Skip to content

Commit b75252e

Browse files
authored
Merge pull request #518 from MicrosoftDocs/main
[admin] merge to live
2 parents 8e575a7 + 1d46f80 commit b75252e

1 file changed

Lines changed: 69 additions & 37 deletions

File tree

office-365-management-api/office-365-management-activity-api-schema.md

Lines changed: 69 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Office 365 Management Activity API schema
44
description: The Office 365 Management Activity API schema is provided as a data service in two layers - Common schema and service-specific schema.
55
ms.ContentId: 1c2bf08c-4f3b-26c0-e1b2-90b190f641f5
66
ms.topic: reference
7-
ms.date: 09/04/2025
7+
ms.date: 09/28/2025
88
ms.localizationpriority: high
99
---
1010

@@ -326,35 +326,29 @@ This article provides details on the Common schema as well as service-specific s
326326
|362|AIInteractionsExport|Events related to export of AI interactions.|
327327
|363|Microsoft365CopilotScheduledPrompt|Events from Microsoft 365 Copilot scheduled prompt.|
328328
|364|PlacesDirectory|Events from Microsoft Places Directory.|
329-
|365|SentinelNotebookOnLake |Events from notebook execution on Sentinel Data Lake.|
330-
|366|SentinelJob |Events from operations on jobs in Sentinel Data Lake.|
331-
|367|SentinelKQLOnLake |Events from running KQL on Sentinel Data Lake.|
332-
|368|SentinelLakeOnboarding |Events from onboarding to Sentinel Data Lake.|
333-
|369|SentinelLakeDataOnboarding |Data loading events into Sentinel Data Lake.|
334-
|370|CrossTenantAccessPolicy|Events from Cross Tenant Access Policies.|
335-
|371|OutlookCopilotAutomation|Events related to back-end automation (without an explicit user interaction) in Microsoft Outlook driven by Agents, Copilot, or other AI scenarios.|
336-
|372|VivaEngageNetworkAssociation|Events related to Network Association in Viva Engage.|
337-
|373|AppAdminActivity|Events related to app admin activity.|
338-
|374|AppSettingsAdminActivity|Events related to app settings admin activity.|
339-
|375|UniversalPrintPrintJob|Audit events related to Print Jobs in Microsoft Universal Print.|
340-
|376|SentinelNotebookOnLake|Events related to Notebook on Lake in Microsoft Sentinel.|
341-
|377|SentinelJob|Events related to Jobs in Microsoft Sentinel.|
342-
|378|SentinelGraph|Events related to Graph in Microsoft Sentinel.|
343-
|379|SentinelKQLOnLake|Events related to KQL on Lake in Microsoft Sentinel.|
344-
|380|SentinelPackage|Events related to Package in Microsoft Sentinel.|
345-
|381|VivaAmplifyOutlookSensitivityLabel|Events related to Outlook Sensitivity Labels in Viva Amplify.|
346-
|382||Deprecated. This value is not used.|
347-
|383|AIInteractionsSubscription|Events related to AI interaction subscriptions.|
348-
|384|AIInteractionsChangeNotification|Events related to AI interaction change notifications.|
349-
|385|FilteringMailMetadataExtended|Events related to filtering mail metadata.|
350-
|386|SentinelLakeOnboarding|Events related to Lake Onboarding in Microsoft Sentinel.|
351-
|387|SentinelLakeDataOnboarding|Events related to Lake Data Onboarding in Microsoft Sentinel.|
352-
|388|OfficeRestrictedModeAction|Audit events related to activities performed in Office Restricted Mode. |
353-
|389|CopilotForSecurityTrigger|Events related to triggers for Security Copilot agents. |
354-
|390|CopilotAgentManagement|Events related to admin activities for Microsoft Copilot agents.|
355-
|391|P4AIAssessmentFabricScannerRecord|Events related to Purview for AI Assessment Fabric Scanner.|
356-
|392|PlannerGoal|Microsoft Planner goal events.|
357-
|393|PlannerGoalList|Microsoft Planner goal list events.|
329+
|365|SentinelNotebookOnLake |Events from notebook execution on Sentinel data lake.|
330+
|366|SentinelJob |Events from operations on jobs in Sentinel data lake.|
331+
|367|SentinelKQLOnLake |Events from running KQL on Sentinel data lake.|
332+
|368|SentinelLakeOnboarding |Events from onboarding to Sentinel data lake.|
333+
|369|SentinelLakeDataOnboarding |Data loading events into Sentinel data lake.|
334+
|370|SentinelAITool|Events from operations on AI tool in Microsoft Sentinel|
335+
|371|SentinelGraph|Events related to Graph in Microsoft Sentinel.|
336+
|372|CrossTenantAccessPolicy|Events from Cross Tenant Access Policies.|
337+
|373|OutlookCopilotAutomation|Events related to back-end automation (without an explicit user interaction) in Microsoft Outlook driven by Agents, Copilot, or other AI scenarios.|
338+
|374|VivaEngageNetworkAssociation|Events related to Network Association in Viva Engage.|
339+
|375|AppAdminActivity|Events related to app admin activity.|
340+
|376|AppSettingsAdminActivity|Events related to app settings admin activity.|
341+
|377|UniversalPrintPrintJob|Audit events related to Print Jobs in Microsoft Universal Print.|
342+
|378|VivaAmplifyOutlookSensitivityLabel|Events related to Outlook Sensitivity Labels in Viva Amplify.|
343+
|379|AIInteractionsSubscription|Events related to AI interaction subscriptions.|
344+
|380|AIInteractionsChangeNotification|Events related to AI interaction change notifications.|
345+
|381|FilteringMailMetadataExtended|Events related to filtering mail metadata.|
346+
|382|OfficeRestrictedModeAction|Audit events related to activities performed in Office Restricted Mode. |
347+
|383|CopilotForSecurityTrigger|Events related to triggers for Security Copilot agents. |
348+
|384|CopilotAgentManagement|Events related to admin activities for Microsoft Copilot agents.|
349+
|385|P4AIAssessmentFabricScannerRecord|Events related to Purview for AI Assessment Fabric Scanner.|
350+
|386|PlannerGoal|Microsoft Planner goal events.|
351+
|387|PlannerGoalList|Microsoft Planner goal list events.|
358352

