SharePoint and OneDrive sharing operations
| Operation | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for M365-SharePointSharingOperation rules matching the RecordType but no specific Operation. | N | N |
| Added | A user was added to a SharePoint or OneDrive permission group, granting the group's access level. | Y | N |
| Anonymous | An anonymous (anyone-with-the-link) sharing link was created for a file or folder, exposing it without authentication. | Y | Y |
| Anonymous | An existing anonymous sharing link was modified (e.g. permission level changed). | N | Y |
| Anonymous | An anonymous sharing link was used to access a file or folder, indicating external/unauthenticated access. | N | Y |
| Company | Company Link Created activity in SharePoint / OneDrive sharing, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Removed | A user was removed from a SharePoint or OneDrive permission group. | Y | N |
| Secure | A 'specific people' sharing link was created for a SharePoint or OneDrive resource, granting access to a specific person or group who may be external to the organization. The target user is identified in the paired AddedToSecureLink event. | Y | N |
| Sharing | Sharing Inheritance Broken activity in SharePoint / OneDrive sharing, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Sharing | Sharing Link Created activity in SharePoint / OneDrive sharing, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Sharing | A sharing grant on a SharePoint or OneDrive resource was revoked. | Y | N |
| Sharing | Sharing permissions were set on a SharePoint or OneDrive resource (a user or group was granted access). | Y | N |
| Site | A user was added as a SharePoint site collection administrator, gaining full control of the site collection. | Y | Y |
| Site | A user was removed as a SharePoint site collection administrator. | Y | N |
any: SharePoint and OneDrive sharing operations (catch-all)
#Description
Catch-all for M365-SharePointSharingOperation rules matching the RecordType but no specific Operation.
References #
AddedToGroup
#Description
A user was added to a SharePoint or OneDrive permission group, granting the group's access level.
Example Audit Record #
{
"ClientIP": "43.242.120.166",
"CorrelationId": "44c1979f-00d2-b000-53ba-4b95683cfb1f",
"CreationTime": "2020-12-16T04:55:53",
"EventData": "<Group>Site Owners</Group>",
"EventSource": "SharePoint",
"Id": "5c5db0d9-6d04-4b10-cd04-08d8a17ede09",
"ItemType": "Web",
"ObjectId": "https://a830edad9050849nda3079.sharepoint.com/sites/automation_test_new",
"Operation": "AddedToGroup",
"OrganizationId": "2ed28a74-1f6f-4829-8530-fe359c77d35c",
"RecordType": 14,
"Site": "e3744300-d4b6-4d18-8f41-6fc9a5466e6e",
"SiteUrl": "https://a830edad9050849nda3079.sharepoint.com/sites/automation_test_new",
"TargetUserOrGroupName": "SHAREPOINT\\system",
"TargetUserOrGroupType": "Member",
"UserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36",
"UserId": "admin@a830edad9050849nda3079.onmicrosoft.com",
"UserKey": "i:0h.f|membership|10037ffe8ec1e08e@live.com",
"UserType": 0,
"Version": 1,
"WebId": "59734b49-8897-44c5-b6c6-125725d069ea",
"Workload": "SharePoint"
}
References #
AnonymousLinkCreated
#Description
An anonymous (anyone-with-the-link) sharing link was created for a file or folder, exposing it without authentication.
