Exchange admin activity

OperationDescriptionSampleRule
anyCatch-all for M365-ExchangeAdmin rules matching the RecordType but no specific Operation.NY
Add-FederatedDomainA federated domain was added to the Exchange Online organization, enabling single-sign-on with an external identity provider.YY
Add-MailboxPermissionA mailbox permission (such as FullAccess) was granted to a user, enabling delegate access to another mailbox.YY
Add-RecipientPermissionA SendAs permission was granted on a recipient object, enabling impersonation of that recipient.YY
Add-RoleGroupMemberA role group member was added via the Add-RoleGroupMember Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Disable-AntiPhishRuleAn anti-phishing rule was disabled in Exchange Online Protection, reducing anti-phishing enforcement.YY
Disable-MalwareFilterRuleA malware filter rule was disabled, reducing malware scanning enforcement.YY
Disable-SafeAttachmentRuleA Safe Attachments policy rule was disabled in Microsoft Defender for Office 365, reducing detonation-sandbox coverage.YY
Disable-SafeLinksRuleA Safe Links policy rule was disabled in Microsoft Defender for Office 365, reducing URL-rewriting coverage.YY
Disable-TransportRuleA mail-flow transport rule was disabled, potentially allowing previously blocked or redirected mail to flow unimpeded.YY
New-AcceptedDomainA new accepted domain was added to the Exchange Online organization.NY
New-AntiPhishPolicyAn anti phish policy was created via the New-AntiPhishPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-AppAn Outlook or Exchange add-in (app) was installed into the organization or a mailbox.NN
New-DistributionGroupA distribution group was created via the New-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-DkimSigningConfigA dkim signing config was created via the New-DkimSigningConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-ExoInformationBarrierSegmentAn exo information barrier segment was created via the New-ExoInformationBarrierSegment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-HostedContentFilterPolicyA hosted content filter policy was created via the New-HostedContentFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-InboundConnectorAn inbound connector was created via the New-InboundConnector Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-InboxRuleAn Exchange inbox rule was created via the New-InboxRule cmdlet; first-party capture confirms it logs under ExchangeAdmin (RecordType 1), not the OWA-context UpdateInboxRules operation under ExchangeItem (RecordType 2).YY
New-MailboxA mailbox was created via the New-Mailbox Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-MalwareFilterPolicyA malware filter policy was created via the New-MalwareFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-ManagementRoleAssignmentA new RBAC management role assignment was created, granting administrative permissions in Exchange Online.YY
New-ManagementScopeA management scope was created via the New-ManagementScope Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-MobileDeviceMailboxPolicyA mobile device mailbox policy was created via the New-MobileDeviceMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-OwaMailboxPolicyAn owa mailbox policy was created via the New-OwaMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-RemoteDomainA remote domain was created via the New-RemoteDomain Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-RetentionPolicyA retention policy was created via the New-RetentionPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-RetentionPolicyTagA retention policy tag was created via the New-RetentionPolicyTag Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-RoleGroupA new RBAC role group was created in Exchange Online.YN
New-SafeAttachmentPolicyA safe attachment policy was created via the New-SafeAttachmentPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-SafeAttachmentRuleA Defender for Office 365 Safe Attachments rule was created, binding a Safe Attachments policy to the recipients it applies to. Observed in first-party Unified Audit Log capture. A policy is inert until a rule references it, and a policy cannot be removed while one does.NN
New-SafeLinksPolicyA safe links policy was created via the New-SafeLinksPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-ServicePrincipalA service principal was created via the New-ServicePrincipal Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-SharingPolicyA sharing policy was created via the New-SharingPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
New-TransportRuleA new mail-flow transport rule was created; adversaries use transport rules to silently copy, redirect, or delete messages.YY
New-UnifiedGroupAn unified group was created via the New-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-AcceptedDomainAn accepted domain was removed from the Exchange Online organization.NY
Remove-AntiPhishPolicyAn anti-phishing policy was deleted.YY
Remove-AntiPhishRuleAn anti-phishing rule was deleted from Exchange Online Protection.YY
Remove-DistributionGroupA distribution group was deleted via the Remove-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-DlpPolicyA Data Loss Prevention policy was deleted from Exchange Online.NY
Remove-ExoInformationBarrierSegmentAn exo information barrier segment was deleted via the Remove-ExoInformationBarrierSegment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-FederatedDomainA federated domain was removed from the Exchange Online organization.NY
Remove-HostedContentFilterPolicyA hosted content filter policy was deleted via the Remove-HostedContentFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-InboundConnectorAn inbound connector was deleted via the Remove-InboundConnector Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-InboxRuleAn inbox rule was deleted via the Remove-InboxRule Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-MailboxA mailbox was deleted via the Remove-Mailbox Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-MailboxPermissionA mailbox permission was removed from a user.YN
Remove-MalwareFilterPolicyA malware filter policy was deleted.YY
Remove-MalwareFilterRuleA malware filter rule was deleted.YY
Remove-ManagementRoleAssignmentA management role assignment was deleted via the Remove-ManagementRoleAssignment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-ManagementScopeA management scope was deleted via the Remove-ManagementScope Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
remove-MobileDeviceMailboxPolicyremove-Mobile Device Mailbox Policy activity in Exchange Online admin, recorded in the Unified Audit Log (observed in first-party capture).YN
Remove-OwaMailboxPolicyAn owa mailbox policy was deleted via the Remove-OwaMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-RecipientPermissionA recipient permission was deleted via the Remove-RecipientPermission Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-RemoteDomainA remote domain was deleted via the Remove-RemoteDomain Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
remove-RetentionPolicyremove-Retention Policy activity in Exchange Online admin, recorded in the Unified Audit Log (observed in first-party capture).YN
Remove-RetentionPolicyTagA retention policy tag was deleted via the Remove-RetentionPolicyTag Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-RoleGroupA role group was deleted via the Remove-RoleGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-SafeAttachmentPolicyA safe attachment policy was deleted via the Remove-SafeAttachmentPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YY
Remove-SafeAttachmentRuleA Defender for Office 365 Safe Attachments rule was deleted, detaching its policy from the recipients it applied to. Observed in first-party Unified Audit Log capture. Deleting the rule leaves the underlying Safe Attachments policy in place but stops it applying to anyone.YY
Remove-SafeLinksPolicyA safe links policy was deleted via the Remove-SafeLinksPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YY
Remove-SharingPolicyA sharing policy was deleted via the Remove-SharingPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Remove-TransportRuleA mail-flow transport rule was deleted.YY
Remove-UnifiedGroupAn unified group was deleted via the Remove-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Set-AcceptedDomainAn accepted domain's configuration was modified.NY
Set-AdminAuditLogConfigThe administrator audit log configuration was changed; adversaries disable audit logging to evade detection.YY
Set-CASMailboxClient-access settings on a mailbox were modified (for example enabling POP, IMAP, or OWA); commonly abused to enable legacy-protocol access.YN
Set-ConditionalAccessPolicyA conditional access policy was modified via the Set-ConditionalAccessPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Set-DistributionGroupA distribution group was modified via the Set-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Set-DkimSigningConfigThe DKIM signing configuration for a domain was modified; disabling DKIM weakens email authentication.YY
Set-InboxRuleAn Exchange inbox rule was modified via the Set-InboxRule cmdlet; first-party capture confirms it logs under ExchangeAdmin (RecordType 1), like New-InboxRule, not the OWA-context UpdateInboxRules operation under ExchangeItem (RecordType 2).YY
Set-MailboxA mailbox configuration was modified; commonly abused to enable forwarding, audit bypass, or delegate access.YY
Set-MailboxAuditBypassAssociationMailbox audit logging was bypassed for a service account, suppressing audit events for that account's actions.YY
Set-MailboxFolderPermissionAn Exchange Online admin cmdlet modified folder-level permissions on a mailbox folder; recorded in the Exchange admin audit log with the Operation set to the cmdlet name (commonly abused to grant a delegate covert folder access).YY
Set-OrganizationConfigAn organization config was modified via the Set-OrganizationConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Set-TransportConfigA transport config was modified via the Set-TransportConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN
Set-TransportRuleAn existing mail-flow transport rule was modified.YY
Set-UnifiedGroupAn unified group was modified via the Set-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).YN

any: Exchange admin activity (catch-all)

#
RecordType
ExchangeAdmin

Description

Catch-all for M365-ExchangeAdmin rules matching the RecordType but no specific Operation.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation2 detection rulesSplunk
Workload2 detection rulesSplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 Email Security Feature Changed source: The following analytic identifies when specific O365 advanced security settings are altered within the Office 365 tenant. If an attacker successfully disables O365 security settings, they can operate within the tenant with reduced risk of…T1685, T1685.002
  • O365 Email Transport Rule Changed source: The following analytic identifies when a user with sufficient access to Exchange Online alters the mail flow/transport rule configuration of the organization. Transport rules are a set of rules that can be used by attackers to modify or…T1114, T1114.003, T1564, T1564.008

References #

Add-FederatedDomain

#
RecordType
ExchangeAdmin

Description

A federated domain was added to the Exchange Online organization, enabling single-sign-on with an external identity provider.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
eventName1 detection ruleSigma
eventSource1 detection ruleSigma
status1 detection ruleSigma

Example Audit Record #

{
  "CreationTime": "2021-01-05T23:39:58",
  "ExternalAccess": false,
  "Id": "93e3dd16-8cf0-4b85-e383-08d8b1d3366c",
  "ObjectId": "Federation",
  "Operation": "Add-FederatedDomain",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "OrganizationName": "rodsoto.onmicrosoft.com",
  "OriginatingServer": "BYAPR14MB2597 (15.20.3721.024)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "rodsoto.onmicrosoft.com"
    },
    {
      "Name": "DomainName",
      "Value": "rodsoto.mail.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "ResultStatus": "True",
  "UserId": "NT AUTHORITY\\SYSTEM (w3wp)",
  "UserKey": "NT AUTHORITY\\SYSTEM (w3wp)",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic
status (sigma rule field)eqsuccess1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

References #

Add-MailboxPermission

#
RecordType
ExchangeAdmin

Description

A mailbox permission (such as FullAccess) was granted to a user, enabling delegate access to another mailbox.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation4 detection rulesKusto, Splunk
UserId2 detection rulesKusto
AccessRights1 detection ruleSplunk
event.action1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
o365.audit.Parameters.AccessRights1 detection ruleElastic
ResultStatus1 detection ruleKusto
TimeGenerated1 detection ruleKusto
user.id1 detection ruleElastic
UserType1 detection ruleElastic
Workload1 detection ruleSplunk

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:25953",
  "CreationTime": "2026-07-02T15:32:01Z",
  "ExternalAccess": false,
  "Id": "80b3dfc7-5aa6-4c84-c7fa-08ded84f0fc4",
  "ObjectId": "dwshared",
  "Operation": "Add-MailboxPermission",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwshared@example.onmicrosoft.com"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "AccessRights",
      "Value": "FullAccess"
    },
    {
      "Name": "User",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "bf13a316-a199-0ece-6ed0-1d2651c6d663",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
AccessRightseqfullaccess2 ruleselastic, splunk
AccessRights (splunk rule field)eqchangeowner1 rulesplunk
AccessRights (splunk rule field)eqchangepermission1 rulesplunk
Parameters[3].Value (kusto rule field)containsfullaccess1 rulekusto
ResultStatus (kusto rule field)eqTrue1 rulekusto
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

