SharePoint and OneDrive sharing operations

OperationDescriptionSampleRule
anyCatch-all for M365-SharePointSharingOperation rules matching the RecordType but no specific Operation.NN
AddedToGroupA user was added to a SharePoint or OneDrive permission group, granting the group's access level.YN
AnonymousLinkCreatedAn anonymous (anyone-with-the-link) sharing link was created for a file or folder, exposing it without authentication.YY
AnonymousLinkUpdatedAn existing anonymous sharing link was modified (e.g. permission level changed).NY
AnonymousLinkUsedAn anonymous sharing link was used to access a file or folder, indicating external/unauthenticated access.NY
CompanyLinkCreatedCompany Link Created activity in SharePoint / OneDrive sharing, recorded in the Unified Audit Log (observed in first-party capture).YN
RemovedFromGroupA user was removed from a SharePoint or OneDrive permission group.YN
SecureLinkCreatedA 'specific people' sharing link was created for a SharePoint or OneDrive resource, granting access to a specific person or group who may be external to the organization. The target user is identified in the paired AddedToSecureLink event.YN
SharingInheritanceBrokenSharing Inheritance Broken activity in SharePoint / OneDrive sharing, recorded in the Unified Audit Log (observed in first-party capture).YN
SharingLinkCreatedSharing Link Created activity in SharePoint / OneDrive sharing, recorded in the Unified Audit Log (observed in first-party capture).YN
SharingRevokedA sharing grant on a SharePoint or OneDrive resource was revoked.YN
SharingSetSharing permissions were set on a SharePoint or OneDrive resource (a user or group was granted access).YN
SiteCollectionAdminAddedA user was added as a SharePoint site collection administrator, gaining full control of the site collection.YY
SiteCollectionAdminRemovedA user was removed as a SharePoint site collection administrator.YN

any: SharePoint and OneDrive sharing operations (catch-all)

#
RecordType
SharePointSharingOperation

Description

Catch-all for M365-SharePointSharingOperation rules matching the RecordType but no specific Operation.

References #

AddedToGroup

#
RecordType
SharePointSharingOperation

Description

A user was added to a SharePoint or OneDrive permission group, granting the group's access level.

Example Audit Record #

{
  "ClientIP": "43.242.120.166",
  "CorrelationId": "44c1979f-00d2-b000-53ba-4b95683cfb1f",
  "CreationTime": "2020-12-16T04:55:53",
  "EventData": "<Group>Site Owners</Group>",
  "EventSource": "SharePoint",
  "Id": "5c5db0d9-6d04-4b10-cd04-08d8a17ede09",
  "ItemType": "Web",
  "ObjectId": "https://a830edad9050849nda3079.sharepoint.com/sites/automation_test_new",
  "Operation": "AddedToGroup",
  "OrganizationId": "2ed28a74-1f6f-4829-8530-fe359c77d35c",
  "RecordType": 14,
  "Site": "e3744300-d4b6-4d18-8f41-6fc9a5466e6e",
  "SiteUrl": "https://a830edad9050849nda3079.sharepoint.com/sites/automation_test_new",
  "TargetUserOrGroupName": "SHAREPOINT\\system",
  "TargetUserOrGroupType": "Member",
  "UserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36",
  "UserId": "admin@a830edad9050849nda3079.onmicrosoft.com",
  "UserKey": "i:0h.f|membership|10037ffe8ec1e08e@live.com",
  "UserType": 0,
  "Version": 1,
  "WebId": "59734b49-8897-44c5-b6c6-125725d069ea",
  "Workload": "SharePoint"
}

