      "Name": "powerplatform.analytics.resource.connection.id",
      "Value": "dwharn1f3b4980"
    },
    {
      "Name": "powerplatform.analytics.operation.is_successful",
      "Value": "True"
    },
    {
      "Name": "powerplatform.analytics.correlation.id",
      "Value": "d4ac6e36-dc99-4829-9b5f-f79068949a7f"
    },
    {
      "Name": "enduser.ip_address",
      "Value": "::ffff:203.0.113.10"
    },
    {
      "Name": "user_agent.original",
      "Value": "python-requests/2.34.2"
    },
    {
      "Name": "powerplatform.analytics.resource.type",
      "Value": "Connection"
    },
    {
      "Name": "version",
      "Value": "1.0"
    },
    {
      "Name": "type",
      "Value": "PowerPlatformAdministratorActivityRecord"
    },
    {
      "Name": "powerplatform.analytics.activity.name",
      "Value": "DeleteConnection"
    },
    {
      "Name": "powerplatform.analytics.activity.id",
      "Value": "c48229f5-e421-4285-a7d6-a4708c40cf0b"
    },
    {
      "Name": "enduser.id",
      "Value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "Name": "powerplatform.analytics.resource.tenant.id",
      "Value": "00000000-0000-0000-0000-000000000001"
    },
    {
      "Name": "enduser.role",
      "Value": "Admin"
    },
    {
      "Name": "powerplatform.analytics.resource.environment.id",
      "Value": "Default-00000000-0000-0000-0000-000000000001"
    },
    {
      "Name": "enduser.principal_name",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 256,
  "RequiresCustomerKeyEncryption": false,
  "ResultStatus": "Succeeded",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "11111111-1111-1111-1111-111111111111",
  "UserType": 2,
  "Version": 1,
  "Workload": "PowerPlatform"
}

Deleted environment

#
RecordType
PowerPlatformAdministratorActivity

Description

The environment was deleted.

DeleteEnvironmentGroup

#
RecordType
PowerPlatformAdministratorActivity

Description

An environment group is deleted.

DeleteRuleBasedPolicyAssignmentOperation

#
RecordType
PowerPlatformAdministratorActivity

Description

A rule-based policy assignment on an environment group is deleted.

DeleteRuleBasedPolicyOperation

#
RecordType
PowerPlatformAdministratorActivity

Description

A rule-based policy on an environment group is deleted.

DeleteRuleSetOperation

#
RecordType
PowerPlatformAdministratorActivity

Description

A rule set on an environment group is deleted.

EnvironmentAddedToEnvironmentGroup

#
RecordType
PowerPlatformAdministratorActivity

Description

An environment is added to an environment group.

EnvironmentDisabledByMiser

#
RecordType
PowerPlatformAdministratorActivity

Description

An environment is automatically disabled because of insufficient database capacity.

EnvironmentRemovedFromEnvironmentGroup

#
RecordType
PowerPlatformAdministratorActivity

Description

An environment is removed from an environment group.

EnvironmentVariableCreate

#
RecordType
PowerPlatformAdministratorActivity

Description

An environment variable is created for an agent in Copilot Studio.

EnvironmentVariableDelete

#
RecordType
PowerPlatformAdministratorActivity

Description

An environment variable is deleted for an agent in Copilot Studio.

EnvironmentVariableUpdate

#
RecordType
PowerPlatformAdministratorActivity

Description

An environment variable is updated for an agent in Copilot Studio.

GovernanceApiPolicyOperation

#
RecordType
PowerPlatformAdministratorActivity

Description

A tenant-wide Power Platform DLP (data loss prevention) policy was created, updated, or deleted via the Power Platform Governance API. Observed in first-party Unified Audit Log capture (a policy-create action) landing on RecordType 256 (PowerPlatformAdministratorActivity) with this literal Operation token, confirming the RecordType 187 (PowerPlatformAdminDlp) entry's documented note that current Power Platform admin activity-logging covers DLP policy events under GovernanceApiPolicyOperation on RT256 rather than RT187. The specific action (create/update/delete) is carried in a nested PropertyCollection/JsonPropertiesCollection field, powerplatform.analytics.resource.tenant.governance.api_policy.operation_name (observed value CreateDlpPolicy for this capture), not in the top-level Operation field.

