Power Platform administrator activity
| Operation | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for M365-PowerPlatformAdministratorActivity rules matching the RecordType but no specific Operation. | N | Y |
| AIPlugin | An AI plugin is created for an agent in Copilot Studio. | N | N |
| AIPlugin | An AI plugin is removed from an agent in Copilot Studio. | N | N |
| AIPlugin | An AI plugin is updated for an agent in Copilot Studio. | N | N |
| Apply | A tenant admin requests the system administrator role in Dataverse in the environment. | N | N |
| Assign | A license is assigned to a user automatically through an auto-claim policy. | N | N |
| Assign | A new license auto-claim policy is created. | N | N |
| Assign | A trial license is assigned to a user. | N | N |
| Backed up environment | The environment was backed up. | N | N |
| Billing | A new billing policy is created. | N | N |
| Billing | A billing policy is deleted. | N | N |
| Billing | The environments linked to a billing policy change, added or removed. | N | N |
| Bot | An agent's App Insights logging configuration is updated in Copilot Studio. | N | N |
| Bot | A component collection is created for an agent in Copilot Studio. | N | N |
| Bot | A component collection is deleted for an agent in Copilot Studio. | N | N |
| Bot | A component collection is updated for an agent in Copilot Studio. | N | N |
| Bot | A component such as a topic or skill is created for an agent in Copilot Studio. | N | N |
| Bot | A component such as a topic or skill is deleted for an agent in Copilot Studio. | N | N |
| Bot | A component such as a topic or skill is updated for an agent in Copilot Studio. | N | N |
| Bot | A new agent is created in Copilot Studio. | N | N |
| Bot | An agent is deleted in Copilot Studio. | N | N |
| Bot | Dependencies are cleaned up after an agent is deleted in Copilot Studio. | N | N |
| Bot | An agent's authentication settings are updated in Copilot Studio. | N | N |
| Bot | An agent's icon is updated in Copilot Studio. | N | N |
| Bot | An agent's name is updated in Copilot Studio. | N | N |
| Bot | An agent is published in Copilot Studio. | N | N |
| Bot | An agent is shared to other users in Copilot Studio. | N | N |
| Changed property on environment | A property on the environment changed, such as display name, domain name, security group ID, admin mode, or background operations state. | N | N |
| CMK-Renewed environment | The customer-managed key (CMK) was renewed on the environment. | N | N |
| CMK-Reverted environment | The environment was removed from its enterprise policy and encryption reverted to a Microsoft-managed key. | N | N |
| Converted environment type | The environment was converted to a different environment type, such as production or sandbox. | N | N |
| Copied environment | The environment, including application data, users, customizations, and schemas, was copied. | N | N |
| Copilot | A user interacts with a Copilot Studio agent, for example asking a question or viewing a response. The audit row carries only the transcript thread ID, not the transcript text. | N | N |
| Create connector blocking policy | A new connector blocking policy is created. | N | N |
| Create Connector Configurations | A connector configuration is created for a data policy. | N | N |
| Create Custom Connector Patterns | A new custom connector URL pattern is created for a data policy. | N | N |
| Create Data Policy | A new data loss prevention (DLP) policy is created. | N | N |
| Create Exempt Resources (Deprecated) | An exempt resources list is created for a data policy. Marked deprecated in the source doc. | N | N |
| Create | A rule-based policy assignment is added to an environment group for the first time. | N | N |
| Create | A rule-based policy is added to an environment group for the first time. | N | N |
| Create | A rule is added to an environment group for the first time. | N | N |
| Currency | A currency add-on is allocated or deallocated to an environment. | N | N |
| Delete connector blocking policy | A connector blocking policy is deleted. | N | N |
| Delete Connector Configurations | A connector configuration is deleted from a data policy. | N | N |
| Delete Custom Connector Patterns | A custom connector URL pattern is deleted from a data policy. | N | N |
| Delete Data Policy | A data loss prevention (DLP) policy is deleted. | N | N |
| Delete Exempt Resources (Deprecated) | An exempt resources list is deleted from a data policy. Marked deprecated in the source doc. | N | N |
| Delete | A Power Apps/Power Automate connection was deleted. Observed in first-party Unified Audit Log capture landing on RecordType 256 (PowerPlatformAdministratorActivity) rather than RecordType 79 (PowerAppsResource), where the Purview activity-logging article documents this event under the human-readable label "Connection deleted". See PutConnection for the RT256-consolidation note. | Y | N |
| Deleted environment | The environment was deleted. | N | N |
| Delete | An environment group is deleted. | N | N |
| Delete | A rule-based policy assignment on an environment group is deleted. | N | N |
| Delete | A rule-based policy on an environment group is deleted. | N | N |
| Delete | A rule set on an environment group is deleted. | N | N |
| Environment | An environment is added to an environment group. | N | N |
| Environment | An environment is automatically disabled because of insufficient database capacity. | N | N |
| Environment | An environment is removed from an environment group. | N | N |
| Environment | An environment variable is created for an agent in Copilot Studio. | N | N |
| Environment | An environment variable is deleted for an agent in Copilot Studio. | N | N |
| Environment | An environment variable is updated for an agent in Copilot Studio. | N | N |
| Governance | A tenant-wide Power Platform DLP (data loss prevention) policy was created, updated, or deleted via the Power Platform Governance API. Observed in first-party Unified Audit Log capture (a policy-create action) landing on RecordType 256 (PowerPlatformAdministratorActivity) with this literal Operation token, confirming the RecordType 187 (PowerPlatformAdminDlp) entry's documented note that current Power Platform admin activity-logging covers DLP policy events under GovernanceApiPolicyOperation on RT256 rather than RT187. The specific action (create/update/delete) is carried in a nested PropertyCollection/JsonPropertiesCollection field, powerplatform.analytics.resource.tenant.governance.api_policy.operation_name (observed value CreateDlpPolicy for this capture), not in the top-level Operation field. | Y | Y |
| Hard-deleted environment | The environment was hard deleted. | N | N |
| Isv | A tenant admin consents to an ISV contract. | N | N |
| Lockbox | A lockbox request is created, approved or denied, or expires/ends access. All lockbox activities are logged under this single activity name. | N | N |
| Moved environment | The environment was moved to a different tenant. | N | N |
| New | A new environment group is created. | N | N |
| Provisioned environment | The environment was created. | N | N |
| Put | A Power Apps/Power Automate connection was created or updated. Observed in first-party Unified Audit Log capture landing on RecordType 256 (PowerPlatformAdministratorActivity) rather than RecordType 79 (PowerAppsResource), where the Purview activity-logging article documents connection lifecycle events under the human-readable label "Connection created or edited". Current live telemetry consolidates Power Apps connection events onto RT256 under a distinct Put/Delete-prefixed operation-name convention not covered by that article. | Y | Y |
| Recovered environment | An environment that was deleted was recovered within seven days. | N | N |
| Reset environment | A sandbox environment was reset. | N | N |
| Restored environment | The environment was restored from a backup. | N | N |
| Trial | A trial plan is converted to a production plan. | N | N |
| Trial | A customer attempts to provision environments beyond the trial limit. | N | N |
| Trial | A new trial plan is provisioned. | N | N |
| Trial | Prior to trial provisioning, a check occurs to determine trial eligibility. | N | N |
| Trial | A tenant changes their consented plan types, reflecting the new state. | N | N |
| Update connector blocking policy | A connector blocking policy is updated. | N | N |
| Update Connector Configurations | A connector configuration is updated for a data policy. | N | N |
| Update Custom Connector Patterns | A custom connector URL pattern is updated for a data policy. | N | N |
| Update Data Policy | A data loss prevention (DLP) policy is updated. | N | N |
| Update Exempt Resources (Deprecated) | An exempt resources list is updated for a data policy. Marked deprecated in the source doc. | N | N |
| Update | An environment group's name or description is updated. | N | N |
| Update | A rule-based policy is added, edited, or removed from an environment group. | N | N |
| Update | A rule is edited in an environment group. | N | N |
| Upgraded environment | A component of the environment was upgraded to a new version. | N | N |
any: Power Platform administrator activity (catch-all)
#Description
Catch-all for M365-PowerPlatformAdministratorActivity rules matching the RecordType but no specific Operation.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Tactics (kusto rule field) | contains | exfiltration | 1 rule | kusto |
Value (kusto rule field) | eq | False | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1567, T1629T1534, T1566, T1587T0826, T1485
AIPluginOperationCreate
#Description
An AI plugin is created for an agent in Copilot Studio.
AIPluginOperationDelete
#Description
An AI plugin is removed from an agent in Copilot Studio.
AIPluginOperationUpdate
#Description
An AI plugin is updated for an agent in Copilot Studio.
ApplyAdminRole
#Description
A tenant admin requests the system administrator role in Dataverse in the environment.
AssignLicenseAutoClaim
#Description
A license is assigned to a user automatically through an auto-claim policy.
AssignLicenseAutoClaimPolicyCreate
#Description
A new license auto-claim policy is created.
AssignLicenseToUser
#Description
A trial license is assigned to a user.
Backed up environment
#Description
The environment was backed up.
BillingPolicyCreate
#Description
A new billing policy is created.
BillingPolicyDelete
#Description
A billing policy is deleted.
BillingPolicyUpdate
#Description
The environments linked to a billing policy change, added or removed.
BotAppInsightsUpdate
#Description
An agent's App Insights logging configuration is updated in Copilot Studio.
BotComponentCollectionCreate
#Description
A component collection is created for an agent in Copilot Studio.
BotComponentCollectionDelete
#Description
A component collection is deleted for an agent in Copilot Studio.
BotComponentCollectionUpdate
#Description
A component collection is updated for an agent in Copilot Studio.
BotComponentCreate
#Description
A component such as a topic or skill is created for an agent in Copilot Studio.
BotComponentDelete
#Description
A component such as a topic or skill is deleted for an agent in Copilot Studio.
BotComponentUpdate
#Description
A component such as a topic or skill is updated for an agent in Copilot Studio.
BotCreate
#Description
A new agent is created in Copilot Studio.
BotDelete
#Description
An agent is deleted in Copilot Studio.
BotDeleteCleanup
#Description
Dependencies are cleaned up after an agent is deleted in Copilot Studio.
BotUpdateOperation-BotAuthUpdate
#Description
An agent's authentication settings are updated in Copilot Studio.
BotUpdateOperation-BotIconUpdate
#Description
An agent's icon is updated in Copilot Studio.
BotUpdateOperation-BotNameUpdate
#Description
An agent's name is updated in Copilot Studio.
BotUpdateOperation-BotPublish
#Description
An agent is published in Copilot Studio.
Changed property on environment
#Description
A property on the environment changed, such as display name, domain name, security group ID, admin mode, or background operations state.
CMK-Renewed environment
#Description
The customer-managed key (CMK) was renewed on the environment.
CMK-Reverted environment
#Description
The environment was removed from its enterprise policy and encryption reverted to a Microsoft-managed key.
Converted environment type
#Description
The environment was converted to a different environment type, such as production or sandbox.
Copied environment
#Description
The environment, including application data, users, customizations, and schemas, was copied.
CopilotInteraction
#Description
A user interacts with a Copilot Studio agent, for example asking a question or viewing a response. The audit row carries only the transcript thread ID, not the transcript text.
Create connector blocking policy
#Description
A new connector blocking policy is created.
Create Connector Configurations
#Description
A connector configuration is created for a data policy.
Create Custom Connector Patterns
#Description
A new custom connector URL pattern is created for a data policy.
Create Data Policy
#Description
A new data loss prevention (DLP) policy is created.
Create Exempt Resources (Deprecated)
#Description
An exempt resources list is created for a data policy. Marked deprecated in the source doc.
CreateRuleBasedPolicyAssignmentOperation
#Description
A rule-based policy assignment is added to an environment group for the first time.
CreateRuleBasedPolicyOperation
#Description
A rule-based policy is added to an environment group for the first time.
CreateRuleSetOperation
#Description
A rule is added to an environment group for the first time.
CurrencyEnvironmentAllocate
#Description
A currency add-on is allocated or deallocated to an environment.
Delete connector blocking policy
#Description
A connector blocking policy is deleted.
Delete Connector Configurations
#Description
A connector configuration is deleted from a data policy.
Delete Custom Connector Patterns
#Description
A custom connector URL pattern is deleted from a data policy.
Delete Data Policy
#Description
A data loss prevention (DLP) policy is deleted.
