MicrosoftPurviewInformationProtection

MicrosoftPurviewInformationProtection Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel Microsoft Purview Information Protection audit logs.

Table retention #

HotDays ColdDays TotalInteractiveDays
14 76 90

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
ActionSource The source of the label action. String
ActionSourceDetail More details about the source of the label action. String
AppAccessContext The application context for the user or service principal that performed the action. Object
Application The application that where the activity happened. String
ApplicationMode The label application mode, how the label was applied. String
ClientIP The IP address of the device that was used when the activity was logged. The IP address is displayed in either an IPv4 or IPv6 address format. String
Common Azure Information Protection - common event data. Object
ConditionMatch The condition match that triggered the auto labeling. Object
ContentType Content type. String
CorrelationId Correlation ID. String
CurrentProtectionType Current protection event information. Object
CurrentProtectionTypeName The type of protection applied. String
DataState Azure Information Protection - data state. String
DeviceName The device on which the activity happened. String
EmailInfo The information required when the internalTarget is an email. Object
ExchangeMetaData Exchange auto labeling metadata. Object
ExecutionRuleId The ID of the rule that was executed. String
ExecutionRuleName The name of the rule that was executed. String
ExecutionRuleVersion The version of the rule that was executed. String
Id Unique identifier of an audit record. String
IrmContentId The unique ID used for identifying the encrypted document after the operation is complete. String
IsViewableByExternalUsers Is viewable by external users. Boolean
ItemCreationTime The date and time the item was created. DateTime
ItemLastModifiedTime The date and time the item was last modified. DateTime
ItemName The item name. String
ItemSize The item size. String
JustificationText The justification to be provided, when configured by the admin in the sensitivity label policy, only when the sensitivity label is downgraded or removed by the user. String
LabelAction The action applied by the label. String
LabelAppliedDateTime The date and time the label was applied. DateTime
LabelEventType The label operation. String
LabelName The label name applied to the item. String
LabelVersion The label version applied by the auto labeling policy. String
MachineName The machine name. String
MgtRuleId Management rule ID. String
ObjectId For SharePoint and OneDrive for Business activity, the full path name of the file or folder accessed by the user. For Exchange admin audit logging, the name of the object that was modified by the cmdlet. String
OldSensitivityLabelId The identifier of the sensitivity label previously applied to the document before the operation to change/remove the label was triggered. String
OldSensitivityLabelOwnerEmail The email address of the owner of the old sensitivity label. String
Operation The name of the user or admin activity. String
OrganizationId The GUID for your organization’s Office 365 tenant. This value will always be the same for your organization, regardless of the Office 365 service in which it occurs. String
OverriddenActions Actions that were overridden by the rule actions. Object
OverRideReason The reason the sensitivity label was overridden. String
OverRideType Override type. String
Platform The platform on which the activity happened. String
PolicyId Policy ID. String
PolicyName Policy name. String
PolicyVersion Policy version. String
PreviousProtectionType Previous protection event information. Object
PreviousProtectionTypeName Previous protection type. String
ProtectionEventData Azure Information Protection - protection event data. Object
ProtectionEventTypeName Protection event type name. String
Receivers The email addresses of the receivers. Object
RecordType The type of operation indicated by the record. Int32
RecordTypeName The record type name. String
ResultStatus Indicates whether the action (specified in the Operation property) was successful or not. Possible values are Succeeded, PartiallySucceeded, or Failed. For Exchange admin activity, the value is either True or False. String
RuleActions Actions defined by the rules. Object
RuleMode The current mode of the rule. String
Scope Was this event created by a hosted O365 service or an on-premises server. String
ScopedLocationId The address that triggered the policy match. String
Sender The email address of the sender. String
SensitiveInfoDetectionIsIncluded Determines if sensitive info detection is included. Boolean
SensitiveInfoTypeData Azure Information Protection - sensitive information types. Object
SensitivityLabelId The identifier for the sensitivity label recommended, as per the policy that was matched based on the contents of the document. String
SensitivityLabelOwnerEmail The email address of the owner of the sensitivity label. String
SensitivityLabelPolicyId The identifier for the sensitivity labeling policy that was matched based on the content of the document. String
Severity The severity of the auto label policy match. String
SharePointMetaData SharePoint auto labeling metadata. Object
SourceSystem String
TargetLocation The location of the document with respect to the user’ device. String
TenantId String
TimeGenerated The date and time when the user performed the activity. DateTime
Type The name of the table String
UserId The UPN (User Principal Name) of the user who performed the action (specified in the Operation property) that resulted in the record being logged. String
UserKey An alternative ID for the user identified in the UserId property. This property is populated with the passport unique ID (PUID) for events performed by users in SharePoint, OneDrive for Business, and Exchange. String
UserType The type of user that performed the operation. String
Workload The Office 365 service where the activity occurred. String
WorkLoadItemId The workload item id. String

Schema changes #

Date Action
2024-10-18 Table added to tracking