Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

AuditData

The JSON column of a Microsoft 365 audit log export that holds the full detail of each record: parameters, client IP, session and token identifiers.

AuditData is the column of a Unified Audit Log export that contains the complete audit record as a JSON string. The other CSV columns (date, user, operation) are only a summary; the evidence is inside AuditData.

Its fields depend on the workload. Exchange admin operations carry Parameters (for an inbox rule: Name, ForwardTo, MoveToFolder, DeleteMessage…); MailItemsAccessed carries OperationProperties, Folders and OperationCount; Entra ID events carry ModifiedProperties; SharePoint events carry SourceFileName and SiteUrl. Many records include ClientIP and AppAccessContext with AADSessionId and UniqueTokenId, the linkable identifiers that connect an action to an Entra sign-in.

Opening an export in a spreadsheet can damage long AuditData values; parse it programmatically. More in Unified Audit Log investigation.