| title | airAdminActionInvestigationData resource type |
|---|---|
| description | Represents an audit record for Automated Investigation and Response (AIR) admin action investigation events. |
| author | diksha27 |
| ms.subservice | compliance |
| ms.localizationpriority | medium |
| doc_type | resourcePageType |
| ms.date | 03/05/2026 |
| toc.title | AIR admin action investigation data |
Namespace: microsoft.graph.security
[!INCLUDE beta-disclaimer]
Represents an audit record for Automated Investigation and Response (AIR) admin action investigation events. This resource captures information about administrative actions taken during automated threat investigations in Microsoft Defender.
Inherits from microsoft.graph.security.auditData. The audit data for this record type is returned as the auditData property in an auditLogRecord.
None.
None.
The following JSON representation shows the resource type.
{
"@odata.type": "#microsoft.graph.security.airAdminActionInvestigationData"
}