References #

AnonymousLinkCreated

#
RecordType
SharePointSharingOperation

Description

An anonymous (anyone-with-the-link) sharing link was created for a file or folder, exposing it without authentication.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppId": "22222222-2222-2222-2222-222222222222",
    "ClientAppName": "dw-activity-gen",
    "CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
    "PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
    "TokenIssuedAtTime": "2026-07-02T17:37:48Z",
    "UniqueTokenId": "yzlSUbnhBUqYEcBwgx5ZAA",
    "UserObjectId": "11111111-1111-1111-1111-111111111111"
  },
  "ApplicationDisplayName": "dw-activity-gen",
  "ApplicationId": "22222222-2222-2222-2222-222222222222",
  "AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
  "AuthenticationType": "OAuth",
  "ClientIP": "203.0.113.10",
  "CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
  "CreationTime": "2026-07-02T17:39:22Z",
  "DeviceDisplayName": "203.0.113.10",
  "EventData": "<Type>View</Type><MembersCanShareApplied>False</MembersCanShareApplied>",
  "EventSignature": "1.CAESFEFub255bW91c0xpbmtDcmVhdGVkGMrEmtIGIhAxMDAzMjAwNTdmNGMxODc5KiQzYzFhODEwNy0wYjdlLTQzMWQtODc4Zi1lYmY0ODg0ODJhZTMyEgljQ2-LKZgKSxGFerztNsK7ODoSCdeMpdpMmqpJEYCoiRuyPumkQhIJ7IbSHdf_y04RjUtiV4YEMJVKEgmJVPk-6cDJRRGDC648S0yvYA.W3mKyol25gcIH1sZvfRKrqv5Oi70TzJD3ITxuoTAoHE",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "Id": "cf596463-913f-4cd7-abfa-08ded860da68",
  "IsManagedDevice": false,
  "ItemType": "File",
  "ListId": "1dd286ec-ffd7-4ecb-8d4b-625786043095",
  "ListItemUniqueId": "3ef95489-c0e9-45c9-830b-ae3c4b4caf60",
  "ObjectId": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com/Documents/dwharn-969d9832.txt",
  "Operation": "AnonymousLinkCreated",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "Permission": "None",
  "Platform": "NotSpecified",
  "RecordType": 14,
  "SharingLinkScope": "Uninitialized",
  "Site": "8b6f4363-9829-4b0a-857a-bced36c2bb38",
  "SiteUrl": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com",
  "SourceFileExtension": "txt",
  "SourceFileName": "dwharn-969d9832.txt",
  "SourceRelativeUrl": "Documents/dwharn-969d9832.txt",
  "UniqueSharingId": "103402c4-cd39-4406-883d-54c62542f627",
  "UserAgent": "python-requests/2.34.2",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
  "UserType": 0,
  "Version": 1,
  "WebId": "daa58cd7-9a4c-49aa-80a8-891bb23ee9a4",
  "Workload": "OneDrive"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

  • O365 OneDrive Anonymous Link Created or Updated source medium: Anonymous links can be used to export files from OneDrive. While this isn't always a sign of malicious activity, some organizations do not support the creation of anonymous links because of the risk of data leakage. This rule detects the creation or modification of anonymous links in OneDrive.↳ also matches AnonymousLinkUpdated

Panther #

References #

AnonymousLinkUpdated

#
RecordType
SharePointSharingOperation

Description

An existing anonymous sharing link was modified (e.g. permission level changed).

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

  • O365 OneDrive Anonymous Link Created or Updated source medium: Anonymous links can be used to export files from OneDrive. While this isn't always a sign of malicious activity, some organizations do not support the creation of anonymous links because of the risk of data leakage. This rule detects the creation or modification of anonymous links in OneDrive.↳ also matches AnonymousLinkCreated

References #

AnonymousLinkUsed

#
RecordType
SharePointSharingOperation

Description

An anonymous sharing link was used to access a file or folder, indicating external/unauthenticated access.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
SubjectUserName (chronicle rule field)eqanonymous1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

  • O365 OneDrive Anonymous Link Accessed source medium: Anonymous links can be used to access files from OneDrive. While this isn't always a sign of malicious activity, some organizations do not support the use of anonymous links because of the risk of data leakage. This rule detects when anonymous links are used to access files from OneDrive.T1048, T1048.002