Kusto #

References #

Add-RecipientPermission

#
RecordType
ExchangeAdmin

Description

A SendAs permission was granted on a recipient object, enabling impersonation of that recipient.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
o365.audit.Parameters.AccessRights1 detection ruleElastic
user.id1 detection ruleElastic
UserType1 detection ruleElastic

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppId": "fb78d390-0c51-40cd-8e17-fdbfab77341b",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:18751",
  "CreationTime": "2026-07-02T15:32:03Z",
  "ExternalAccess": false,
  "Id": "fcec1905-2018-4d62-e023-08ded84f116c",
  "ObjectId": "dwshared",
  "Operation": "Add-RecipientPermission",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "AccessRights",
      "Value": "SendAs"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwshared@example.onmicrosoft.com"
    },
    {
      "Name": "Trustee",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "8d5b0e61-9a50-1fcb-2603-cc3b8978abdc",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
AccessRights (elastic rule field)eqsendas1 ruleelastic
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Add-RoleGroupMember

#
RecordType
ExchangeAdmin

Description

A role group member was added via the Add-RoleGroupMember Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-837c-68c5-982d-be027a762ba3",
    "IssuedAtTime": "2026-07-03T04:26:34",
    "UniqueTokenId": "EvPNS22bdEiTvnGJY_ASAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:22290",
  "CreationDate": "2026-07-03T04:31:48",
  "CreationTime": "2026-07-03T04:31:48",
  "ExternalAccess": false,
  "Id": "d1890a7e-2eb0-4d63-32fb-08ded8bbfef1",
  "ObjectId": "Organization Management",
  "Operation": "Add-RoleGroupMember",
  "Operations": "Add-RoleGroupMember",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DM5PR16MB2165 (15.21.0159.018)",
  "Parameters": [
    {
      "Name": "Member",
      "Value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
    },
    {
      "Name": "Identity",
      "Value": "Organization Management"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "2e66f4b8-59d6-0dd2-ba3b-3d35c96f3f0c",
  "ResultStatus": "True",
  "SessionId": "006b4cda-837c-68c5-982d-be027a762ba3",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Disable-AntiPhishRule

#
RecordType
ExchangeAdmin

Description

An anti-phishing rule was disabled in Exchange Online Protection, reducing anti-phishing enforcement.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
Operation1 detection ruleKusto
RecordType1 detection ruleKusto
UserType1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:29572",
  "CreationTime": "2026-07-02T15:31:26Z",
  "ExternalAccess": false,
  "Id": "eeb1f490-8f1b-4752-ad48-08ded84efb41",
  "ObjectId": "dwapr",
  "Operation": "Disable-AntiPhishRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwapr"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "2df24877-e91d-b347-9673-8d8615b95e63",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

Disable-MalwareFilterRule

#
RecordType
ExchangeAdmin

Description

A malware filter rule was disabled, reducing malware scanning enforcement.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:27248",
  "CreationTime": "2026-07-02T15:31:30Z",
  "ExternalAccess": false,
  "Id": "df0f7edc-b5e4-40c2-9691-08ded84efda9",
  "ObjectId": "dwmfr",
  "Operation": "Disable-MalwareFilterRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwmfr"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "a6c40dec-7a3d-9ee7-045f-23fd2247f5cb",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Disable-SafeAttachmentRule

#
RecordType
ExchangeAdmin

Description

A Safe Attachments policy rule was disabled in Microsoft Defender for Office 365, reducing detonation-sandbox coverage.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
Operation1 detection ruleKusto
RecordType1 detection ruleKusto
UserType1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006ea83a-c87c-9d74-7069-3efed03a3197",
    "IssuedAtTime": "2026-07-25T21:14:40",
    "UniqueTokenId": "QvBHGk0zqkKjWpKkIiwiAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:19486",
  "CreationDate": "2026-07-25T21:22:50",
  "CreationTime": "2026-07-25T21:22:50",
  "ExternalAccess": false,
  "Id": "aaa78829-8025-42f5-78fb-08deea92e1ac",
  "ObjectId": "dwharn412a7798-sar",
  "Operation": "Disable-SafeAttachmentRule",
  "Operations": "Disable-SafeAttachmentRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "IA3PR16MB6655 (15.21.0245.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn412a7798-sar"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    }
  ],
  "RecordType": 1,
  "RequestId": "00bf62ab-aa73-899c-bcde-8c0068bf1f1a",
  "ResultStatus": "True",
  "SessionId": "006ea83a-c87c-9d74-7069-3efed03a3197",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange Email Safe Attachment Rule Disabled source low: Identifies when a safe attachment rule is disabled in Microsoft 365. Safe attachment rules can extend malware protections to include routing all messages and attachments without a known malware signature to a special hypervisor environment. An adversary or insider threat may disable a safe attachment rule to exfiltrate data or evade defenses.T1562, T1562.001

Kusto #

References #

Disable-SafeLinksRule

#
RecordType
ExchangeAdmin

Description

A Safe Links policy rule was disabled in Microsoft Defender for Office 365, reducing URL-rewriting coverage.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
Operation1 detection ruleKusto
RecordType1 detection ruleKusto
UserType1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2024-02-01T22:21:33",
    "UniqueTokenId": "87Hz6J-5h0K6bJR_NT9QAA"
  },
  "AppId": "80ccca67-54bd-44ab-8625-4b79c4dc7775",
  "AppPoolName": "MSExchangeAdminApiAppPool",
  "ClientIP": "189.135.168.197:14381",
  "CreationTime": "2024-02-01T22:26:34",
  "ExternalAccess": false,
  "Id": "477ed988-73b0-493a-b3a9-08dc2374d903",
  "ObjectId": "Safe-Links Org-Wide",
  "Operation": "Disable-SafeLinksRule",
  "OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "OrganizationName": "attack_range.onmicrosoft.com",
  "OriginatingServer": "BYAPR08MB5704 (15.20.7249.013)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "56216be3-9e84-411a-af36-13f200007341"
    }
  ],
  "RecordType": 1,
  "RequestId": "9f9f2ef1-0861-91d6-68da-af7ccdc0c5a2",
  "ResultStatus": "True",
  "SessionId": "c85d6a46-8c63-449b-9591-c3ab602dac97",
  "UserId": "attacker@attack_range.lan",
  "UserKey": "1003200143005E6B",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

Disable-TransportRule

#
RecordType
ExchangeAdmin

Description

A mail-flow transport rule was disabled, potentially allowing previously blocked or redirected mail to flow unimpeded.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:24923",
  "CreationTime": "2026-07-02T15:30:56Z",
  "ExternalAccess": false,
  "Id": "b85b63db-add2-4d0e-9cca-08ded84ee8fc",
  "ObjectId": "dwtr",
  "Operation": "Disable-TransportRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwtr"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "d1796c27-76a4-a1c8-71d5-7bb7defa703c",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

New-AcceptedDomain

#
RecordType
ExchangeAdmin

Description

A new accepted domain was added to the Exchange Online organization.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

New-AntiPhishPolicy

#
RecordType
ExchangeAdmin

Description

An anti phish policy was created via the New-AntiPhishPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:21085",
  "CreationTime": "2026-07-02T15:31:24Z",
  "ExternalAccess": false,
  "Id": "0eae10b5-72b2-4178-6e59-08ded84efa23",
  "ObjectId": "example.onmicrosoft.com\\dwap",
  "Operation": "New-AntiPhishPolicy",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Name",
      "Value": "dwap"
    }
  ],
  "RecordType": 1,
  "RequestId": "711769be-29d9-8491-bd32-4caf6eab90f8",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-App

#
RecordType
ExchangeAdmin

Description

An Outlook or Exchange add-in (app) was installed into the organization or a mailbox.

References #

New-DistributionGroup

#
RecordType
ExchangeAdmin

Description

A distribution group was created via the New-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:23717",
  "CreationDate": "2026-07-03T01:55:17",
  "CreationTime": "2026-07-03T01:55:17",
  "ExternalAccess": false,
  "Id": "d258fca2-67d8-4982-6823-08ded8a621ab",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/dwharna9dd06c7-dg",
  "Operation": "New-DistributionGroup",
  "Operations": "New-DistributionGroup",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "BN7PPF175DB1016 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharna9dd06c7-dg"
    },
    {
      "Name": "Type",
      "Value": "Distribution"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "63cfd54f-e2a7-ff76-a7ee-79921cf5daab",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-DkimSigningConfig

#
RecordType
ExchangeAdmin

Description

A dkim signing config was created via the New-DkimSigningConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:16271",
  "CreationDate": "2026-07-03T04:03:10",
  "CreationTime": "2026-07-03T04:03:10",
  "ExternalAccess": false,
  "Id": "8d97ce5e-bb1d-4526-20bc-08ded8b7ff19",
  "ObjectId": "example.onmicrosoft.com\\example.onmicrosoft.com",
  "Operation": "New-DkimSigningConfig",
  "Operations": "New-DkimSigningConfig",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "CH3PR16MB5969 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "DomainName",
      "Value": "example.onmicrosoft.com"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Enabled",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "94fc7691-f72f-629e-d023-868adeb8a8e3",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-ExoInformationBarrierSegment

#
RecordType
ExchangeAdmin

Description

An exo information barrier segment was created via the New-ExoInformationBarrierSegment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2026-07-03T05:56:29",
    "UniqueTokenId": "245eff30-bd3a-8dc4-91ce-bd632687c63c"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "[2001:db8::10]:14571",
  "CreationDate": "2026-07-03T06:00:46",
  "CreationTime": "2026-07-03T06:00:46",
  "ExternalAccess": false,
  "Id": "0e4bf4ee-4657-4691-560a-08ded8c86ced",
  "ObjectId": "example.onmicrosoft.com\\2bb8ca5f-c452-48c0-9e0f-99a7603caab7",
  "Operation": "New-ExoInformationBarrierSegment",
  "Operations": "New-ExoInformationBarrierSegment",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SN1PR16MB2397 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "SegmentId",
      "Value": "2bb8ca5f-c452-48c0-9e0f-99a7603caab7"
    },
    {
      "Name": "MembershipFilter",
      "Value": "Department -eq 'zzzdwharn'"
    },
    {
      "Name": "DisplayName",
      "Value": "dwharnee8749b4-seg"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "4b6cbc11-4a4b-1e9c-dbd0-0c4193693c24",
  "ResultStatus": "True",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-HostedContentFilterPolicy

#
RecordType
ExchangeAdmin

Description

A hosted content filter policy was created via the New-HostedContentFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:11876",
  "CreationDate": "2026-07-03T01:55:39",
  "CreationTime": "2026-07-03T01:55:39",
  "ExternalAccess": false,
  "Id": "5393934e-7b70-4bac-00ad-08ded8a62f21",
  "ObjectId": "example.onmicrosoft.com\\dwharna9dd06c7-spam",
  "Operation": "New-HostedContentFilterPolicy",
  "Operations": "New-HostedContentFilterPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DM6PR16MB2668 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharna9dd06c7-spam"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "ae29f3c7-dc66-65f8-b128-ca5f7e13f651",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-InboundConnector

#
RecordType
ExchangeAdmin

Description

An inbound connector was created via the New-InboundConnector Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:46184",
  "CreationDate": "2026-07-03T04:02:39",
  "CreationTime": "2026-07-03T04:02:39",
  "ExternalAccess": false,
  "Id": "b790651e-9258-4c62-1aae-08ded8b7ecba",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-ic",
  "Operation": "New-InboundConnector",
  "Operations": "New-InboundConnector",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "IA6PR16MB6837 (15.21.0159.018)",
  "Parameters": [
    {
      "Name": "ConnectorType",
      "Value": "Partner"
    },
    {
      "Name": "SenderDomains",
      "Value": "smtp:*.example.com;1"
    },
    {
      "Name": "Name",
      "Value": "dwharn867f01-ic"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "8b50e0ca-7ad0-b6f2-514f-96cf0269bc2b",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-InboxRule

#
RecordType
ExchangeAdmin

Description

An Exchange inbox rule was created via the New-InboxRule cmdlet; first-party capture confirms it logs under ExchangeAdmin (RecordType 1), not the OWA-context UpdateInboxRules operation under ExchangeItem (RecordType 2).

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation9 detection rulesKusto, Sigma, Splunk
Parameters4 detection rulesKusto, Sigma
event.action3 detection rulesElastic
event.outcome3 detection rulesElastic
event.provider2 detection rulesElastic
UserId2 detection rulesKusto
Workload2 detection rulesSplunk
o365.audit.Parameters.BlindCopyTo1 detection ruleElastic
o365.audit.Parameters.BodyContainsWords1 detection ruleElastic
o365.audit.Parameters.DeleteMessage1 detection ruleElastic
o365.audit.Parameters.ForwardingAddress1 detection ruleElastic
o365.audit.Parameters.ForwardingSmtpAddress1 detection ruleElastic
o365.audit.Parameters.MoveToFolder1 detection ruleElastic
o365.audit.Parameters.RedirectMessageTo1 detection ruleElastic
o365.audit.Parameters.RedirectToRecipients1 detection ruleElastic
o365.audit.Parameters.SubjectContainsWords1 detection ruleElastic
o365.audit.Parameters.WithinSizeRangeMinimum1 detection ruleElastic
ObjectId1 detection ruleElastic
OperationProperties1 detection ruleSigma
Parameters.ForwardAsAttachmentTo1 detection ruleElastic
Parameters.ForwardTo1 detection ruleElastic
Parameters.RedirectTo1 detection ruleElastic
Parameters{}.Name1 detection ruleSplunk
ResultStatus1 detection ruleKusto
TimeGenerated1 detection ruleKusto
Workload1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:23059",
  "CreationTime": "2026-07-02T15:31:20Z",
  "ExternalAccess": false,
  "Id": "c2d4654f-074e-4ec9-2911-08ded84ef746",
  "ObjectId": "11111111-1111-1111-1111-111111111111\\dwir",
  "Operation": "New-InboxRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "DeleteMessage",
      "Value": "True"
    },
    {
      "Name": "Name",
      "Value": "dwir"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Mailbox",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "SubjectContainsWords",
      "Value": "x"
    }
  ],
  "RecordType": 1,
  "RequestId": "75896e1e-3a27-9b7c-c38b-89c552840b3c",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
m365::Parameterscontainsdeletemessage3 ruleskusto, sigma
m365::Parameters (kusto rule field)containsdeleted items2 ruleskusto
m365::Parameters (kusto rule field)containsjunk email2 ruleskusto
BodyContainsWords (kusto rule field)containsphishing2 ruleskusto
BodyContainsWords (kusto rule field)contains alert1 rulekusto
BodyContainsWords (kusto rule field)contains suspicious1 rulekusto
BodyContainsWords (kusto rule field)containsdo not click1 rulekusto
BodyContainsWords (kusto rule field)containsdo not open1 rulekusto
BodyContainsWords (kusto rule field)containsfake1 rulekusto
BodyContainsWords (kusto rule field)containsfatal1 rulekusto
BodyContainsWords (kusto rule field)containshelpdesk1 rulekusto
BodyContainsWords (kusto rule field)containshijacked1 rulekusto
BodyContainsWords (kusto rule field)containsmalicious1 rulekusto
SubjectContainsWords (kusto rule field)containsphishing2 ruleskusto
SubjectOrBodyContainsWords (kusto rule field)containsphishing2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • M365 Exchange Inbox Forwarding Rule Created source medium: Identifies when a new Inbox forwarding rule is created in Microsoft 365. Inbox rules process messages in the Inbox based on conditions and take actions. In this case, the rules will forward the emails to a defined address. Attackers can abuse Inbox Rules to intercept and exfiltrate email data without making organization-wide configuration changes or having the corresponding privileges.T1114, T1114.003↳ also matches New-TransportRule, Set-InboxRule, Set-Mailbox, Set-TransportRule
  • M365 Exchange Inbox Rule with Obfuscated Name source medium: Identifies when a Microsoft Exchange inbox rule is created or modified with a name composed only of special characters. Adversaries may use obfuscated inbox rule names to evade detection, hide malicious forwarding or deletion rules, or blend in with benign audit noise. The rule name is parsed from "o365.audit.ObjectId", which encodes the mailbox identity and rule name separated by a backslash.T1137, T1137.005, T1564, T1564.008↳ also matches Set-InboxRule
  • M365 Exchange Inbox Phishing Evasion Rule Created source high: Identifies when a user creates a new inbox rule in Microsoft 365 that deletes or moves emails containing suspicious keywords. Adversaries who have compromised accounts often create inbox rules to hide alerts, security notifications, or other sensitive messages by automatically deleting them or moving them to obscure folders. Common destinations include Deleted Items, Junk Email, RSS Feeds, and RSS Subscriptions. This is a New Terms rule that triggers only when the user principal name and associated source IP address have not been observed performing this activity in the past 14 days.T1137, T1137.005, T1564, T1564.008↳ also matches Set-InboxRule

Splunk #

Kusto #

  • Malicious BEC Inbox Rule source medium: 'Often times after the initial compromise in a BEC attack the attackers create inbox rules to delete emails that contain certain keywords related to their BEC attack. This is done so as to limit ability to warn compromised users that they've been compromised.T1078, T1098
  • Malicious Inbox Rule source medium: Often times after the initial compromise the attackers create inbox rules to delete emails that contain certain keywords. This is done so as to limit ability to warn compromised users that they've been compromised. Below is a sample query that tries to detect this. Reference: https://www.reddit.com/r/sysadmin/comments/7kyp0a/recent_phishing_attempts_my_experience_and_what/T1078, T1098
  • High risk Office operation conducted by IP Address that recently attempted to log into a disabled account source medium: It is possible that a disabled user account is compromised and another account on the same IP is used to perform operations that are not typical for that user. The query filters the SigninLogs for entries where ResultType is indicates a disabled account and the TimeGenerated is within a defined time range. It then summarizes these entries by IPAddress and AppId, calculating various statistics such as number of login attempts, distinct UPNs, App IDs etc and joins these results with another set of results from SigninLogs, filtering for entries with less than normal number of successful sign-ins. It then filters out entries where there were no successful sign-ins or where successful sign-ins did not occur within the same lookback period as the failed sign-ins, later projecting relevant fields by the count of login attempts, and expands the set of successful sign-ins into individual events. Finally, it joins these results with entries from OfficeActivity where certain operations deemed rare and high risk have been performed, ensuring their occurrance within a certain time range of the successful sign-ins.T1078, T1098, T1114↳ also matches Add-MailboxPermission, New-ManagementRoleAssignment, Set-InboxRule, Set-Mailbox, Set-TransportRule

References #

New-Mailbox

#
RecordType
ExchangeAdmin

Description

A mailbox was created via the New-Mailbox Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:33:23Z",
    "UniqueTokenId": "puNkY8foYkSQSz011CYOAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28645",
  "CreationTime": "2026-07-02T15:38:34Z",
  "ExternalAccess": false,
  "Id": "3ac8a4c1-bdce-416f-3bf2-08ded84ffa6c",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/dwshared2",
  "Operation": "New-Mailbox",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwshared2"
    },
    {
      "Name": "DisplayName",
      "Value": "dw shared2"
    },
    {
      "Name": "Shared",
      "Value": "True"
    },
    {
      "Name": "PrimarySmtpAddress",
      "Value": "dwshared2@example.onmicrosoft.com"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "WindowsLiveID",
      "Value": "dwshared2@example.onmicrosoft.com"
    },
    {
      "Name": "Password",
      "Value": "<Secure Information Omitted>"
    }
  ],
  "RecordType": 1,
  "RequestId": "304497c0-b535-26fe-bc04-a2912b562a1b",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-MalwareFilterPolicy

#
RecordType
ExchangeAdmin

Description

A malware filter policy was created via the New-MalwareFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:12976",
  "CreationTime": "2026-07-02T15:31:29Z",
  "ExternalAccess": false,
  "Id": "42083e17-4aee-4ee3-442d-08ded84efcc7",
  "ObjectId": "example.onmicrosoft.com\\dwmf",
  "Operation": "New-MalwareFilterPolicy",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Name",
      "Value": "dwmf"
    }
  ],
  "RecordType": 1,
  "RequestId": "25ba1270-d345-238a-71f2-6cfda0ce10bf",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-ManagementRoleAssignment

#
RecordType
ExchangeAdmin

Description

A new RBAC management role assignment was created, granting administrative permissions in Exchange Online.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation3 detection rulesKusto, Splunk
UserId2 detection rulesKusto
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
Role1 detection ruleSplunk
TimeGenerated1 detection ruleKusto
Workload1 detection ruleSplunk

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:26315",
  "CreationTime": "2026-07-02T15:31:32Z",
  "ExternalAccess": false,
  "Id": "155e24be-1cac-44ba-3ee5-08ded84efebf",
  "ObjectId": "example.onmicrosoft.com\\dwmra",
  "Operation": "New-ManagementRoleAssignment",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwmra"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Role",
      "Value": "View-Only Recipients"
    },
    {
      "Name": "User",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "4be42e87-23fa-fe08-4a55-91d29c3e1332",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
Role (splunk rule field)eqapplicationimpersonation1 rulesplunk
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

Kusto #

References #

New-ManagementScope

#
RecordType
ExchangeAdmin

Description

A management scope was created via the New-ManagementScope Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:46574",
  "CreationDate": "2026-07-03T04:03:13",
  "CreationTime": "2026-07-03T04:03:13",
  "ExternalAccess": false,
  "Id": "559b6c19-1b1f-4f31-5581-08ded8b800ee",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-ms",
  "Operation": "New-ManagementScope",
  "Operations": "New-ManagementScope",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "BYAPR16MB2949 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "RecipientRestrictionFilter",
      "Value": "Name -like 'zzz*'"
    },
    {
      "Name": "Name",
      "Value": "dwharn867f01-ms"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "bb22ced8-73dc-f6e9-ac46-25a9d18ecff6",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-MobileDeviceMailboxPolicy

#
RecordType
ExchangeAdmin

Description

A mobile device mailbox policy was created via the New-MobileDeviceMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:12012",
  "CreationDate": "2026-07-03T01:55:53",
  "CreationTime": "2026-07-03T01:55:53",
  "ExternalAccess": false,
  "Id": "5413d57f-0d2f-4bad-d807-08ded8a6374a",
  "ObjectId": "example.onmicrosoft.com\\dwharna9dd06c7-mdm",
  "Operation": "New-MobileDeviceMailboxPolicy",
  "Operations": "New-MobileDeviceMailboxPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "LV3PR16MB5882 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharna9dd06c7-mdm"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "e54ce337-e737-9d71-a08e-58483f07e7b6",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-OwaMailboxPolicy

