⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Marko Lauren |
| Support Tier | Partner |
| Support Link | https://markolauren.github.io/M365AuditGeneralAndDLPSolution/ |
| Categories | Cloud Provider |
| Version | 3.0.0 |
| Author | Marko Lauren - M365AuditGeneralAndDLPSolution@outlook.com |
| First Published | 2026-01-08 |
| Solution Folder | Microsoft 365 Audit General and DLP |
The Microsoft 365 Audit General & DLP solution provides capability to ingest M365 Audit.General and Audit.DLP logs into Microsoft Sentinel using the Codeless Connector Platform. This solution enables comprehensive auditing and DLP monitoring for Microsoft 365 environments covering 29 specialty workloads including Copilot, Power BI, Viva suite, Security & Compliance, eDiscovery, and Sentinel platform operations.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
• Microsoft Sentinel Codeless Connector Framework
This solution provides 2 data connector(s):
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
M365AuditGeneral_CL |
Microsoft 365 Audit.DLP, Microsoft 365 Audit.General | - |
Author: Marko Lauren
This solution provides two codeless connectors (CCF) for ingesting Microsoft 365 audit logs from the Office 365 Management Activity API into Microsoft Sentinel:
These connectors use the Office 365 Management Activity API to retrieve Microsoft 365 audit logs into a shared 321-column schema covering 30 specialty workload types:
Schema Design: This connector follows the official Office 365 Management Activity API Schema as documented by Microsoft. All field names, types, and structures are mapped directly from the API schema to ensure compatibility and accuracy.
The Office 365 Management Activity API organizes audit data into different content types:
✅ Included (29 specialty workload schemas):
❌ Excluded (have dedicated Microsoft Sentinel connectors or filtered):
[Content truncated...]
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 20-04-2026 | Initial release with Microsoft 365 Audit.General and Audit.DLP data connectors using Codeless Connector Framework. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