Example Audit Record #

{
  "CreationTime": "2026-07-04T19:16:09Z",
  "Id": "218b72ad-32a5-4e6a-86b0-6353ba7ea5fe",
  "JsonPropertiesCollection": {
    "powerplatform.analytics.resource.tenant.governance.api_policy.additional_resources": {
      "DefaultConnectorClassification": "General",
      "DlpPolicyType": "AllEnvironments",
      "DlpChangeSet": null
    },
    "powerplatform.analytics.resource.display_name": "dwharn-1f3b4980-dlp",
    "powerplatform.analytics.resource.tenant.governance.api_policy.operation_result": "True",
    "powerplatform.analytics.resource.id": "15d81275-8068-4008-8088-981253affffc",
    "powerplatform.analytics.resource.type": "ApiPolicy",
    "powerplatform.analytics.resource.tenant.governance.api_policy.operation_name": "CreateDlpPolicy",
    "version": "1.0",
    "type": "PowerPlatformAdministratorActivityRecord",
    "powerplatform.analytics.activity.name": "GovernanceApiPolicyOperation",
    "powerplatform.analytics.activity.id": "218b72ad-32a5-4e6a-86b0-6353ba7ea5fe",
    "enduser.id": "11111111-1111-1111-1111-111111111111",
    "enduser.principal_name": "adminuser@example.onmicrosoft.com",
    "enduser.role": "Admin",
    "powerplatform.analytics.resource.tenant.id": "00000000-0000-0000-0000-000000000001"
  },
  "Operation": "GovernanceApiPolicyOperation",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "PropertyCollection": [
    {
      "Name": "powerplatform.analytics.resource.tenant.governance.api_policy.additional_resources",
      "Value": {
        "DefaultConnectorClassification": "General",
        "DlpPolicyType": "AllEnvironments",
        "DlpChangeSet": null
      }
    },
    {
      "Name": "powerplatform.analytics.resource.display_name",
      "Value": "dwharn-1f3b4980-dlp"
    },
    {
      "Name": "powerplatform.analytics.resource.tenant.governance.api_policy.operation_result",
      "Value": "True"
    },
    {
      "Name": "powerplatform.analytics.resource.id",
      "Value": "15d81275-8068-4008-8088-981253affffc"
    },
    {
      "Name": "powerplatform.analytics.resource.type",
      "Value": "ApiPolicy"
    },
    {
      "Name": "powerplatform.analytics.resource.tenant.governance.api_policy.operation_name",
      "Value": "CreateDlpPolicy"
    },
    {
      "Name": "version",
      "Value": "1.0"
    },
    {
      "Name": "type",
      "Value": "PowerPlatformAdministratorActivityRecord"
    },
    {
      "Name": "powerplatform.analytics.activity.name",
      "Value": "GovernanceApiPolicyOperation"
    },
    {
      "Name": "powerplatform.analytics.activity.id",
      "Value": "218b72ad-32a5-4e6a-86b0-6353ba7ea5fe"
    },
    {
      "Name": "enduser.id",
      "Value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "Name": "enduser.principal_name",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "enduser.role",
      "Value": "Admin"
    },
    {
      "Name": "powerplatform.analytics.resource.tenant.id",
      "Value": "00000000-0000-0000-0000-000000000001"
    }
  ],
  "RecordType": 256,
  "RequiresCustomerKeyEncryption": false,
  "ResultStatus": "Succeeded",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "11111111-1111-1111-1111-111111111111",
  "UserType": 2,
  "Version": 1,
  "Workload": "PowerPlatform"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

Hard-deleted environment

#
RecordType
PowerPlatformAdministratorActivity

Description

The environment was hard deleted.

IsvContractConsent

#
RecordType
PowerPlatformAdministratorActivity

Description

A tenant admin consents to an ISV contract.

LockboxRequestOperation

#
RecordType
PowerPlatformAdministratorActivity

Description

A lockbox request is created, approved or denied, or expires/ends access. All lockbox activities are logged under this single activity name.

Moved environment

#
RecordType
PowerPlatformAdministratorActivity

Description

The environment was moved to a different tenant.

NewEnvironmentGroup

#
RecordType
PowerPlatformAdministratorActivity

Description

A new environment group is created.

Provisioned environment

#
RecordType
PowerPlatformAdministratorActivity

Description

The environment was created.

PutConnection

#
RecordType
PowerPlatformAdministratorActivity

Description

A Power Apps/Power Automate connection was created or updated. Observed in first-party Unified Audit Log capture landing on RecordType 256 (PowerPlatformAdministratorActivity) rather than RecordType 79 (PowerAppsResource), where the Purview activity-logging article documents connection lifecycle events under the human-readable label "Connection created or edited". Current live telemetry consolidates Power Apps connection events onto RT256 under a distinct Put/Delete-prefixed operation-name convention not covered by that article.