#
RecordType
ExchangeAdmin

Description

An owa mailbox policy was created via the New-OwaMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:16516",
  "CreationDate": "2026-07-03T01:55:49",
  "CreationTime": "2026-07-03T01:55:49",
  "ExternalAccess": false,
  "Id": "a9e9fbd4-f182-4e75-54ae-08ded8a6351f",
  "ObjectId": "example.onmicrosoft.com\\dwharna9dd06c7-owa",
  "Operation": "New-OwaMailboxPolicy",
  "Operations": "New-OwaMailboxPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DS0PR16MB6878 (15.21.0159.007)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharna9dd06c7-owa"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "915f1229-8120-369a-4066-f024d651c3c2",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-RemoteDomain

#
RecordType
ExchangeAdmin

Description

A remote domain was created via the New-RemoteDomain Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:19441",
  "CreationDate": "2026-07-03T04:02:49",
  "CreationTime": "2026-07-03T04:02:49",
  "ExternalAccess": false,
  "Id": "c07a07c6-18be-4b16-4c8c-08ded8b7f2a9",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-rd",
  "Operation": "New-RemoteDomain",
  "Operations": "New-RemoteDomain",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "CH3PR16MB6372 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharn867f01-rd"
    },
    {
      "Name": "DomainName",
      "Value": "dwharn867f01.example.com"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "a90b03a0-e874-f8b5-cda6-175d0e710849",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-RetentionPolicy

#
RecordType
ExchangeAdmin

Description

A retention policy was created via the New-RetentionPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:16484",
  "CreationDate": "2026-07-03T04:02:57",
  "CreationTime": "2026-07-03T04:02:57",
  "ExternalAccess": false,
  "Id": "35cf24ff-101d-4579-38a9-08ded8b7f76e",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-rp",
  "Operation": "New-RetentionPolicy",
  "Operations": "New-RetentionPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA5PPFC5A1786DC (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharn867f01-rp"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "cd045617-e0a9-9752-8964-ee0f0dcdb008",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-RetentionPolicyTag

#
RecordType
ExchangeAdmin

Description

A retention policy tag was created via the New-RetentionPolicyTag Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:14757",
  "CreationDate": "2026-07-03T04:03:02",
  "CreationTime": "2026-07-03T04:03:02",
  "ExternalAccess": false,
  "Id": "eacc3de6-2b4b-4456-3c2b-08ded8b7faa9",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-rpt",
  "Operation": "New-RetentionPolicyTag",
  "Operations": "New-RetentionPolicyTag",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA6PR16MB6695 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Type",
      "Value": "All"
    },
    {
      "Name": "AgeLimitForRetention",
      "Value": "365.00:00:00"
    },
    {
      "Name": "RetentionEnabled",
      "Value": "True"
    },
    {
      "Name": "RetentionAction",
      "Value": "DeleteAndAllowRecovery"
    },
    {
      "Name": "Name",
      "Value": "dwharn867f01-rpt"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "e335dfb8-9fe4-4a9a-9b01-f1db349b82ec",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-RoleGroup

#
RecordType
ExchangeAdmin

Description

A new RBAC role group was created in Exchange Online.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:20325",
  "CreationTime": "2026-07-02T15:31:34Z",
  "ExternalAccess": false,
  "Id": "ac68f239-eb02-4baa-d265-08ded84effec",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/dwrg",
  "Operation": "New-RoleGroup",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Roles",
      "Value": "View-Only Recipients"
    },
    {
      "Name": "Name",
      "Value": "dwrg"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    }
  ],
  "RecordType": 1,
  "RequestId": "137a6d48-09cb-6af0-0c4a-f479dfe1ea63",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-SafeAttachmentPolicy

#
RecordType
ExchangeAdmin

Description

A safe attachment policy was created via the New-SafeAttachmentPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:29457",
  "CreationDate": "2026-07-03T04:02:26",
  "CreationTime": "2026-07-03T04:02:26",
  "ExternalAccess": false,
  "Id": "9032a13c-2a86-4ada-8d51-08ded8b7e50d",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-sa",
  "Operation": "New-SafeAttachmentPolicy",
  "Operations": "New-SafeAttachmentPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DM4PR16MB5419 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Enable",
      "Value": "True"
    },
    {
      "Name": "Name",
      "Value": "dwharn867f01-sa"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "efc477f8-8b01-a528-ceb5-1de23c41fe4c",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-SafeAttachmentRule

#
RecordType
ExchangeAdmin

Description

A Defender for Office 365 Safe Attachments rule was created, binding a Safe Attachments policy to the recipients it applies to. Observed in first-party Unified Audit Log capture. A policy is inert until a rule references it, and a policy cannot be removed while one does.

References #

New-SafeLinksPolicy

#
RecordType
ExchangeAdmin

Description

A safe links policy was created via the New-SafeLinksPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:23168",
  "CreationDate": "2026-07-03T04:02:31",
  "CreationTime": "2026-07-03T04:02:31",
  "ExternalAccess": false,
  "Id": "828a31f2-d960-404e-84ec-08ded8b7e7b5",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-sl",
  "Operation": "New-SafeLinksPolicy",
  "Operations": "New-SafeLinksPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA2PR16MB4186 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharn867f01-sl"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "544b81ea-01ff-79cd-90ca-1bfaecbd0169",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-ServicePrincipal

#
RecordType
ExchangeAdmin

Description

A service principal was created via the New-ServicePrincipal Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-837c-68c5-982d-be027a762ba3",
    "IssuedAtTime": "2026-07-03T04:26:34",
    "UniqueTokenId": "EvPNS22bdEiTvnGJY_ASAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:36904",
  "CreationDate": "2026-07-03T04:31:43",
  "CreationTime": "2026-07-03T04:31:43",
  "ExternalAccess": false,
  "Id": "195b0e02-c074-4daf-5455-08ded8bbfc43",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "Operation": "New-ServicePrincipal",
  "Operations": "New-ServicePrincipal",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SJ2PR16MB6037 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "AppId",
      "Value": "22222222-2222-2222-2222-222222222222"
    },
    {
      "Name": "ServiceId",
      "Value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
    },
    {
      "Name": "DisplayName",
      "Value": "dw-activity-gen"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "014615a2-5ffb-f5ec-8a17-a3580108a7d3",
  "ResultStatus": "True",
  "SessionId": "006b4cda-837c-68c5-982d-be027a762ba3",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-SharingPolicy

#
RecordType
ExchangeAdmin

Description

A sharing policy was created via the New-SharingPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
    "IssuedAtTime": "2026-07-03T03:57:19",
    "UniqueTokenId": "UDdTvw0gP0-KXuQYegQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:26833",
  "CreationDate": "2026-07-03T04:02:52",
  "CreationTime": "2026-07-03T04:02:52",
  "ExternalAccess": false,
  "Id": "a863e1e3-e1f0-4647-1f51-08ded8b7f4ba",
  "ObjectId": "example.onmicrosoft.com\\dwharn867f01-sp",
  "Operation": "New-SharingPolicy",
  "Operations": "New-SharingPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "MW5PR16MB4738 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Name",
      "Value": "dwharn867f01-sp"
    },
    {
      "Name": "Domains",
      "Value": "Anonymous:CalendarSharingFreeBusySimple"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "66c3d910-71d2-351d-509b-f8bc984e62fa",
  "ResultStatus": "True",
  "SessionId": "006b4cda-9fde-e01a-d94e-64d9931a8822",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

New-TransportRule

#
RecordType
ExchangeAdmin

Description

A new mail-flow transport rule was created; adversaries use transport rules to silently copy, redirect, or delete messages.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation3 detection rulesKusto, Splunk
event.action2 detection rulesElastic
event.outcome2 detection rulesElastic
event.provider2 detection rulesElastic
Workload2 detection rulesKusto
event.category1 detection ruleElastic
ExpandedParameters.Name1 detection ruleKusto
ExpandedParameters.Value1 detection ruleKusto
o365.audit.Parameters.BlindCopyTo1 detection ruleElastic
o365.audit.Parameters.ForwardingAddress1 detection ruleElastic
o365.audit.Parameters.ForwardingSmtpAddress1 detection ruleElastic
o365.audit.Parameters.RedirectMessageTo1 detection ruleElastic
o365.audit.Parameters.RedirectToRecipients1 detection ruleElastic
p.Name1 detection ruleKusto
p.Value1 detection ruleKusto
Parameters.ForwardAsAttachmentTo1 detection ruleElastic
Parameters.ForwardTo1 detection ruleElastic
Parameters.RedirectTo1 detection ruleElastic
Workload1 detection ruleSplunk

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2024-04-05T02:04:16",
    "UniqueTokenId": "MlCqXpE8E0WXmJNhOtNuAA"
  },
  "CreationTime": "2024-04-05T02:09:30",
  "Id": "cae78cca-32a7-4589-8ee8-08dc55156db3",
  "Operation": "New-TransportRule",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 1,
  "ResultStatus": "True",
  "UserKey": "1003BFFD98415B4E",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange",
  "ClientIP": "120.1.121.43:15922",
  "UserId": "user30@splunkresearch.onmicrosoft.com",
  "AppId": "d3590ed6-52b3-4102-aeff-aad2292ab01c",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ExternalAccess": false,
  "OrganizationName": "splunkresearch.onmicrosoft.com",
  "OriginatingServer": "CH0PR18MB4290 (15.20.7409.037)",
  "Parameters": [
    {
      "Name": "Priority",
      "Value": "0"
    },
    {
      "Name": "BlindCopyTo",
      "Value": "attacker@evil.com"
    },
    {
      "Name": "Name",
      "Value": "msInvader mailfow rule"
    }
  ],
  "RequestId": "6864046b-09f3-66e9-8e2a-0e184ff4f19b",
  "SessionId": "3aee2e0a-dbf2-49eb-982c-5ecc93a41c29"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess2 ruleselastic
ExpandedParameters.Name (kusto rule field)inblindcopyto1 rulekusto
ExpandedParameters.Name (kusto rule field)inredirectmessageto1 rulekusto
ExpandedParameters.Value (kusto rule field)is_not_null1 rulekusto
m365::Parameters.ForwardAsAttachmentTo (elastic rule field)is_not_null1 ruleelastic
m365::Parameters.ForwardTo (elastic rule field)is_not_null1 ruleelastic
m365::Parameters.RedirectTo (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.BlindCopyTo (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.ForwardingAddress (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.ForwardingSmtpAddress (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.RedirectMessageTo (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.RedirectToRecipients (elastic rule field)is_not_null1 ruleelastic
p.Name (kusto rule field)eqblindcopyto1 rulekusto
p.Name (kusto rule field)eqredirectmessageto1 rulekusto
p.Value (kusto rule field)is_not_null1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

  • O365 New Forwarding Mailflow Rule Created source: The following analytic detects the creation of new mail flow rules in Office 365 that may redirect or copy emails to unauthorized or external addresses. It leverages Office 365 Management Activity logs, specifically querying for the…T1114

Kusto #

References #

New-UnifiedGroup

#
RecordType
ExchangeAdmin

Description

An unified group was created via the New-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppPoolName": "Microsoft.Exchange.DsApi.GRpc.NetCore",
  "CreationTime": "2026-07-04T16:14:05Z",
  "ExternalAccess": false,
  "Id": "957e14b8-9e38-49fa-c659-08ded9e7451d",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/AllCompany.181245214720.zzjydiec_24c1912b67",
  "Operation": "New-UnifiedGroup",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DS4PR16MB7145 (15.21.0159.007)",
  "Parameters": [
    {
      "Name": "IgnoreNamingPolicy",
      "Value": "True"
    },
    {
      "Name": "DomainController",
      "Value": "SJ0PR16A14DC003.NAMPR16A014.PROD.OUTLOOK.COM"
    },
    {
      "Name": "UnifiedGroupAccessType",
      "Value": "Public"
    },
    {
      "Name": "ProvisioningOptions",
      "Value": "YammerProvisioning"
    },
    {
      "Name": "GroupPersonification"
    },
    {
      "Name": "InformationBarrierMode",
      "Value": "Open"
    },
    {
      "Name": "EmailAddresses",
      "Value": "SMTP:AllCompany.181245214720.zzjydiec@example.onmicrosoft.com"
    },
    {
      "Name": "Database",
      "Value": "NAMPR16DG406-db377"
    }
  ],
  "RecordType": 1,
  "RequestId": "3f74cfbf-4aa2-44b9-b757-33e8fed6802b",
  "ResultStatus": "True",
  "UserId": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-AcceptedDomain

#
RecordType
ExchangeAdmin

Description

An accepted domain was removed from the Exchange Online organization.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Remove-AntiPhishPolicy

#
RecordType
ExchangeAdmin

Description

An anti-phishing policy was deleted.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
Operation1 detection ruleKusto
RecordType1 detection ruleKusto
UserType1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:19711",
  "CreationTime": "2026-07-02T15:31:28Z",
  "ExternalAccess": false,
  "Id": "694337cf-2b6a-4c8c-1a56-08ded84efc34",
  "ObjectId": "dwap",
  "Operation": "Remove-AntiPhishPolicy",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwap"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "a0ec8e4e-882b-0dd7-4296-9ee845a02d23",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange Anti-Phish Policy Deleted source medium: Identifies the deletion of an anti-phishing policy in Microsoft 365. By default, Microsoft 365 includes built-in features that help protect users from phishing attacks. Anti-phishing polices increase this protection by refining settings to better detect and prevent attacks.T1484, T1562, T1562.001

Kusto #

References #

Remove-AntiPhishRule

#
RecordType
ExchangeAdmin

Description

An anti-phishing rule was deleted from Exchange Online Protection.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
Operation1 detection ruleKusto
RecordType1 detection ruleKusto
UserType1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:17896",
  "CreationTime": "2026-07-02T15:31:27Z",
  "ExternalAccess": false,
  "Id": "5a3c9793-27fa-45b4-6be2-08ded84efbaf",
  "ObjectId": "dwapr",
  "Operation": "Remove-AntiPhishRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwapr"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "1727cef2-6742-fe9e-8c45-b28696b853df",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

Remove-DistributionGroup

#
RecordType
ExchangeAdmin

Description

A distribution group was deleted via the Remove-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:18301",
  "CreationDate": "2026-07-03T01:56:31",
  "CreationTime": "2026-07-03T01:56:31",
  "ExternalAccess": false,
  "Id": "e8b2e134-1c36-4de7-2e6e-08ded8a64e15",
  "ObjectId": "dwharna9dd06c7-dg",
  "Operation": "Remove-DistributionGroup",
  "Operations": "Remove-DistributionGroup",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "LV8PR16MB6471 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharna9dd06c7-dg"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "f0010549-9587-4766-b2f6-884ea498a27f",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-DlpPolicy

#
RecordType
ExchangeAdmin

Description

A Data Loss Prevention policy was deleted from Exchange Online.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
Operation1 detection ruleKusto
RecordType1 detection ruleKusto
UserType1 detection ruleKusto

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

Remove-ExoInformationBarrierSegment

#
RecordType
ExchangeAdmin

Description

An exo information barrier segment was deleted via the Remove-ExoInformationBarrierSegment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2026-07-03T06:00:49",
    "UniqueTokenId": "32437bbd-6d7d-8789-a4d0-45da268ac647"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "[2001:db8::10]:11014",
  "CreationDate": "2026-07-03T06:00:52",
  "CreationTime": "2026-07-03T06:00:52",
  "ExternalAccess": false,
  "Id": "4c717efb-f797-4c04-5133-08ded8c87085",
  "ObjectId": "2bb8ca5f-c452-48c0-9e0f-99a7603caab7",
  "Operation": "Remove-ExoInformationBarrierSegment",
  "Operations": "Remove-ExoInformationBarrierSegment",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "BY1PR16MB6484 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "2bb8ca5f-c452-48c0-9e0f-99a7603caab7"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "d5437e85-06f0-62aa-8baa-1d7456a51fa2",
  "ResultStatus": "True",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-FederatedDomain

#
RecordType
ExchangeAdmin

Description

A federated domain was removed from the Exchange Online organization.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Remove-HostedContentFilterPolicy

#
RecordType
ExchangeAdmin

Description

A hosted content filter policy was deleted via the Remove-HostedContentFilterPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:30226",
  "CreationDate": "2026-07-03T04:11:39",
  "CreationTime": "2026-07-03T04:11:39",
  "ExternalAccess": false,
  "Id": "011645be-efed-45c4-ff42-08ded8b92ee5",
  "ObjectId": "dwharn75efecde-spam",
  "Operation": "Remove-HostedContentFilterPolicy",
  "Operations": "Remove-HostedContentFilterPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "BN7PPF93464F273 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-spam"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "db8700c2-5735-6ca6-22ec-1de5dd0a42bd",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-InboundConnector

#
RecordType
ExchangeAdmin

Description

An inbound connector was deleted via the Remove-InboundConnector Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:22802",
  "CreationDate": "2026-07-03T04:12:01",
  "CreationTime": "2026-07-03T04:12:01",
  "ExternalAccess": false,
  "Id": "79023267-f2e3-47c0-7c6c-08ded8b93bff",
  "ObjectId": "dwharn75efecde-ic",
  "Operation": "Remove-InboundConnector",
  "Operations": "Remove-InboundConnector",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SJ2PR16MB6249 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-ic"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "87468291-f901-c8af-79bb-75799231e1be",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-InboxRule

#
RecordType
ExchangeAdmin

Description

An inbox rule was deleted via the Remove-InboxRule Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:20058",
  "CreationTime": "2026-07-02T15:31:23Z",
  "ExternalAccess": false,
  "Id": "50dac51b-793c-4618-7485-08ded84ef996",
  "ObjectId": "11111111-1111-1111-1111-111111111111\\5819733106155847681",
  "Operation": "Remove-InboxRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwir"
    },
    {
      "Name": "Mailbox",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "05a466ea-54ec-920b-55aa-6b631e49d70d",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-Mailbox

#
RecordType
ExchangeAdmin

Description

A mailbox was deleted via the Remove-Mailbox Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppId": "fb78d390-0c51-40cd-8e17-fdbfab77341b",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28436",
  "CreationTime": "2026-07-02T15:32:12Z",
  "ExternalAccess": false,
  "Id": "a5489d96-ee2c-48cd-4a6b-08ded84f1670",
  "ObjectId": "dwshared",
  "Operation": "Remove-Mailbox",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwshared@example.onmicrosoft.com"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "4226dd1a-be57-b1a1-64a6-7a60d40795d2",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-MailboxPermission

#
RecordType
ExchangeAdmin

Description

A mailbox permission was removed from a user.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppId": "fb78d390-0c51-40cd-8e17-fdbfab77341b",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:20785",
  "CreationTime": "2026-07-02T15:32:06Z",
  "ExternalAccess": false,
  "Id": "8c7509ea-c8d0-48ef-425c-08ded84f12b6",
  "ObjectId": "dwshared",
  "Operation": "Remove-MailboxPermission",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwshared@example.onmicrosoft.com"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "AccessRights",
      "Value": "FullAccess"
    },
    {
      "Name": "User",
      "Value": "adminuser@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "b1128244-ecdc-8a94-2338-739197ff03b9",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-MalwareFilterPolicy

#
RecordType
ExchangeAdmin

Description

A malware filter policy was deleted.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:22692",
  "CreationTime": "2026-07-02T15:31:31Z",
  "ExternalAccess": false,
  "Id": "52ed5062-086c-43d1-bc07-08ded84efe49",
  "ObjectId": "dwmf",
  "Operation": "Remove-MalwareFilterPolicy",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwmf"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "563e6919-ccdc-f0af-0144-4e5a86563674",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange Malware Filter Policy Deleted source medium: Identifies when a malware filter policy has been deleted in Microsoft 365. A malware filter policy is used to alert administrators that an internal user sent a message that contained malware. This may indicate an account or machine compromise that would need to be investigated. Deletion of a malware filter policy may be done to evade detection.T1562, T1562.001

References #

Remove-MalwareFilterRule

#
RecordType
ExchangeAdmin

Description

A malware filter rule was deleted.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:16762",
  "CreationTime": "2026-07-02T15:31:31Z",
  "ExternalAccess": false,
  "Id": "8ab219ca-8333-4b6a-59a7-08ded84efdfa",
  "ObjectId": "dwmfr",
  "Operation": "Remove-MalwareFilterRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwmfr"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "d55abd3b-e7b6-c8b2-05fc-1124a498287b",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Remove-ManagementRoleAssignment

#
RecordType
ExchangeAdmin

Description

A management role assignment was deleted via the Remove-ManagementRoleAssignment Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:17489",
  "CreationTime": "2026-07-02T15:31:33Z",
  "ExternalAccess": false,
  "Id": "894082ed-4b20-41bb-0623-08ded84eff3a",
  "ObjectId": "dwmra",
  "Operation": "Remove-ManagementRoleAssignment",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwmra"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "304a0458-313f-8ae1-6b60-bb35fe2abaaa",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-ManagementScope

#
RecordType
ExchangeAdmin

Description

A management scope was deleted via the Remove-ManagementScope Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:26667",
  "CreationDate": "2026-07-03T04:12:37",
  "CreationTime": "2026-07-03T04:12:37",
  "ExternalAccess": false,
  "Id": "3a18d037-f320-45ec-97bc-08ded8b9517e",
  "ObjectId": "dwharn75efecde-ms",
  "Operation": "Remove-ManagementScope",
  "Operations": "Remove-ManagementScope",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "IA2PR16MB6478 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-ms"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "593f7c24-f4ca-46d8-8479-603fedb6909d",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

remove-MobileDeviceMailboxPolicy

#
RecordType
ExchangeAdmin

Description

remove-Mobile Device Mailbox Policy activity in Exchange Online admin, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:29244",
  "CreationDate": "2026-07-03T01:55:59",
  "CreationTime": "2026-07-03T01:55:59",
  "ExternalAccess": false,
  "Id": "87d6f89d-9220-4f6d-65ed-08ded8a63b06",
  "ObjectId": "dwharna9dd06c7-mdm",
  "Operation": "remove-MobileDeviceMailboxPolicy",
  "Operations": "remove-MobileDeviceMailboxPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "MW3PR16MB3771 (15.21.0159.007)",
  "Parameters": [
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "Identity",
      "Value": "dwharna9dd06c7-mdm"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "8bef7c74-782c-8afe-676e-07dd0bbb2a53",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-OwaMailboxPolicy