Example Audit Record #
{
"AppAccessContext": {
"AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"APIId": "00000003-0000-0000-c000-000000000000",
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"ClientAppName": "dw-activity-gen",
"CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
"PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
"TokenIssuedAtTime": "2026-07-02T17:37:48Z",
"UniqueTokenId": "yzlSUbnhBUqYEcBwgx5ZAA",
"UserObjectId": "11111111-1111-1111-1111-111111111111"
},
"ApplicationDisplayName": "dw-activity-gen",
"ApplicationId": "22222222-2222-2222-2222-222222222222",
"AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
"AuthenticationType": "OAuth",
"ClientIP": "203.0.113.10",
"CorrelationId": "70c0f69d-32b2-4cc1-977a-6ab5419206cb",
"CreationTime": "2026-07-02T17:39:22Z",
"DeviceDisplayName": "203.0.113.10",
"EventData": "<Type>View</Type><MembersCanShareApplied>False</MembersCanShareApplied>",
"EventSignature": "1.CAESFEFub255bW91c0xpbmtDcmVhdGVkGMrEmtIGIhAxMDAzMjAwNTdmNGMxODc5KiQzYzFhODEwNy0wYjdlLTQzMWQtODc4Zi1lYmY0ODg0ODJhZTMyEgljQ2-LKZgKSxGFerztNsK7ODoSCdeMpdpMmqpJEYCoiRuyPumkQhIJ7IbSHdf_y04RjUtiV4YEMJVKEgmJVPk-6cDJRRGDC648S0yvYA.W3mKyol25gcIH1sZvfRKrqv5Oi70TzJD3ITxuoTAoHE",
"EventSource": "SharePoint",
"GeoLocation": "NAM",
"Id": "cf596463-913f-4cd7-abfa-08ded860da68",
"IsManagedDevice": false,
"ItemType": "File",
"ListId": "1dd286ec-ffd7-4ecb-8d4b-625786043095",
"ListItemUniqueId": "3ef95489-c0e9-45c9-830b-ae3c4b4caf60",
"ObjectId": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com/Documents/dwharn-969d9832.txt",
"Operation": "AnonymousLinkCreated",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"Permission": "None",
"Platform": "NotSpecified",
"RecordType": 14,
"SharingLinkScope": "Uninitialized",
"Site": "8b6f4363-9829-4b0a-857a-bced36c2bb38",
"SiteUrl": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com",
"SourceFileExtension": "txt",
"SourceFileName": "dwharn-969d9832.txt",
"SourceRelativeUrl": "Documents/dwharn-969d9832.txt",
"UniqueSharingId": "103402c4-cd39-4406-883d-54c62542f627",
"UserAgent": "python-requests/2.34.2",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
"UserType": 0,
"Version": 1,
"WebId": "daa58cd7-9a4c-49aa-80a8-891bb23ee9a4",
"Workload": "OneDrive"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
Panther #
T1039
References #
AnonymousLinkUpdated
#Description
An existing anonymous sharing link was modified (e.g. permission level changed).
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
References #
AnonymousLinkUsed
#Description
An anonymous sharing link was used to access a file or folder, indicating external/unauthenticated access.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
SubjectUserName (chronicle rule field) | eq | anonymous | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1048, T1048.002
References #
CompanyLinkCreated
#Description
Company Link Created activity in SharePoint / OneDrive sharing, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"AppAccessContext": {
"AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"APIId": "00000003-0000-0000-c000-000000000000",
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"ClientAppName": "dw-activity-gen",
"CorrelationId": "c1e814ee-6deb-4166-8795-61613f5f09f6",
"PFTTokenAppId": "22222222-2222-2222-2222-222222222222",
"TokenIssuedAtTime": "2026-07-02T02:09:44Z",
"UniqueTokenId": "fok73fVNMECa2s8q2X5cAA",
"UserObjectId": "11111111-1111-1111-1111-111111111111"
},
"ApplicationDisplayName": "dw-activity-gen",
"ApplicationId": "22222222-2222-2222-2222-222222222222",
