The Enabling Technologies Blog


Chris Stegh / / Categories: Best Practices, SharePoint/OneDrive

Log Entries Tracked in Weekly Activity Report

File and page activities
Friendly name Description
Deleted file from recycle bin User deletes a file from the recycle bin of a site.
Deleted file from second-stage recycle bin User deletes a file from the second-stage recycle bin of a site.
Detected malware in file SharePoint anti-virus engine detects malware in a file.
Folder activities
Friendly name Description
Copied folder User copies a folder from a site to another location in SharePoint or OneDrive for Business.
Deleted folder from recycle bin User deletes a folder from the recycle bin on a site.
Deleted folder from second-stage recycle bin User deletes a folder from the second-stage recycle bin on a site.
Sharing and access request activities
Friendly name Description
Created sharing invitation User shared a resource in SharePoint Online or OneDrive for Business with a user who isn't in your organization's directory.
Synchronization activities
Friendly name Description
Allowed computer to sync files User successfully establishes a sync relationship with a site. The sync relationship is successful because the user's computer is a member of a domain that's been added to the list of domains (called the safe recipients list) that can access document libraries in your organization.
Blocked computer from syncing files User tries to establish a sync relationship with a site from a computer that isn't a member of your organization's domain or is a member of a domain that hasn't been added to the list of domains (called the safe recipients list) that can access document libraries in your organization. The sync relationship is not allowed, and the user's computer is blocked from syncing, downloading, or uploading files on a document library.
Site administration activities
Friendly name Description
Added site collection admin Site collection administrator or owner adds a person as a site collection administrator for a site. Site collection administrators have full control permissions for the site collection and all subsites.
Changed a sharing policy A SharePoint or global administrator changed a SharePoint sharing policy by using the Office 365 admin portal, SharePoint admin portal, or SharePoint Online Management Shell. Any change to the settings in the sharing policy in your organization will be logged. The policy that was changed is identified in the ModifiedProperties field in the detailed properties of the event record.
Changed network access policy A SharePoint or global administrator changed the location-based access policy (also called a trusted network boundary) in the SharePoint admin center or by using SharePoint Online PowerShell. This type of policy controls who can access SharePoint and OneDrive resources in your organization based on authorized IP address ranges that you specify. For more information, see Control access to SharePoint Online and OneDrive data based on defined network locations.
Created group Site administrator or owner creates a group for a site, or performs a task that results in a group being created. For example, the first time a user creates a link to share a file, a system group is added to the user's OneDrive for Business site. This event can also be a result of a user creating a link with edit permissions to a shared file.
Deleted group User deletes a group from a site.
Deleted site Site administrator deletes a site.
Exchange mailbox activities
Friendly name Description
Added delegate mailbox permissions An administrator assigned the FullAccess mailbox permission to a user (known as a delegate) to another person's mailbox. The FullAccess permission allows the delegate to open the other person's mailbox, and read and manage the contents of the mailbox. 
Purged messages from the mailbox A message was purged from the Recoverable Items folder (permanently deleted from the mailbox).
Sent message using Send As permissions A message was sent using the SendAs permission. This means another user sent the message as though it came from the mailbox owner.
User administration activities 
Friendly name Description
Changed user license The license assigned to a user what changed. To see what licenses were changes, see the corresponding Updated user activity.
Azure AD group administration activities  
Friendly name Description
Added group A group was created.
Deleted group A group was deleted.
Application administration activities 
Friendly name Description
Added delegation entry A authentication permission was created/granted to an application in Azure AD.
Added service principal An application was registered in Azure AD. An application is represented by a service principal in the directory.
Added credentials to a service principal Credentials were added to a service principal in Azure AD. A service principle represents an application in the directory.
Removed delegation entry A authentication permission was removed from an application in Azure AD.
Removed a service principal from the directory An application was deleted/unregistered from Azure AD. An application is represented by a service principal in the directory.
Removed credentials from a service principal Credentials were removed from a service principal in Azure AD. A service principle represents an application in the directory.
Set delegation entry An authentication permission was updated for an application in Azure AD.
Role administration activities 
Friendly name Description
Add member to Role Added a user to an admin role in Office 365.
Removed a user from a directory role Removed a user to from an admin role in Office 365.
Set company contact information Updated the company-level contact preferences for your Office 365 organization. This includes email addresses for subscription-related email sent by Office 365, as well as technical notifications about Office 365 services.
Directory administration activities 
Friendly name Description
Added domain to company Added a domain to your Office 365 organization.
Added a partner to the directory Added a partner (delegated administrator) to your Office 365 organization.
Removed domain from company Removed a domain from your Office 365 organization.
Removed a partner from the directory Removed a partner (delegated administrator) from your Office 365 organization.
Set company information Updated the company information for your Office 365 organization. This includes email addresses for subscription-related email sent by Office 365, as well as technical notifications about Office 365 services.
Set domain authentication Changed the domain authentication setting for your Office 365 organization.
Updated the federation settings for a domain Changed the federation (external sharing) settings for your Office 365 organization.
Set password policy Changed the length and character constraints for user passwords in your Office 365 organization.
Turned on Azure AD sync Set the property that enables a directory for Azure AD Sync.
Updated domain Updated the settings of a domain in your Office 365 organization.
Verified domain Verified that your organization is the owner of a domain.
Verified email verified domain Used email verification to verify that your organization is the owner of a domain.
Microsoft Teams activities 
Friendly name Description
Changed organization setting Enables or disables Microsoft Teams for the organization (Microsoft Teams). 
Created team A user creates a new team.
Deleted team A team admin deletes a team.

Subscribe to Email Updates

Refine by

To expand the list, please click on the double arrows.

 

Search by Category or Author: