SharePoint site and admin activity

OperationDescriptionSampleRule
anyCatch-all for M365-SharePoint rules matching the RecordType but no specific Operation.NN
BaselineSecurityModeThirdPartyAppHPABaseline Security Mode Third Party App HPA activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).YN
GroupAddedGroup Added activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).YN
PermissionLevelAddedPermission Level Added activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).YN
SharingPolicyChangedA SharePoint or OneDrive sharing policy was changed at the tenant or site-collection level.YY
SiteCollectionCreatedSite Collection Created activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).YN
SiteIBModeSetSite IB Mode Set activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).YN
SiteLocksChangedSite Locks Changed activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).YN

any: SharePoint site and admin activity (catch-all)

#
RecordType
SharePoint

Description

Catch-all for M365-SharePoint rules matching the RecordType but no specific Operation.

References #

BaselineSecurityModeThirdPartyAppHPA

#
RecordType
SharePoint

Description

Baseline Security Mode Third Party App HPA activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppId": "22222222-2222-2222-2222-222222222222",
    "ClientAppName": "dw-activity-gen",
    "CorrelationId": "a7e3f8ed-d1b6-479b-819b-bdc46d8252c0",
    "PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
    "TokenIssuedAtTime": "2026-07-02T02:09:44Z",
    "UniqueTokenId": "fok73fVNMECa2s8q2X5cAA",
    "UserObjectId": "11111111-1111-1111-1111-111111111111"
  },
  "ApplicationDisplayName": "dw-activity-gen",
  "ApplicationId": "22222222-2222-2222-2222-222222222222",
  "AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
  "AuthenticationType": "OAuth",
  "ClientIP": "203.0.113.10",
  "CorrelationId": "a7e3f8ed-d1b6-479b-819b-bdc46d8252c0",
  "CreationTime": "2026-07-02T02:09:55Z",
  "DeviceDisplayName": "203.0.113.10",
  "EventData": "<App ID>22222222-2222-2222-2222-222222222222</App ID><Site Accessed>https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com/_api/v2.0/drive/root:/dw-harness-60974bd7-test.txt:/content</Site Accessed><App Name>dw-activity-gen</App Name><App Permissions>myfiles.write group.write allsites.write allprofiles.read</App Permissions><UPN>adminuser@example.onmicrosoft.com</UPN>",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "Id": "2ed4f606-bcd1-4d18-50be-08ded7df0290",
  "IsManagedDevice": false,
  "ItemType": "Site",
  "Operation": "BaselineSecurityModeThirdPartyAppHPA",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "Platform": "NotSpecified",
  "RecordType": 4,
  "UserAgent": "python-requests/2.34.2",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "SharePoint"
}

References #

GroupAdded

#
RecordType
SharePoint

Description

Group Added activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppName": "dw-activity-gen",
    "CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
    "PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
    "TokenIssuedAtTime": "2026-07-02T17:37:48Z",
    "UniqueTokenId": "yzlSUbnhBUqYEcBwgx5ZAA",
    "UserObjectId": "11111111-1111-1111-1111-111111111111"
  },
  "ApplicationDisplayName": "dw-activity-gen",
  "AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
  "AuthenticationType": "OAuth",
  "ClientIP": "203.0.113.10",
  "CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
  "CreationTime": "2026-07-02T17:39:22Z",
  "DeviceDisplayName": "203.0.113.10",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "Id": "e120798d-23ae-4451-873e-08ded860da56",
  "IsManagedDevice": false,
  "ItemType": "Site",
  "ModifiedProperties": [
    {
      "Name": "Name",
      "NewValue": "Limited Access System Group For Web daa58cd7-9a4c-49aa-80a8-891bb23ee9a4"
    }
  ],
  "ObjectId": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com",
  "Operation": "GroupAdded",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "Platform": "NotSpecified",
  "RecordType": 4,
  "Site": "8b6f4363-9829-4b0a-857a-bced36c2bb38",
  "UserAgent": "python-requests/2.34.2",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "OneDrive"
}

References #

PermissionLevelAdded

#
RecordType
SharePoint

Description

Permission Level Added activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppName": "dw-activity-gen",
    "CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
    "PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
    "TokenIssuedAtTime": "2026-07-02T17:37:48Z",
    "UniqueTokenId": "yzlSUbnhBUqYEcBwgx5ZAA",
    "UserObjectId": "11111111-1111-1111-1111-111111111111"
  },
  "ApplicationDisplayName": "dw-activity-gen",
  "AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
  "AuthenticationType": "OAuth",
  "ClientIP": "203.0.113.10",
  "CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
  "CreationTime": "2026-07-02T17:39:22Z",
  "DeviceDisplayName": "203.0.113.10",
  "EventData": "<PermissionLevel>System.LimitedView</PermissionLevel><BasePermissions>ViewListItems, OpenItems, ViewFormPages, Open, ViewPages, BrowseUserInfo, UseClientIntegration, UseRemoteAPIs</BasePermissions>",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "Id": "5ff0d84c-651e-4c06-1262-08ded860da38",
  "IsManagedDevice": false,
  "ItemType": "Web",
  "ObjectId": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com",
  "Operation": "PermissionLevelAdded",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "Platform": "NotSpecified",
  "RecordType": 4,
  "Site": "8b6f4363-9829-4b0a-857a-bced36c2bb38",
  "UserAgent": "python-requests/2.34.2",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
  "UserType": 0,
  "Version": 1,
  "WebId": "daa58cd7-9a4c-49aa-80a8-891bb23ee9a4",
  "Workload": "OneDrive"
}

References #

SharingPolicyChanged

#
RecordType
SharePoint

Description

A SharePoint or OneDrive sharing policy was changed at the tenant or site-collection level.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "db6903cb-7633-4574-a602-9d0b211312b2",
    "ClientAppName": "Unknown",
    "CorrelationId": "ae3617a1-d097-0000-04fe-d03fd79ad5b6",
    "UniqueTokenId": "cWix_Ic8r0ytOcjRtLy5AA"
  },
  "ApplicationDisplayName": "Unknown",
  "AuthenticationType": "FormsCookieAuth",
  "BrowserName": "Edge",
  "BrowserVersion": "122.0.0.0",
  "ClientIP": "189.135.168.197",
  "CorrelationId": "ae3617a1-d097-0000-04fe-d03fd79ad5b6",
  "CreationTime": "2024-03-21T13:41:05",
  "DeviceDisplayName": "189.135.168.197",
  "EventData": "<AuditSequenceId>5d3fc8f6-c10c-467b-901b-091788dd7bfd_0</AuditSequenceId>",
  "EventSource": "SharePoint",
  "Id": "82e317a0-22ad-4d37-dd27-08dc49ac8e8e",
  "IsManagedDevice": false,
  "ItemType": "Tenant",
  "ModifiedProperties": [
    {
      "Name": "AllowDomainList",
      "NewValue": "attack_range.lan,attack_range.com,attack_range_old....",
      "OldValue": "attack_range.lan,attack_range.com,attack_range_old...."
    }
  ],
  "Operation": "SharingPolicyChanged",
  "OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "Platform": "WinDesktop",
  "RecordType": 4,
  "UserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0",
  "UserId": "attacker@attack_range.lan",
  "UserKey": "i:0h.f|membership|1003200353e086c7@live.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "SharePoint"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Name (elastic rule field)inonedrive1 ruleelastic
Provider_Name (elastic rule field)insharepoint1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 SharePoint Site Sharing Policy Weakened source medium: Identifies when a SharePoint or OneDrive site sharing policy is changed to weaken security controls. The SharingPolicyChanged event fires for many routine policy modifications, but this rule targets specific high-risk transitions where sharing restrictions are relaxed. This includes enabling guest sharing, enabling anonymous link sharing, making a site public, or enabling guest user access. Adversaries who compromise administrative accounts may weaken sharing policies to exfiltrate data to external accounts or create persistent external access paths.T1484, T1562, T1562.001

Splunk #

References #

SiteCollectionCreated

#
RecordType
SharePoint

Description

Site Collection Created activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "CorrelationId": "fe90cb0f-ae9a-467e-9a8c-69ad41ef6c8f"
  },
  "ApplicationDisplayName": "Microsoft Graph",
  "ApplicationId": "00000003-0000-0000-c000-000000000000",
  "CorrelationId": "fe90cb0f-ae9a-467e-9a8c-69ad41ef6c8f",
  "CreationTime": "2026-07-02T02:10:32Z",
  "EventData": "<SiteCreationSource>MSGraph</SiteCreationSource><TenantSettings.ShowCreateSiteCommand>True</TenantSettings.ShowCreateSiteCommand><TenantSettings.UseCustomSiteCreationForm>False</TenantSettings.UseCustomSiteCreationForm>",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "Id": "85aafd47-15e6-4a44-ece3-08ded7df1895",
  "ItemType": "Site",
  "ObjectId": "https://example.sharepoint.com/sites/dw-harness-planner-60974bd7",
  "Operation": "SiteCollectionCreated",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 4,
  "Site": "33da9946-db86-406e-899b-5aafbb32be5e",
  "UserId": "app@sharepoint",
  "UserKey": "i:0i.t|00000003-0000-0ff1-ce00-000000000000|app@sharepoint",
  "UserType": 0,
  "Version": 1,
  "Workload": "SharePoint"
}

References #

SiteIBModeSet

#
RecordType
SharePoint

Description

Site IB Mode Set activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "CorrelationId": "55e56196-d60e-4e74-9b1f-8c10770a35e0"
  },
  "CorrelationId": "55e56196-d60e-4e74-9b1f-8c10770a35e0",
  "CreationTime": "2026-07-02T02:10:11Z",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "Id": "11b6d96e-c23b-4b03-2ec0-08ded7df0c15",
  "ItemType": "Site",
  "ModifiedProperties": [
    {
      "Name": "SiteIBMode",
      "NewValue": "Implicit"
    }
  ],
  "ObjectId": "https://example.sharepoint.com/sites/dw-harness-60974bd7",
  "Operation": "SiteIBModeSet",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 4,
  "Site": "11905796-6c39-4276-88b3-32acc73c3105",
  "UserId": "Microsoft\\ServiceAccount",
  "UserKey": "S-1-0-0",
  "UserType": 0,
  "Version": 1,
  "Workload": "SharePoint"
}

References #

SiteLocksChanged

#
RecordType
SharePoint

Description

Site Locks Changed activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "CorrelationId": "fe90cb0f-ae9a-467e-9a8c-69ad41ef6c8f"
  },
  "CorrelationId": "fe90cb0f-ae9a-467e-9a8c-69ad41ef6c8f",
  "CreationTime": "2026-07-02T02:10:31Z",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "Id": "4987405e-6d31-4d35-62b2-08ded7df17f2",
  "ItemType": "Site",
  "ModifiedProperties": [
    {
      "Name": "SiteAccess",
      "NewValue": "False",
      "OldValue": "True"
    }
  ],
  "ObjectId": "https://example.sharepoint.com/sites/dw-harness-planner-60974bd7",
  "Operation": "SiteLocksChanged",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 4,
  "Site": "33da9946-db86-406e-899b-5aafbb32be5e",
  "UserId": "Microsoft\\ServiceAccount",
  "UserKey": "S-1-0-0",
  "UserType": 0,
  "Version": 1,
  "Workload": "SharePoint"
}

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.