Chat now with support
Chat with Support

Change Auditor 7.1.1 - Office 365 and Azure Active Directory Event Reference Guide

Office 365 SharePoint Online

Group member added in SharePoint Online

Created when a member is added to a SharePoint Online group. The target for this event is the group.

Medium

Group member removed in SharePoint Online

Created when a member is removed from a SharePoint Online group. The target for this event is the group.

Medium

Member added to group in SharePoint Online

Created when a member is added to a SharePoint Online group. The target for this event is the member.

Medium

Member removed from group in SharePoint Online

Created when a member is removed from a SharePoint Online group. The target for this event is the member.

Medium

 

File accessed in SharePoint Online

Created when a user or system account accesses a file in a SharePoint Online site.

Low

File checked in in SharePoint Online

Created when a user checks a file back in to a document library after they have completed their edits.

Medium

File checked out and discarded in SharePoint Online

Created when a file check out is undone resulting in no edits to the file in the document library.

Medium

File checked out in SharePoint Online

Created when a user checks out a file from a document library to ensure it is not accessed by others while being edited.

Medium

File copied in SharePoint Online

Created when a file is copied in a SharePoint Online site.

Medium

File deleted in SharePoint Online

Created when a file is deleted from a SharePoint Online site.

Medium

File downloaded in SharePoint Online

Created when a file is downloaded from a SharePoint Online site.

Medium

File modified in SharePoint Online

Created when file contents or properties are changed by a user or system account in a SharePoint Online site.

Medium

File moved in SharePoint Online

Created when a file is moved in a SharePoint Online site.

Medium

File previewed in SharePoint Online

Created when a file is viewed by a user or system account in a SharePoint Online site.

Low

File renamed in SharePoint Online

Created when a file is renamed in a SharePoint Online site.

Medium

File restored in SharePoint Online

Created when a deleted file is restored in a SharePoint Online site.

Medium

File uploaded in SharePoint Online

Created when a file is uploaded to a SharePoint Online site.

Medium

Folder accessed in SharePoint Online

Created when a user or system account accesses a folder in a SharePoint Online site.

Low

Folder created in SharePoint Online

Created when a folder is created in a SharePoint Online site.

Medium

Folder deleted in SharePoint Online

Created when a folder is deleted from a SharePoint Online site.

Medium

Folder modified in SharePoint Online

Created when a folder’s properties are changed in a SharePoint Online site.

Medium

Folder moved in SharePoint Online

Created when a folder is moved in a SharePoint Online site.

Medium

Folder renamed in SharePoint Online

Created when a folder is renamed in a SharePoint Online site.

Medium

 

Office 365 SharePoint Online event

Generic SharePoint Online event with a dynamically constructed event description (What statement). The event is created when SharePoint Online activity is detected that does not have a corresponding event defined in Change Auditor.

Low

Office 365 OneDrive for Business

 

File accessed in OneDrive for Business

Created when a user or system account accesses a file in a OneDrive for Business site.

Low

File checked in in OneDrive for Business

Created when a user checks in a file to a document library.

Medium

File checked out and discarded in OneDrive for Business

Created when a file check out is undone resulting in no edits to the file in the document library.

Medium

File checked out in OneDrive for Business

Created when a user checks out a file from a document library.

Medium

File copied in OneDrive for Business

Created when a file is copied in a OneDrive for Business site.

Medium

File deleted in OneDrive for Business

Created when a file is deleted from a OneDrive for Business site.

Medium

File downloaded in OneDrive for Business

Created when a file is downloaded from a OneDrive for Business site.

Medium

File modified in OneDrive for Business

Created when file contents or properties are changed by a user or system account in a OneDrive for Business site.

Medium

File moved in OneDrive for Business

Created when a file is moved in a OneDrive for Business site.

Medium

File previewed in OneDrive for Business

Created when a user or system account views a file in a OneDrive for Business site.

Low

File renamed in OneDrive for Business

Created when a file is renamed in a OneDrive for Business site.

Medium

File restored in OneDrive for Business

Created when a deleted file is restored in a OneDrive for Business site.

Medium

File synchronized from a local OneDrive folder to OneDrive for Business

Created when a file is uploaded to a remote OneDrive folder from local OneDrive folder.

Low

File synchronized from OneDrive for Business to a local OneDrive folder

Created when a file is uploaded to a remote OneDrive folder from a local OneDrive folder.

