| AccountObjectId |
Unique identifier for the account in Microsoft Entra ID |
String |
| AccountUpn |
User principal name (UPN) of the account |
String |
| ActionType |
Type of activity that triggered the event |
String |
| ActivityId |
Unique identifier of the activity log |
String |
| AlertInfo |
Information about the alert to which the activity is a part of |
Object |
| ApplicationNames |
List of application names used or related to the event |
String |
| AttachmentInfo |
Details of attachments |
Object |
| CcPolicyMatchInfo |
Details of the Communications Compliance policy matches for this event |
Object |
| ContentInfo |
Information about the content involved in the event |
Object |
| Department |
Name of the department that the account user belongs to |
String |
| DeviceDestinationLocationType |
Indicates the type of location where the endpoint signals connected to; values can be: 0 (Unknown), 1 (Local), 2 (Remote), 3 (Removable), 4 (Cloud), 5 (File share) |
String |
| DeviceInfo |
List of device information for the device involved in this behavior, including device ID, device name, and the number of events in which the device is involved |
Object |
| DeviceSourceLocationType |
Indicates the type of location where the endpoint signals originated from; values can be: 0 (Unknown), 1 (Local), 2 (Remote), 3 (Removable), 4 (Cloud), 5 (File share) |
String |
| DlpPolicyEnforcementMode |
Indicates the Data Loss Prevention policy that was enforced; value can be: 0 (None), 1 (Audit), 2 (Warn), 3 (Warn and bypass), 4 (Block), 5 (Allow) |
Int32 |
| DlpPolicyMatchInfo |
Information around the list of data loss prevention (DLP) policies matching this event |
Object |
| DlpPolicyRuleMatchInfo |
Details of the data loss prevention (DLP) rules that matched with this event |
Object |
| EmailSubject |
Subject of the email |
String |
| EventTime |
Indicates the timestamp of when the event occurred |
DateTime |
| ExternalUrlDomains |
Websites or service URLs involved in this event that are classified as External in Insider Risk Management global settings |
String |
| FileRenameInfo |
Details of the file (file name and extension) prior to this event |
Object |
| InternetMessageId |
Public-facing identifier for the email that is set by the sending email system |
String |
| IPAddress |
IP addresses of the clients on which the activity was performed; can contain multiple Ips if related to Microsoft Defender for Cloud Apps alerts |
String |
| IrmActionCategory |
A unique enumeration value indicating the activity category in Microsoft Purview Insider Risk Management |
String |
| IrmPolicyMatchInfo |
Details of Insider Risk Management policy matches for the content involved in the event |
Object |
| IrmSequenceInfo |
Information about the sequence of activities in the event |
Object |
| IsIrmInteresting |
Indicates if the event is included in insider risk alerts (true) or not (false) |
Boolean |
| NetworkMessageId |
Unique identifier for the email, generated by Microsoft 365 |
String |
| ObjectId |
Unique identifier of the object that the recorded action was applied to, in case of files it includes the extension |
String |
| Operation |
Name of the admin activity |
String |
| ParentContentInfo |
Information about the parent content of the content involved in the event |
Object |
| PhysicalAccessPointInfo |
Information about the physical access in the event, including the physical access point’s unique identifier, name, status, and the tag assigned to the asset |
Object |
| PreviousSensitivityLabelId |
The previous Microsoft Information Protection sensitivity label ID associated with the item in case of activities where the sensitivity label was changed |
String |
| PrinterName |
List of printers involved in the behavior |
String |
| Recipients |
List of information about the recipient involved in the behavior, including the email address of the recipient and the number of events in the behavior involving the recipient |
String |
| RemovableMediaInfo |
List of any removable media involved in the behavior, including the serial number of the removable media deivce, the manufacturer of the removable media device, and the model of the removable device |
Object |
| RiskyAIUsageAccessedResourceInfo |
Details of the resources accessed or referenced by the application involved in the risky AI usage event |
Object |
| RiskyAIUsageAppCategory |
Details of the category of the application involved in the risky AI usage event |
String |
| RiskyAIUsageSensitivityLabelsInfo |
Information regarding the sensitivity labels of entities involved in the risky AI usage event |
Object |
| SensitiveInfoTypeInfo |
Details of Data Loss Prevention sensitive info types detected in the impacted asset |
Object |
| SensitivityLabelId |
The current Microsoft Information Protection sensitivity label ID associated with the item |
String |
| SharepointSiteSensitivityLabelId |
The current Microsoft Information Protection sensitivity label ID assigned to the parent site of the item related to SharePoint activities |
String |
| SourceCodeInfo |
Details of the source code repository involved in the event |
Object |
| SourceRelativeUrl |
The URL of the folder that contains the file accessed by the user |
String |
| SourceSystem |
|
String |
| SourceUrlDomain |
Domain where the device and email signals originated |
String |
| TargetFilePath |
Target file path of endpoint activities |
String |
| TargetUrlDomain |
Domain where the content was shared with or the user has browsed to |
String |
| TeamsChannelInfo |
Information about the Teams channel involved in the event |
Object |
| TenantId |
|
String |
| TimeGenerated |
|
DateTime |
| Timestamp |
Date and time when the record was generated |
DateTime |
| Type |
|
String |
| UnallowedUrlDomains |
Websites or service URLs involved in this event that are configured as Unallowed in Insider Risk Management global settings |
String |
| UrlDomainInfo |
Details about the websites or service URLs involved in the event |
Object |
| UserAlternateEmails |
Alternate emails or aliases of the user |
String |
| Workload |
The Microsoft 365 service where the event occurred |
String |