Skip to content

Commit b0fc12b

Browse files
diksha27guptadiksha_microsoftmsewaweruFaithOmbongi
authored
Users/guptadiksha/auditcore doc changes (#28450)
* Add 157 new auditLogRecordType enum members for AuditCore CSDL update * Add 132 new auditData derived type resource docs for AuditCore CSDL update - Created resource documentation for 132 new audit record types - Updated auditdata-derived-types.md listing page (272 -> 404 entries) - New types cover Copilot, Sentinel, Viva Glint, Defender, Purview, Fabric, and other M365 services * Fix duplicate description attributes across resource files * Add ConnectedAIAppInteraction member to auditLogRecordType enum * Add connectedAIAppInteractionAuditRecord resource and derived type entry * Refactor security audit log record type enum and update documentation * Update the author of the new files * Update changelog date, add what's new --------- Co-authored-by: guptadiksha_microsoft <guptadiksha@microsoft.com> Co-authored-by: Eunice Waweru <eunicewaweru@microsoft.com> Co-authored-by: Faith Moraa Ombongi <ombongi.moraa.fe@gmail.com>
1 parent c8041aa commit b0fc12b

144 files changed

Lines changed: 6125 additions & 553 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

api-reference/beta/resources/enums-security.md

Lines changed: 0 additions & 293 deletions
Original file line numberDiff line numberDiff line change
@@ -281,299 +281,6 @@ Namespace: microsoft.graph.security
281281
|cancelled|
282282
|unknownFutureValue|
283283

