Skip to content

Commit c8c9d80

Browse files
authored
Merge pull request #538 from chrisda/chrisda
MDO P2 clarifications and EOP rebranding
2 parents c258b60 + 5b7eb9d commit c8c9d80

1 file changed

Lines changed: 26 additions & 18 deletions

File tree

office-365-management-api/office-365-management-activity-api-schema.md

Lines changed: 26 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Office 365 Management Activity API schema
44
description: The Office 365 Management Activity API schema is provided as a data service in two layers - Common schema and service-specific schema.
55
ms.ContentId: 1c2bf08c-4f3b-26c0-e1b2-90b190f641f5
66
ms.topic: reference
7-
ms.date: 09/28/2025
7+
ms.date: 10/15/2025
88
ms.localizationpriority: high
99
---
1010

@@ -46,8 +46,8 @@ This article provides details on the Common schema as well as service-specific s
4646
|[Microsoft Teams schema](#microsoft-teams-schema)|Extends the Common schema with the properties specific to all Microsoft Teams events.|
4747
|[Microsoft Defender for Office 365 and Threat Investigation and Response schema](#microsoft-defender-for-office-365-and-threat-investigation-and-response-schema)|Extends the Common schema with the properties specific to Defender for Office 365 and threat investigation and response data.|
4848
|[Submission schema](#submission-schema)|Extends the Common schema with the properties specific to user and admin submissions in Microsoft Defender for Office 365.|
49-
|[Automated investigation and response events schema](#automated-investigation-and-response-events-in-office-365)|Extends the Common schema with the properties specific to Office 365 automated investigation and response (AIR) events. To see an example, see [Tech Community blog: Improve the Effectiveness of your SOC with Microsoft Defender for Office 365 and the Office 365 Management API](https://techcommunity.microsoft.com/t5/microsoft-security-and/improve-the-effectiveness-of-your-soc-with-office-365-atp-and/ba-p/1525185).|
50-
|[Hygiene events schema](#hygiene-events-schema)|Extends the Common schema with the properties specific to events in default email protections for cloud mailboxes and Microsoft Defender for Office 365.|
49+
|[Automated investigation and response events in Microsoft Defender for Office 365 Plan 2](#automated-investigation-and-response-events-in-microsoft-defender-for-office-365-plan-2)|Extends the Common schema with the properties specific to Office 365 automated investigation and response (AIR) events. To see an example, see [Tech Community blog: Improve the Effectiveness of your SOC with Microsoft Defender for Office 365 and the Office 365 Management API](https://techcommunity.microsoft.com/t5/microsoft-security-and/improve-the-effectiveness-of-your-soc-with-office-365-atp-and/ba-p/1525185).|
50+
|[Hygiene events schema](#hygiene-events-schema)|Extends the Common schema with the properties specific to events in [the built-in security features for all cloud mailboxes](/defender-office-365/eop-about) and Microsoft Defender for Office 365.|
5151
|[Power BI schema](#power-bi-schema)|Extends the Common schema with the properties specific to all Power BI events.|
5252
|[Dynamics 365 schema](#dynamics-365-schema)|Extends the Common schema with the properties specific to Dynamics 365 events.|
5353
|[Viva Insights schema](#viva-insights-schema)|Extends the Common schema with the properties specific to all Microsoft Viva Insights events.|
@@ -140,16 +140,16 @@ This article provides details on the Common schema as well as service-specific s
140140
|15|AzureActiveDirectoryStsLogon|Secure Token Service (STS) logon events in Microsoft Entra ID.|
141141
|16|SkypeForBusinessPSTNUsage|Public Switched Telephone Network (PSTN) events from Skype for Business.|
142142
|17|SkypeForBusinessUsersBlocked|Blocked user events from Skype for Business.|
143-
|18|SecurityComplianceCenterEOPCmdlet|Admin actions in [default email protections for cloud mailboxes](/defender-office-365/eop-about) from the Microsoft 365 Defender portal.|
143+
|18|SecurityComplianceCenterEOPCmdlet|Admin actions in [the built-in security features for all cloud mailboxes](/defender-office-365/eop-about) from the Microsoft Defender portal.|
144144
|19|ExchangeAggregatedOperation|Aggregated Exchange mailbox auditing events.|
145145
|20|PowerBIAudit|Power BI events.|
146146
|21|CRM|Dynamics 365 events.|
147147
|22|Viva Engage|Viva Engage events.|
148148
|23|SkypeForBusinessCmdlets|Skype for Business events.|
149149
|24|Discovery|Events for eDiscovery activities performed by running content searches and managing eDiscovery cases in the Microsoft Purview portal.|
150150
|25|MicrosoftTeams|Events from Microsoft Teams.|
151-
|28|ThreatIntelligence|Phishing and malware events from default email protections for cloud mailboxes and Microsoft Defender for Office 365.|
152-
|29|MailSubmission|Submission events from default email protections for cloud mailboxes and Microsoft Defender for Office 365.|
151+
|28|ThreatIntelligence|Phishing and malware events from [the built-in security features for all cloud mailboxes](/defender-office-365/eop-about) and Microsoft Defender for Office 365.|
152+
|29|MailSubmission|Submission events from [the built-in security features for all cloud mailboxes](/defender-office-365/eop-about) and Microsoft Defender for Office 365.|
153153
|30|MicrosoftFlow|Microsoft Power Automate (formerly called Microsoft Flow) events.|
154154
|31|AeD|Advanced eDiscovery events.|
155155
|32|MicrosoftStream|Microsoft Stream events.|
@@ -1432,17 +1432,17 @@ The UserId and UserKey of these events are always SecurityComplianceAlerts. Ther
14321432