Delete Exempt Resources (Deprecated)
#Description
An exempt resources list is deleted from a data policy. Marked deprecated in the source doc.
DeleteConnection
#Description
A Power Apps/Power Automate connection was deleted. Observed in first-party Unified Audit Log capture landing on RecordType 256 (PowerPlatformAdministratorActivity) rather than RecordType 79 (PowerAppsResource), where the Purview activity-logging article documents this event under the human-readable label "Connection deleted". See PutConnection for the RT256-consolidation note.
Example Audit Record #
{
"ClientIP": "::ffff:203.0.113.10",
"CreationTime": "2026-07-04T19:16:06Z",
"EnvironmentId": "Default-00000000-0000-0000-0000-000000000001",
"Id": "c48229f5-e421-4285-a7d6-a4708c40cf0b",
"JsonPropertiesCollection": {
"powerplatform.analytics.resource.connector.name": "shared_rss",
"powerplatform.analytics.resource.connection.action_name": "DELETE/PROVIDERS/MICROSOFT.POWERAPPS/APIS/CONNECTIONS/.User",
"powerplatform.analytics.resource.connection.id": "dwharn1f3b4980",
"powerplatform.analytics.operation.is_successful": "True",
"powerplatform.analytics.correlation.id": "d4ac6e36-dc99-4829-9b5f-f79068949a7f",
"enduser.ip_address": "::ffff:203.0.113.10",
"user_agent.original": "python-requests/2.34.2",
"powerplatform.analytics.resource.type": "Connection",
"version": "1.0",
"type": "PowerPlatformAdministratorActivityRecord",
"powerplatform.analytics.activity.name": "DeleteConnection",
"powerplatform.analytics.activity.id": "c48229f5-e421-4285-a7d6-a4708c40cf0b",
"enduser.id": "11111111-1111-1111-1111-111111111111",
"powerplatform.analytics.resource.tenant.id": "00000000-0000-0000-0000-000000000001",
"enduser.role": "Admin",
"powerplatform.analytics.resource.environment.id": "Default-00000000-0000-0000-0000-000000000001",
"enduser.principal_name": "adminuser@example.onmicrosoft.com"
},
"Operation": "DeleteConnection",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"PropertyCollection": [
{
"Name": "powerplatform.analytics.resource.connector.name",
"Value": "shared_rss"
},
{
"Name": "powerplatform.analytics.resource.connection.action_name",
"Value": "DELETE/PROVIDERS/MICROSOFT.POWERAPPS/APIS/CONNECTIONS/.User"
},
{
"Name": "powerplatform.analytics.resource.connection.id",
"Value": "dwharn1f3b4980"
},
{
"Name": "powerplatform.analytics.operation.is_successful",
"Value": "True"
},
{
"Name": "powerplatform.analytics.correlation.id",
"Value": "d4ac6e36-dc99-4829-9b5f-f79068949a7f"
},
{
"Name": "enduser.ip_address",
"Value": "::ffff:203.0.113.10"
},
{
"Name": "user_agent.original",
"Value": "python-requests/2.34.2"
},
{
"Name": "powerplatform.analytics.resource.type",
"Value": "Connection"
},
{
"Name": "version",
"Value": "1.0"
},
{
"Name": "type",
"Value": "PowerPlatformAdministratorActivityRecord"
},
{
"Name": "powerplatform.analytics.activity.name",
"Value": "DeleteConnection"
},
{
"Name": "powerplatform.analytics.activity.id",
"Value": "c48229f5-e421-4285-a7d6-a4708c40cf0b"
},
{
"Name": "enduser.id",
"Value": "11111111-1111-1111-1111-111111111111"
},
{
"Name": "powerplatform.analytics.resource.tenant.id",
"Value": "00000000-0000-0000-0000-000000000001"
},
{
"Name": "enduser.role",
"Value": "Admin"
},
{
"Name": "powerplatform.analytics.resource.environment.id",
"Value": "Default-00000000-0000-0000-0000-000000000001"
},
{
"Name": "enduser.principal_name",
"Value": "adminuser@example.onmicrosoft.com"
}
],
"RecordType": 256,
"RequiresCustomerKeyEncryption": false,
"ResultStatus": "Succeeded",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "11111111-1111-1111-1111-111111111111",
"UserType": 2,
"Version": 1,
"Workload": "PowerPlatform"
}
Deleted environment
#Description
The environment was deleted.
DeleteEnvironmentGroup
#Description
An environment group is deleted.
DeleteRuleBasedPolicyAssignmentOperation
#Description
A rule-based policy assignment on an environment group is deleted.
DeleteRuleBasedPolicyOperation
#Description
A rule-based policy on an environment group is deleted.
DeleteRuleSetOperation
#Description
A rule set on an environment group is deleted.
EnvironmentAddedToEnvironmentGroup
#Description
An environment is added to an environment group.
EnvironmentDisabledByMiser
#Description
An environment is automatically disabled because of insufficient database capacity.
EnvironmentRemovedFromEnvironmentGroup
#Description
An environment is removed from an environment group.
EnvironmentVariableCreate
#Description
An environment variable is created for an agent in Copilot Studio.
EnvironmentVariableDelete
#Description
An environment variable is deleted for an agent in Copilot Studio.
EnvironmentVariableUpdate
#Description
An environment variable is updated for an agent in Copilot Studio.
GovernanceApiPolicyOperation
#Description
A tenant-wide Power Platform DLP (data loss prevention) policy was created, updated, or deleted via the Power Platform Governance API. Observed in first-party Unified Audit Log capture (a policy-create action) landing on RecordType 256 (PowerPlatformAdministratorActivity) with this literal Operation token, confirming the RecordType 187 (PowerPlatformAdminDlp) entry's documented note that current Power Platform admin activity-logging covers DLP policy events under GovernanceApiPolicyOperation on RT256 rather than RT187. The specific action (create/update/delete) is carried in a nested PropertyCollection/JsonPropertiesCollection field, powerplatform.analytics.resource.tenant.governance.api_policy.operation_name (observed value CreateDlpPolicy for this capture), not in the top-level Operation field.
Example Audit Record #
{
"CreationTime": "2026-07-04T19:16:09Z",
"Id": "218b72ad-32a5-4e6a-86b0-6353ba7ea5fe",
"JsonPropertiesCollection": {
"powerplatform.analytics.resource.tenant.governance.api_policy.additional_resources": {
"DefaultConnectorClassification": "General",
"DlpPolicyType": "AllEnvironments",
"DlpChangeSet": null
},
"powerplatform.analytics.resource.display_name": "dwharn-1f3b4980-dlp",
"powerplatform.analytics.resource.tenant.governance.api_policy.operation_result": "True",
"powerplatform.analytics.resource.id": "15d81275-8068-4008-8088-981253affffc",
"powerplatform.analytics.resource.type": "ApiPolicy",
"powerplatform.analytics.resource.tenant.governance.api_policy.operation_name": "CreateDlpPolicy",
"version": "1.0",
"type": "PowerPlatformAdministratorActivityRecord",
"powerplatform.analytics.activity.name": "GovernanceApiPolicyOperation",
"powerplatform.analytics.activity.id": "218b72ad-32a5-4e6a-86b0-6353ba7ea5fe",
"enduser.id": "11111111-1111-1111-1111-111111111111",
"enduser.principal_name": "adminuser@example.onmicrosoft.com",
"enduser.role": "Admin",
"powerplatform.analytics.resource.tenant.id": "00000000-0000-0000-0000-000000000001"
},
"Operation": "GovernanceApiPolicyOperation",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"PropertyCollection": [
{
"Name": "powerplatform.analytics.resource.tenant.governance.api_policy.additional_resources",
"Value": {
"DefaultConnectorClassification": "General",
"DlpPolicyType": "AllEnvironments",
"DlpChangeSet": null
}
},
{
"Name": "powerplatform.analytics.resource.display_name",
"Value": "dwharn-1f3b4980-dlp"
},
{
"Name": "powerplatform.analytics.resource.tenant.governance.api_policy.operation_result",
"Value": "True"
},
{
"Name": "powerplatform.analytics.resource.id",
"Value": "15d81275-8068-4008-8088-981253affffc"
},
{
"Name": "powerplatform.analytics.resource.type",
"Value": "ApiPolicy"
},
{
"Name": "powerplatform.analytics.resource.tenant.governance.api_policy.operation_name",
"Value": "CreateDlpPolicy"
},
{
"Name": "version",
"Value": "1.0"
},
{
"Name": "type",
"Value": "PowerPlatformAdministratorActivityRecord"
},
{
"Name": "powerplatform.analytics.activity.name",
"Value": "GovernanceApiPolicyOperation"
},
{
"Name": "powerplatform.analytics.activity.id",
"Value": "218b72ad-32a5-4e6a-86b0-6353ba7ea5fe"
},
{
"Name": "enduser.id",
"Value": "11111111-1111-1111-1111-111111111111"
},
{
"Name": "enduser.principal_name",
"Value": "adminuser@example.onmicrosoft.com"
},
{
"Name": "enduser.role",
"Value": "Admin"
},
{
"Name": "powerplatform.analytics.resource.tenant.id",
"Value": "00000000-0000-0000-0000-000000000001"
}
],
"RecordType": 256,
"RequiresCustomerKeyEncryption": false,
"ResultStatus": "Succeeded",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "11111111-1111-1111-1111-111111111111",
"UserType": 2,
"Version": 1,
"Workload": "PowerPlatform"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1480
Hard-deleted environment
#Description
The environment was hard deleted.
IsvContractConsent
#Description
A tenant admin consents to an ISV contract.
LockboxRequestOperation
#Description
A lockbox request is created, approved or denied, or expires/ends access. All lockbox activities are logged under this single activity name.
Moved environment
#Description
The environment was moved to a different tenant.
NewEnvironmentGroup
#Description
A new environment group is created.
Provisioned environment
#Description
The environment was created.
PutConnection
#Description
A Power Apps/Power Automate connection was created or updated. Observed in first-party Unified Audit Log capture landing on RecordType 256 (PowerPlatformAdministratorActivity) rather than RecordType 79 (PowerAppsResource), where the Purview activity-logging article documents connection lifecycle events under the human-readable label "Connection created or edited". Current live telemetry consolidates Power Apps connection events onto RT256 under a distinct Put/Delete-prefixed operation-name convention not covered by that article.
Example Audit Record #
{
"ClientIP": "::ffff:203.0.113.10",
"CreationTime": "2026-07-04T19:16:05Z",
"EnvironmentId": "Default-00000000-0000-0000-0000-000000000001",
"Id": "9fb91dd2-f232-4a34-841e-87ca7e04f8dd",
"JsonPropertiesCollection": {
"powerplatform.analytics.resource.connector.name": "shared_rss",
"powerplatform.analytics.resource.connection.action_name": "PUT/PROVIDERS/MICROSOFT.POWERAPPS/APIS/CONNECTIONS/.User",
"powerplatform.analytics.resource.connection.id": "dwharn1f3b4980",
"powerplatform.analytics.operation.is_successful": "True",
"powerplatform.analytics.correlation.id": "d50be856-5b38-49fb-8d27-97d4a00283b3",
"enduser.ip_address": "::ffff:203.0.113.10",
"user_agent.original": "python-requests/2.34.2",
"powerplatform.analytics.resource.type": "Connection",
"version": "1.0",
"type": "PowerPlatformAdministratorActivityRecord",
"powerplatform.analytics.activity.name": "PutConnection",
"powerplatform.analytics.activity.id": "9fb91dd2-f232-4a34-841e-87ca7e04f8dd",
"enduser.id": "11111111-1111-1111-1111-111111111111",
"powerplatform.analytics.resource.tenant.id": "00000000-0000-0000-0000-000000000001",
"enduser.role": "Admin",
"powerplatform.analytics.resource.environment.id": "Default-00000000-0000-0000-0000-000000000001",
"enduser.principal_name": "adminuser@example.onmicrosoft.com"
},
"Operation": "PutConnection",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"PropertyCollection": [
{
"Name": "powerplatform.analytics.resource.connector.name",
"Value": "shared_rss"
},
{
"Name": "powerplatform.analytics.resource.connection.action_name",
"Value": "PUT/PROVIDERS/MICROSOFT.POWERAPPS/APIS/CONNECTIONS/.User"
},
{
"Name": "powerplatform.analytics.resource.connection.id",
"Value": "dwharn1f3b4980"
},
{
"Name": "powerplatform.analytics.operation.is_successful",
"Value": "True"
},
{
"Name": "powerplatform.analytics.correlation.id",
"Value": "d50be856-5b38-49fb-8d27-97d4a00283b3"
},
{
"Name": "enduser.ip_address",
"Value": "::ffff:203.0.113.10"
},
{
"Name": "user_agent.original",
"Value": "python-requests/2.34.2"
},
{
"Name": "powerplatform.analytics.resource.type",
"Value": "Connection"
},
{
"Name": "version",
"Value": "1.0"
},
{
"Name": "type",
"Value": "PowerPlatformAdministratorActivityRecord"
},
{
"Name": "powerplatform.analytics.activity.name",
"Value": "PutConnection"
},
{
"Name": "powerplatform.analytics.activity.id",
"Value": "9fb91dd2-f232-4a34-841e-87ca7e04f8dd"
},
{
"Name": "enduser.id",
"Value": "11111111-1111-1111-1111-111111111111"
},
{
