You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@@ -46,8 +46,8 @@ This article provides details on the Common schema as well as service-specific s
46
46
|[Microsoft Teams schema](#microsoft-teams-schema)|Extends the Common schema with the properties specific to all Microsoft Teams events.|
47
47
|[Microsoft Defender for Office 365 and Threat Investigation and Response schema](#microsoft-defender-for-office-365-and-threat-investigation-and-response-schema)|Extends the Common schema with the properties specific to Defender for Office 365 and threat investigation and response data.|
48
48
|[Submission schema](#submission-schema)|Extends the Common schema with the properties specific to user and admin submissions in Microsoft Defender for Office 365.|
49
-
|[Automated investigation and response events schema](#automated-investigation-and-response-events-in-office-365)|Extends the Common schema with the properties specific to Office 365 automated investigation and response (AIR) events. To see an example, see [Tech Community blog: Improve the Effectiveness of your SOC with Microsoft Defender for Office 365 and the Office 365 Management API](https://techcommunity.microsoft.com/t5/microsoft-security-and/improve-the-effectiveness-of-your-soc-with-office-365-atp-and/ba-p/1525185).|
50
-
|[Hygiene events schema](#hygiene-events-schema)|Extends the Common schema with the properties specific to events in default email protections for cloud mailboxes and Microsoft Defender for Office 365.|
49
+
|[Automated investigation and response events in Microsoft Defender for Office 365 Plan 2](#automated-investigation-and-response-events-in-microsoft-defender-for-office-365-plan-2)|Extends the Common schema with the properties specific to Office 365 automated investigation and response (AIR) events. To see an example, see [Tech Community blog: Improve the Effectiveness of your SOC with Microsoft Defender for Office 365 and the Office 365 Management API](https://techcommunity.microsoft.com/t5/microsoft-security-and/improve-the-effectiveness-of-your-soc-with-office-365-atp-and/ba-p/1525185).|
50
+
|[Hygiene events schema](#hygiene-events-schema)|Extends the Common schema with the properties specific to events in [the built-in security features for all cloud mailboxes](/defender-office-365/eop-about) and Microsoft Defender for Office 365.|
51
51
|[Power BI schema](#power-bi-schema)|Extends the Common schema with the properties specific to all Power BI events.|
52
52
|[Dynamics 365 schema](#dynamics-365-schema)|Extends the Common schema with the properties specific to Dynamics 365 events.|
53
53
|[Viva Insights schema](#viva-insights-schema)|Extends the Common schema with the properties specific to all Microsoft Viva Insights events.|
@@ -140,16 +140,16 @@ This article provides details on the Common schema as well as service-specific s
140
140
|15|AzureActiveDirectoryStsLogon|Secure Token Service (STS) logon events in Microsoft Entra ID.|
141
141
|16|SkypeForBusinessPSTNUsage|Public Switched Telephone Network (PSTN) events from Skype for Business.|
142
142
|17|SkypeForBusinessUsersBlocked|Blocked user events from Skype for Business.|
143
-
|18|SecurityComplianceCenterEOPCmdlet|Admin actions in [default email protections for cloud mailboxes](/defender-office-365/eop-about) from the Microsoft 365 Defender portal.|
143
+
|18|SecurityComplianceCenterEOPCmdlet|Admin actions in [the built-in security features for all cloud mailboxes](/defender-office-365/eop-about) from the Microsoft Defender portal.|
|23|SkypeForBusinessCmdlets|Skype for Business events.|
149
149
|24|Discovery|Events for eDiscovery activities performed by running content searches and managing eDiscovery cases in the Microsoft Purview portal.|
150
150
|25|MicrosoftTeams|Events from Microsoft Teams.|
151
-
|28|ThreatIntelligence|Phishing and malware events from default email protections for cloud mailboxes and Microsoft Defender for Office 365.|
152
-
|29|MailSubmission|Submission events from default email protections for cloud mailboxes and Microsoft Defender for Office 365.|
151
+
|28|ThreatIntelligence|Phishing and malware events from [the built-in security features for all cloud mailboxes](/defender-office-365/eop-about) and Microsoft Defender for Office 365.|
152
+
|29|MailSubmission|Submission events from [the built-in security features for all cloud mailboxes](/defender-office-365/eop-about) and Microsoft Defender for Office 365.|
153
153
|30|MicrosoftFlow|Microsoft Power Automate (formerly called Microsoft Flow) events.|
154
154
|31|AeD|Advanced eDiscovery events.|
155
155
|32|MicrosoftStream|Microsoft Stream events.|
@@ -1432,17 +1432,17 @@ The UserId and UserKey of these events are always SecurityComplianceAlerts. Ther
1432
1432
1433
1433
## Microsoft Defender for Office 365 and Threat Investigation and Response schema
1434
1434
1435
-
[Microsoft Defender for Office 365](/defender-office-365/mdo-about)and [Threat Investigation and Response](/defender-office-365/office-365-ti)events are available for Microsoft 365 customers who have Defender for Office 365, ether included or as an add-on subscription. For example, Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, and Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2.
1435
+
[Microsoft Defender for Office 365](/defender-office-365/mdo-about) events are available for Microsoft 365 customers who have Defender for Office 365, ether included or as an add-on subscription. For example, Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, and Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2.