References #

CompanyLinkCreated

#
RecordType
SharePointSharingOperation

Description

Company Link Created activity in SharePoint / OneDrive sharing, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppId": "22222222-2222-2222-2222-222222222222",
    "ClientAppName": "dw-activity-gen",
    "CorrelationId": "c1e814ee-6deb-4166-8795-61613f5f09f6",
    "PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
    "TokenIssuedAtTime": "2026-07-02T02:09:44Z",
    "UniqueTokenId": "fok73fVNMECa2s8q2X5cAA",
    "UserObjectId": "11111111-1111-1111-1111-111111111111"
  },
  "ApplicationDisplayName": "dw-activity-gen",
  "ApplicationId": "22222222-2222-2222-2222-222222222222",
  "AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
  "AuthenticationType": "OAuth",
  "ClientIP": "203.0.113.10",
  "CorrelationId": "c1e814ee-6deb-4166-8795-61613f5f09f6",
  "CreationTime": "2026-07-02T02:09:58Z",
  "DeviceDisplayName": "203.0.113.10",
  "EventData": "<Type>View</Type><MembersCanShareApplied>False</MembersCanShareApplied>",
  "EventSignature": "1.CAESEkNvbXBhbnlMaW5rQ3JlYXRlZBj2kJfSBiIQMTAwMzIwMDU3ZjRjMTg3OSokM2MxYTgxMDctMGI3ZS00MzFkLTg3OGYtZWJmNDg4NDgyYWUzMhIJY0NviymYCksRhXq87TbCuzg6EgnXjKXaTJqqSRGAqIkbsj7ppEISCeyG0h3X_8tOEY1LYleGBDCVShIJcw29-mVin04RpuUj04_RWg0.gdD37z92wc_VK417XmnnZc8C3n2Tbv0k2y11Ew2LIcc",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "Id": "78520081-f723-4b83-472a-08ded7df0429",
  "IsManagedDevice": false,
  "ItemType": "File",
  "ListId": "1dd286ec-ffd7-4ecb-8d4b-625786043095",
  "ListItemUniqueId": "fabd0d73-6265-4e9f-a6e5-23d38fd15a0d",
  "ObjectId": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com/Documents/dw-harness-60974bd7-test.txt",
  "Operation": "CompanyLinkCreated",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "Permission": "None",
  "Platform": "NotSpecified",
  "RecordType": 14,
  "SharingLinkScope": "Uninitialized",
  "Site": "8b6f4363-9829-4b0a-857a-bced36c2bb38",
  "SiteUrl": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com",
  "SourceFileExtension": "txt",
  "SourceFileName": "dw-harness-60974bd7-test.txt",
  "SourceRelativeUrl": "Documents/dw-harness-60974bd7-test.txt",
  "UniqueSharingId": "b6f59f26-1ce7-44b2-8a57-af25b73491f8",
  "UserAgent": "python-requests/2.34.2",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
  "UserType": 0,
  "Version": 1,
  "WebId": "daa58cd7-9a4c-49aa-80a8-891bb23ee9a4",
  "Workload": "OneDrive"
}

References #

RemovedFromGroup

#
RecordType
SharePointSharingOperation

Description

A user was removed from a SharePoint or OneDrive permission group.

Example Audit Record #

{
  "CreationTime": "2019-12-02T13:52:42",
  "Id": "*REDACTED*",
  "Operation": "RemovedFromGroup",
  "OrganizationId": "*REDACTED*",
  "RecordType": 14,
  "UserKey": "*REDACTED*",
  "UserType": 0,
  "Version": 1,
  "Workload": "SharePoint",
  "ClientIP": "*REDACTED*",
  "ObjectId": "*REDACTED*",
  "UserId": "*REDACTED*",
  "CorrelationId": "*REDACTED*",
  "EventSource": "SharePoint",
  "ItemType": "Web",
  "Site": "*REDACTED*",
  "UserAgent": "*REDACTED*",
  "WebId": "*REDACTED*",
  "EventData": "*REDACTED*",
  "TargetUserOrGroupType": "Member",
  "SiteUrl": "*REDACTED*",
  "TargetUserOrGroupName": "*REDACTED*"
}

References #

SecureLinkCreated

#
RecordType
SharePointSharingOperation

Description

A 'specific people' sharing link was created for a SharePoint or OneDrive resource, granting access to a specific person or group who may be external to the organization. The target user is identified in the paired AddedToSecureLink event.

Example Audit Record #

{
  "CreationTime": "2019-11-26T15:57:25",
  "Id": "*REDACTED*",
  "Operation": "SecureLinkCreated",
  "OrganizationId": "*REDACTED*",
  "RecordType": 14,
  "UserKey": "*REDACTED*",
  "UserType": 0,
  "Version": 1,
  "Workload": "OneDrive",
  "ClientIP": "*REDACTED*",
  "ObjectId": "*REDACTED*",
  "UserId": "*REDACTED*",
  "CorrelationId": "*REDACTED*",
  "EventSource": "SharePoint",
  "ItemType": "File",
  "ListId": "*REDACTED*",
  "ListItemUniqueId": "*REDACTED*",
  "Site": "*REDACTED*",
  "UserAgent": "*REDACTED*",
  "WebId": "*REDACTED*",
  "EventData": "*REDACTED*",
  "SourceFileExtension": "xlsx",
  "UniqueSharingId": "*REDACTED*",
  "SiteUrl": "*REDACTED*",
  "SourceFileName": "*REDACTED*",
  "SourceRelativeUrl": "*REDACTED*"
}

