SharePoint site and admin activity
| Operation | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for M365-SharePoint rules matching the RecordType but no specific Operation. | N | N |
| Baseline | Baseline Security Mode Third Party App HPA activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Group | Group Added activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Permission | Permission Level Added activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Sharing | A SharePoint or OneDrive sharing policy was changed at the tenant or site-collection level. | Y | Y |
| Site | Site Collection Created activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Site | Site IB Mode Set activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Site | Site Locks Changed activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
any: SharePoint site and admin activity (catch-all)
#Description
Catch-all for M365-SharePoint rules matching the RecordType but no specific Operation.
References #
BaselineSecurityModeThirdPartyAppHPA
#Description
Baseline Security Mode Third Party App HPA activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"AppAccessContext": {
"AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"APIId": "00000003-0000-0000-c000-000000000000",
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"ClientAppName": "dw-activity-gen",
"CorrelationId": "a7e3f8ed-d1b6-479b-819b-bdc46d8252c0",
"PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
"TokenIssuedAtTime": "2026-07-02T02:09:44Z",
"UniqueTokenId": "fok73fVNMECa2s8q2X5cAA",
"UserObjectId": "11111111-1111-1111-1111-111111111111"
},
"ApplicationDisplayName": "dw-activity-gen",
"ApplicationId": "22222222-2222-2222-2222-222222222222",
"AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
"AuthenticationType": "OAuth",
"ClientIP": "203.0.113.10",
"CorrelationId": "a7e3f8ed-d1b6-479b-819b-bdc46d8252c0",
"CreationTime": "2026-07-02T02:09:55Z",
"DeviceDisplayName": "203.0.113.10",
"EventData": "<App ID>22222222-2222-2222-2222-222222222222</App ID><Site Accessed>https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com/_api/v2.0/drive/root:/dw-harness-60974bd7-test.txt:/content</Site Accessed><App Name>dw-activity-gen</App Name><App Permissions>myfiles.write group.write allsites.write allprofiles.read</App Permissions><UPN>adminuser@example.onmicrosoft.com</UPN>",
"EventSource": "SharePoint",
"GeoLocation": "NAM",
"Id": "2ed4f606-bcd1-4d18-50be-08ded7df0290",
"IsManagedDevice": false,
"ItemType": "Site",
"Operation": "BaselineSecurityModeThirdPartyAppHPA",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"Platform": "NotSpecified",
"RecordType": 4,
"UserAgent": "python-requests/2.34.2",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
"UserType": 0,
"Version": 1,
"Workload": "SharePoint"
}
References #
GroupAdded
#Description
Group Added activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"AppAccessContext": {
"AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"APIId": "00000003-0000-0000-c000-000000000000",
"ClientAppName": "dw-activity-gen",
"CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
"PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
"TokenIssuedAtTime": "2026-07-02T17:37:48Z",
"UniqueTokenId": "yzlSUbnhBUqYEcBwgx5ZAA",
"UserObjectId": "11111111-1111-1111-1111-111111111111"
},
"ApplicationDisplayName": "dw-activity-gen",
"AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
"AuthenticationType": "OAuth",
"ClientIP": "203.0.113.10",
"CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
"CreationTime": "2026-07-02T17:39:22Z",
"DeviceDisplayName": "203.0.113.10",
"EventSource": "SharePoint",
"GeoLocation": "NAM",
"Id": "e120798d-23ae-4451-873e-08ded860da56",
"IsManagedDevice": false,
"ItemType": "Site",
"ModifiedProperties": [
{
"Name": "Name",
"NewValue": "Limited Access System Group For Web daa58cd7-9a4c-49aa-80a8-891bb23ee9a4"
}
],
"ObjectId": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com",
"Operation": "GroupAdded",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"Platform": "NotSpecified",
"RecordType": 4,
"Site": "8b6f4363-9829-4b0a-857a-bced36c2bb38",
"UserAgent": "python-requests/2.34.2",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
"UserType": 0,
"Version": 1,
"Workload": "OneDrive"
}
References #
PermissionLevelAdded
#Description
Permission Level Added activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"AppAccessContext": {
"AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"APIId": "00000003-0000-0000-c000-000000000000",
"ClientAppName": "dw-activity-gen",
"CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
"PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
"TokenIssuedAtTime": "2026-07-02T17:37:48Z",
"UniqueTokenId": "yzlSUbnhBUqYEcBwgx5ZAA",
"UserObjectId": "11111111-1111-1111-1111-111111111111"
},
"ApplicationDisplayName": "dw-activity-gen",
"AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
"AuthenticationType": "OAuth",
"ClientIP": "203.0.113.10",
"CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
"CreationTime": "2026-07-02T17:39:22Z",
"DeviceDisplayName": "203.0.113.10",
"EventData": "<PermissionLevel>System.LimitedView</PermissionLevel><BasePermissions>ViewListItems, OpenItems, ViewFormPages, Open, ViewPages, BrowseUserInfo, UseClientIntegration, UseRemoteAPIs</BasePermissions>",
"EventSource": "SharePoint",
"GeoLocation": "NAM",
"Id": "5ff0d84c-651e-4c06-1262-08ded860da38",
"IsManagedDevice": false,
"ItemType": "Web",
"ObjectId": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com",
"Operation": "PermissionLevelAdded",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"Platform": "NotSpecified",
"RecordType": 4,
"Site": "8b6f4363-9829-4b0a-857a-bced36c2bb38",
"UserAgent": "python-requests/2.34.2",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
"UserType": 0,
"Version": 1,
"WebId": "daa58cd7-9a4c-49aa-80a8-891bb23ee9a4",
"Workload": "OneDrive"
}
References #
SiteCollectionCreated
#Description
Site Collection Created activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"AppAccessContext": {
"CorrelationId": "fe90cb0f-ae9a-467e-9a8c-69ad41ef6c8f"
},
"ApplicationDisplayName": "Microsoft Graph",
"ApplicationId": "00000003-0000-0000-c000-000000000000",
"CorrelationId": "fe90cb0f-ae9a-467e-9a8c-69ad41ef6c8f",
"CreationTime": "2026-07-02T02:10:32Z",
"EventData": "<SiteCreationSource>MSGraph</SiteCreationSource><TenantSettings.ShowCreateSiteCommand>True</TenantSettings.ShowCreateSiteCommand><TenantSettings.UseCustomSiteCreationForm>False</TenantSettings.UseCustomSiteCreationForm>",
"EventSource": "SharePoint",
"GeoLocation": "NAM",
"Id": "85aafd47-15e6-4a44-ece3-08ded7df1895",
"ItemType": "Site",
"ObjectId": "https://example.sharepoint.com/sites/dw-harness-planner-60974bd7",
"Operation": "SiteCollectionCreated",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 4,
"Site": "33da9946-db86-406e-899b-5aafbb32be5e",
"UserId": "app@sharepoint",
"UserKey": "i:0i.t|00000003-0000-0ff1-ce00-000000000000|app@sharepoint",
"UserType": 0,
"Version": 1,
"Workload": "SharePoint"
}
References #
SiteIBModeSet
#Description
Site IB Mode Set activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"AppAccessContext": {
"CorrelationId": "55e56196-d60e-4e74-9b1f-8c10770a35e0"
},
"CorrelationId": "55e56196-d60e-4e74-9b1f-8c10770a35e0",
"CreationTime": "2026-07-02T02:10:11Z",
"EventSource": "SharePoint",
"GeoLocation": "NAM",
"Id": "11b6d96e-c23b-4b03-2ec0-08ded7df0c15",
"ItemType": "Site",
"ModifiedProperties": [
{
"Name": "SiteIBMode",
"NewValue": "Implicit"
}
],
"ObjectId": "https://example.sharepoint.com/sites/dw-harness-60974bd7",
"Operation": "SiteIBModeSet",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 4,
"Site": "11905796-6c39-4276-88b3-32acc73c3105",
"UserId": "Microsoft\\ServiceAccount",
"UserKey": "S-1-0-0",
"UserType": 0,
"Version": 1,
"Workload": "SharePoint"
}
References #
SiteLocksChanged
#Description
Site Locks Changed activity in SharePoint Online, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"AppAccessContext": {
"CorrelationId": "fe90cb0f-ae9a-467e-9a8c-69ad41ef6c8f"
},
"CorrelationId": "fe90cb0f-ae9a-467e-9a8c-69ad41ef6c8f",
"CreationTime": "2026-07-02T02:10:31Z",
"EventSource": "SharePoint",
"GeoLocation": "NAM",
"Id": "4987405e-6d31-4d35-62b2-08ded7df17f2",
"ItemType": "Site",
"ModifiedProperties": [
{
"Name": "SiteAccess",
"NewValue": "False",
"OldValue": "True"
}
],
"ObjectId": "https://example.sharepoint.com/sites/dw-harness-planner-60974bd7",
"Operation": "SiteLocksChanged",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 4,
"Site": "33da9946-db86-406e-899b-5aafbb32be5e",
"UserId": "Microsoft\\ServiceAccount",
"UserKey": "S-1-0-0",
"UserType": 0,
"Version": 1,
"Workload": "SharePoint"
}
References #
M365 audit records use different field names on each surface #
The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.
- Purview CSV export flattens each record to four columns (
CreationDate,UserIds,Operations,AuditData). The API field names live only inside theAuditDataJSON blob. Expand it withConvertFrom-Json. The wrapper columns are renamed too:CreationDatenotCreationTime,UserIdsnotUserId,OperationsnotOperation. - Sentinel's
OfficeActivitytable renames several fields and turns two integer enum columns into strings. The table below maps them.
| API JSON (event pages) | OfficeActivity column | Note |
|---|---|---|
Id | OfficeId | Renamed. |
Workload | OfficeWorkload | Renamed. |
ObjectId | OfficeObjectId | Renamed. |
CreationTime | TimeGenerated | Renamed. OfficeActivity has no CreationTime column. |
SiteUrl | Site_Url | Renamed (SharePoint family). |
RecordType | RecordType | Same name; the Int32 enum becomes its string enum name. |
UserType | UserType | Same name; the Int32 enum becomes a string. |
ClientIP | ClientIP, Client_IPAddress | Both columns present on OfficeActivity. |
Scope | (none) | No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob. |
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationId | same names | Unchanged. No _s / _d suffixes (a native table, not a custom log). |
Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.