The following list of audit events are supported for Microsoft Office 365 SharePoint Sites. For event description, refer to the Microsoft article.
Event Name |
---|
AccessInvitationAccepted |
AccessInvitationCreated |
AccessInvitationExpired |
AccessInvitationRevoked |
AccessInvitationUpdated |
AccessRequestAccepted |
AccessRequestApproved |
AccessRequestCreated |
AccessRequestDenied |
AccessRequestExpired |
AccessRequestRejected |
ActivationEnabled |
Add app role assignment grant to user |
Add app role assignment to group |
Add application |
Add delegation entry |
Add device |
Add domain to company |
Add external user to group. |
Add group |
Add member to group |
Add member to role |
Add OAuth2PermissionGrant |
Add owner to application |
Add owner to group |
Add owner to service principal |
Add partner to company |
Add policy |
Add policy to service principal |
Add registered owner to device |
Add registered users to device |
Add role member to Role |
Add service principal |
Add service principal credentials |
Add unverified domain |
Add user |
AddedToGroup |
AddedToSecureLink |
AdministratorAddedToTermStore |
AdministratorDeletedFromTermStore |
AllowGroupCreationSet |
AnonymousLinkCreated |
AnonymousLinkRemoved |
AnonymousLinkUpdated |
AnonymousLinkUsed |
AppCatalogCreated |
Assign external user to application. |
AuditPolicyRemoved |
AuditPolicyUpdate |
AzureStreamingEnabledSet |
Batch invites processed. |
Batch invites uploaded. |
Change user license |
Change user password |
ChannelAdded |
ChannelDeleted |
CollaborationTypeModified |
CompanyLinkCreated |
CompanyLinkRemoved |
CompanyLinkUsed |
Consent to application |
Create application password for user |
Create company |
CreateSSOApplication |
CustomizeExemptUsers |
DefaultLanguageChangedInTermStore |
Delete device |
Delete group |
Delete user |
DeleteSSOApplication |
DisableSharingForNonOwners |
eDiscoveryHoldApplied |
eDiscoveryHoldRemoved |
eDiscoverySearchPerformed |
ExemptUserAgentSet |
Failed Login |
FileAccessed |
FileCheckedIn |
FileCheckedOut |
FileCheckOutDiscarded |
FileCopied |
FileDeleted |
FileDeletedFirstStageRecycleBin |
FileDownloaded |
FileFetched |
FileModified |
FileMoved |
FilePreviewed |
FileRenamed |
FileRestored |
FileSyncDownloadedFull |
FileSyncDownloadedPartial |
FileSyncUploadedFull |
FileSyncUploadedPartial |
FileUploaded |
FileViewed |
Finish applying group based license to users |
FolderCreated |
FolderDeleted |
FolderDeletedFirstStageRecycleBin |
FolderModified |
FolderMoved |
FolderRenamed |
FolderRestored |
ForeignRealmIndexLogonCookieCopyUsingDAToken |
ForeignRealmIndexLogonInitialAuthUsingADFSFederatedToken |
GroupAdded |
GroupRemoved |
GroupUpdated |
Invite external user. |
LanguageAddedToTermStore |
LanguageRemovedFromTermStore |
LegacyWorkflowEnabledSet |
Login |
MaxQuotaModified |
MaxResourceUsageModified |
MemberAdded |
MemberRemoved |
MySitePublicEnabledSet |
NewsFeedEnabledSet |
ODBNextUXSettings |
OfficeOnDemandSet |
PageViewed |
PasswordLogonCookieCopyUsingDAToken |
PasswordLogonInitialAuthUsingADFSFederatedToken |
PasswordLogonInitialAuthUsingPassword |
PeopleResultsScopeSet |
PreviewModeEnabledSet |
QuotaWarningEnabledModified |
Redeem external user invite. |
Remove app role assignment from user |
Remove delegation entry |
Remove domain from company |
Remove eligible member from role |
Remove member from group |
Remove member from role |
Remove OAuth2PermissionGrant |
Remove owner from group |
Remove Partner from company |
Remove policy credentials |
Remove role member from Role |
Remove service principal |
Remove service principal credentials |
RemovedFromGroup |
RemovedFromSharedWithMe |
RemovedFromSiteCollection |
RenderingEnabled |
Reset user password |
ResourceWarningEnabledModified |
Restore user |
Revoke consent |
SearchCenterUrlSet |
SecondaryMySiteOwnerSet |
SecureLinkCreated |
SecureLinkUsed |
SendToConnectionAdded |
SendToConnectionRemoved |
Set Company contact information |
Set Company Information |
Set delegation entry |
Set DirSyncEnabled flag on company |
Set domain authentication |
Set federation settings on domain |
Set force change user password |
Set group license |
Set license properties |
Set Password Policy |
SharedLinkCreated |
SharedLinkDisabled |
SharingInheritanceBroken |
SharingInvitationAccepted |
SharingInvitationCreated |
SharingInvitationRevoked |
SharingPolicyChanged |
SharingRevoked |
SharingSet |
SiteAdminChangeRequest |
SiteCollectionAdminAdded |
SiteCollectionAdminRemoved |
SiteCollectionCreated |
SitePermissionsModified |
SiteRenamed |
SSOGroupCredentialsSet |
SSOUserCredentialsSet |
Start applying group based license to users |
SyncGetChanges |
TeamCreated |
TeamDeleted |
TeamSettingChanged |
Trigger group license recalculation |
UnmanagedSyncClientBlocked |
Update application |
Update device |
Update domain |
Update external secrets |
Update group |
Update policy |
Update service principal |
Update user |
UpdateSSOApplication |
UserAddedToGroup |
UserLoggedIn |
UserLoginFailed |
UserRemovedFromGroup |
Verify domain |
Verify email verified domain |
VideoRequested |
Viral tenant creation. |
Viral user creation. |
WACTokenShared |