⚠️ Microsoft 365 Audit General and DLP

⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.

Microsoft 365 Audit General and DLP Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index


Attribute Value
Publisher Marko Lauren
Support Tier Partner
Support Link https://markolauren.github.io/M365AuditGeneralAndDLPSolution/
Categories Cloud Provider
Version 3.0.0
Author Marko Lauren - M365AuditGeneralAndDLPSolution@outlook.com
First Published 2026-01-08
Solution Folder Microsoft 365 Audit General and DLP

The Microsoft 365 Audit General & DLP solution provides capability to ingest M365 Audit.General and Audit.DLP logs into Microsoft Sentinel using the Codeless Connector Platform. This solution enables comprehensive auditing and DLP monitoring for Microsoft 365 environments covering 29 specialty workloads including Copilot, Power BI, Viva suite, Security & Compliance, eDiscovery, and Sentinel platform operations.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

Microsoft Sentinel Codeless Connector Framework

Contents

Data Connectors

This solution provides 2 data connector(s):

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
M365AuditGeneral_CL Microsoft 365 Audit.DLP, Microsoft 365 Audit.General -

Additional Documentation

📄 Source: Microsoft 365 Audit General and DLP/README.md

Author: Marko Lauren

This solution provides two codeless connectors (CCF) for ingesting Microsoft 365 audit logs from the Office 365 Management Activity API into Microsoft Sentinel:

Overview

These connectors use the Office 365 Management Activity API to retrieve Microsoft 365 audit logs into a shared 321-column schema covering 30 specialty workload types:

Schema Design: This connector follows the official Office 365 Management Activity API Schema as documented by Microsoft. All field names, types, and structures are mapped directly from the API schema to ensure compatibility and accuracy.

Content Types Coverage

The Office 365 Management Activity API organizes audit data into different content types:

Audit.General Connector Scope

✅ Included (29 specialty workload schemas):

❌ Excluded (have dedicated Microsoft Sentinel connectors or filtered):

[Content truncated...]

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 20-04-2026 Initial release with Microsoft 365 Audit.General and Audit.DLP data connectors using Codeless Connector Framework.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index