#
RecordType
ExchangeAdmin

Description

An owa mailbox policy was deleted via the Remove-OwaMailboxPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:16056",
  "CreationDate": "2026-07-03T01:59:55",
  "CreationTime": "2026-07-03T01:59:55",
  "ExternalAccess": false,
  "Id": "8090a71e-c3cb-4610-441c-08ded8a6c75c",
  "ObjectId": "dwharna9dd06c7-owa",
  "Operation": "Remove-OwaMailboxPolicy",
  "Operations": "Remove-OwaMailboxPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "CH0PR16MB4563 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharna9dd06c7-owa"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "a910bca7-e8f3-4284-8b15-5ed0bef36491",
  "ResultStatus": "True",
  "SessionId": "006b4cda-5120-b5de-f02d-f24f872aa1a6",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-RecipientPermission

#
RecordType
ExchangeAdmin

Description

A recipient permission was deleted via the Remove-RecipientPermission Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:29692",
  "CreationDate": "2026-07-03T01:55:13",
  "CreationTime": "2026-07-03T01:55:13",
  "ExternalAccess": false,
  "Id": "d8994509-5f5e-4dda-3085-08ded8a61f1f",
  "ObjectId": "aaaaaaaa-0000-0000-0000-000000000001",
  "Operation": "Remove-RecipientPermission",
  "Operations": "Remove-RecipientPermission",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DM4PR16MB5002 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "Identity",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "Trustee",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "AccessRights",
      "Value": "SendAs"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "228d36a9-b32c-4cde-dc62-8ded9e926fcd",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-RemoteDomain

#
RecordType
ExchangeAdmin

Description

A remote domain was deleted via the Remove-RemoteDomain Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:29999",
  "CreationDate": "2026-07-03T04:12:09",
  "CreationTime": "2026-07-03T04:12:09",
  "ExternalAccess": false,
  "Id": "52239b20-6fa0-43cb-086a-08ded8b94055",
  "ObjectId": "dwharn75efecde-rd",
  "Operation": "Remove-RemoteDomain",
  "Operations": "Remove-RemoteDomain",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "LV8PR16MB6758 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-rd"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "1175d96e-b8cd-4637-9ad2-16f24965ac37",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

remove-RetentionPolicy

#
RecordType
ExchangeAdmin

Description

remove-Retention Policy activity in Exchange Online admin, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:22431",
  "CreationDate": "2026-07-03T04:12:18",
  "CreationTime": "2026-07-03T04:12:18",
  "ExternalAccess": false,
  "Id": "eac782db-65a4-46ef-375d-08ded8b94633",
  "ObjectId": "dwharn75efecde-rp",
  "Operation": "remove-RetentionPolicy",
  "Operations": "remove-RetentionPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB7027 (15.21.0159.018)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-rp"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "fd7f8ca7-c3b4-53af-026e-da883d67b5ed",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-RetentionPolicyTag

#
RecordType
ExchangeAdmin

Description

A retention policy tag was deleted via the Remove-RetentionPolicyTag Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppId": "22222222-2222-2222-2222-222222222222",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:43190",
  "CreationDate": "2026-07-03T04:12:31",
  "CreationTime": "2026-07-03T04:12:31",
  "ExternalAccess": false,
  "Id": "f08cfb42-86d6-4a81-fcaa-08ded8b94d98",
  "ObjectId": "dwharn75efecde-rpt",
  "Operation": "Remove-RetentionPolicyTag",
  "Operations": "Remove-RetentionPolicyTag",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SJ2PR16MB5189 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-rpt"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "4601f706-8f5f-40d1-842f-077da6dbfbf3",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-RoleGroup

#
RecordType
ExchangeAdmin

Description

A role group was deleted via the Remove-RoleGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:30430",
  "CreationTime": "2026-07-02T15:31:35Z",
  "ExternalAccess": false,
  "Id": "a5261a07-db26-4305-8f9f-08ded84f0086",
  "ObjectId": "dwrg",
  "Operation": "Remove-RoleGroup",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwrg"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "b3ef24a6-0fbf-e3ed-592c-57e5690bc64b",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-SafeAttachmentPolicy

#
RecordType
ExchangeAdmin

Description

A safe attachment policy was deleted via the Remove-SafeAttachmentPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation1 detection ruleKusto
RecordType1 detection ruleKusto
UserType1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:21076",
  "CreationDate": "2026-07-03T04:11:54",
  "CreationTime": "2026-07-03T04:11:54",
  "ExternalAccess": false,
  "Id": "1478534a-75bf-480b-8607-08ded8b937b4",
  "ObjectId": "dwharn75efecde-sa",
  "Operation": "Remove-SafeAttachmentPolicy",
  "Operations": "Remove-SafeAttachmentPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB6812 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-sa"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "241e5166-866a-d10d-b631-289c91ecfc01",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Remove-SafeAttachmentRule

#
RecordType
ExchangeAdmin

Description

A Defender for Office 365 Safe Attachments rule was deleted, detaching its policy from the recipients it applied to. Observed in first-party Unified Audit Log capture. Deleting the rule leaves the underlying Safe Attachments policy in place but stops it applying to anyone.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation1 detection ruleKusto
RecordType1 detection ruleKusto
UserType1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006ea83a-ea88-19ef-0c5d-d3f2d744c4fe",
    "IssuedAtTime": "2026-07-25T21:05:48",
    "UniqueTokenId": "qtYdrqugs0qgOaLoYW4kAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:19834",
  "CreationDate": "2026-07-25T21:11:00",
  "CreationTime": "2026-07-25T21:11:00",
  "ExternalAccess": false,
  "Id": "4d1fe66b-0ef7-43d6-7bd0-08deea913aa7",
  "ObjectId": "dwharndiag1-sar2",
  "Operation": "Remove-SafeAttachmentRule",
  "Operations": "Remove-SafeAttachmentRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA0PR16MB3773 (15.21.0223.005)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharndiag1-sar2"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "78f515bc-f30b-3cac-22af-eba98e7c9324",
  "ResultStatus": "True",
  "SessionId": "006ea83a-ea88-19ef-0c5d-d3f2d744c4fe",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Remove-SafeLinksPolicy

#
RecordType
ExchangeAdmin

Description

A safe links policy was deleted via the Remove-SafeLinksPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation1 detection ruleKusto
RecordType1 detection ruleKusto
UserType1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-f544-cad9-543e-871e394fced1",
    "IssuedAtTime": "2026-07-03T03:59:33",
    "UniqueTokenId": "5C9dC0LSzkKNhApry74CAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:54960",
  "CreationDate": "2026-07-03T04:04:46",
  "CreationTime": "2026-07-03T04:04:46",
  "ExternalAccess": false,
  "Id": "0d964f43-ec9d-4ed7-5179-08ded8b83878",
  "ObjectId": "dwharn867f01-sl",
  "Operation": "Remove-SafeLinksPolicy",
  "Operations": "Remove-SafeLinksPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "MW2PR16MB2363 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Confirm",
      "Value": "False"
    },
    {
      "Name": "Identity",
      "Value": "dwharn867f01-sl"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "090a55cc-b821-07ed-b62a-69042e006491",
  "ResultStatus": "True",
  "SessionId": "006b4cda-f544-cad9-543e-871e394fced1",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Remove-SharingPolicy

#
RecordType
ExchangeAdmin

Description

A sharing policy was deleted via the Remove-SharingPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:12038",
  "CreationDate": "2026-07-03T04:12:14",
  "CreationTime": "2026-07-03T04:12:14",
  "ExternalAccess": false,
  "Id": "80c37e5c-9a0f-4a36-9f33-08ded8b94379",
  "ObjectId": "dwharn75efecde-shp",
  "Operation": "Remove-SharingPolicy",
  "Operations": "Remove-SharingPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DS4PR16MB6922 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-shp"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "d4d9e6ec-f203-626c-558e-6475e2231f86",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Remove-TransportRule

#
RecordType
ExchangeAdmin

Description

A mail-flow transport rule was deleted.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b25ca-8a7e-0c9f-50a5-1338131ca95c",
    "IssuedAtTime": "2026-07-02T00:51:46Z",
    "UniqueTokenId": "Gnv7bm9T4UKndwcLdscpAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28436",
  "CreationTime": "2026-07-02T00:57:31Z",
  "ExternalAccess": false,
  "Id": "8396ca95-334d-4a59-feec-08ded7d4e560",
  "ObjectId": "dw-ual-probe",
  "Operation": "Remove-TransportRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "CH4PR16MB6628 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "SilentlyContinue"
    },
    {
      "Name": "Identity",
      "Value": "dw-ual-probe"
    },
    {
      "Name": "Confirm",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "27c69567-3222-6667-38e5-550c4b08b0d2",
  "ResultStatus": "True",
  "SessionId": "006b25ca-8a7e-0c9f-50a5-1338131ca95c",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Remove-UnifiedGroup

#
RecordType
ExchangeAdmin

Description

An unified group was deleted via the Remove-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {},
  "AppPoolName": "Microsoft.Exchange.DsApi.GRpc.NetCore",
  "CreationDate": "2026-07-03T01:58:05",
  "CreationTime": "2026-07-03T01:58:05",
  "ExternalAccess": false,
  "Id": "ba8e5cc2-8aa2-41d8-fab3-08ded8a685da",
  "ObjectId": "dw-harness-planner-a9dd06c7_1a4adb2a-96c9-4df2-84be-fb5a7f0b1c16",
  "Operation": "Remove-UnifiedGroup",
  "Operations": "Remove-UnifiedGroup",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "DomainController",
      "Value": "SJ0PR16A14DC003.NAMPR16A014.PROD.OUTLOOK.COM"
    },
    {
      "Name": "Identity",
      "Value": "1a4adb2a-96c9-4df2-84be-fb5a7f0b1c16"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "a3c60667-0ac3-4d6a-9d03-cb49f0bc32b0",
  "ResultStatus": "True",
  "UserId": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-AcceptedDomain

#
RecordType
ExchangeAdmin

Description

An accepted domain's configuration was modified.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Set-AdminAuditLogConfig

#
RecordType
ExchangeAdmin

Description

The administrator audit log configuration was changed; adversaries disable audit logging to evade detection.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
security_result.detection_fields["UnifiedAuditLogIngestionEnabled"]2 detection rulesYARA-L
Operation1 detection ruleKusto
UserType1 detection ruleKusto
Workload1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
    "IssuedAtTime": "2026-07-03T01:48:00",
    "UniqueTokenId": "xGKhWEz58Eu_GIdEzQkBAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:60026",
  "CreationDate": "2026-07-03T01:56:19",
  "CreationTime": "2026-07-03T01:56:19",
  "ExternalAccess": false,
  "Id": "f8e09c2a-390e-4274-fbdc-08ded8a646d5",
  "ObjectId": "Admin Audit Log Settings",
  "Operation": "Set-AdminAuditLogConfig",
  "Operations": "Set-AdminAuditLogConfig",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SJ2PR16MB5913 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "UnifiedAuditLogIngestionEnabled",
      "Value": "True"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "488036dc-7381-1174-3746-88a0e8bb85d2",
  "ResultStatus": "True",
  "SessionId": "006b4cda-e430-2bb0-a583-8bae99d22ccc",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
UserType (kusto rule field)inadmin1 rulekusto
UserType (kusto rule field)indcadmin1 rulekusto
security_result.detection_fields["UnifiedAuditLogIngestionEnabled"] (Chronicle)eqFalse1 rulechronicle
security_result.detection_fields["UnifiedAuditLogIngestionEnabled"] (Chronicle)eqTrue1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • Exchange AuditLog Disabled source medium: Identifies when the exchange audit logging has been disabled which may be an adversary attempt to evade detection or avoid other defenses.T1562

YARA-L #

References #

Set-CASMailbox

#
RecordType
ExchangeAdmin

Description

Client-access settings on a mailbox were modified (for example enabling POP, IMAP, or OWA); commonly abused to enable legacy-protocol access.