14331433
## Microsoft Defender for Office 365 and Threat Investigation and Response schema
14341434

1435-
[Microsoft Defender for Office 365](/defender-office-365/mdo-about) and [Threat Investigation and Response](/defender-office-365/office-365-ti) events are available for Microsoft 365 customers who have Defender for Office 365, ether included or as an add-on subscription. For example, Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, and Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2.
1435+
[Microsoft Defender for Office 365](/defender-office-365/mdo-about) events are available for Microsoft 365 customers who have Defender for Office 365, ether included or as an add-on subscription. For example, Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, and Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2.
14361436

1437-
Each event in the Defender for Office 365 feed corresponds to the following events that were determined to contain a threat:
1437+
[Threat Investigation and Response](/defender-office-365/office-365-ti) events are available only to customers with Defender for Office 365 Plan 2.
14381438

1439-
- Delivered email messages acted on by [zero-hour auto purge (ZAP)](/defender-office-365/zero-hour-auto-purge).
1439+
Each event in the Defender for Office 365 feed corresponds to the following features:
1440+
1441+
- Delivered email messages detected and acted on by [zero-hour auto purge (ZAP)](/defender-office-365/zero-hour-auto-purge).
14401442
- URLs detected at time-of-click by [Safe Links](/defender-office-365/safe-links-about).
14411443
- Files detected by [Safe Attachments for SharePoint, OneDrive, and Microsoft Teams](/defender-office-365/safe-attachments-for-spo-odfb-teams-about).
1442-
- Alerts that triggered [automated investigations](/defender-office-365/air-about).
1443-
1444-
> [!NOTE]
1445-
> Threat Investigation and Response (formerly known as Office 365 Threat Intelligence) is part of Defender for Office 365 Plan 2. For more information, see [Defender for Office 365 Plan 1 vs. Plan 2 cheat sheet](/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet) and the [Defender for Office 365 Service Description](/office365/servicedescriptions/office-365-advanced-threat-protection-service-description).
1444+
- Alerts that triggered [automated investigations](/defender-office-365/air-about) (Defender for Office 365 Plan 2 only).
1445+
- [Attack simulation training](/defender-office-365/attack-simulation-training-get-started) events (Defender for Office 365 Plan 2 only).
14461446

14471447
### Email message events
14481448

@@ -1515,7 +1515,7 @@ Each event in the Defender for Office 365 feed corresponds to the following even
15151515
|SHA256|Edm.String|Yes|The file SHA256 hash.|
15161516

15171517
> [!NOTE]
1518-
> Within the Malware family, you'll be able to see the exact MalwareFamily name (for example, HTML/Phish.VS!MSR) or Malicious Payload as a static string. A Malicious Payload should still be treated as malicious email when a specific name isn't identified.
1518+
> Within the Malware family, you see the exact MalwareFamily name (for example, HTML/Phish.VS!MSR) or Malicious Payload as a static string. A Malicious Payload should still be treated as malicious email when a specific name isn't identified.
15191519
15201520
### SystemOverrides complex type
15211521

@@ -1646,9 +1646,11 @@ Each event in the Defender for Office 365 feed corresponds to the following even
16461646
|1|OneDrive|
16471647
|2|Microsoft Teams|
16481648

1649-
## Attack Sim schema
1649+
<a name='attack-sim-schema'></a>
1650+
1651+
## Attack Sim schema in Microsoft Defender for Office 365 Plan 2
16501652

1651-
For more information about attack simulation and training in Defender for Office 365 Plan 2, see [Get started using Attack simulation training](/defender-office-365/attack-simulation-training-get-started).
1653+
[Attack simulation training](/defender-office-365/attack-simulation-training-get-started) events are available for Microsoft 365 customers who have Defender for Office 365 Plan 2, either included or as an add-on subscription. For example Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2.
16521654

16531655
|Parameters|Type|Mandatory?|Description|
16541656
|---|---|---|---|
@@ -1680,7 +1682,11 @@ For more information about attack simulation and training in Defender for Office
16801682
|17|OutOfOffice|Automatic replies in Outlook enabled for recipient.|
16811683
|18|PositiveReinforcementMessageDelivered|Positive reinforcement message delivered successfully to recipient.|
16821684

1683-
## Attack Sim Admin schema
1685+
<a name='attack-sim-admin-schema'></a>
1686+
1687+
## Attack Sim Admin schema in Microsoft Defender for Office 365 Plan 2
1688+
1689+
[Attack simulation training](/defender-office-365/attack-simulation-training-get-started) admin events are available for Microsoft 365 customers who have Defender for Office 365 Plan 2, either included or as an add-on subscription. For example Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2.
16841690

16851691
|Parameters|Type|Mandatory?|Description|
16861692
|---|---|---|---|
@@ -1759,7 +1765,9 @@ Events for submitting false positives or false negatives to Microsoft for analys
17591765
|AdminSubmissionTablAllow|Edm.String|No|An allow entry in the [Tenant Allow/Block List](/defender-office-365/tenant-allow-block-list-about) was created at time of submission to immediately take action on similar messages while it is being rescanned.|
17601766
|SubmissionNotification|Edm.String|No|Admin feedback is sent to end user.|
17611767

1762-
## Automated investigation and response events in Office 365
1768+
<a name='automated-investigation-and-response-events-in-office-365'></a>
1769+
1770+
## Automated investigation and response events in Microsoft Defender for Office 365 Plan 2
17631771

17641772
[Automated investigation and response (AIR)](/defender-office-365/air-about) events are available for Microsoft 365 customers who have Defender for Office 365 Plan 2, either included or as an add-on subscription. For example Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2.
17651773

0 commit comments

Comments
 (0)