Low

File uploaded in OneDrive for Business

Created when a file is uploaded to a OneDrive for Business site.

Medium

Folder accessed in OneDrive for Business

Created when a user or system account accesses a folder in a OneDrive for Business site.

Low

Folder created in OneDrive for Business

Created when a folder is created in a OneDrive for Business site.

Medium

Folder deleted in OneDrive for Business

Created when a folder is deleted from a OneDrive for Business site.

Medium

Folder modified in OneDrive for Businesse

Created when a folder’s properties are changed in a OneDrive for Business site.

Medium

Folder moved in OneDrive for Business

Created when a folder is moved in a OneDrive for Business site.

Medium

Folder renamed in OneDrive for Business

Created when a folder is renamed in a OneDrive for Business site.

Medium

 

Office 365 OneDrive for Business event

Generic OneDrive for Business event with a dynamically constructed event description (What statement). The event is created when OneDrive for Business activity is detected that does not have a corresponding event defined in Change Auditor.

Low

Azure Active Directory

Change Auditor audits activities in the Azure Active Directory that correspond to the events in the Audit logs in the Azure Active Directory portal.

User added

Created when a user is added to the directory.

Medium

User deleted

Created when a user is deleted from the directory.

Medium

User restored

Created when a user is restored in the directory.

Medium

User updated

Created when a user account is updated. See User attribute events.

Medium

License properties set

Created when the Global Administrator assigns a license for a particular plan to a user in the directory.

Medium

User license changed

Created when the license assigned to a user in the directory is changed. See User license attributes events.

Medium

User password changed

Created when the password for a user in the directory is changed.

Medium

User password reset

Created when the password for a user in the directory is reset.

Medium

Azure Active Directory - User event

Generic user event with a dynamically constructed event description (What statement). The event is created when user activity is detected that does not have a corresponding event defined in Change Auditor.

Medium

User AccountEnabled property changed

Created when a user’s sign-in status is changed. (Administrators can set the status to allowed and blocked.)

Medium

User AlternativeSecurityId property changed

Created when a user’s alternate security ID is changed as part of the Azure Active Directory external account workflow.

Medium

User PreferredDataLocation property changed

Created when the preferred location for the user data is changed.

Medium

User Mobile property changed

Created when a user’s mobile phone number is changed.

Medium

User MSExchRemoteRecipientType property changed

Created when mailbox type is changed. For example, an on-premises mailbox was migrated to Exchange Online or archive mailbox was added.

Medium

User OtherMail property changed

Created when a user's alternate email address is changed.

Medium

User OtherMobile property changed

Created when a user's alternate mobile phone number is changed.

Medium

User ProxyAddresses property changed

Created when one of the user proxy addresses is changed, added, or removed.

Medium

User TelephoneNumber property changed

Created when a user's telephone number is changed.

Medium

User StrongAuthenticationMethod property changed

Created when the multi-factor authentication for verification method has been changed for a user. Available methods include call to phone, text message to phone, notification through mobile application, and verification code from mobile application.

Medium

User StrongAuthenticationPhoneAppDetail property changed .

Created when a user’s phone application used for multi-factor authentication and password reset verification have been changed

Medium

User StrongAuthenticationUserDetail property changed

Created when a user’s phone number, alternative phone number, or email address used for multi-factor authentication and password reset verification have been changed.

Medium

User StrongAuthenticationRequirement property changed

Created when multi-factor authentication is enforced, enabled, or disabled for a user. Turning on multi-factor authentication changes the state to enabled. The state changes to enforced when the user signs in and authenticates.

Medium

User StsRefreshTokensValidFrom property changed

Created when a user's StsRefreshTokenValidFrom property is changed. For example, when a user’s authorization token should be invalidated.

Medium

User UserPrincipalName property changed

Created when the UPN for a user account is changed.

Medium

User UserType property changed

Created when the user type is changed. The available type includes member, guest, or viral.

Medium

User UserStateChangedOn property changed

Created when the timestamp of the last change to the UserState is changed as part of the Azure Active Directory external account workflow.

Medium

User UserState property changed

 

 

Created when the user state is changed as part of the Azure Active Directory external account workflow. (PendingApproval/PendingAcceptance/Accepted/
PendingVerification)

Medium

 

Force change user password property set

Created when the property that requires a user to change their password is set.

Medium

User AssignedLicense property changed

Created when a user’s product licenses has been edited. (Administrators can assign, reassign, or remove licenses as required.)

