DataverseActivity

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Reference for DataverseActivity table in Azure Monitor Logs.

Attribute Value
Category Audit, Security
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Azure Monitor Tables Reference View Documentation

Contents

Schema (32 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account
ClientIp string The IP address of the device that was used when the activity was logged.
CorrelationId string A unique value used to associate related rows.
CrmOrganizationUniqueName string Unique name of the organization.
EntityId string Unique identifier of the entity.
EntityName string Name of the entity in the organization.
Fields dynamic JSON of Key Value pair reflecting the values that were created or updated.
InstanceUrl string URL to the instance.
ItemType string The type of object that was accessed or modified. See the ItemType table for details on the types of objects.
ItemUrl string URL to the record emitting the log.
Message string Name of the message called in the Dynamics 365 SDK.
Operation string The name of the operation that the user is performing.
OrganizationId string The GUID for your organization's Office 365 tenant. This value will always be the same for your organization.
OriginalObjectId string The ObjectId for Dataverse operation or business activity.
Query string The query filter parameters used while executing the FetchXML.
QueryResults dynamic One or multiple unique records returned by the Retrieve and Retrieve Multiple SDK message call.
ResultStatus string Indicates whether the action (specified in the Operation property) was successful or not.
ServiceContextId string The unique id associated with service context.
ServiceContextIdType string Application defined token to define context use.
ServiceName string Name of the Service generating the log.
SourceRecordId string Unique identifier of an audit record.
SourceSystem string The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics
SystemUserId string Unique identifier of the user GUID in the organization.
TenantId string The Log Analytics workspace ID
TimeGenerated datetime The date and time in (UTC) when the user performed the activity.
Type string The name of the table
UserAgent string The user agent.
UserId string The Dataverse user ID of the user who performed the action (specified in the Operation property) that resulted in the record being logged.
UserKey string An alternative ID for the user identified in the UserId property.
UserType string The type of user that performed the operation. See the UserType table in Office 365 management activity api schema documentation for details on the types of users.
UserUpn string The UPN (User Principal Name) of the user who performed the action (specified in the Operation property) that resulted in the record being logged.

Additional Information

📖 Related Documentation: Microsoft Dataverse activity logging - Enable and configure Dataverse auditing

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Microsoft Dataverse

Content Items Using This Table (38)

Analytic Rules (30)

In solution Microsoft Business Applications:

Analytic Rule Selection Criteria
Dataverse - Anomalous application user activity
Dataverse - Audit log data deletion
Dataverse - Audit logging disabled
Dataverse - Bulk record ownership re-assignment or sharing
Dataverse - Export activity from terminated or notified employee
Dataverse - Hierarchy security manipulation
Dataverse - Honeypot instance activity
Dataverse - Login by a sensitive privileged user
Dataverse - Login from IP in the block list
Dataverse - Login from IP not in the allow list
Dataverse - Malware found in SharePoint document management site
Dataverse - Mass deletion of records
Dataverse - Mass export of records to Excel
Dataverse - Mass record updates
Dataverse - New Dataverse application user activity type
Dataverse - New non-interactive identity granted access
Dataverse - New sign-in from an unauthorized domain
Dataverse - New user agent type that was not used before
Dataverse - New user agent type that was not used with Office 365
Dataverse - Organization settings modified
Dataverse - Removal of blocked file extensions
Dataverse - SharePoint document management site added or updated
Dataverse - Suspicious security role modifications
Dataverse - Suspicious use of TDS endpoint
Dataverse - Suspicious use of Web API
Dataverse - TI map IP to DataverseActivity
Dataverse - TI map URL to DataverseActivity
Dataverse - Terminated employee exfiltration to USB drive
Dataverse - Unusual sign-in following disabled IP address-based cookie binding protection
Dataverse - User bulk retrieval outside normal activity

Hunting Queries (7)

In solution Microsoft Business Applications:

Hunting Query Selection Criteria
Dataverse - Activity after Microsoft Entra alerts
Dataverse - Activity after failed logons
Dataverse - Cross-environment data export activity
Dataverse - Dataverse export copied to USB devices
Dataverse - Generic client app used to access production environments
Dataverse - Identity management activity outside of privileged directory role membership
Dataverse - Identity management changes without MFA

Workbooks (1)

In solution Microsoft Business Applications:

Workbook Selection Criteria
Dynamics365Activity

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index