1436
1436
1437
-
Each event in the Defender for Office 365 feed corresponds to the following events that were determined to contain a threat:
1437
+
[Threat Investigation and Response](/defender-office-365/office-365-ti) events are available only to customers with Defender for Office 365 Plan 2.
1438
1438
1439
-
- Delivered email messages acted on by [zero-hour auto purge (ZAP)](/defender-office-365/zero-hour-auto-purge).
1439
+
Each event in the Defender for Office 365 feed corresponds to the following features:
1440
+
1441
+
- Delivered email messages detected and acted on by [zero-hour auto purge (ZAP)](/defender-office-365/zero-hour-auto-purge).
1440
1442
- URLs detected at time-of-click by [Safe Links](/defender-office-365/safe-links-about).
1441
1443
- Files detected by [Safe Attachments for SharePoint, OneDrive, and Microsoft Teams](/defender-office-365/safe-attachments-for-spo-odfb-teams-about).
1442
-
- Alerts that triggered [automated investigations](/defender-office-365/air-about).
1443
-
1444
-
> [!NOTE]
1445
-
> Threat Investigation and Response (formerly known as Office 365 Threat Intelligence) is part of Defender for Office 365 Plan 2. For more information, see [Defender for Office 365 Plan 1 vs. Plan 2 cheat sheet](/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet) and the [Defender for Office 365 Service Description](/office365/servicedescriptions/office-365-advanced-threat-protection-service-description).
1444
+
- Alerts that triggered [automated investigations](/defender-office-365/air-about) (Defender for Office 365 Plan 2 only).
1445
+
-[Attack simulation training](/defender-office-365/attack-simulation-training-get-started) events (Defender for Office 365 Plan 2 only).
1446
1446
1447
1447
### Email message events
1448
1448
@@ -1515,7 +1515,7 @@ Each event in the Defender for Office 365 feed corresponds to the following even
1515
1515
|SHA256|Edm.String|Yes|The file SHA256 hash.|
1516
1516
1517
1517
> [!NOTE]
1518
-
> Within the Malware family, you'll be able to see the exact MalwareFamily name (for example, HTML/Phish.VS!MSR) or Malicious Payload as a static string. A Malicious Payload should still be treated as malicious email when a specific name isn't identified.
1518
+
> Within the Malware family, you see the exact MalwareFamily name (for example, HTML/Phish.VS!MSR) or Malicious Payload as a static string. A Malicious Payload should still be treated as malicious email when a specific name isn't identified.
1519
1519
1520
1520
### SystemOverrides complex type
1521
1521
@@ -1646,9 +1646,11 @@ Each event in the Defender for Office 365 feed corresponds to the following even
1646
1646
|1|OneDrive|
1647
1647
|2|Microsoft Teams|
1648
1648
1649
-
## Attack Sim schema
1649
+
<aname='attack-sim-schema'></a>
1650
+
1651
+
## Attack Sim schema in Microsoft Defender for Office 365 Plan 2
1650
1652
1651
-
For more information about attack simulation and training in Defender for Office 365 Plan 2, see [Get started using Attack simulation training](/defender-office-365/attack-simulation-training-get-started).
1653
+
[Attack simulation training](/defender-office-365/attack-simulation-training-get-started) events are available for Microsoft 365 customers who have Defender for Office 365 Plan 2, either included or as an add-on subscription. For example Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2.
1652
1654
1653
1655
|Parameters|Type|Mandatory?|Description|
1654
1656
|---|---|---|---|
@@ -1680,7 +1682,11 @@ For more information about attack simulation and training in Defender for Office
1680
1682
|17|OutOfOffice|Automatic replies in Outlook enabled for recipient.|
1681
1683
|18|PositiveReinforcementMessageDelivered|Positive reinforcement message delivered successfully to recipient.|
1682
1684
1683
-
## Attack Sim Admin schema
1685
+
<aname='attack-sim-admin-schema'></a>
1686
+
1687
+
## Attack Sim Admin schema in Microsoft Defender for Office 365 Plan 2
1688
+
1689
+
[Attack simulation training](/defender-office-365/attack-simulation-training-get-started) admin events are available for Microsoft 365 customers who have Defender for Office 365 Plan 2, either included or as an add-on subscription. For example Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2.
1684
1690
1685
1691
|Parameters|Type|Mandatory?|Description|
1686
1692
|---|---|---|---|
@@ -1759,7 +1765,9 @@ Events for submitting false positives or false negatives to Microsoft for analys
1759
1765
|AdminSubmissionTablAllow|Edm.String|No|An allow entry in the [Tenant Allow/Block List](/defender-office-365/tenant-allow-block-list-about) was created at time of submission to immediately take action on similar messages while it is being rescanned.|
1760
1766
|SubmissionNotification|Edm.String|No|Admin feedback is sent to end user.|
1761
1767
1762
-
## Automated investigation and response events in Office 365
## Automated investigation and response events in Microsoft Defender for Office 365 Plan 2
1763
1771
1764
1772
[Automated investigation and response (AIR)](/defender-office-365/air-about) events are available for Microsoft 365 customers who have Defender for Office 365 Plan 2, either included or as an add-on subscription. For example Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2.
0 commit comments