"AssertingApplicationId": "00000003-0000-0000-c000-000000000000",
"AuthenticationType": "OAuth",
"ClientIP": "203.0.113.10",
"CorrelationId": "c1e814ee-6deb-4166-8795-61613f5f09f6",
"CreationTime": "2026-07-02T02:09:58Z",
"DeviceDisplayName": "203.0.113.10",
"EventData": "<Type>View</Type><MembersCanShareApplied>False</MembersCanShareApplied>",
"EventSignature": "1.CAESEkNvbXBhbnlMaW5rQ3JlYXRlZBj2kJfSBiIQMTAwMzIwMDU3ZjRjMTg3OSokM2MxYTgxMDctMGI3ZS00MzFkLTg3OGYtZWJmNDg4NDgyYWUzMhIJY0NviymYCksRhXq87TbCuzg6EgnXjKXaTJqqSRGAqIkbsj7ppEISCeyG0h3X_8tOEY1LYleGBDCVShIJcw29-mVin04RpuUj04_RWg0.gdD37z92wc_VK417XmnnZc8C3n2Tbv0k2y11Ew2LIcc",
"EventSource": "SharePoint",
"GeoLocation": "NAM",
"Id": "78520081-f723-4b83-472a-08ded7df0429",
"IsManagedDevice": false,
"ItemType": "File",
"ListId": "1dd286ec-ffd7-4ecb-8d4b-625786043095",
"ListItemUniqueId": "fabd0d73-6265-4e9f-a6e5-23d38fd15a0d",
"ObjectId": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com/Documents/dw-harness-60974bd7-test.txt",
"Operation": "CompanyLinkCreated",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"Permission": "None",
"Platform": "NotSpecified",
"RecordType": 14,
"SharingLinkScope": "Uninitialized",
"Site": "8b6f4363-9829-4b0a-857a-bced36c2bb38",
"SiteUrl": "https://example-my.sharepoint.com/personal/adminuser_example_onmicrosoft_com",
"SourceFileExtension": "txt",
"SourceFileName": "dw-harness-60974bd7-test.txt",
"SourceRelativeUrl": "Documents/dw-harness-60974bd7-test.txt",
"UniqueSharingId": "b6f59f26-1ce7-44b2-8a57-af25b73491f8",
"UserAgent": "python-requests/2.34.2",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "i:0h.f|membership|10000000aaaaaaaa@live.com",
"UserType": 0,
"Version": 1,
"WebId": "daa58cd7-9a4c-49aa-80a8-891bb23ee9a4",
"Workload": "OneDrive"
}
References #
RemovedFromGroup
#Description
A user was removed from a SharePoint or OneDrive permission group.
Example Audit Record #
{
"CreationTime": "2019-12-02T13:52:42",
"Id": "*REDACTED*",
"Operation": "RemovedFromGroup",
"OrganizationId": "*REDACTED*",
"RecordType": 14,
"UserKey": "*REDACTED*",
"UserType": 0,
"Version": 1,
"Workload": "SharePoint",
"ClientIP": "*REDACTED*",
"ObjectId": "*REDACTED*",
"UserId": "*REDACTED*",
"CorrelationId": "*REDACTED*",
"EventSource": "SharePoint",
"ItemType": "Web",
"Site": "*REDACTED*",
"UserAgent": "*REDACTED*",
"WebId": "*REDACTED*",
"EventData": "*REDACTED*",
"TargetUserOrGroupType": "Member",
"SiteUrl": "*REDACTED*",
"TargetUserOrGroupName": "*REDACTED*"
}
References #
SecureLinkCreated
#Description
A 'specific people' sharing link was created for a SharePoint or OneDrive resource, granting access to a specific person or group who may be external to the organization. The target user is identified in the paired AddedToSecureLink event.
Example Audit Record #
{
"CreationTime": "2019-11-26T15:57:25",
"Id": "*REDACTED*",
"Operation": "SecureLinkCreated",
"OrganizationId": "*REDACTED*",
"RecordType": 14,
"UserKey": "*REDACTED*",
"UserType": 0,
"Version": 1,
"Workload": "OneDrive",
"ClientIP": "*REDACTED*",
"ObjectId": "*REDACTED*",
"UserId": "*REDACTED*",
"CorrelationId": "*REDACTED*",
"EventSource": "SharePoint",
"ItemType": "File",
"ListId": "*REDACTED*",
"ListItemUniqueId": "*REDACTED*",
"Site": "*REDACTED*",
"UserAgent": "*REDACTED*",
"WebId": "*REDACTED*",
"EventData": "*REDACTED*",
"SourceFileExtension": "xlsx",
"UniqueSharingId": "*REDACTED*",
"SiteUrl": "*REDACTED*",
"SourceFileName": "*REDACTED*",
"SourceRelativeUrl": "*REDACTED*"
}
References #
SiteCollectionAdminAdded
#Description
A user was added as a SharePoint site collection administrator, gaining full control of the site collection.
