Skip to main content

CollectorsCloud Collectors Administration Guide

Supported Sources from Microsoft 365 Management Activity

This table lists the data sources and endpoints supported by the Microsoft 365 Management Activity collector. You must have the minimum required subscriptions associated with your Microsoft account in order to collect data from the data sources supported by the collector.

Service Covered

Data Sources

Endpoint/API 

Notes

Active Directory

Active Directory

Management Activity API

Azure Active Directory events. The following Audit Record Types are supported:

  • AzureActiveDirectory

  • AzureActiveDirectoryAccountLogon

  • AzureActiveDirectoryStsLogon

Audit Events

General

Management Activity API

Microsoft 365 audit events. The following Audit Record Types are supported:

  • DataCenterSecurityCmdlet

  • Sway

  • SecurityComplianceCenterEOPCmdlet

  • PowerBIAudit

  • CRM

  • Yammer

  • SkypeForBusinessCmdlets

  • Discover

  • MicrosoftTeams

  • ThreatIntelligence

  • MicrosoftFlow

  • MicrosoftStream

  • Project

  • DataGovernance

  • SecurityComplianceAlerts

  • ThreatIntelligenceUrl

  • WorkplaceAnalytics

  • PowerAppsApp

  • ThreatIntelligenceAtpContent

SharePoint

SharePoint

Management Activity API

SharePoint administrative and file management operations. The following Audit Record Types are supported:

  • SharePoint

  • SharePointFileOperation

  • SharePointSharingOperation

  • SharePointListOperation

Exchange 

Exchange

Management Activity API

Events from the Exchange admin audit log. Events from an Exchange mailbox audit log for actions that are performed on a single item, such as creating or receiving an email message. Events from an Exchange mailbox audit log for actions that can be performed on multiple items, such as moving or deleted one or more email messages.

The following Audit Record Types are supported:

  • ExchangeAdmin

  • ExchangeItem

  • ExchangeItemGroup

DLP

DLP

Management Activity API

Data loss protection (DLP) events in SharePoint and OneDrive for Business. Data loss protection (DLP) events in Exchange, when configured via Unified DLP Policy. DLP events based on Exchange Transport Rules are not supported.

The following Audit Record Types are supported:

  • ComplianceDLPExchange

  • ComplianceDLPSharePoint