References #

SharingInheritanceBroken

#
RecordType
SharePointSharingOperation

Description

Sharing Inheritance Broken activity in SharePoint / OneDrive sharing, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppName": "dw-activity-gen",
    "CorrelationId": "c1e814ee-6deb-4166-8795-61613f5f09f6",
    "PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
    "TokenIssuedAtTime": "2026-07-02T02:09:44Z",
    "UniqueTokenId": "fok73fVNMECa2s8q2X5cAA",
    "UserObjectId": "11111111-1111-1111-1111-111111111111"
  },
  "ApplicationDisplayName": "dw-activity-gen",
  "AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
  "AuthenticationType": "OAuth",
  "ClientIP": "203.0.113.10",
  "CorrelationId": "c1e814ee-6deb-4166-8795-61613f5f09f6",
  "CreationTime": "2026-07-02T02:09:57Z",
  "DeviceDisplayName": "203.0.113.10",
  "EventData": "<copyRoleAssignments>True</copyRoleAssignments><clearSubScopes>False</clearSubScopes><dontAddCurrentUserToRoleAssignments>False</dontAddCurrentUserToRoleAssignments><copySpecificRoleAssignments>False</copySpecificRoleAssignments>",
  "EventSignature": "1.CAESGFNoYXJpbmdJbmhlcml0YW5jZUJyb2tlbhj1kJfSBiIQMTAwMzIwMDU3ZjRjMTg3OTISCWNDb4spmApLEYV6vO02wrs4OhIJ14yl2kyaqkkRgKiJG7I-6aRCEgnshtId1__LThGNS2JXhgQwlUoSCXMNvfplYp9OEablI9OP0VoN.gzXzrci1BhJmnqpmJ-VfoiZ71HpyxOFi4QbZFIb1VH0",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "Id": "911e14f2-a10f-469a-1671-08ded7df041a",
  "IsManagedDevice": false,
  "ItemType": "File",
  "ListId": "1dd286ec-ffd7-4ecb-8d4b-625786043095",
  "ListItemUniqueId": "fabd0d73-6265-4e9f-a6e5-23d38fd15a0d",
  "ObjectId": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com/Documents/dw-harness-60974bd7-test.txt",
  "Operation": "SharingInheritanceBroken",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "Permission": "None",
  "Platform": "NotSpecified",
  "RecordType": 14,
  "SharingLinkScope": "Uninitialized",
  "Site": "8b6f4363-9829-4b0a-857a-bced36c2bb38",
  "SiteUrl": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com",
  "SourceFileExtension": "txt",
  "SourceFileName": "dw-harness-60974bd7-test.txt",
  "SourceRelativeUrl": "Documents/dw-harness-60974bd7-test.txt",
  "UserAgent": "python-requests/2.34.2",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
  "UserType": 0,
  "Version": 1,
  "WebId": "daa58cd7-9a4c-49aa-80a8-891bb23ee9a4",
  "Workload": "OneDrive"
}