284-
### auditLogRecordType values
285-
286-
|Member|
287-
|:---|
288-
|ExchangeAdmin|
289-
|ExchangeItem|
290-
|ExchangeItemGroup|
291-
|SharePoint|
292-
|SyntheticProbe|
293-
|SharePointFileOperation|
294-
|OneDrive|
295-
|AzureActiveDirectory|
296-
|AzureActiveDirectoryAccountLogon|
297-
|DataCenterSecurityCmdlet|
298-
|ComplianceDLPSharePoint|
299-
|Sway|
300-
|ComplianceDLPExchange|
301-
|SharePointSharingOperation|
302-
|AzureActiveDirectoryStsLogon|
303-
|SkypeForBusinessPSTNUsage|
304-
|SkypeForBusinessUsersBlocked|
305-
|SecurityComplianceCenterEOPCmdlet|
306-
|ExchangeAggregatedOperation|
307-
|PowerBIAudit|
308-
|CRM|
309-
|Yammer|
310-
|SkypeForBusinessCmdlets|
311-
|Discovery|
312-
|MicrosoftTeams|
313-
|ThreatIntelligence|
314-
|MailSubmission|
315-
|MicrosoftFlow|
316-
|AeD|
317-
|MicrosoftStream|
318-
|ComplianceDLPSharePointClassification|
319-
|ThreatFinder|
320-
|Project|
321-
|SharePointListOperation|
322-
|SharePointCommentOperation|
323-
|DataGovernance|
324-
|Kaizala|
325-
|SecurityComplianceAlerts|
326-
|ThreatIntelligenceUrl|
327-
|SecurityComplianceInsights|
328-
|MIPLabel|
329-
|WorkplaceAnalytics|
330-
|PowerAppsApp|
331-
|PowerAppsPlan|
332-
|ThreatIntelligenceAtpContent|
333-
|LabelContentExplorer|
334-
|TeamsHealthcare|
335-
|ExchangeItemAggregated|
336-
|HygieneEvent|
337-
|DataInsightsRestApiAudit|
338-
|InformationBarrierPolicyApplication|
339-
|SharePointListItemOperation|
340-
|SharePointContentTypeOperation|
341-
|SharePointFieldOperation|
342-
|MicrosoftTeamsAdmin|
343-
|HRSignal|
344-
|MicrosoftTeamsDevice|
345-
|MicrosoftTeamsAnalytics|
346-
|InformationWorkerProtection|
347-
|Campaign|
348-
|DLPEndpoint|
349-
|AirInvestigation|
350-
|Quarantine|
351-
|MicrosoftForms|
352-
|ApplicationAudit|
353-
|ComplianceSupervisionExchange|
354-
|CustomerKeyServiceEncryption|
355-
|OfficeNative|
356-
|MipAutoLabelSharePointItem|
357-
|MipAutoLabelSharePointPolicyLocation|
358-
|MicrosoftTeamsShifts|
359-
|SecureScore|
360-
|MipAutoLabelExchangeItem|
361-
|CortanaBriefing|
362-
|Search|
363-
|WDATPAlerts|
364-
|PowerPlatformAdminDlp|
365-
|PowerPlatformAdminEnvironment|
366-
|MDATPAudit|
367-
|SensitivityLabelPolicyMatch|
368-
|SensitivityLabelAction|
369-
|SensitivityLabeledFileAction|
370-
|AttackSim|
371-
|AirManualInvestigation|
372-
|SecurityComplianceRBAC|
373-
|UserTraining|
374-
|AirAdminActionInvestigation|
375-
|MSTIC|
376-
|PhysicalBadgingSignal|
377-
|TeamsEasyApprovals|
378-
|AipDiscover|
379-
|AipSensitivityLabelAction|
380-
|AipProtectionAction|
381-
|AipFileDeleted|
382-
|AipHeartBeat|
383-
|MCASAlerts|
384-
|OnPremisesFileShareScannerDlp|
385-
|OnPremisesSharePointScannerDlp|
386-
|ExchangeSearch|
387-
|SharePointSearch|
388-
|PrivacyDataMinimization|
389-
|LabelAnalyticsAggregate|
390-
|MyAnalyticsSettings|
391-
|SecurityComplianceUserChange|
392-
|ComplianceDLPExchangeClassification|
393-
|ComplianceDLPEndpoint|
394-
|MipExactDataMatch|
395-
|MSDEResponseActions|
396-
|MSDEGeneralSettings|
397-
|MSDEIndicatorsSettings|
398-
|MS365DCustomDetection|
399-
|MSDERolesSettings|
400-
|MAPGAlerts|
401-
|MAPGPolicy|
402-
|MAPGRemediation|
403-
|PrivacyRemediationAction|
404-
|PrivacyDigestEmail|
405-
|MipAutoLabelSimulationProgress|
406-
|MipAutoLabelSimulationCompletion|
407-
|MipAutoLabelProgressFeedback|
408-
|DlpSensitiveInformationType|
409-
|MipAutoLabelSimulationStatistics|
410-
|LargeContentMetadata|
411-
|Microsoft365Group|
412-
|CDPMlInferencingResult|
413-
|FilteringMailMetadata|
414-
|CDPClassificationMailItem|
415-
|CDPClassificationDocument|
416-
|OfficeScriptsRunAction|
417-
|FilteringPostMailDeliveryAction|
418-
|CDPUnifiedFeedback|
419-
|TenantAllowBlockList|
420-
|ConsumptionResource|
421-
|HealthcareSignal|
422-
|DlpImportResult|
423-
|CDPCompliancePolicyExecution|
424-
|MultiStageDisposition|
425-
|PrivacyDataMatch|
426-
|FilteringDocMetadata|
427-
|FilteringEmailFeatures|
428-
|PowerBIDlp|
429-
|FilteringUrlInfo|
430-
|FilteringAttachmentInfo|
431-
|CoreReportingSettings|
432-
|ComplianceConnector|
433-
|PowerPlatformLockboxResourceAccessRequest|
434-
|PowerPlatformLockboxResourceCommand|
435-
|CDPPredictiveCodingLabel|
436-
|CDPCompliancePolicyUserFeedback|