359353
### Enum: User Type - Type: Edm.Int32
360354

@@ -2807,9 +2801,9 @@ The audit records for events related to Places Directory operations use this sch
28072801
|Parameters|Collection(Common.NameValuePair)|No|The name and value for all parameters that were used with the cmdlet that is identified in the Operations property.|
28082802
|ModifiedProperties|Collection(Common.ModifiedProperty)|No|The property includes the name of the property that was modified, the new value of the modified property, and the previous value of the modified object.|
28092803

2810-
## Microsoft Sentinel data lake schema
2804+
## Microsoft Sentinel data lake and graph schema
28112805

2812-
The audit records for events related to Microsoft Sentinel data lake operations use this schema (in addition to the [Common schema](#common-schema)). For details on how you can search for the audit logs from the compliance portal, see [Audit log activities](/microsoft-365/compliance/audit-log-activities).
2806+
The audit records for events related to Microsoft Sentinel data lake and graphoperations use this schema (in addition to the [Common schema](#common-schema)). For details on how you can search for the audit logs from the compliance portal, see [Audit log activities](/microsoft-365/compliance/audit-log-activities).
28132807

28142808
### SentinelNotebookOnLake
28152809

@@ -2845,13 +2839,18 @@ The audit records for events related to Microsoft Sentinel data lake operations
28452839
| JobStartTime | Edm.Date | No | Start time of the job. |
28462840
| JobEndTime | Edm.Date | No | End time of the job. |
28472841
| Interface | Edm.String | Yes | Interface from where the job operation was done. |
2842+
| DatabasesRead | Collection(Edm.String) | No | The list of workspaces read by the job. |
2843+
| DatabasesWrite | Collection(Edm.String) | No | The list of workspaces written to by the job |
2844+
| TablesRead | Collection(Edm.String) | No | The list of tables read by the job. |
2845+
| TablesWrite | Collection(Edm.String) | No | The list of tables written to by the job. |
2846+
| Query | Edm.String | No | KQL query or notebook executed in the job. |
28482847

28492848
### SentinelKQLOnLake
28502849

28512850
| **Parameter** | **Type** | **Mandatory?** | **Description** |
28522851
|------------------|---------------------|:--------------:|----------------------|
28532852
| EventTime | Edm.Date | Yes | Timestamp of KQL query execution. |
2854-
| DatabaseName | Edm.String | Yes | The workspace the KQL query ran on. |
2853+
| DatabaseName | Collection(Edm.String) | Yes | The workspaces the KQL query ran on. |
28552854
| ResultTableCount | Edm.Int64 | No | Output Table Count. |
28562855
| QueryResponse | Edm.String | Yes | Response from executing the KQL query. |
28572856
| TotalRows | Collection(Edm.Int64)| Yes | Total Rows returned from query execution. List of values if multiple queries executed at once. |
@@ -2861,25 +2860,58 @@ The audit records for events related to Microsoft Sentinel data lake operations
28612860
| TotalCPU | Edm.Int64 | Yes | Total CPU Duration of the run. |
28622861
| MemoryPeak | Edm.Int64 | Yes | Memory Peak of the KQL query execution. |
28632862
| Interface | Edm.String | Yes | Interface from where the KQL query was executed.|
2863+
| TablesRead | Collection(Edm.String) | Yes | The list of tables read in the KQL query. |
2864+
| QueryText | Edm.String | Yes | The KQL query executed in scrubbed form. |
28642865