Example Audit Record #
{
"ClientIP": "52.109.2.1",
"CorrelationId": "c235c958-b437-46c9-bafc-fc3a384298ca",
"CreationTime": "2020-12-16T17:18:39",
"EventSource": "SharePoint",
"Id": "5351be23-6ae7-48b5-5742-08d8a1e6a192",
"ItemType": "Web",
"ModifiedProperties": [
{
"Name": "SiteAdmin",
"NewValue": "mhaag@rodsoto.onmicrosoft.com",
"OldValue": ""
}
],
"ObjectId": "https://rodsoto-my.sharepoint.com/personal/mhaag_rodsoto_onmicrosoft_com",
"Operation": "SiteCollectionAdminAdded",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"RecordType": 14,
"Site": "93e25121-6997-4ac9-9bab-86eedaf46a2e",
"SiteUrl": "https://rodsoto-my.sharepoint.com/personal/mhaag_rodsoto_onmicrosoft_com",
"TargetUserOrGroupName": "mhaag@rodsoto.onmicrosoft.com",
"TargetUserOrGroupType": "Member",
"UserAgent": "OfficeDiscovery",
"UserId": "mhaag@rodsoto.onmicrosoft.com",
"UserKey": "i:0h.f|membership|100320010405e870@live.com",
"UserType": 0,
"Version": 1,
"WebId": "aef3faf1-a682-44f2-a614-55246569c234",
"Workload": "OneDrive"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Provider_Name (elastic rule field) | in | onedrive | 1 rule | elastic |
Provider_Name (elastic rule field) | in | sharepoint | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.003
References #
SiteCollectionAdminRemoved
#Description
A user was removed as a SharePoint site collection administrator.
Example Audit Record #
{
"ClientIP": "52.109.2.1",
"CorrelationId": "c235c958-b437-46c9-bafc-fc3a384298ca",
"CreationTime": "2020-12-16T17:18:39",
"EventSource": "SharePoint",
"Id": "960ab304-369a-4f8c-7cd0-08d8a1e6a199",
"ItemType": "Web",
"ModifiedProperties": [
{
"Name": "SiteAdmin",
"NewValue": "",
"OldValue": ""
}
],
"ObjectId": "https://rodsoto-my.sharepoint.com/personal/mhaag_rodsoto_onmicrosoft_com",
"Operation": "SiteCollectionAdminRemoved",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"RecordType": 14,
"Site": "93e25121-6997-4ac9-9bab-86eedaf46a2e",
"SiteUrl": "https://rodsoto-my.sharepoint.com/personal/mhaag_rodsoto_onmicrosoft_com",
"TargetUserOrGroupName": "SHAREPOINT\\system",
"TargetUserOrGroupType": "Member",
"UserAgent": "OfficeDiscovery",
"UserId": "mhaag@rodsoto.onmicrosoft.com",
"UserKey": "i:0h.f|membership|100320010405e870@live.com",
"UserType": 0,
"Version": 1,
"WebId": "aef3faf1-a682-44f2-a614-55246569c234",
"Workload": "OneDrive"
}
References #
M365 audit records use different field names on each surface #
The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.
- Purview CSV export flattens each record to four columns (
CreationDate,UserIds,Operations,AuditData). The API field names live only inside theAuditDataJSON blob. Expand it withConvertFrom-Json. The wrapper columns are renamed too:CreationDatenotCreationTime,UserIdsnotUserId,OperationsnotOperation. - Sentinel's
OfficeActivitytable renames several fields and turns two integer enum columns into strings. The table below maps them.
| API JSON (event pages) | OfficeActivity column | Note |
|---|---|---|
Id | OfficeId | Renamed. |
Workload | OfficeWorkload | Renamed. |
ObjectId | OfficeObjectId | Renamed. |
CreationTime | TimeGenerated | Renamed. OfficeActivity has no CreationTime column. |
SiteUrl | Site_Url | Renamed (SharePoint family). |
RecordType | RecordType | Same name; the Int32 enum becomes its string enum name. |
UserType | UserType | Same name; the Int32 enum becomes a string. |
ClientIP | ClientIP, Client_IPAddress | Both columns present on OfficeActivity. |
Scope | (none) | No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob. |
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationId | same names | Unchanged. No _s / _d suffixes (a native table, not a custom log). |
Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.