Defender-CloudAppEvents

ActionTypeTitleSampleRule
anyCloud app activityYY

any: Cloud app activity

#
Table
CloudAppEvents

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
ActionType4 detection rulesKusto
Application2 detection rulesKusto
AccountObjectId1 detection ruleKusto
ApplicationId1 detection ruleKusto
IPAddress1 detection ruleKusto

Example Event #

{
  "AccountDisplayName": "Admin User",
  "AccountId": "11111111-1111-1111-1111-111111111111",
  "AccountObjectId": "11111111-1111-1111-1111-111111111111",
  "AccountType": "Admin",
  "ActionType": "Add service principal.",
  "ActivityObjects": [
    {
      "Type": "Application",
      "Role": "Parameter",
      "ServiceObjectType": "Azure Service Principal - Object ID"
    },
    {
      "Type": "Application",
      "Role": "Target object",
      "Name": "dw-rt2-delegate"
    },
    {
      "Type": "Application",
      "Role": "Parameter",
      "Id": "Other",
      "ServiceObjectType": "Azure Service Principal - Application ID"
    },
    {
      "Type": "Tenant",
      "Role": "Parameter",
      "Id": "00000000-0000-0000-0000-000000000001"
    },
    {
      "Type": "User",
      "Role": "Actor",
      "Name": "Admin User",
      "Id": "11111111-1111-1111-1111-111111111111",
      "ApplicationId": 11161,
      "ApplicationInstance": 0
    }
  ],
  "ActivityObjects@odata.type": "#Collection(String)",
  "ActivityType": "Add",
  "AdditionalFields": {
    "@odata.type": "#microsoft.graph.security.dynamicColumnValue"
  },
  "AppInstanceId": 0,
  "Application": "Microsoft 365",
  "ApplicationId": 11161,
  "AuditSource": "Defender for Cloud Apps app connector",
  "DeviceType": "Other",
  "IsAdminOperation": 0,
  "IsAdminOperation@odata.type": "#SByte",
  "IsExternalUser": 0,
  "IsExternalUser@odata.type": "#SByte",
  "IsImpersonated": 0,
  "IsImpersonated@odata.type": "#SByte",
  "LastSeenForUser": {
    "@odata.type": "#microsoft.graph.security.dynamicColumnValue",
    "ActionType": 0,
    "ActionType@odata.type": "#Int64",
    "Application": 0,
    "Application@odata.type": "#Int64",
    "OSPlatform": 0,
    "OSPlatform@odata.type": "#Int64",
    "UserAgent": 0,
    "UserAgent@odata.type": "#Int64"
  },
  "OAuthAppId": "5165532d-c344-423b-973e-b4493d5450c5",
  "OSPlatform": "Linux",
  "ObjectName": "dw-rt2-delegate",
  "ObjectType": "Application",
  "RawEventData": {
    "@odata.type": "#microsoft.graph.security.dynamicColumnValue",
    "Actor": [
      {
        "ID": "adminuser@example.onmicrosoft.com",
        "Type": 5
      },
      {
        "ID": "10000000AAAAAAAA",
        "Type": 3
      },
      {
        "ID": "User_11111111-1111-1111-1111-111111111111",
        "Type": 2
      },
      {
        "ID": "11111111-1111-1111-1111-111111111111",
        "Type": 2
      },
      {
        "ID": "User",
        "Type": 2
      },
      {
        "ID": "NotAgentic",
        "Type": 2
      }
    ],
    "Actor@odata.type": "#Collection(String)",
    "ActorContextId": "00000000-0000-0000-0000-000000000001",
    "AzureActiveDirectoryEventType": 1,
    "AzureActiveDirectoryEventType@odata.type": "#Int64",
    "CreationTime": "2026-07-25T21:49:08.0000000Z",
    "ExtendedProperties": [
      {
        "Name": "additionalDetails",
        "Value": {
          "User-Agent": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)",
          "AppId": "5165532d-c344-423b-973e-b4493d5450c5",
          "AppOwnerOrganizationId": "00000000-0000-0000-0000-000000000001",
          "ServicePrincipalProvisioningType": "Other"
        }
      },
      {
        "Name": "extendedAuditEventCategory",
        "Value": "ServicePrincipal"
      }
    ],
    "ExtendedProperties@odata.type": "#Collection(String)",
    "Id": "7943e2c0-acf1-4d0a-ab3f-ee682ed1d93e",
    "InterSystemsId": "d557c366-e388-4fdc-8160-62c183a4bba8",
    "IntraSystemId": "00000000-0000-0000-0000-000000000000",
    "ModifiedProperties": [
      {
        "Name": "AccountEnabled",
        "NewValue": [
          true
        ],
        "OldValue": []
      },
      {
        "Name": "AppPrincipalId",
        "NewValue": [
          "5165532d-c344-423b-973e-b4493d5450c5"
        ],
        "OldValue": []
      },
      {
        "Name": "DisplayName",
        "NewValue": [
          "dw-rt2-delegate"
        ],
        "OldValue": []
      },
      {
        "Name": "ServicePrincipalName",
        "NewValue": [
          "5165532d-c344-423b-973e-b4493d5450c5"
        ],
        "OldValue": []
      },
      {
        "Name": "Credential",
        "NewValue": [
          {
            "CredentialType": 2,
            "KeyStoreId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c",
            "KeyGroupId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c"
          }
        ],
        "OldValue": []
      },
      {
        "Name": "Included Updated Properties",
        "NewValue": "AccountEnabled, AppPrincipalId, DisplayName, ServicePrincipalName, Credential",
        "OldValue": ""
      }
    ],
    "ModifiedProperties@odata.type": "#Collection(String)",
    "ObjectId": "5165532d-c344-423b-973e-b4493d5450c5",
    "Operation": "Add service principal.",
    "OrganizationId": "00000000-0000-0000-0000-000000000001",
    "RecordType": 8,
    "RecordType@odata.type": "#Int64",
    "ResultStatus": "Success",
    "SupportTicketId": "",
    "Target": [
      {
        "ID": "ServicePrincipal_3ce33562-8f77-4735-afa3-eb60a90c3377",
        "Type": 2
      },
      {
        "ID": "3ce33562-8f77-4735-afa3-eb60a90c3377",
        "Type": 2
      },
      {
        "ID": "ServicePrincipal",
        "Type": 2
      },
      {
        "ID": "NotAgentic",
        "Type": 2
      },
      {
        "ID": "dw-rt2-delegate",
        "Type": 1
      },
      {
        "ID": "5165532d-c344-423b-973e-b4493d5450c5",
        "Type": 2
      },
      {
        "ID": "5165532d-c344-423b-973e-b4493d5450c5",
        "Type": 4
      },
      {
        "ID": "00000000-0000-0000-0000-000000000001",
        "Type": 2
      },
      {
        "ID": "Other",
        "Type": 2
      }
    ],
    "Target@odata.type": "#Collection(String)",
    "TargetContextId": "00000000-0000-0000-0000-000000000001",
    "UserId": "adminuser@example.onmicrosoft.com",
    "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
    "UserType": 0,
    "UserType@odata.type": "#Int64",
    "Version": 1,
    "Version@odata.type": "#Int64",
    "Workload": "AzureActiveDirectory"
  },
  "ReportId": "75768946_11161_7943e2c0-acf1-4d0a-ab3f-ee682ed1d93e",
  "Timestamp": "2026-07-25T21:49:08Z",
  "UncommonForUser@odata.type": "#Collection(String)",
  "UserAgent": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}