References #

SharingLinkCreated

#
RecordType
SharePointSharingOperation

Description

Sharing Link Created activity in SharePoint / OneDrive sharing, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppId": "22222222-2222-2222-2222-222222222222",
    "ClientAppName": "dw-activity-gen",
    "CorrelationId": "c1e814ee-6deb-4166-8795-61613f5f09f6",
    "PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
    "TokenIssuedAtTime": "2026-07-02T02:09:44Z",
    "UniqueTokenId": "fok73fVNMECa2s8q2X5cAA",
    "UserObjectId": "11111111-1111-1111-1111-111111111111"
  },
  "ApplicationDisplayName": "dw-activity-gen",
  "ApplicationId": "22222222-2222-2222-2222-222222222222",
  "AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
  "AuthenticationType": "OAuth",
  "ClientIP": "203.0.113.10",
  "CorrelationId": "c1e814ee-6deb-4166-8795-61613f5f09f6",
  "CreationTime": "2026-07-02T02:09:58Z",
  "DeviceDisplayName": "203.0.113.10",
  "EventData": "<AllowAnonymousAccess>False</AllowAnonymousAccess><SubmitOnly>False</SubmitOnly><MembersCanShareApplied>False</MembersCanShareApplied>",
  "EventSignature": "1.CAESElNoYXJpbmdMaW5rQ3JlYXRlZBj2kJfSBiIQMTAwMzIwMDU3ZjRjMTg3OSokM2MxYTgxMDctMGI3ZS00MzFkLTg3OGYtZWJmNDg4NDgyYWUzMhIJY0NviymYCksRhXq87TbCuzg6EgnXjKXaTJqqSRGAqIkbsj7ppEISCeyG0h3X_8tOEY1LYleGBDCVShIJcw29-mVin04RpuUj04_RWg0.6srI0tLQGm0OUSW_UPhse2mD8ARcjWS7kBQXi-Wk4kc",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "Id": "38c04f68-3064-45de-53bf-08ded7df0428",
  "IsManagedDevice": false,
  "ItemType": "File",
  "ListId": "1dd286ec-ffd7-4ecb-8d4b-625786043095",
  "ListItemUniqueId": "fabd0d73-6265-4e9f-a6e5-23d38fd15a0d",
  "ObjectId": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com/Documents/dw-harness-60974bd7-test.txt",
  "Operation": "SharingLinkCreated",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "Permission": "View",
  "Platform": "NotSpecified",
  "RecordType": 14,
  "SharingLinkScope": "Organization",
  "Site": "8b6f4363-9829-4b0a-857a-bced36c2bb38",
  "SiteUrl": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com",
  "SourceFileExtension": "txt",
  "SourceFileName": "dw-harness-60974bd7-test.txt",
  "SourceRelativeUrl": "Documents/dw-harness-60974bd7-test.txt",
  "UniqueSharingId": "b6f59f26-1ce7-44b2-8a57-af25b73491f8",
  "UserAgent": "python-requests/2.34.2",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
  "UserType": 0,
  "Version": 1,
  "WebId": "daa58cd7-9a4c-49aa-80a8-891bb23ee9a4",
  "Workload": "OneDrive"
}

References #

SharingRevoked

#
RecordType
SharePointSharingOperation

Description

A sharing grant on a SharePoint or OneDrive resource was revoked.

Example Audit Record #

{
  "CreationTime": "2019-12-02T14:23:00",
  "Id": "*REDACTED*",
  "Operation": "SharingRevoked",
  "OrganizationId": "*REDACTED*",
  "RecordType": 14,
  "UserKey": "*REDACTED*",
  "UserType": 0,
  "Version": 1,
  "Workload": "OneDrive",
  "ClientIP": "*REDACTED*",
  "ObjectId": "*REDACTED*",
  "UserId": "*REDACTED*",
  "CorrelationId": "*REDACTED*",
  "EventSource": "SharePoint",
  "ItemType": "File",
  "ListId": "*REDACTED*",
  "ListItemUniqueId": "*REDACTED*",
  "Site": "*REDACTED*",
  "UserAgent": "*REDACTED*",
  "WebId": "*REDACTED*",
  "SourceFileExtension": "xlsx",
  "TargetUserOrGroupType": "SharePointGroup",
  "SiteUrl": "*REDACTED*",
  "SourceFileName": "*REDACTED*",
  "SourceRelativeUrl": "*REDACTED*",
  "TargetUserOrGroupName": "*REDACTED*"
}

References #

SharingSet

#
RecordType
SharePointSharingOperation

Description

Sharing permissions were set on a SharePoint or OneDrive resource (a user or group was granted access).

Example Audit Record #

{
  "CreationTime": "2019-12-02T14:23:00",
  "Id": "*REDACTED*",
  "Operation": "SharingSet",
  "OrganizationId": "*REDACTED*",
  "RecordType": 14,
  "UserKey": "*REDACTED*",
  "UserType": 0,
  "Version": 1,
  "Workload": "OneDrive",
  "ClientIP": "*REDACTED*",
  "ObjectId": "*REDACTED*",
  "UserId": "*REDACTED*",
  "CorrelationId": "*REDACTED*",
  "EventSource": "SharePoint",
  "ItemType": "File",
  "ListId": "*REDACTED*",
  "ListItemUniqueId": "*REDACTED*",
  "Site": "*REDACTED*",
  "UserAgent": "*REDACTED*",
  "WebId": "*REDACTED*",
  "EventData": "*REDACTED*",
  "SourceFileExtension": "xlsx",
  "TargetUserOrGroupType": "SharePointGroup",
  "SiteUrl": "*REDACTED*",
  "SourceFileName": "*REDACTED*",
  "SourceRelativeUrl": "*REDACTED*",
  "TargetUserOrGroupName": "*REDACTED*"
}

References #

SiteCollectionAdminAdded

#
RecordType
SharePointSharingOperation

Description

A user was added as a SharePoint site collection administrator, gaining full control of the site collection.