Example Audit Record #

{
  "ClientIP": "::ffff:203.0.113.10",
  "CreationTime": "2026-07-04T19:16:05Z",
  "EnvironmentId": "Default-00000000-0000-0000-0000-000000000001",
  "Id": "9fb91dd2-f232-4a34-841e-87ca7e04f8dd",
  "JsonPropertiesCollection": {
    "powerplatform.analytics.resource.connector.name": "shared_rss",
    "powerplatform.analytics.resource.connection.action_name": "PUT/PROVIDERS/MICROSOFT.POWERAPPS/APIS/CONNECTIONS/.User",
    "powerplatform.analytics.resource.connection.id": "dwharn1f3b4980",
    "powerplatform.analytics.operation.is_successful": "True",
    "powerplatform.analytics.correlation.id": "d50be856-5b38-49fb-8d27-97d4a00283b3",
    "enduser.ip_address": "::ffff:203.0.113.10",
    "user_agent.original": "python-requests/2.34.2",
    "powerplatform.analytics.resource.type": "Connection",
    "version": "1.0",
    "type": "PowerPlatformAdministratorActivityRecord",
    "powerplatform.analytics.activity.name": "PutConnection",
    "powerplatform.analytics.activity.id": "9fb91dd2-f232-4a34-841e-87ca7e04f8dd",
    "enduser.id": "11111111-1111-1111-1111-111111111111",
    "powerplatform.analytics.resource.tenant.id": "00000000-0000-0000-0000-000000000001",
    "enduser.role": "Admin",
    "powerplatform.analytics.resource.environment.id": "Default-00000000-0000-0000-0000-000000000001",
    "enduser.principal_name": "adminuser@example.onmicrosoft.com"
  },
  "Operation": "PutConnection",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "PropertyCollection": [
    {
      "Name": "powerplatform.analytics.resource.connector.name",
      "Value": "shared_rss"
    },
    {
      "Name": "powerplatform.analytics.resource.connection.action_name",
      "Value": "PUT/PROVIDERS/MICROSOFT.POWERAPPS/APIS/CONNECTIONS/.User"
    },
    {
      "Name": "powerplatform.analytics.resource.connection.id",
      "Value": "dwharn1f3b4980"
    },
    {
      "Name": "powerplatform.analytics.operation.is_successful",
      "Value": "True"
    },
    {
      "Name": "powerplatform.analytics.correlation.id",
      "Value": "d50be856-5b38-49fb-8d27-97d4a00283b3"
    },
    {
      "Name": "enduser.ip_address",
      "Value": "::ffff:203.0.113.10"
    },
    {
      "Name": "user_agent.original",
      "Value": "python-requests/2.34.2"
    },
    {
      "Name": "powerplatform.analytics.resource.type",
      "Value": "Connection"
    },
    {
      "Name": "version",
      "Value": "1.0"
    },
    {
      "Name": "type",
      "Value": "PowerPlatformAdministratorActivityRecord"
    },
    {
      "Name": "powerplatform.analytics.activity.name",
      "Value": "PutConnection"
    },
    {
      "Name": "powerplatform.analytics.activity.id",
      "Value": "9fb91dd2-f232-4a34-841e-87ca7e04f8dd"
    },
    {
      "Name": "enduser.id",
      "Value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "Name": "powerplatform.analytics.resource.tenant.id",
      "Value": "00000000-0000-0000-0000-000000000001"
    },
    {
      "Name": "enduser.role",
      "Value": "Admin"
    },
    {
      "Name": "powerplatform.analytics.resource.environment.id",
      "Value": "Default-00000000-0000-0000-0000-000000000001"
    },
    {
      "Name": "enduser.principal_name",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 256,
  "RequiresCustomerKeyEncryption": false,
  "ResultStatus": "Succeeded",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "11111111-1111-1111-1111-111111111111",
  "UserType": 2,
  "Version": 1,
  "Workload": "PowerPlatform"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

Recovered environment

#
RecordType
PowerPlatformAdministratorActivity

Description

An environment that was deleted was recovered within seven days.

Reset environment

#
RecordType
PowerPlatformAdministratorActivity

Description

A sandbox environment was reset.

Restored environment

#
RecordType
PowerPlatformAdministratorActivity

Description

The environment was restored from a backup.

TrialConvertToProduction

#
RecordType
PowerPlatformAdministratorActivity

Description

A trial plan is converted to a production plan.

TrialEnforce

#
RecordType
PowerPlatformAdministratorActivity

Description

A customer attempts to provision environments beyond the trial limit.

TrialProvision

#
RecordType
PowerPlatformAdministratorActivity

Description

A new trial plan is provisioned.

TrialSignUpEligibilityCheck

#
RecordType
PowerPlatformAdministratorActivity

Description

Prior to trial provisioning, a check occurs to determine trial eligibility.

TrialViralConsent

#
RecordType
PowerPlatformAdministratorActivity

Description

A tenant changes their consented plan types, reflecting the new state.

Update connector blocking policy

#
RecordType
PowerPlatformAdministratorActivity

Description

A connector blocking policy is updated.

Update Connector Configurations

#
RecordType
PowerPlatformAdministratorActivity

Description

A connector configuration is updated for a data policy.

Update Custom Connector Patterns

#
RecordType
PowerPlatformAdministratorActivity

Description

A custom connector URL pattern is updated for a data policy.

Update Data Policy

#
RecordType
PowerPlatformAdministratorActivity

Description

A data loss prevention (DLP) policy is updated.

Update Exempt Resources (Deprecated)

#
RecordType
PowerPlatformAdministratorActivity

Description

An exempt resources list is updated for a data policy. Marked deprecated in the source doc.

UpdateEnvironmentGroup

#
RecordType
PowerPlatformAdministratorActivity

Description

An environment group's name or description is updated.

UpdateRuleBasedPolicyOperation

#
RecordType
PowerPlatformAdministratorActivity

Description

A rule-based policy is added, edited, or removed from an environment group.

UpdateRuleSetOperation

#
RecordType
PowerPlatformAdministratorActivity

Description

A rule is edited in an environment group.

Upgraded environment

#
RecordType
PowerPlatformAdministratorActivity

Description

A component of the environment was upgraded to a new version.

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.