437-
|WebpageActivityEndpoint|
438-
|OMEPortal|
439-
|CMImprovementActionChange|
440-
|FilteringUrlClick|
441-
|MipLabelAnalyticsAuditRecord|
442-
|FilteringEntityEvent|
443-
|FilteringRuleHits|
444-
|FilteringMailSubmission|
445-
|LabelExplorer|
446-
|MicrosoftManagedServicePlatform|
447-
|PowerPlatformServiceActivity|
448-
|ScorePlatformGenericAuditRecord|
449-
|FilteringTimeTravelDocMetadata|
450-
|Alert|
451-
|AlertStatus|
452-
|AlertIncident|
453-
|IncidentStatus|
454-
|Case|
455-
|CaseInvestigation|
456-
|RecordsManagement|
457-
|PrivacyRemediation|
458-
|DataShareOperation|
459-
|CdpDlpSensitive|
460-
|EHRConnector|
461-
|FilteringMailGradingResult|
462-
|PublicFolder|
463-
|PrivacyTenantAuditHistoryRecord|
464-
|AipScannerDiscoverEvent|
465-
|EduDataLakeDownloadOperation|
466-
|M365ComplianceConnector|
467-
|MicrosoftGraphDataConnectOperation|
468-
|MicrosoftPurview|
469-
|FilteringEmailContentFeatures|
470-
|PowerPagesSite|
471-
|PowerAppsResource|
472-
|PlannerPlan|
473-
|PlannerCopyPlan|
474-
|PlannerTask|
475-
|PlannerRoster|
476-
|PlannerPlanList|
477-
|PlannerTaskList|
478-
|PlannerTenantSettings|
479-
|ProjectForTheWebProject|
480-
|ProjectForTheWebTask|
481-
|ProjectForTheWebRoadmap|
482-
|ProjectForTheWebRoadmapItem|
483-
|ProjectForTheWebProjectSettings|
484-
|ProjectForTheWebRoadmapSettings|
485-
|QuarantineMetadata|
486-
|MicrosoftTodoAudit|
487-
|TimeTravelFilteringDocMetadata|
488-
|TeamsQuarantineMetadata|
489-
|SharePointAppPermissionOperation|
490-
|MicrosoftTeamsSensitivityLabelAction|
491-
|FilteringTeamsMetadata|
492-
|FilteringTeamsUrlInfo|
493-
|FilteringTeamsPostDeliveryAction|
494-
|MDCAssessments|
495-
|MDCRegulatoryComplianceStandards|
496-
|MDCRegulatoryComplianceControls|
497-
|MDCRegulatoryComplianceAssessments|
498-
|MDCSecurityConnectors|
499-
|MDADataSecuritySignal|
500-
|VivaGoals|
501-
|FilteringRuntimeInfo|
502-
|AttackSimAdmin|
503-
|MicrosoftGraphDataConnectConsent|
504-
|FilteringAtpDetonationInfo|
505-
|PrivacyPortal|
506-
|ManagedTenants|
507-
|UnifiedSimulationMatchedItem|
508-
|UnifiedSimulationSummary|
509-
|UpdateQuarantineMetadata|
510-
|MS365DSuppressionRule|
511-
|PurviewDataMapOperation|
512-
|FilteringUrlPostClickAction|
513-
|IrmUserDefinedDetectionSignal|
514-
|TeamsUpdates|
515-
|PlannerRosterSensitivityLabel|
516-
|MS365DIncident|
517-
|FilteringDelistingMetadata|
518-
|ComplianceDLPSharePointClassificationExtended|
519-
|MicrosoftDefenderForIdentityAudit|
520-
|SupervisoryReviewDayXInsight|
521-
|DefenderExpertsforXDRAdmin|
522-
|CDPEdgeBlockedMessage|
523-
|HostedRpa|
524-
|CdpContentExplorerAggregateRecord|
525-
|CDPHygieneAttachmentInfo|
526-
|CDPHygieneSummary|
527-
|CDPPostMailDeliveryAction|
528-
|CDPEmailFeatures|
529-
|CDPHygieneUrlInfo|
530-
|CDPUrlClick|
531-
|CDPPackageManagerHygieneEvent|
532-
|FilteringDocScan|
533-
|TimeTravelFilteringDocScan|
534-
|MAPGOnboard|
535-
|VfamCreatePolicy|
536-
|VfamUpdatePolicy|
537-
|VfamDeletePolicy|
538-
|M365DAAD|
539-
|CdpColdCrawlStatus|
540-
|PowerPlatformAdministratorActivity|
541-
|Windows365CustomerLockbox|
542-
|CdpResourceScopeChangeEvent|
543-
|ComplianceCCExchangeExecutionResult|
544-
|CdpOcrCostEstimatorRecord|
545-
|CopilotInteraction|
546-
|CdpOcrBillingRecord|
547-
|ComplianceDLPApplications|
548-
|UAMOperation|
549-
|VivaLearning|
550-
|VivaLearningAdmin|
551-
|PurviewPolicyOperation|
552-
|PurviewMetadataPolicyOperation|
553-
|PeopleAdminSettings|
554-
|CdpComplianceDLPExchangeClassification|
555-
|CdpComplianceDLPSharePointClassification|
556-
|FilteringBulkSenderInsightData|
557-
|FilteringBulkThresholdInsightData|
558-
|PrivacyOpenAccess|
559-
|OWAAuth|
560-
|ComplianceDLPApplicationsClassification|
561-
|SharePointESignature|
562-
|Dynamics365BusinessCentral|
563-
|MeshWorlds|
564-
|VivaPulseResponse|
565-
|VivaPulseOrganizer|
566-
|VivaPulseAdmin|
567-
|VivaPulseReport|
568-
|AIAppInteraction|
569-
|ComplianceDLMExchange|
570-
|ComplianceDLMSharePoint|
571-
|ProjectForTheWebAssignedToMeSettings|
572-
|CPSOperation|
573-
|ComplianceDLPExchangeDiscovery|
574-
|PurviewMCRecommendation|
575-
|unknownFutureValue|
576-
577284
### auditLogUserType values
578285

579286

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
---
2+
title: "a365AiExecuteTool resource type"
3+
description: "Represents an audit record for Microsoft 365 AI tool execution events."
4+
author: "diksha27"
5+
ms.subservice: security
6+
ms.localizationpriority: medium
7+
doc_type: resourcePageType
8+
ms.date: 03/17/2026
9+
toc.title: "A365Ai Execute Tool"
10+
---
11+
# a365AiExecuteTool resource type
12+
13+
Namespace: microsoft.graph.security
14+
15+
[!INCLUDE [beta-disclaimer](../../includes/beta-disclaimer.md)]
16+
17+
Represents an audit record for Microsoft 365 AI tool execution events.
18+
19+
Inherits from [microsoft.graph.security.auditData](../resources/security-auditdata.md). The audit data for this record type is returned as the **auditData** property in an [auditLogRecord](../resources/security-auditlogrecord.md).
20+
21+
22+
## Properties
23+
None.
24+
25+
## Relationships
26+
None.
27+
28+
## JSON representation
29+
The following JSON representation shows the resource type.
30+
<!-- {
31+
"blockType": "resource",
32+
"@odata.type": "microsoft.graph.security.a365AiExecuteTool"
33+
}
34+
-->
35+
``` json
36+
{
37+
"@odata.type": "#microsoft.graph.security.a365AiExecuteTool"
38+
}
39+
```
Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
---
2+
title: "a365AiInferenceCall resource type"
3+
description: "Represents an audit record for Microsoft 365 AI inference call events."
4+
author: "diksha27"
5+
ms.subservice: security
6+
ms.localizationpriority: medium
7+
doc_type: resourcePageType
8+
ms.date: 03/17/2026
9+
toc.title: "A365Ai Inference Call"
10+
---
11+
# a365AiInferenceCall resource type
12+
13+
Namespace: microsoft.graph.security
14+
15+
[!INCLUDE [beta-disclaimer](../../includes/beta-disclaimer.md)]
16+
17+
Represents an audit record for Microsoft 365 AI inference call events.
18+
19+
Inherits from [microsoft.graph.security.auditData](../resources/security-auditdata.md). The audit data for this record type is returned as the **auditData** property in an [auditLogRecord](../resources/security-auditlogrecord.md).
20+
21+
22+
## Properties
23+
None.
24+
25+
## Relationships
26+
None.
27+
28+
## JSON representation
29+
The following JSON representation shows the resource type.
30+
<!-- {
31+
"blockType": "resource",
32+
"@odata.type": "microsoft.graph.security.a365AiInferenceCall"
33+
}
34+
-->
35+
``` json
36+
{
37+
"@odata.type": "#microsoft.graph.security.a365AiInferenceCall"
38+
}
39+
```

0 commit comments

Comments
 (0)