サポートと今すぐチャット
サポートとのチャット

Change Auditor 7.4 - Office 365 and Azure Active Directory Event Reference Guide

Office 365 SharePoint Online

 

File accessed in SharePoint Online

Created when a user or system account accesses a file in a SharePoint Online site.

Low

File checked in in SharePoint Online

Created when a user checks a file back in to a document library after they have completed their edits.

Medium

File checked out and discarded in SharePoint Online

Created when a file check out is undone resulting in no edits to the file in the document library.

Medium

File checked out in SharePoint Online

Created when a user checks out a file from a document library to ensure it is not accessed by others while being edited.

Medium

File copied in SharePoint Online

Created when a file is copied in a SharePoint Online site.

Medium

File deleted in SharePoint Online

Created when a file is deleted from a SharePoint Online site.

Medium

File downloaded in SharePoint Online

Created when a file is downloaded from a SharePoint Online site.

Medium

File modified in SharePoint Online

Created when file contents or properties are changed by a user or system account in a SharePoint Online site.

Medium

File moved in SharePoint Online

Created when a file is moved in a SharePoint Online site.

Medium

File previewed in SharePoint Online

Created when a file is viewed by a user or system account in a SharePoint Online site.

Low

File renamed in SharePoint Online

Created when a file is renamed in a SharePoint Online site.

Medium

File restored in SharePoint Online

Created when a deleted file is restored in a SharePoint Online site.

Medium

File uploaded in SharePoint Online

Created when a file is uploaded to a SharePoint Online site.

Medium

 

Office 365 OneDrive for Business

 

File accessed in OneDrive for Business

Created when a user or system account accesses a file in a OneDrive for Business site.

Low

File checked in in OneDrive for Business

Created when a user checks in a file to a document library.

Medium

File checked out and discarded in OneDrive for Business

Created when a file check out is undone resulting in no edits to the file in the document library.

Medium

File checked out in OneDrive for Business

Created when a user checks out a file from a document library.

Medium

File copied in OneDrive for Business

Created when a file is copied in a OneDrive for Business site.

Medium

File deleted in OneDrive for Business

Created when a file is deleted from a OneDrive for Business site.

Medium

File downloaded in OneDrive for Business

Created when a file is downloaded from a OneDrive for Business site.

Medium

File modified in OneDrive for Business

Created when file contents or properties are changed by a user or system account in a OneDrive for Business site.

Medium

File moved in OneDrive for Business

Created when a file is moved in a OneDrive for Business site.

Medium

File previewed in OneDrive for Business

Created when a user or system account views a file in a OneDrive for Business site.

Low

File renamed in OneDrive for Business

Created when a file is renamed in a OneDrive for Business site.

Medium

File restored in OneDrive for Business

Created when a deleted file is restored in a OneDrive for Business site.

Medium

File synchronized from a local OneDrive folder to OneDrive for Business

Created when a file is uploaded to a remote OneDrive folder from local OneDrive folder.

Low

File synchronized from OneDrive for Business to a local OneDrive folder

Created when a file is uploaded to a remote OneDrive folder from a local OneDrive folder.

Low

File uploaded in OneDrive for Business

Created when a file is uploaded to a OneDrive for Business site.

Medium

 

Azure Active Directory

Change Auditor audits activities in the Azure Active Directory that correspond to the events in the Audit logs in the Azure Active Directory portal.

User AccountEnabled property changed

Created when a user’s sign-in status is changed. (Administrators can set the status to allowed and blocked.)

Medium

User AlternativeSecurityId property changed

Created when a user’s alternate security ID is changed as part of the Azure Active Directory external account workflow.

Medium

User PreferredDataLocation property changed

Created when the preferred location for the user data is changed.

Medium

User Mobile property changed

Created when a user’s mobile phone number is changed.

Medium

User MSExchRemoteRecipientType property changed

Created when mailbox type is changed. For example, an on-premises mailbox was migrated to Exchange Online or archive mailbox was added.

Medium

User OtherMail property changed

Created when a user's alternate email address is changed.

Medium

User OtherMobile property changed

Created when a user's alternate mobile phone number is changed.

Medium

User ProxyAddresses property changed

Created when one of the user proxy addresses is changed, added, or removed.

Medium

User TelephoneNumber property changed

Created when a user's telephone number is changed.

Medium

User StrongAuthenticationMethod property changed

Created when the multi-factor authentication for verification method has been changed for a user. Available methods include call to phone, text message to phone, notification through mobile application, and verification code from mobile application.

Medium

User StrongAuthenticationPhoneAppDetail property changed .

Created when a user’s phone application used for multi-factor authentication and password reset verification have been changed

Medium

User StrongAuthenticationUserDetail property changed

Created when a user’s phone number, alternative phone number, or email address used for multi-factor authentication and password reset verification have been changed.

Medium

User StrongAuthenticationRequirement property changed

Created when multi-factor authentication is enforced, enabled, or disabled for a user. Turning on multi-factor authentication changes the state to enabled. The state changes to enforced when the user signs in and authenticates.

Medium

User StsRefreshTokensValidFrom property changed

Created when a user's StsRefreshTokenValidFrom property is changed. For example, when a user’s authorization token should be invalidated.

Medium

User UserPrincipalName property changed

Created when the UPN for a user account is changed.

Medium

User UserType property changed

Created when the user type is changed. The available type includes member, guest, or viral.

Medium

User UserStateChangedOn property changed

Created when the timestamp of the last change to the UserState is changed as part of the Azure Active Directory external account workflow.

Medium

User UserState property changed

 

 

Created when the user state is changed as part of the Azure Active Directory external account workflow. (PendingApproval/PendingAcceptance/Accepted/
PendingVerification)

Medium

 

Group Property changes are monitored for the following types of groups: Office 365, Distribution list, and Security groups.

Group Description property changed

Created when the group description is changed.

Low

Group DisplayName property changed

Created when the group display name (friendly name) is changed.

Medium

Group GroupType property changed

Created when the group type (Office 365, Distribution List, or Security) and the group membership type (assigned or dynamic) is changed.

NOTE:  

Medium

Group IsPublic property changed

Created when the group privacy setting (public or private) is changed.

High

Group MailNickName property changed

Created when the group alias is changed.

Medium

Group MembershipRule property changed

Created when the criteria that determines which members should belong to a dynamic group is changed.

High

Group MembershipRuleProcessingState property changed

Created when the status of membership processing state is changed for a group.

High

Group SecurityEnabled property changed

Created when the property that determined whether a group is security enabled is changed.

Medium

Set group to be managed by user

Created when a group is set to be managed by a user in the directory.

Medium

 

 

 

Azure Active Directory Sign-Ins

Change Auditor audits activities in the Azure Active Directory that correspond to the events in the Sign-ins report in the Azure Active Directory portal.

The document was helpful.

評価を選択

I easily found the information I needed.

評価を選択