Skip to content

Latest commit

 

History

History
41 lines (31 loc) · 1.29 KB

File metadata and controls

41 lines (31 loc) · 1.29 KB
title airAdminActionInvestigationData resource type
description Represents an audit record for Automated Investigation and Response (AIR) admin action investigation events.
author diksha27
ms.subservice compliance
ms.localizationpriority medium
doc_type resourcePageType
ms.date 03/05/2026
toc.title AIR admin action investigation data

airAdminActionInvestigationData resource type

Namespace: microsoft.graph.security

[!INCLUDE beta-disclaimer]

Represents an audit record for Automated Investigation and Response (AIR) admin action investigation events. This resource captures information about administrative actions taken during automated threat investigations in Microsoft Defender.

Inherits from microsoft.graph.security.auditData. The audit data for this record type is returned as the auditData property in an auditLogRecord.

Properties

None.

Relationships

None.

JSON representation

The following JSON representation shows the resource type.

{
  "@odata.type": "#microsoft.graph.security.airAdminActionInvestigationData"
}