Azure Active Directory Template

Azure Active Directory (Standard Datasource)

Action

Original Name

Description

Operation Name

System Activity
Check It Domain Verification Verified that your organization is the owner of a domain Verify domain
Check It Email Domain Verification Used email verification to verify that your organization is the owner of a domain Verify email verified domain
Check It Non-compliant Policy A device is non-compliant with defined device compliance policy settings Device no longer compliant
System Management

Configuration Rule Modification

Device no longer managed

A device is no longer managed in Azure AD

Device no longer managed

Configuration Rule Modification Add OAuthPermissionGrant OAuth2PermissionGrant was created for an application in Azure AD Add OAuth2PermissionGrant
Configuration Rule Modification Set company contact information Company-level contact preferences for the Office 365 organization were updated Set company contact information
Configuration Rule Modification Set Company information Company information for an Office 365 organization was updated Set company information
Configuration Rule Modification Set Delegation entry An authentication permission was updated for an application in Azure AD Set delegation entry
Configuration Rule Modification Set DirSyncEnabled flag on company Set the property that enables a directory for Azure AD Sync Set DirSyncEnabled flag on company
Configuration Rule Modification Set domain authentication Changed the domain authentication setting for an Office 365 organization Set domain authentication
Configuration Rule Modification Updated the federation settings for a domain Changed the federation (external sharing) settings for an Office 365 organization Set federation settings on domain
Object Creation Add delegation entry Authentication permission was created/granted to an application in Azure AD Add delegation entry
Object Creation Add domain to company A domain was added to an Office 365 organization Add domain to company
Object Creation Add service principal An application was registered in Azure AD Add service principal
Object Creation Added credentials to a service principal Credentials were added to a service principal in Azure AD Added credentials to a service principal
Object Creation Application Creation A new application was registered in Azure AD Add application
Object Creation Company Creation An Office 365 organization was created Create company
Object Creation Company Settings Creation An Office 365 organization settings were created Create company settings
Object Creation Device Addition A device was registered with Azure AD Add device
Object Creation Partner Addition A partner (delegated administrator) was added to an Office 365 organization Add partner to company
Object Creation Service principal credentials addiction Credentials were added to a service principal in Azure AD Add service principal credentials
Object Deletion Application Deletion An application was removed from Azure AD ^Delete application
Object Deletion Application Hard Deletion An application was permanently removed from Azure AD Hard Delete application
Object Deletion Device Deletion A device was deleted from Azure AD ^Delete device
Object Deletion Remove delegation entry An authentication permission was removed from an application in Azure AD Remove delegation entry
Object Deletion Remove domain from company A domain was removed from an Office 365 organization Remove domain from company
Object Deletion Remove partner from company A partner (delegated administrator) was removed from an Office 365 organization Remove partner from company
Object Deletion Remove service principal An application was deleted/unregistered from Azure AD Remove service principal
Object Deletion Remove service principal credentials Credentials were removed from a service principal in Azure AD Remove service principal credentials
Object Modification Application Modification Configuration options of an application were changed in Azure AD Update application
Object Modification Device Modification A device was enabled/disabled in Azure AD Update device
Object Modification Domain Modification Updated the settings of a domain in an Office 365 organization Update domain
Object Modification License Modification License properties were set for a user in Azure AD Set license properties
Object Modification Service Principal Modification Properties of a service principal were updated Update service principal
Object Modification StsRefreshTokenValidFrom Timestamp Modification Updated StsRefreshTokenValidFrom Timestamp Update StsRefreshTokenValidFrom Timestamp
Object Modification Update external secrets Secrets for external-facing services were updated Update external secrets
Policy Rule Modification Set password policy Changed the length and character constraints for user passwords in an Office 365 organization Set password policy
User Activity
Logon Failure Logon Failure User Login Failed UserLogin Failed
Successful Login Successful Login User logged In Successfully UserLoggedIn
Users' Management
Grant Permission Grant Permission to Admin Admin consent was granted to an enterprise app in Azure AD Consent to application
Grant Permission Set user manager A user manager was set in Azure AD Set user manager
Group/Role/Profile Creation Group Creation A group was created Add group\.?
Group/Role/Profile Deletion Group Deletion A group was deleted ^Delete group
Group/Role/Profile Deletion Hard Delete group A group was deleted from the recycle bin Hard Delete group
Group/Role/Profile Modification Group Modification A property of a group was changed Update group
Password Modification Password Modification Administrator changed the password for a user Change user password
Password Modification Set force change user password Administrator set the property that forces a user to change their password on next sign in Set force change user password
Password Reset Password Reset Administrator reset the password for a user Reset user password
User Addition to Grouup/Role/Profile Add registered owner to device A registered owner was added to a device in Azure AD Add registered owner to device
User Addition to Group/Role/Profile Add registered users to device A registered user was added to a device in Azure AD Add registered users to device
User Addition to Group/Role/Profile Added app role assignment to service principal An app role was assigned to a user in Azure AD Add app role assignment to service principal
User Addition to Group/Role/Profile Member Addition to Directory Role A user was added to an admin role in Office 365 Add role member to role
User Addition to Group/Role/Profile Member addition to User/Role Member added to a role in AzureAD Add member to role
User Addition to Group/Role/Profile Owner Addition to Application An owner was added to an application in Azure AD Add owner to application
User Addition to Group/Role/Profile Owner Addition to Policy An owner was added to a policy in Azure AD Add owner to policy
User Addition to Group/Role/Profile User Addition to Service Principal An owner was added to a service principal in Azure AD Add owner to service principal
User Addition to Group/Role/Profile User Addition to Application Role An app role was assigned to a user in Azure AD Add app role assignment grant to user
User Addition to Group/Role/Profile User Addition to Group A member was added to a group Add member to group
User Creation User Creation An Office 365 user account was created Add user
User Creation User Restore A deleted user account was restored Restore user
User Deletion Hard Delete user A user was permanently deleted from Azure AD Hard Delete user
User Deletion User Deletion A user was deleted from Azure AD ^Delete user
User Modification Application Password Creation An application password was created for a user in Azure AD Create application password for user
User Modification Change user license The license assigned to a user was changed Change user license
User Modification Enable Strong Authentication A strong authentication method was enabled for a user in Azure AD Enable Strong Authentication
User Modification User Modification Administrator changed one or more properties of a user account Update user
User Removal From Group/Role/Profile Member Removal from Directory Role A user was removed from an admin role in Office 365 Remove role member from role
User Removal From Group/Role/Profile Member Removal from User/Role Member removed from a role in AzureAD Remove member from role
User Removal From Group/Role/Profile Owner Removal from Group An owner was removed from a group Remove owner from group
User Removal from Group User Removal from Group A member was removed from a group Remove member from group