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:13434",
  "CreationTime": "2026-07-02T15:31:36Z",
  "ExternalAccess": false,
  "Id": "8d4d327c-cfc9-4128-52b3-08ded84f013a",
  "ObjectId": "11111111-1111-1111-1111-111111111111",
  "Operation": "Set-CASMailbox",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "ImapEnabled",
      "Value": "False"
    },
    {
      "Name": "PopEnabled",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "eb483126-8215-1bb5-56bd-68977780e2c8",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-ConditionalAccessPolicy

#
RecordType
ExchangeAdmin

Description

A conditional access policy was modified via the Set-ConditionalAccessPolicy Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2026-07-03T02:37:56",
    "UniqueTokenId": "ecd03fcc-f954-8335-9c1d-3ecc25d48b19"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28300",
  "CreationDate": "2026-07-03T02:37:58",
  "CreationTime": "2026-07-03T02:37:58",
  "ExternalAccess": true,
  "Id": "423111a8-0ada-4da2-9370-08ded8ac1830",
  "ObjectId": "example.onmicrosoft.com\\12b1e3b4-7e38-4b24-a740-186a3e9e8556",
  "Operation": "Set-ConditionalAccessPolicy",
  "Operations": "Set-ConditionalAccessPolicy",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SJ2PR16MB5119 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "example.onmicrosoft.com\\12b1e3b4-7e38-4b24-a740-186a3e9e8556"
    },
    {
      "Name": "PolicyDetails",
      "Value": {
        "DummyKnownNetworkPolicy": ""
      }
    },
    {
      "Name": "PolicyLastUpdatedTime",
      "Value": "07/03/2026 02:37:57"
    },
    {
      "Name": "TenantDefaultPolicy",
      "Value": "6"
    },
    {
      "Name": "DisplayName",
      "Value": "Known Networks List"
    },
    {
      "Name": "PolicyIdentifierString",
      "Value": "2026-07-03T01:52:53.8030224Z"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "972156ee-5838-8ed5-9a0d-6fcd9cfe91af",
  "ResultStatus": "True",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserType": "DcAdmin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-DistributionGroup

#
RecordType
ExchangeAdmin

Description

A distribution group was modified via the Set-DistributionGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:51150",
  "CreationDate": "2026-07-03T04:09:00",
  "CreationTime": "2026-07-03T04:09:00",
  "ExternalAccess": false,
  "Id": "49afcf55-700d-41d7-ce4e-08ded8b8cfa8",
  "ObjectId": "dwharn75efecde-dg",
  "Operation": "Set-DistributionGroup",
  "Operations": "Set-DistributionGroup",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "IA6PR16MB7054 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "dwharn75efecde-dg"
    },
    {
      "Name": "HiddenFromAddressListsEnabled",
      "Value": "True"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "00b49648-7b24-6ab5-4ca8-161717ee817c",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-DkimSigningConfig

#
RecordType
ExchangeAdmin

Description

The DKIM signing configuration for a domain was modified; disabling DKIM weakens email authentication.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.category1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
o365.audit.Parameters.Enabled1 detection ruleElastic

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006ea83a-48e6-e856-a0c6-63b801badfa7",
    "IssuedAtTime": "2026-07-25T20:58:32",
    "UniqueTokenId": "qUaKtx20zEShctAylTcjAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:17313",
  "CreationDate": "2026-07-25T21:07:40",
  "CreationTime": "2026-07-25T21:07:40",
  "ExternalAccess": false,
  "Id": "9a0ee24b-d391-4f4b-99e3-08deea90c30c",
  "ObjectId": "example.onmicrosoft.com",
  "Operation": "Set-DkimSigningConfig",
  "Operations": "Set-DkimSigningConfig",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "DM5PR16MB2230 (15.21.0245.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "example.onmicrosoft.com"
    },
    {
      "Name": "Enabled",
      "Value": "False"
    }
  ],
  "RecordType": 1,
  "RequestId": "6e47c62c-f13e-d610-4bda-0c46ecd38230",
  "ResultStatus": "True",
  "SessionId": "006ea83a-48e6-e856-a0c6-63b801badfa7",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic
o365.audit.Parameters.Enabled (elastic rule field)eqfalse1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange DKIM Signing Configuration Disabled source medium: Identifies when a DomainKeys Identified Mail (DKIM) signing configuration is disabled in Microsoft 365. With DKIM in Microsoft 365, messages that are sent from Exchange Online will be cryptographically signed. This will allow the receiving email system to validate that the messages were generated by a server that the organization authorized and were not spoofed.T1484, T1562, T1562.001

References #

Set-InboxRule

#
RecordType
ExchangeAdmin

Description

An Exchange inbox rule was modified via the Set-InboxRule cmdlet; first-party capture confirms it logs under ExchangeAdmin (RecordType 1), like New-InboxRule, not the OWA-context UpdateInboxRules operation under ExchangeItem (RecordType 2).

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation7 detection rulesKusto, Sigma, Splunk
event.action3 detection rulesElastic
event.outcome3 detection rulesElastic
event.provider2 detection rulesElastic
Parameters2 detection rulesSigma
UserId2 detection rulesKusto
Workload2 detection rulesSplunk
o365.audit.Parameters.BlindCopyTo1 detection ruleElastic
o365.audit.Parameters.BodyContainsWords1 detection ruleElastic
o365.audit.Parameters.DeleteMessage1 detection ruleElastic
o365.audit.Parameters.ForwardingAddress1 detection ruleElastic
o365.audit.Parameters.ForwardingSmtpAddress1 detection ruleElastic
o365.audit.Parameters.MoveToFolder1 detection ruleElastic
o365.audit.Parameters.RedirectMessageTo1 detection ruleElastic
o365.audit.Parameters.RedirectToRecipients1 detection ruleElastic
o365.audit.Parameters.SubjectContainsWords1 detection ruleElastic
o365.audit.Parameters.WithinSizeRangeMinimum1 detection ruleElastic
ObjectId1 detection ruleElastic
OperationProperties1 detection ruleSigma
Parameters.ForwardAsAttachmentTo1 detection ruleElastic
Parameters.ForwardTo1 detection ruleElastic
Parameters.RedirectTo1 detection ruleElastic
Parameters{}.Name1 detection ruleSplunk
TimeGenerated1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:20791",
  "CreationTime": "2026-07-02T15:31:21Z",
  "ExternalAccess": false,
  "Id": "9edc78e0-e3bb-4360-3066-08ded84ef84f",
  "ObjectId": "11111111-1111-1111-1111-111111111111\\5819733106155847681",
  "Operation": "set-InboxRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwir"
    },
    {
      "Name": "Mailbox",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "MarkAsRead",
      "Value": "True"
    }
  ],
  "RecordType": 1,
  "RequestId": "d8b1e178-d27b-89ac-a0c6-3813583de487",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
ResultType (kusto rule field)eq500571 rulekusto
m365::ObjectId (elastic rule field)is_not_null1 ruleelastic
m365::Parameters (sigma rule field)containsdeletemessage1 rulesigma
m365::Parameters (sigma rule field)containsforwardingsmtpaddress1 rulesigma
m365::Parameters (sigma rule field)containsforwardto1 rulesigma
m365::Parameters (sigma rule field)containsredirectto1 rulesigma
match1 (splunk rule field)ge01 rulesplunk
match2 (splunk rule field)ge01 rulesplunk
match3 (splunk rule field)ge01 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • M365 Exchange Inbox Forwarding Rule Created source medium: Identifies when a new Inbox forwarding rule is created in Microsoft 365. Inbox rules process messages in the Inbox based on conditions and take actions. In this case, the rules will forward the emails to a defined address. Attackers can abuse Inbox Rules to intercept and exfiltrate email data without making organization-wide configuration changes or having the corresponding privileges.T1114, T1114.003↳ also matches New-InboxRule, New-TransportRule, Set-Mailbox, Set-TransportRule
  • M365 Exchange Inbox Rule with Obfuscated Name source medium: Identifies when a Microsoft Exchange inbox rule is created or modified with a name composed only of special characters. Adversaries may use obfuscated inbox rule names to evade detection, hide malicious forwarding or deletion rules, or blend in with benign audit noise. The rule name is parsed from "o365.audit.ObjectId", which encodes the mailbox identity and rule name separated by a backslash.T1137, T1137.005, T1564, T1564.008↳ also matches New-InboxRule
  • M365 Exchange Inbox Phishing Evasion Rule Created source high: Identifies when a user creates a new inbox rule in Microsoft 365 that deletes or moves emails containing suspicious keywords. Adversaries who have compromised accounts often create inbox rules to hide alerts, security notifications, or other sensitive messages by automatically deleting them or moving them to obscure folders. Common destinations include Deleted Items, Junk Email, RSS Feeds, and RSS Subscriptions. This is a New Terms rule that triggers only when the user principal name and associated source IP address have not been observed performing this activity in the past 14 days.T1137, T1137.005, T1564, T1564.008↳ also matches New-InboxRule

Splunk #

Kusto #

References #

Set-Mailbox

#
RecordType
ExchangeAdmin

Description

A mailbox configuration was modified; commonly abused to enable forwarding, audit bypass, or delegate access.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation4 detection rulesKusto, Sigma, Splunk
event.action2 detection rulesElastic
event.outcome2 detection rulesElastic
event.provider2 detection rulesElastic
UserId2 detection rulesKusto
o365.audit.Parameters.BlindCopyTo1 detection ruleElastic
o365.audit.Parameters.ForwardingAddress1 detection ruleElastic
o365.audit.Parameters.ForwardingSmtpAddress1 detection ruleElastic
o365.audit.Parameters.GrantSendOnBehalfTo1 detection ruleElastic
o365.audit.Parameters.RedirectMessageTo1 detection ruleElastic
o365.audit.Parameters.RedirectToRecipients1 detection ruleElastic
OperationProperties1 detection ruleSigma
Parameters1 detection ruleSigma
Parameters.ForwardAsAttachmentTo1 detection ruleElastic
Parameters.ForwardTo1 detection ruleElastic
Parameters.RedirectTo1 detection ruleElastic
TimeGenerated1 detection ruleKusto
user.id1 detection ruleElastic
UserType1 detection ruleElastic