Detection Patterns #

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
Active (kusto rule field)eqtrue4 ruleskusto
ValidUntil (kusto rule field)is_null4 ruleskusto
CloudAppEvents_TimeGenerated (kusto rule field)cross_field_compareExpirationDateTime3 ruleskusto
CloudAppEvents_TimeGenerated (kusto rule field)cross_field_compareValidUntil3 ruleskusto
ActionType (kusto rule field)eqUsbDriveMounted1 rulekusto
ActionType (kusto rule field)inExecuteToolByGateway2 ruleskusto
ActionType (kusto rule field)inExecuteToolByMCPServer2 ruleskusto
ActionType (kusto rule field)inExecuteToolBySDK2 ruleskusto
ActionType (kusto rule field)inInferenceCall2 ruleskusto
ActionType (kusto rule field)inInvokeAgent2 ruleskusto
ActionType (kusto rule field)inFileCreated1 rulekusto
Image (kusto rule field)is_not_null2 ruleskusto
User_Id (kusto rule field)is_not_null2 ruleskusto
User_Id (kusto rule field)regex_match^[a-zA-Z0-9_.+-]+@[a-zA-Z0-9-]+\.[a-zA-Z0-9-.]+$2 ruleskusto
AccountObjectId (kusto rule field)is_not_null1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #