Security & Compliance Center EOP cmdlet activity
| Operation | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for M365-SecurityComplianceCenterEOPCmdlet rules matching the RecordType but no specific Operation. | N | Y |
| Get-Auto | An auto sensitivity label policy was read via the Get-AutoSensitivityLabelPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Case | A case hold policy was read via the Get-CaseHoldPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Compliance | A compliance case was read via the Get-ComplianceCase Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Compliance | A compliance search was read via the Get-ComplianceSearch Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Compliance | A compliance tag was read via the Get-ComplianceTag Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Dlp | A dlp compliance policy was read via the Get-DlpCompliancePolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Dlp | A dlp sensitive information type was read via the Get-DlpSensitiveInformationType Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Label | A label was read via the Get-Label Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Label | A label policy was read via the Get-LabelPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Organization | An organization segment was read via the Get-OrganizationSegment Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Retention | A retention compliance policy was read via the Get-RetentionCompliancePolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Get-Supervisory | A supervisory review policy v2 was read via the Get-SupervisoryReviewPolicyV2 Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Microsoft. | Microsoft.Office.Compliance Policy.Tasks.Enable Compliance Tag Storage activity in Security & Compliance Center, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| New-Case | A case hold policy was created via the New-CaseHoldPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| New-Compliance | A compliance case was created via the New-ComplianceCase Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| New-Compliance | A new content search (eDiscovery collection) was created in the Security and Compliance Center. | Y | N |
| New-Compliance | A content-search action was created (preview, export, or purge of results); export and purge are exfiltration- and destruction-relevant. | Y | N |
| New-Compliance | A compliance tag was created via the New-ComplianceTag Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| New-Dlp | A new Data Loss Prevention compliance policy was created. | Y | N |
| New-Dlp | A new Data Loss Prevention compliance rule was created. | Y | N |
| New-Dlp | A dlp sensitive information type was created via the New-DlpSensitiveInformationType Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| New-Label | A label was created via the New-Label Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| New-Label | A label policy was created via the New-LabelPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| New-Organization | An organization segment was created via the New-OrganizationSegment Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| New-Retention | A retention compliance policy was created via the New-RetentionCompliancePolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| New-Retention | A retention compliance rule was created via the New-RetentionComplianceRule Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| New-Supervisory | A supervisory review policy v2 was created via the New-SupervisoryReviewPolicyV2 Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Remove-Case | A case hold policy was deleted via the Remove-CaseHoldPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Remove-Compliance | A compliance case was deleted via the Remove-ComplianceCase Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Remove-Compliance | A compliance search was deleted via the Remove-ComplianceSearch Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Remove-Compliance | A compliance tag was deleted via the Remove-ComplianceTag Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Remove-Dlp | A Data Loss Prevention compliance policy was deleted. | Y | N |
| Remove-Dlp | A dlp sensitive information type was deleted via the Remove-DlpSensitiveInformationType Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Remove-Label | A label was deleted via the Remove-Label Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Remove-Label | A label policy was deleted via the Remove-LabelPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Remove-Organization | An organization segment was deleted via the Remove-OrganizationSegment Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Remove-Retention | A retention compliance policy was deleted via the Remove-RetentionCompliancePolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Remove-Supervisory | A supervisory review policy v2 was deleted via the Remove-SupervisoryReviewPolicyV2 Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Set-Compliance | An existing content search was modified. | Y | N |
| Set-Compliance | A compliance tag was modified via the Set-ComplianceTag Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Set-Dlp | A dlp compliance policy was modified via the Set-DlpCompliancePolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture). | Y | N |
| Set-Role | A Security and Compliance Center RBAC role group was modified. | Y | N |
| Start-Compliance | A content search was started (executed). | Y | N |
| Update-e | The organization-wide list of eDiscovery administrators was changed. | Y | N |
| Update-Role | Membership of a Security and Compliance Center RBAC role group was changed. | Y | N |
any: Security & Compliance Center EOP cmdlet activity (catch-all)
#Description
Catch-all for M365-SecurityComplianceCenterEOPCmdlet rules matching the RecordType but no specific Operation.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1059, T1059.001, T1098, T1562, T1562.001
References #
Get-AutoSensitivityLabelPolicy
#Description
An auto sensitivity label policy was read via the Get-AutoSensitivityLabelPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"CmdletVersion": "...",
"CreationDate": "2026-07-03T04:30:59",
"CreationTime": "2026-07-03T04:30:59",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "895f302d-682c-4bd2-bd7d-889d09cd6b06",
"NonPIIParameters": "-Organization \"11111111-1111-1111-1111-111111111111\"",
"Operation": "Get-AutoSensitivityLabelPolicy",
"Operations": "Get-AutoSensitivityLabelPolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Organization \"11111111-1111-1111-1111-111111111111\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T04:30:59",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "adminuser@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-CaseHoldPolicy
#Description
A case hold policy was read via the Get-CaseHoldPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:02:03",
"CreationTime": "2026-07-03T06:02:03",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "cb443430-06c9-40fe-81ef-102446596e9e",
"Operation": "Get-CaseHoldPolicy",
"Operations": "Get-CaseHoldPolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Error",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:02:03",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-ComplianceCase
#Description
A compliance case was read via the Get-ComplianceCase Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:01:03",
"CreationTime": "2026-07-03T06:01:03",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "cf8d0f53-cf4a-4ef3-ab02-2dc1ea1ab2f1",
"Operation": "Get-ComplianceCase",
"Operations": "Get-ComplianceCase",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:01:03",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-ComplianceSearch
#Description
A compliance search was read via the Get-ComplianceSearch Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:02:04",
"CreationTime": "2026-07-03T06:02:04",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "1ef41a31-c38f-4ee5-8c2e-92e03ba5dafe",
"Operation": "Get-ComplianceSearch",
"Operations": "Get-ComplianceSearch",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:02:04",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-ComplianceTag
#Description
A compliance tag was read via the Get-ComplianceTag Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:01:57",
"CreationTime": "2026-07-03T06:01:57",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "eaadc222-edae-4e55-a328-da3c772d1957",
"Operation": "Get-ComplianceTag",
"Operations": "Get-ComplianceTag",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:01:57",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-DlpCompliancePolicy
#Description
A dlp compliance policy was read via the Get-DlpCompliancePolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:57:27",
"CreationTime": "2026-07-03T05:57:27",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "dcb2b65a-84fe-47c1-9050-9ace4385cdce",
"Operation": "Get-DlpCompliancePolicy",
"Operations": "Get-DlpCompliancePolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:57:27",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-DlpSensitiveInformationType
#Description
A dlp sensitive information type was read via the Get-DlpSensitiveInformationType Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:02:07",
"CreationTime": "2026-07-03T06:02:07",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "e36d60f0-8ea5-4055-8520-12d88f577e1a",
"Operation": "Get-DlpSensitiveInformationType",
"Operations": "Get-DlpSensitiveInformationType",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:02:07",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-Label
#Description
A label was read via the Get-Label Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:01:58",
"CreationTime": "2026-07-03T06:01:58",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "067b8ad0-e2c4-423e-b663-2a8eb926f9ca",
"Operation": "Get-Label",
"Operations": "Get-Label",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:01:58",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-LabelPolicy
#Description
A label policy was read via the Get-LabelPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"CmdletVersion": "...",
"CreationDate": "2026-07-03T04:30:57",
"CreationTime": "2026-07-03T04:30:57",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "6988896e-3f59-4758-adcc-39e8bf38b95f",
"NonPIIParameters": "-Organization \"11111111-1111-1111-1111-111111111111\"",
"Operation": "Get-LabelPolicy",
"Operations": "Get-LabelPolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Organization \"11111111-1111-1111-1111-111111111111\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T04:30:57",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "adminuser@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-OrganizationSegment
#Description
An organization segment was read via the Get-OrganizationSegment Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:02:05",
"CreationTime": "2026-07-03T06:02:05",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "72c6855c-87f5-4b6f-889c-a1c75c51c128",
"Operation": "Get-OrganizationSegment",
"Operations": "Get-OrganizationSegment",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:02:05",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-RetentionCompliancePolicy
#Description
A retention compliance policy was read via the Get-RetentionCompliancePolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:01:10",
"CreationTime": "2026-07-03T06:01:10",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "3087278d-6c2b-461a-9c16-1ad1f3ac8586",
"ObjectId": "bc8eb520-d184-435d-973c-04cff5dadd2e",
"Operation": "Get-RetentionCompliancePolicy",
"Operations": "Get-RetentionCompliancePolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:01:10",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Get-SupervisoryReviewPolicyV2
#Description
A supervisory review policy v2 was read via the Get-SupervisoryReviewPolicyV2 Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:01:16",
"CreationTime": "2026-07-03T06:01:16",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "e83b7310-6087-4cca-ba3d-d1de89341890",
"Operation": "Get-SupervisoryReviewPolicyV2",
"Operations": "Get-SupervisoryReviewPolicyV2",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:01:16",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-CaseHoldPolicy
#Description
A case hold policy was created via the New-CaseHoldPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:56:50",
"CreationTime": "2026-07-03T05:56:50",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "5e793fef-af7b-42d7-a67e-c2e1b47e6d44",
"NonPIIParameters": "-Name \"<SNIP-PII>\" -Case \"<SNIP-PII>\" -ExchangeLocation (\"<SNIP-PII>\")",
"Operation": "New-CaseHoldPolicy",
"Operations": "New-CaseHoldPolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Name \"dwharn9babc3-hold\" -Case \"dwharn9babc3-hc\" -ExchangeLocation (\"adminuser@example.onmicrosoft.com\")",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Error",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:56:50",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-ComplianceCase
#Description
A compliance case was created via the New-ComplianceCase Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:56:48",
"CreationTime": "2026-07-03T05:56:48",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "16da9210-b89d-4ce7-8869-8415b10b0a3d",
"NonPIIParameters": "-Name \"<SNIP-PII>\"",
"Operation": "New-ComplianceCase",
"Operations": "New-ComplianceCase",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Name \"dwharn9babc3-hc\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:56:48",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-ComplianceSearch
#Description
A new content search (eDiscovery collection) was created in the Security and Compliance Center.
Example Audit Record #
{
"CreationTime": "2024-04-01T16:11:26",
"Id": "210fadae-25b9-4bc3-950e-963d031eb59c",
"Operation": "New-ComplianceSearch",
"OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 18,
"ResultStatus": "Success",
"UserKey": "attacker@splunkresearch.com",
"UserType": 2,
"Version": 1,
"Workload": "SecurityComplianceCenter",
"UserId": "attacker@splunkresearch.com",
"SecurityComplianceCenterEventType": 0,
"ClientApplication": "EMC",
"CmdletVersion": "...",
"EffectiveOrganization": "splunkresearch.com",
"NonPIIParameters": "-Name \"<SNIP-PII>\" -Description \"<SNIP-PII>\" -HoldNames () -PublicFolderLocation () -ExchangeLocationExclusion () -IncludeUserAppContent \"<SNIP-PII>\" -SharePointLocationExclusion () -Force \"True\" -Language \"<SNIP-PII>\" -SharePointLocation () -ExchangeLocation (\"<SNIP-PII>\") -ContentMatchQuery \"<SNIP-PII>\"",
"Parameters": "-Name \"browser search\" -Description \"\" -HoldNames () -PublicFolderLocation () -ExchangeLocationExclusion () -IncludeUserAppContent \"True\" -SharePointLocationExclusion () -Force \"True\" -Language \"\" -SharePointLocation () -ExchangeLocation (\"All\") -ContentMatchQuery \" (c:c)(subject:test)\"",
"StartTime": "2024-04-01T16:11:26"
}
References #
New-ComplianceSearchAction
#Description
A content-search action was created (preview, export, or purge of results); export and purge are exfiltration- and destruction-relevant.
Example Audit Record #
{
"CreationTime": "2024-04-01T19:27:15",
"Id": "9f37bdc9-e64f-45c5-81e8-724bd755bc9e",
"Operation": "New-ComplianceSearchAction",
"OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 18,
"ResultStatus": "Success",
"UserKey": "attacker@splunkresearch.com",
"UserType": 2,
"Version": 1,
"Workload": "SecurityComplianceCenter",
"UserId": "attacker@splunkresearch.com",
"SecurityComplianceCenterEventType": 0,
"ClientApplication": "EMC",
"CmdletVersion": "...",
"EffectiveOrganization": "splunkresearch.com",
"NonPIIParameters": "-EnableDedupe \"<SNIP-PII>\" -Format \"<SNIP-PII>\" -Export \"<SNIP-PII>\" -Scope \"<SNIP-PII>\" -IncludeSharePointDocumentVersions \"<SNIP-PII>\" -SharePointArchiveFormat \"<SNIP-PII>\" -SearchName (\"<SNIP-PII>\") -Scenario \"<SNIP-PII>\" -ExchangeArchiveFormat \"<SNIP-PII>\"",
"Parameters": "-EnableDedupe \"False\" -Format \"FxStream\" -Export \"True\" -Scope \"IndexedItemsOnly\" -IncludeSharePointDocumentVersions \"False\" -SharePointArchiveFormat \"IndividualMessage\" -SearchName (\"msInvader 365 search\") -Scenario \"General\" -ExchangeArchiveFormat \"PerUserPst\"",
"StartTime": "2024-04-01T19:27:15"
}
References #
New-ComplianceTag
#Description
A compliance tag was created via the New-ComplianceTag Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:29:58",
"CreationTime": "2026-07-03T05:29:58",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "0b714c4e-5e07-4b04-b7aa-10800511d742",
"NonPIIParameters": "-Name \"<SNIP-PII>\" -Organization \"11111111-1111-1111-1111-111111111111\" -RetentionAction \"<SNIP-PII>\" -RetentionDuration \"<SNIP-PII>\" -RetentionType \"<SNIP-PII>\" -Comment \"<SNIP-PII>\"",
"ObjectId": "6abe80c5-29ea-4b98-83bc-cdab2fb733c7",
"Operation": "New-ComplianceTag",
"Operations": "New-ComplianceTag",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Name \"dw-harness-rl-7ec88469\" -Organization \"11111111-1111-1111-1111-111111111111\" -RetentionAction \"Keep\" -RetentionDuration \"Unlimited\" -RetentionType \"TaggedAgeInDays\" -Comment \"harness\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:29:58",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "adminuser@example.onmicrosoft.com",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-DlpCompliancePolicy
#Description
A new Data Loss Prevention compliance policy was created.
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationTime": "2026-07-02T15:42:13Z",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "319e2fb1-61d5-4cde-b55f-952c37a6bb55",
"NonPIIParameters": "-Mode \"<SNIP-PII>\" -Name \"<SNIP-PII>\" -ExchangeLocation (\"<SNIP-PII>\") -ErrorAction \"Stop\"",
"ObjectId": "23bac226-705b-4207-9f57-c90aca5e137e",
"Operation": "New-DlpCompliancePolicy",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"Parameters": "-Mode \"TestWithoutNotifications\" -Name \"dwdlp\" -ExchangeLocation (\"All\") -ErrorAction \"Stop\"",
"RecordType": 18,
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-02T15:42:13Z",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "adminuser@example.onmicrosoft.com",
"UserType": 2,
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-DlpComplianceRule
#Description
A new Data Loss Prevention compliance rule was created.
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationTime": "2026-07-02T15:42:18Z",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "8f1ffe1f-3293-4aa5-9b28-e06d95ba98f4",
"NonPIIParameters": "-ErrorAction \"Stop\" -Name \"<SNIP-PII>\" -Policy \"<SNIP-PII>\" -ContentContainsSensitiveInformation (\"<SNIP-PII>\")",
"ObjectId": "dd98ec7b-3186-4469-b15b-6c3070edd327",
"Operation": "New-DlpComplianceRule",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"Parameters": "-ErrorAction \"Stop\" -Name \"dwdlpr\" -Policy \"dwdlp\" -ContentContainsSensitiveInformation (\"{\"Name\":\"Credit Card Number\"}\")",
"RecordType": 18,
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-02T15:42:18Z",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "adminuser@example.onmicrosoft.com",
"UserType": 2,
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-DlpSensitiveInformationType
#Description
A dlp sensitive information type was created via the New-DlpSensitiveInformationType Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:00:56",
"CreationTime": "2026-07-03T06:00:56",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "5aebdfb7-d2af-4445-b2eb-04f1bc81513d",
"NonPIIParameters": "-Fingerprints $null -Description \"<SNIP-PII>\" -Name \"<SNIP-PII>\"",
"Operation": "New-DlpSensitiveInformationType",
"Operations": "New-DlpSensitiveInformationType",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Fingerprints $null -Description \"harness\" -Name \"dwharnee8749b4-sit\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Error",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:00:56",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-Label
#Description
A label was created via the New-Label Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:56:09",
"CreationTime": "2026-07-03T05:56:09",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "09b02192-2d62-4e1f-9f96-ab55e0583cfb",
"NonPIIParameters": "-Name \"<SNIP-PII>\" -Tooltip \"<SNIP-PII>\" -DisplayName \"<SNIP-PII>\"",
"ObjectId": "e5397acb-0e87-476e-91b3-bf2d0c53fd2b",
"Operation": "New-Label",
"Operations": "New-Label",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Name \"dwharn9babc3-lbl\" -Tooltip \"harness\" -DisplayName \"dwharn9babc3 label\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:56:09",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-LabelPolicy
#Description
A label policy was created via the New-LabelPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:00:18",
"CreationTime": "2026-07-03T06:00:18",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "076c4c35-b32d-4a11-977f-0dbe0a747ec7",
"NonPIIParameters": "-Labels (\"<SNIP-PII>\") -Name \"<SNIP-PII>\"",
"Operation": "New-LabelPolicy",
"Operations": "New-LabelPolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Labels (\"dwharnee8749b4-lbl\") -Name \"dwharnee8749b4-lblp\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Error",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:00:18",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-OrganizationSegment
#Description
An organization segment was created via the New-OrganizationSegment Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:56:28",
"CreationTime": "2026-07-03T05:56:28",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "c39ba8e4-ce0d-4669-b76c-6d0d73933510",
"NonPIIParameters": "-UserGroupFilter \"<SNIP-PII>\" -Name \"<SNIP-PII>\"",
"ObjectId": "a49908bc-8bdf-4cbb-9dbe-4373da5a6f4a",
"Operation": "New-OrganizationSegment",
"Operations": "New-OrganizationSegment",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-UserGroupFilter \"Department -eq 'zzz'\" -Name \"dwharn9babc3-seg\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:56:28",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-RetentionCompliancePolicy
#Description
A retention compliance policy was created via the New-RetentionCompliancePolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:55:53",
"CreationTime": "2026-07-03T05:55:53",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "0fd7412b-cd95-44b5-85a8-89d61cafb007",
"NonPIIParameters": "-ExchangeLocation (\"<SNIP-PII>\") -Name \"<SNIP-PII>\"",
"ObjectId": "98a8c1b6-8cf1-4485-bd92-076f648498fe",
"Operation": "New-RetentionCompliancePolicy",
"Operations": "New-RetentionCompliancePolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-ExchangeLocation (\"All\") -Name \"dwharn9babc3-ret\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:55:53",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-RetentionComplianceRule
#Description
A retention compliance rule was created via the New-RetentionComplianceRule Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:59:53",
"CreationTime": "2026-07-03T05:59:53",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "aa923f6f-1fcb-41d1-8b51-badd5d76ef7d",
"NonPIIParameters": "-RetentionComplianceAction \"<SNIP-PII>\" -Name \"<SNIP-PII>\" -RetentionDuration \"<SNIP-PII>\" -Policy \"<SNIP-PII>\"",
"ObjectId": "a886e044-bb26-4f89-b5e9-8416055fc11c",
"Operation": "New-RetentionComplianceRule",
"Operations": "New-RetentionComplianceRule",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-RetentionComplianceAction \"Keep\" -Name \"dwharnee8749b4-retr\" -RetentionDuration \"365\" -Policy \"dwharnee8749b4-ret\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:59:53",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
New-SupervisoryReviewPolicyV2
#Description
A supervisory review policy v2 was created via the New-SupervisoryReviewPolicyV2 Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:56:37",
"CreationTime": "2026-07-03T05:56:37",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "b83aaaa9-a57e-4974-9c65-6fb9d873e746",
"NonPIIParameters": "-Reviewers (\"<SNIP-PII>\") -Name \"<SNIP-PII>\"",
"Operation": "New-SupervisoryReviewPolicyV2",
"Operations": "New-SupervisoryReviewPolicyV2",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Reviewers (\"adminuser@example.onmicrosoft.com\") -Name \"dwharn9babc3-srp\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Error",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:56:37",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-CaseHoldPolicy
#Description
A case hold policy was deleted via the Remove-CaseHoldPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:00:33",
"CreationTime": "2026-07-03T06:00:33",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "817a2361-e58a-4ca2-b418-407f26d29a89",
"NonPIIParameters": "-Confirm \"False\" -Identity \"<SNIP-PII>\"",
"Operation": "Remove-CaseHoldPolicy",
"Operations": "Remove-CaseHoldPolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Confirm \"False\" -Identity \"dwharnee8749b4-hold\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Error",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:00:33",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-ComplianceCase
#Description
A compliance case was deleted via the Remove-ComplianceCase Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:56:22",
"CreationTime": "2026-07-03T05:56:22",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "3c79ab8c-74f4-4ae3-bb4d-5b259b855aa1",
"NonPIIParameters": "-Confirm \"False\" -Identity \"<SNIP-PII>\"",
"Operation": "Remove-ComplianceCase",
"Operations": "Remove-ComplianceCase",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Confirm \"False\" -Identity \"dwharn9babc3-case\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Error",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:56:22",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-ComplianceSearch
#Description
A compliance search was deleted via the Remove-ComplianceSearch Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:56:25",
"CreationTime": "2026-07-03T05:56:25",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "0db1c16a-222d-43b3-96fd-400eeee5de52",
"NonPIIParameters": "-Confirm \"False\" -Identity \"<SNIP-PII>\"",
"Operation": "Remove-ComplianceSearch",
"Operations": "Remove-ComplianceSearch",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Confirm \"False\" -Identity \"dwharn9babc3-search\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:56:25",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-ComplianceTag
#Description
A compliance tag was deleted via the Remove-ComplianceTag Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:30:24",
"CreationTime": "2026-07-03T05:30:24",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "6c0a362f-4f25-4d6a-99f9-3b5348289fa1",
"NonPIIParameters": "-Identity \"<SNIP-PII>\"",
"ObjectId": "6abe80c5-29ea-4b98-83bc-cdab2fb733c7",
"Operation": "Remove-ComplianceTag",
"Operations": "Remove-ComplianceTag",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Identity \"6abe80c5-29ea-4b98-83bc-cdab2fb733c7\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:30:24",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "adminuser@example.onmicrosoft.com",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-DlpCompliancePolicy
#Description
A Data Loss Prevention compliance policy was deleted.
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationTime": "2026-07-02T15:42:25Z",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "8d0623df-b0d3-4d64-8dd1-40b35df01aab",
"NonPIIParameters": "-ErrorAction \"Stop\" -Identity \"<SNIP-PII>\" -Confirm \"False\" -Name \"<SNIP-PII>\" -DisplayName \"<SNIP-PII>\"",
"ObjectId": "23bac226-705b-4207-9f57-c90aca5e137e",
"Operation": "Remove-DlpCompliancePolicy",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"Parameters": "-ErrorAction \"Stop\" -Identity \"dwdlp\" -Confirm \"False\" -Name \"dwdlp\" -DisplayName \"dwdlp\"",
"RecordType": 18,
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-02T15:42:25Z",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "adminuser@example.onmicrosoft.com",
"UserType": 2,
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-DlpSensitiveInformationType
#Description
A dlp sensitive information type was deleted via the Remove-DlpSensitiveInformationType Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:56:46",
"CreationTime": "2026-07-03T05:56:46",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "f23c1f89-20a1-4688-a707-a7d6b9109b14",
"NonPIIParameters": "-Confirm \"False\" -Identity \"<SNIP-PII>\"",
"Operation": "Remove-DlpSensitiveInformationType",
"Operations": "Remove-DlpSensitiveInformationType",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Confirm \"False\" -Identity \"dwharn9babc3-sit\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Error",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:56:46",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-Label
#Description
A label was deleted via the Remove-Label Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:56:14",
"CreationTime": "2026-07-03T05:56:14",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "31de5873-5e2b-4dd3-af48-58db4d158057",
"NonPIIParameters": "-Confirm \"False\" -Identity \"<SNIP-PII>\"",
"ObjectId": "e5397acb-0e87-476e-91b3-bf2d0c53fd2b",
"Operation": "Remove-Label",
"Operations": "Remove-Label",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Confirm \"False\" -Identity \"dwharn9babc3-lbl\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:56:14",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-LabelPolicy
#Description
A label policy was deleted via the Remove-LabelPolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:00:22",
"CreationTime": "2026-07-03T06:00:22",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "14e55468-f089-45b2-98ca-5e2ea18e3437",
"NonPIIParameters": "-Confirm \"False\" -Identity \"<SNIP-PII>\"",
"Operation": "Remove-LabelPolicy",
"Operations": "Remove-LabelPolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Confirm \"False\" -Identity \"dwharnee8749b4-lblp\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Error",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:00:22",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-OrganizationSegment
#Description
An organization segment was deleted via the Remove-OrganizationSegment Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:00:48",
"CreationTime": "2026-07-03T06:00:48",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "a2d4af10-c1a6-4210-8cb5-e094a112db43",
"NonPIIParameters": "-Confirm \"False\" -Identity \"<SNIP-PII>\"",
"ObjectId": "ed31a621-e78c-4ec4-901c-aad21709723c",
"Operation": "Remove-OrganizationSegment",
"Operations": "Remove-OrganizationSegment",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Confirm \"False\" -Identity \"dwharnee8749b4-seg\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:00:48",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-RetentionCompliancePolicy
#Description
A retention compliance policy was deleted via the Remove-RetentionCompliancePolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T06:02:34",
"CreationTime": "2026-07-03T06:02:34",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "d8d4c49b-cacc-4d46-997a-60fbeec89c5f",
"NonPIIParameters": "-ErrorAction \"Stop\" -Identity \"<SNIP-PII>\" -Confirm \"False\"",
"ObjectId": "bc8eb520-d184-435d-973c-04cff5dadd2e",
"Operation": "Remove-RetentionCompliancePolicy",
"Operations": "Remove-RetentionCompliancePolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-ErrorAction \"Stop\" -Identity \"dwharnee8749b4-ret\" -Confirm \"False\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T06:02:34",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Remove-SupervisoryReviewPolicyV2
#Description
A supervisory review policy v2 was deleted via the Remove-SupervisoryReviewPolicyV2 Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:56:38",
"CreationTime": "2026-07-03T05:56:38",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "6fa5bca6-ccf1-486e-b4f5-8d4d82237a1d",
"NonPIIParameters": "-Confirm \"False\" -Identity \"<SNIP-PII>\"",
"Operation": "Remove-SupervisoryReviewPolicyV2",
"Operations": "Remove-SupervisoryReviewPolicyV2",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Confirm \"False\" -Identity \"dwharn9babc3-srp\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Error",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:56:38",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Set-ComplianceSearch
#Description
An existing content search was modified.