Example Audit Record #

{
  "ClientIP": "52.109.2.1",
  "CorrelationId": "c235c958-b437-46c9-bafc-fc3a384298ca",
  "CreationTime": "2020-12-16T17:18:39",
  "EventSource": "SharePoint",
  "Id": "5351be23-6ae7-48b5-5742-08d8a1e6a192",
  "ItemType": "Web",
  "ModifiedProperties": [
    {
      "Name": "SiteAdmin",
      "NewValue": "mhaag@rodsoto.onmicrosoft.com",
      "OldValue": ""
    }
  ],
  "ObjectId": "https://rodsoto-my.sharepoint.com/personal/mhaag_rodsoto_onmicrosoft_com",
  "Operation": "SiteCollectionAdminAdded",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "RecordType": 14,
  "Site": "93e25121-6997-4ac9-9bab-86eedaf46a2e",
  "SiteUrl": "https://rodsoto-my.sharepoint.com/personal/mhaag_rodsoto_onmicrosoft_com",
  "TargetUserOrGroupName": "mhaag@rodsoto.onmicrosoft.com",
  "TargetUserOrGroupType": "Member",
  "UserAgent": "OfficeDiscovery",
  "UserId": "mhaag@rodsoto.onmicrosoft.com",
  "UserKey": "i:0h.f|membership|100320010405e870@live.com",
  "UserType": 0,
  "Version": 1,
  "WebId": "aef3faf1-a682-44f2-a614-55246569c234",
  "Workload": "OneDrive"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Name (elastic rule field)inonedrive1 ruleelastic
Provider_Name (elastic rule field)insharepoint1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 SharePoint Site Administrator Added source medium: Identifies when a new SharePoint Site Administrator is added in Microsoft 365. Site Administrators have full control over SharePoint Sites, including the ability to manage permissions, access all content, and modify site settings. Adversaries who compromise a privileged account may add themselves or a controlled account as a Site Administrator to maintain persistent, high-privilege access to sensitive SharePoint data. This technique was notably observed in the 0mega ransomware campaign, where attackers elevated privileges to exfiltrate data and deploy ransom notes across SharePoint sites.T1098, T1098.003

References #

SiteCollectionAdminRemoved

#
RecordType
SharePointSharingOperation

Description

A user was removed as a SharePoint site collection administrator.

Example Audit Record #

{
  "ClientIP": "52.109.2.1",
  "CorrelationId": "c235c958-b437-46c9-bafc-fc3a384298ca",
  "CreationTime": "2020-12-16T17:18:39",
  "EventSource": "SharePoint",
  "Id": "960ab304-369a-4f8c-7cd0-08d8a1e6a199",
  "ItemType": "Web",
  "ModifiedProperties": [
    {
      "Name": "SiteAdmin",
      "NewValue": "",
      "OldValue": ""
    }
  ],
  "ObjectId": "https://rodsoto-my.sharepoint.com/personal/mhaag_rodsoto_onmicrosoft_com",
  "Operation": "SiteCollectionAdminRemoved",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "RecordType": 14,
  "Site": "93e25121-6997-4ac9-9bab-86eedaf46a2e",
  "SiteUrl": "https://rodsoto-my.sharepoint.com/personal/mhaag_rodsoto_onmicrosoft_com",
  "TargetUserOrGroupName": "SHAREPOINT\\system",
  "TargetUserOrGroupType": "Member",
  "UserAgent": "OfficeDiscovery",
  "UserId": "mhaag@rodsoto.onmicrosoft.com",
  "UserKey": "i:0h.f|membership|100320010405e870@live.com",
  "UserType": 0,
  "Version": 1,
  "WebId": "aef3faf1-a682-44f2-a614-55246569c234",
  "Workload": "OneDrive"
}

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.