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2026-07-03T05:28:29Z",
    "UniqueTokenId": "7e7a831a-e1ff-81fc-8d45-c6142671e9a8"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "[2001:db8::10]:12026",
  "CreationTime": "2026-07-03T05:28:35Z",
  "ExternalAccess": true,
  "Id": "2ae66aa0-ea92-4dab-c281-08ded8c3edcd",
  "ObjectId": "NAMPR16A014.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/example.onmicrosoft.com/RecordReview{2b9ab0b1-2e7a-410b-9c30-a873824b4813}",
  "Operation": "Set-Mailbox",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "PH0PR16MB4040 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "RecordReview{2b9ab0b1-2e7a-410b-9c30-a873824b4813}@example.onmicrosoft.com"
    }
  ],
  "RecordType": 1,
  "RequestId": "6b1c4f08-79ad-ec5a-382f-e20662066e29",
  "ResultStatus": "True",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserType": 3,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess2 ruleselastic
m365::OperationProperties (sigma rule field)containsforward1 rulesigma
m365::OperationProperties (sigma rule field)containsrecipients1 rulesigma
m365::Parameters (sigma rule field)containsforwardasattachmentto1 rulesigma
m365::Parameters (sigma rule field)containsforwardingaddress1 rulesigma
m365::Parameters (sigma rule field)containsforwardingsmtpaddress1 rulesigma
m365::Parameters (sigma rule field)containsforwardto1 rulesigma
m365::Parameters (sigma rule field)containsredirectto1 rulesigma
m365::Parameters (sigma rule field)containsredirecttorecipients1 rulesigma
m365::Parameters.ForwardAsAttachmentTo (elastic rule field)is_not_null1 ruleelastic
m365::Parameters.ForwardTo (elastic rule field)is_not_null1 ruleelastic
m365::Parameters.RedirectTo (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.BlindCopyTo (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.ForwardingAddress (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.ForwardingSmtpAddress (elastic rule field)is_not_null1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Splunk #

  • O365 Mailbox Email Forwarding Enabled source: The following analytic identifies instances where email forwarding has been enabled on mailboxes within an Office 365 environment. It detects this activity by monitoring the Set-Mailbox operation within the o365_management_activity logs,…T1114, T1114.003

Kusto #

References #

Set-MailboxAuditBypassAssociation

#
RecordType
ExchangeAdmin

Description

Mailbox audit logging was bypassed for a service account, suppressing audit events for that account's actions.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:17802",
  "CreationTime": "2026-07-02T15:31:38Z",
  "ExternalAccess": false,
  "Id": "ff4128b0-672e-41f3-b663-08ded84f0233",
  "ObjectId": "11111111-1111-1111-1111-111111111111",
  "Operation": "Set-MailboxAuditBypassAssociation",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "AuditBypassEnabled",
      "Value": "False"
    },
    {
      "Name": "Identity",
      "Value": "adminuser@example.onmicrosoft.com"
    },
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    }
  ],
  "RecordType": 1,
  "RequestId": "707b5aeb-749a-801f-b156-8ac44d10fe11",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange Mailbox Audit Logging Bypass Added source medium: Detects the occurrence of mailbox audit bypass associations. The mailbox audit is responsible for logging specified mailbox events (like accessing a folder or a message or permanently deleting a message). However, actions taken by some authorized accounts, such as accounts used by third-party tools or accounts used for lawful monitoring, can create a large number of mailbox audit log entries and may not be of interest to your organization. Because of this, administrators can create bypass associations, allowing certain accounts to perform their tasks without being logged. Attackers can abuse this allowlist mechanism to conceal actions taken, as the mailbox audit will log no activity done by the account.T1098, T1562, T1562.001

References #

Set-MailboxFolderPermission

#
RecordType
ExchangeAdmin

Description

An Exchange Online admin cmdlet modified folder-level permissions on a mailbox folder; recorded in the Exchange admin audit log with the Operation set to the cmdlet name (commonly abused to grant a delegate covert folder access).

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation1 detection ruleSplunk
Workload1 detection ruleSplunk

Example Audit Record #

{
  "AppAccessContext": {
    "IssuedAtTime": "2024-03-28T22:32:11",
    "UniqueTokenId": "HY_070GwA0efL-yHfwALAA"
  },
  "CreationTime": "2024-03-28T22:37:13",
  "Id": "c5062b01-a400-4212-1c0a-08dc4f779cd7",
  "Operation": "Set-MailboxFolderPermission",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 1,
  "ResultStatus": "True",
  "UserKey": "100320030DF47B14",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange",
  "ClientIP": "120.1.121.43:28973",
  "ObjectId": "2d2f9e2c-8350-4d98-852e-3f06daaf7185:\\Inbox",
  "UserId": "victim@splunkresearch.com",
  "AppId": "00b41c95-dab0-4487-9791-b9d2c32c80f2",
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ExternalAccess": false,
  "OrganizationName": "splunkresearch.com",
  "OriginatingServer": "MN2PR18MB3053 (15.20.7409.026)",
  "Parameters": [
    {
      "Name": "AccessRights",
      "Value": "Author"
    },
    {
      "Name": "User",
      "Value": "Default"
    },
    {
      "Name": "Identity",
      "Value": "victim@splunkresearch.com:\\Inbox"
    }
  ],
  "RequestId": "f4340c78-7dae-0700-1cdc-829d6eaad5cc",
  "SessionId": "d0e022ae-5d62-48da-aca4-a8d401c128e1"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

Set-OrganizationConfig

#
RecordType
ExchangeAdmin

Description

An organization config was modified via the Set-OrganizationConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-a1b3-9e63-d5b5-a8bb31828c96",
    "IssuedAtTime": "2026-07-03T05:58:00",
    "UniqueTokenId": "b5LCVRhMZk6Y4kZ2fSYUAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:13818",
  "CreationDate": "2026-07-03T06:03:01",
  "CreationTime": "2026-07-03T06:03:01",
  "ExternalAccess": false,
  "Id": "e64f5100-80b3-4497-2802-08ded8c8bd35",
  "ObjectId": "First Organization",
  "Operation": "Set-OrganizationConfig",
  "Operations": "Set-OrganizationConfig",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4804 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "InPlaceHolds",
      "Value": ""
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "d4cd117b-05fa-71ea-084a-14dc3f7286e4",
  "ResultStatus": "True",
  "SessionId": "006b4cda-a1b3-9e63-d5b5-a8bb31828c96",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeAdminApiNetCore (Microsoft.Exchange.AdminApi.NetCore)",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-TransportConfig

#
RecordType
ExchangeAdmin

Description

A transport config was modified via the Set-TransportConfig Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
    "IssuedAtTime": "2026-07-03T04:01:47",
    "UniqueTokenId": "5ENALe5qU0uB6rv2ExQDAA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28876",
  "CreationDate": "2026-07-03T04:11:05",
  "CreationTime": "2026-07-03T04:11:05",
  "ExternalAccess": false,
  "Id": "446af425-d709-4351-fe5b-08ded8b91a12",
  "ObjectId": "Transport Settings",
  "Operation": "Set-TransportConfig",
  "Operations": "Set-TransportConfig",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "BY1PR16MB6382 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ExternalPostmasterAddress",
      "Value": "dwharna9dd06c7@example.com"
    }
  ],
  "RecordType": "ExchangeAdmin",
  "RequestId": "00261cb3-1740-4f59-e94c-ba7278ec5462",
  "ResultStatus": "True",
  "SessionId": "006b4cda-916a-cebe-75d7-5b33e67b1837",
  "TokenObjectId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
  "TokenTenantId": "11111111-1111-1111-1111-111111111111",
  "UserId": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserKey": "example.onmicrosoft.com\\22222222-2222-2222-2222-222222222222",
  "UserType": "Admin",
  "Version": 1,
  "Workload": "Exchange"
}

References #

Set-TransportRule

#
RecordType
ExchangeAdmin

Description

An existing mail-flow transport rule was modified.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation4 detection rulesKusto
UserId2 detection rulesKusto
Workload2 detection rulesKusto
event.action1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
ExpandedParameters.Name1 detection ruleKusto
ExpandedParameters.Value1 detection ruleKusto
o365.audit.Parameters.BlindCopyTo1 detection ruleElastic
o365.audit.Parameters.ForwardingAddress1 detection ruleElastic
o365.audit.Parameters.ForwardingSmtpAddress1 detection ruleElastic
o365.audit.Parameters.RedirectMessageTo1 detection ruleElastic
o365.audit.Parameters.RedirectToRecipients1 detection ruleElastic
p.Name1 detection ruleKusto
p.Value1 detection ruleKusto
Parameters.ForwardAsAttachmentTo1 detection ruleElastic
Parameters.ForwardTo1 detection ruleElastic
Parameters.RedirectTo1 detection ruleElastic
TimeGenerated1 detection ruleKusto

Example Audit Record #

{
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "IssuedAtTime": "2026-07-02T15:24:51Z",
    "UniqueTokenId": "ud1bqbqyGUSbpLANgG12AA"
  },
  "AppPoolName": "MSExchangeAdminApiNetCore",
  "ClientIP": "203.0.113.10:28540",
  "CreationTime": "2026-07-02T15:30:36Z",
  "ExternalAccess": false,
  "Id": "1516f079-7c62-4568-da44-08ded84edd10",
  "ObjectId": "dwtr",
  "Operation": "Set-TransportRule",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "ErrorAction",
      "Value": "Stop"
    },
    {
      "Name": "Identity",
      "Value": "dwtr"
    },
    {
      "Name": "SubjectContainsWords",
      "Value": "y"
    }
  ],
  "RecordType": 1,
  "RequestId": "45101c08-78b1-ab30-7581-3d1359353099",
  "ResultStatus": "True",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "adminuser@example.onmicrosoft.com",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
ExpandedParameters.Name (kusto rule field)inblindcopyto1 rulekusto
ExpandedParameters.Name (kusto rule field)inredirectmessageto1 rulekusto
ExpandedParameters.Value (kusto rule field)is_not_null1 rulekusto
event.outcome (elastic rule field)eqsuccess1 ruleelastic
m365::Parameters.ForwardAsAttachmentTo (elastic rule field)is_not_null1 ruleelastic
m365::Parameters.ForwardTo (elastic rule field)is_not_null1 ruleelastic
m365::Parameters.RedirectTo (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.BlindCopyTo (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.ForwardingAddress (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.ForwardingSmtpAddress (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.RedirectMessageTo (elastic rule field)is_not_null1 ruleelastic
o365.audit.Parameters.RedirectToRecipients (elastic rule field)is_not_null1 ruleelastic
p.Name (kusto rule field)eqblindcopyto1 rulekusto
p.Name (kusto rule field)eqredirectmessageto1 rulekusto
p.Value (kusto rule field)is_not_null1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

Set-UnifiedGroup

#
RecordType
ExchangeAdmin

Description

An unified group was modified via the Set-UnifiedGroup Exchange Online admin cmdlet (observed in first-party Unified Audit Log capture).

Example Audit Record #

{
  "AppPoolName": "Microsoft.Exchange.DsApi.GRpc.NetCore",
  "CreationTime": "2026-07-02T02:11:04Z",
  "ExternalAccess": false,
  "Id": "23399412-d36e-472e-69f1-08ded7df2ba7",
  "ObjectId": "dw-harness-60974bd7_72ff2416-ca78-4443-8b25-800823d06143",
  "Operation": "Set-UnifiedGroup",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.21.0181.008)",
  "Parameters": [
    {
      "Name": "Identity",
      "Value": "72ff2416-ca78-4443-8b25-800823d06143"
    },
    {
      "Name": "Notes",
      "Value": "dw harness group (updated) run=60974bd7"
    },
    {
      "Name": "DisplayName",
      "Value": "dw-harness-60974bd7-group"
    },
    {
      "Name": "UnifiedGroupAccessType",
      "Value": "Private"
    }
  ],
  "RecordType": 1,
  "RequestId": "f1e9843c-f7ea-4207-810a-56efd2ea15ea",
  "ResultStatus": "True",
  "UserId": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserKey": "NT SERVICE\\MSExchangeDsApiGRPC (Microsoft.Exchange.DsApi.GRpc.NetCore)",
  "UserType": 2,
  "Version": 1,
  "Workload": "Exchange"
}

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.