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationTime": "2020-12-15T19:42:00",
"EffectiveOrganization": "rodsoto.onmicrosoft.com",
"Id": "b55350ff-4093-42f8-9f45-8489df0589c8",
"NonPIIParameters": "-Name \"<SNIP-PII>\" -Description \"<SNIP-PII>\" -HoldNames () -AllowNotFoundExchangeLocationsEnabled \"<SNIP-PII>\" -PublicFolderLocation () -SharePointLocation (\"<SNIP-PII>\") -ExchangeLocationExclusion () -SharePointLocationExclusion () -Force \"True\" -Language \"<SNIP-PII>\" -Identity \"<SNIP-PII>\" -ExchangeLocation (\"<SNIP-PII>\") -ContentMatchQuery \"<SNIP-PII>\"",
"Operation": "Set-ComplianceSearch",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"Parameters": "-Name \"TestSearch\" -Description \"\" -HoldNames () -AllowNotFoundExchangeLocationsEnabled \"True\" -PublicFolderLocation () -SharePointLocation (\"All\") -ExchangeLocationExclusion () -SharePointLocationExclusion () -Force \"True\" -Language \"\" -Identity \"YzUxMWZjMmYtNzdlNC00OTA3LTllMzgtMDhkOGExMmY0ZTAz0\" -ExchangeLocation (\"rodsoto@rodsoto.onmicrosoft.com\") -ContentMatchQuery \"(c:c)(date=2020-11-01..2020-12-15)(senderauthor=rodsoto@rodsoto.onmicrosoft.com)(size>1)(subjecttitle=test)(kind=email)(partici",
"RecordType": 18,
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2020-12-15T19:42:00",
"UserId": "rodsoto@rodsoto.onmicrosoft.com",
"UserKey": "rodsoto@rodsoto.onmicrosoft.com",
"UserType": 2,
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Set-ComplianceTag
#Description
A compliance tag was modified via the Set-ComplianceTag Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:30:05",
"CreationTime": "2026-07-03T05:30:05",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "1be7d8db-a79d-4fc3-95ea-dae019bfd32a",
"NonPIIParameters": "-Identity \"<SNIP-PII>\" -Comment \"<SNIP-PII>\"",
"ObjectId": "6abe80c5-29ea-4b98-83bc-cdab2fb733c7",
"Operation": "Set-ComplianceTag",
"Operations": "Set-ComplianceTag",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Identity \"6abe80c5-29ea-4b98-83bc-cdab2fb733c7\" -Comment \"updated\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:30:05",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "adminuser@example.onmicrosoft.com",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Set-DlpCompliancePolicy
#Description
A dlp compliance policy was modified via the Set-DlpCompliancePolicy Security & Compliance Center cmdlet (observed in first-party Unified Audit Log capture).
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationDate": "2026-07-03T05:59:43",
"CreationTime": "2026-07-03T05:59:43",
"EffectiveOrganization": "example.onmicrosoft.com",
"Id": "27cf59df-0dcb-45a3-a9a8-e279631c112f",
"NonPIIParameters": "-Comment \"<SNIP-PII>\" -Identity \"<SNIP-PII>\" -Name \"<SNIP-PII>\" -DisplayName \"<SNIP-PII>\"",
"ObjectId": "f2535860-acc2-4740-9823-c75d1929a14f",
"Operation": "Set-DlpCompliancePolicy",
"Operations": "Set-DlpCompliancePolicy",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"Parameters": "-Comment \"harness\" -Identity \"dwharnee8749b4-dlp\" -Name \"dwharnee8749b4-dlp\" -DisplayName \"dwharnee8749b4-dlp\"",
"RecordType": "SecurityComplianceCenterEOPCmdlet",
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2026-07-03T05:59:43",
"UserId": "AppId\\22222222-2222-2222-2222-222222222222",
"UserKey": "AppId\\22222222-2222-2222-2222-222222222222",
"UserType": "Admin",
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Set-RoleGroup
#Description
A Security and Compliance Center RBAC role group was modified.
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationTime": "2020-12-15T19:14:02",
"EffectiveOrganization": "rodsoto.onmicrosoft.com",
"Id": "98a1f5c5-0e95-4b14-9be3-5d487ffe834f",
"NonPIIParameters": "-Identity \"<SNIP-PII>\" -DisplayName \"<SNIP-PII>\"",
"ObjectId": "84d7d9bc-f1b4-aeba-6fc8-bc86ef251075",
"Operation": "Set-RoleGroup",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"Parameters": "-Identity \"ODRkN2Q5YmMtZjFiNC1hZWJhLTZmYzgtYmM4NmVmMjUxMDc10\" -DisplayName \"eDiscovery Manager\"",
"RecordType": 18,
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2020-12-15T19:14:02",
"UserId": "rodsoto@rodsoto.onmicrosoft.com",
"UserKey": "rodsoto@rodsoto.onmicrosoft.com",
"UserType": 2,
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Start-ComplianceSearch
#Description
A content search was started (executed).
Example Audit Record #
{
"CreationTime": "2024-04-01T16:11:27",
"Id": "8d1d5975-0a63-4303-adba-8a36d2023fcd",
"Operation": "Start-ComplianceSearch",
"OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 18,
"ResultStatus": "Success",
"UserKey": "attacker@splunkresearch.com",
"UserType": 2,
"Version": 1,
"Workload": "SecurityComplianceCenter",
"UserId": "attacker@splunkresearch.com",
"SecurityComplianceCenterEventType": 0,
"ClientApplication": "EMC",
"CmdletVersion": "...",
"EffectiveOrganization": "splunkresearch.com",
"NonPIIParameters": "-Identity \"<SNIP-PII>\"",
"Parameters": "-Identity \"YnJvd3NlciBzZWFyY2g1\"",
"StartTime": "2024-04-01T16:11:27"
}
References #
Update-eDiscoveryCaseAdmin
#Description
The organization-wide list of eDiscovery administrators was changed.
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationTime": "2020-12-15T19:11:39",
"EffectiveOrganization": "rodsoto.onmicrosoft.com",
"Id": "146622ba-f20f-442e-a0ca-4f1f0356811e",
"NonPIIParameters": "-Users (\"<SNIP-PII>\",\"<SNIP-PII>\",\"<SNIP-PII>\",\"<SNIP-PII>\")",
"Operation": "Update-eDiscoveryCaseAdmin",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"Parameters": "-Users (\"746a9075-97ca-497f-8799-29e4a768e624\",\"bfb8c366-0406-41a5-b3e3-328f4a3b4484\",\"c0282018-2447-42b4-88a5-fe4ddf5f4c9f\",\"425b75db-38be-4c7b-a474-5f0709247370\")",
"RecordType": 18,
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2020-12-15T19:11:39",
"UserId": "rodsoto@rodsoto.onmicrosoft.com",
"UserKey": "rodsoto@rodsoto.onmicrosoft.com",
"UserType": 2,
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
Update-RoleGroupMember
#Description
Membership of a Security and Compliance Center RBAC role group was changed.
Example Audit Record #
{
"ClientApplication": "EMC",
"CmdletVersion": "...",
"CreationTime": "2020-12-15T19:11:38",
"EffectiveOrganization": "rodsoto.onmicrosoft.com",
"Id": "b83557e4-2427-4ff3-8e79-c951a5c71125",
"NonPIIParameters": "-Identity \"<SNIP-PII>\" -Members (\"<SNIP-PII>\",\"<SNIP-PII>\",\"<SNIP-PII>\",\"<SNIP-PII>\")",
"ObjectId": "84d7d9bc-f1b4-aeba-6fc8-bc86ef251075",
"Operation": "Update-RoleGroupMember",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"Parameters": "-Identity \"ODRkN2Q5YmMtZjFiNC1hZWJhLTZmYzgtYmM4NmVmMjUxMDc10\" -Members (\"746a9075-97ca-497f-8799-29e4a768e624\",\"bfb8c366-0406-41a5-b3e3-328f4a3b4484\",\"425b75db-38be-4c7b-a474-5f0709247370\",\"c0282018-2447-42b4-88a5-fe4ddf5f4c9f\")",
"RecordType": 18,
"ResultStatus": "Success",
"SecurityComplianceCenterEventType": 0,
"StartTime": "2020-12-15T19:11:38",
"UserId": "rodsoto@rodsoto.onmicrosoft.com",
"UserKey": "rodsoto@rodsoto.onmicrosoft.com",
"UserType": 2,
"Version": 1,
"Workload": "SecurityComplianceCenter"
}
References #
M365 audit records use different field names on each surface #
The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.
- Purview CSV export flattens each record to four columns (
CreationDate,UserIds,Operations,AuditData). The API field names live only inside theAuditDataJSON blob. Expand it withConvertFrom-Json. The wrapper columns are renamed too:CreationDatenotCreationTime,UserIdsnotUserId,OperationsnotOperation. - Sentinel's
OfficeActivitytable renames several fields and turns two integer enum columns into strings. The table below maps them.
| API JSON (event pages) | OfficeActivity column | Note |
|---|---|---|
Id | OfficeId | Renamed. |
Workload | OfficeWorkload | Renamed. |
ObjectId | OfficeObjectId | Renamed. |
CreationTime | TimeGenerated | Renamed. OfficeActivity has no CreationTime column. |
SiteUrl | Site_Url | Renamed (SharePoint family). |
RecordType | RecordType | Same name; the Int32 enum becomes its string enum name. |
UserType | UserType | Same name; the Int32 enum becomes a string. |
ClientIP | ClientIP, Client_IPAddress | Both columns present on OfficeActivity. |
Scope | (none) | No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob. |
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationId | same names | Unchanged. No _s / _d suffixes (a native table, not a custom log). |
Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.