"Name": "powerplatform.analytics.resource.tenant.id",
"Value": "00000000-0000-0000-0000-000000000001"
},
{
"Name": "enduser.role",
"Value": "Admin"
},
{
"Name": "powerplatform.analytics.resource.environment.id",
"Value": "Default-00000000-0000-0000-0000-000000000001"
},
{
"Name": "enduser.principal_name",
"Value": "adminuser@example.onmicrosoft.com"
}
],
"RecordType": 256,
"RequiresCustomerKeyEncryption": false,
"ResultStatus": "Succeeded",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "11111111-1111-1111-1111-111111111111",
"UserType": 2,
"Version": 1,
"Workload": "PowerPlatform"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T0871, T1537, T1567
Recovered environment
#Description
An environment that was deleted was recovered within seven days.
Reset environment
#Description
A sandbox environment was reset.
Restored environment
#Description
The environment was restored from a backup.
TrialConvertToProduction
#Description
A trial plan is converted to a production plan.
TrialEnforce
#Description
A customer attempts to provision environments beyond the trial limit.
TrialProvision
#Description
A new trial plan is provisioned.
TrialSignUpEligibilityCheck
#Description
Prior to trial provisioning, a check occurs to determine trial eligibility.
Update connector blocking policy
#Description
A connector blocking policy is updated.
Update Connector Configurations
#Description
A connector configuration is updated for a data policy.
Update Custom Connector Patterns
#Description
A custom connector URL pattern is updated for a data policy.
Update Data Policy
#Description
A data loss prevention (DLP) policy is updated.
Update Exempt Resources (Deprecated)
#Description
An exempt resources list is updated for a data policy. Marked deprecated in the source doc.
UpdateEnvironmentGroup
#Description
An environment group's name or description is updated.
UpdateRuleBasedPolicyOperation
#Description
A rule-based policy is added, edited, or removed from an environment group.
UpdateRuleSetOperation
#Description
A rule is edited in an environment group.
Upgraded environment
#Description
A component of the environment was upgraded to a new version.
References #
M365 audit records use different field names on each surface #
The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.
- Purview CSV export flattens each record to four columns (
CreationDate,UserIds,Operations,AuditData). The API field names live only inside theAuditDataJSON blob. Expand it withConvertFrom-Json. The wrapper columns are renamed too:CreationDatenotCreationTime,UserIdsnotUserId,OperationsnotOperation. - Sentinel's
OfficeActivitytable renames several fields and turns two integer enum columns into strings. The table below maps them.
| API JSON (event pages) | OfficeActivity column | Note |
|---|---|---|
Id | OfficeId | Renamed. |
Workload | OfficeWorkload | Renamed. |
ObjectId | OfficeObjectId | Renamed. |
CreationTime | TimeGenerated | Renamed. OfficeActivity has no CreationTime column. |
SiteUrl | Site_Url | Renamed (SharePoint family). |
RecordType | RecordType | Same name; the Int32 enum becomes its string enum name. |
UserType | UserType | Same name; the Int32 enum becomes a string. |
ClientIP | ClientIP, Client_IPAddress | Both columns present on OfficeActivity. |
Scope | (none) | No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob. |
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationId | same names | Unchanged. No _s / _d suffixes (a native table, not a custom log). |
Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.