28652866
### SentinelLakeOnboarding
28662867

28672868
| Parameter | Type | Mandatory? | Description |
28682869
|------------------------------|-------------|------------|---------------------------------------------------------|
2869-
| BillingAzureSubscriptionId | Edm.String | No | Azure subscription chosen for Sentinel Data Lake billing.|
2870-
| BillingAzureResourceGroupName| Edm.String | No | Azure resource group chosen for Sentinel Data Lake billing.|
2870+
| BillingAzureSubscriptionId | Edm.String | No | Azure subscription chosen for Sentinel data lake billing.|
2871+
| BillingAzureResourceGroupName| Edm.String | No | Azure resource group chosen for Sentinel data lake billing.|
28712872
| TenantId | Edm.String | No | Tenant ID associated with the lake setup or update. |
28722873
| ProvisioningStatus | Edm.String | No | Status of provisioning the lake. |
28732874

28742875
### SentinelLakeDataOnboarding
28752876

28762877
| Property Name | Type | Mandatory? | Description |
28772878
|--------------------------|------------------------|------------|----------------------------------------------------------------|
2878-
| DataOnboardingAtSetup | Edm.String | No | Data sets ingested during Sentinel Data Lake onboarding. |
2879-
| Tables | Collection(Edm.String) | No | List of table names ingested during Sentinel Data Lake onboarding. |
2879+
| DataOnboardingAtSetup | Edm.String | No | Data sets ingested during Sentinel data lake onboarding. |
2880+
| Tables | Collection(Edm.String) | No | List of table names ingested during Sentinel data lake onboarding. |
28802881
| SubscriptionsEnabled | Collection(Edm.String) | No | List of subscriptions enabled for ARG ingestion. |
28812882
| DataOnboardingStatus | Edm.String | No | Status of operation. |
28822883

2884+
### SentinelAITool
2885+
2886+
| Parameter | Type | Mandatory? | Description |
2887+
| ------------------ | ---------------------- | ---------- | ------------------------------------------------ |
2888+
| EventOccurenceTime | Edm.Date | Yes | Timestamp of the operation. |
2889+
| ToolID | Edm.Guid | Yes | Identifier of the AI Tool. |
2890+
| ToolName | Edm.String | Yes | Name of the AI Tool. |
2891+
| Interface | Edm.String | Yes | Interface from where the AI Tool was run. |
2892+
| InputParameters | Edm.String | No | Parameters given to the tool. |
2893+
| DatabasesRead | Collection(Edm.String) | No | The list of databases read from in the run. |
2894+
| TablesRead | Collection(Edm.String) | No | The list of tables read from in the run. |
2895+
| APIsCalled | Collection(Edm.String) | No | APIs called by the AI Tool. |
2896+
| FailureReason | Edm.String | No | If the run failed, the reason for failure. |
2897+
| TotalRows | Collection(Edm.Int64) | No | Total Rows returned. |
2898+
| DataScanned | Edm.Int64 | No | Total GBs Scanned. |
2899+
| ExecutionDuration | Edm.Int64 | No | Time taken for query execution, in milliseconds. |
2900+
| TotalCpuHours | Edm.Int64 | No | Total CPU Duration of the run. |
2901+
| TotalSCUHours | Edm.Int64 | No | Total SCUs used in the run. |
2902+
2903+
### SentinelGraph
2904+
2905+
| Parameters | Type | Mandatory? | Description |
2906+
| ----------------- | ---------- | ---------- | ------------------------------------------------ |
2907+
| EventTime | Edm.Date | Yes | Timestamp of the operation. |
2908+
| GraphName | Edm.String | Yes | Name of the graph instance. |
2909+
| Operation | Edm.string | Yes | Action taken on graph. |
2910+
| OperationInput | Edm.string | No | Parameters of graph action. |
2911+
| GraphQuery Stats | Edm.string | No | Collection of response metadata. |
2912+
| GraphQuery Status | Edm.String | No | Response of the query or action on graph. |
2913+
| Interface | Edm.String | Yes | Interface from where the graph action was taken. |
2914+
28832915
## Purview On-demand classification schema
28842916

28852917
The audit records for events related to Purview On-demand classification use this schema. For more information about On-demand classification, see [Learn about On-demand classification in Microsoft Purview](https://go.microsoft.com/fwlink/?linkid=2309600)

0 commit comments

Comments
 (0)