Medium

User AssignedPlan property changed

Created when a licensed user’s assigned plan details are changed.

Medium

User LicenseAssignmentDetail property changed

Created when the license detail assigned to a user is changed.

Medium

Eligible member added to role

Created when an eligible member is added to a role.

High

Eligible member removed from role

Created when an eligible member is removed from a role.

High

Role assigned to eligible member

Created when an eligible member is added to a role.

High

Role assigned to member

Created when a member is added to a role.

High

Role member added

Created when a user or service principal is added to a directory role.

High

Role member removed

Created when a user or service principle is removed from a directory role.

High

Role removed from eligible member

Created when an eligible member is removed from a role.

High

Role removed from member

Created when a member is removed from a role.

High

Azure Active Directory - Role event

Generic user event with a dynamically constructed event description (What statement). The event is created when user activity is detected that does not have a corresponding event defined in Change Auditor.

Medium

Group Property changes are monitored for the following types of groups: Office 365, Distribution list, and Security groups.

Group added

Created when a group is created in the directory.

Medium

Group deleted

Created when a group is deleted from the directory.

Medium

Group member added

Created when a member is added to a group in the directory.

Medium

Group member removed

Created when a member is removed from a group in the directory.

Medium

Group owner added

Created when an owner is added to a group in the directory.

Medium

Group owner removed

Created when an owner is removed from a group in the directory.

Medium

Group updated

Created when a group is updated. See Group attributes events.

Medium

Member added to group

Created when a member is added to a group.

Medium

Member removed from group

Created when a member is removed from a group.

Medium

Owner added to group

Created when an owner is added to a group.

Medium

Owner removed from group

Created when an owner is removed from a group.

Medium

Set group to be managed by user

Created when a group is set to be managed by a user in the directory.

Medium

Set group license

Created when a license is assigned to a group in the directory.

Medium

Azure Active Directory - Group event

Generic group event with a dynamically constructed event description (What statement). The event is created when group activity is detected that does not have a corresponding event defined in Change Auditor.

Medium

Group Description property changed

Created when the group description is changed.

Low

Group DisplayName property changed

Created when the group display name (friendly name) is changed.

Medium

Group GroupType property changed

Created when the group type (Office 365, Distribution List, or Security) and the group membership type (assigned or dynamic) is changed.

NOTE:  

Medium

Group IsPublic property changed

Created when the group privacy setting (public or private) is changed.

High

Group MailNickName property changed

Created when the group alias is changed.

Medium

Group MembershipRule property changed

Created when the criteria that determines which members should belong to a dynamic group is changed.

High

Group MembershipRuleProcessingState property changed

Created when the status of membership processing state is changed for a group.

High

Group SecurityEnabled property changed

Created when the property that determined whether a group is security enabled is changed.

Medium

Set group to be managed by user

Created when a group is set to be managed by a user in the directory.

Medium

 

Azure Active Directory - Application event

Generic application event with a dynamically constructed event description (What statement). The event is created when application activity is detected that does not have a corresponding event defined in Change Auditor.

Medium

 

Azure Active Directory - resource event

Generic resource event with a dynamically constructed event description (What statement). The event is created when resource activity is detected that does not have a corresponding event defined in Change Auditor.

Low

Azure Active Directory - Directory event

Generic directory event with a dynamically constructed event description (What statement). The event is created when directory activity is detected that does not have a corresponding event defined in Change Auditor.

Medium

 

Azure Active Directory - Policy Directory event

 

Generic policy event with a dynamically constructed event description (What statement). The event is created when policy activity is detected that does not have a corresponding event defined in Change Auditor.

Low

Azure Active Directory audit event

Created when Azure Active Directory activity is generated that does not have a corresponding event defined in Change Auditor.

Low

Azure Active Directory Sign-Ins

Change Auditor audits activities in the Azure Active Directory that correspond to the events in the Sign-ins report in the Azure Active Directory portal.

Failed Azure Active Directory
sign-in 

Created when a user fails to sign-in to an application. The event details show the user whose attempt failed, their location, and the application they attempted to access.

Medium

Successful Azure Active Directory sign-in

Created when a user successfully signs-in to an application. The event details show the user whose attempt failed, their location, and the application they attempted to access.

Low

Azure Active Directory - sign-in event

 

Generic sign-in event with a dynamically constructed event description (What statement). The event is created when sign-in activity is detected that does not have a corresponding event defined in Change Auditor.

Low

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating