Table of Contents

AuditLogsQuery-OneDrive.Read.All

Allows the app to read and query audit logs from OneDrive workload, on behalf of a signed-in user.

Merill's Note

For an app to access data in Microsoft Graph, the user or administrator must grant it the permissions it needs. This article lists all the Microsoft Graph APIs and your tenant data that can be accessed by the application (vendor/developer) if you consent to the AuditLogsQuery-OneDrive.Read.All permission.

If you need to create an audit report of the permissions granted to all the apps in your tenant, you can run the Export-MsIdAppConsentGrantReport command. See How To: Run a quick OAuth app audit of your tenant

Category Application Delegated
Identifier 8a169a81-841c-45fd-ad43-96aede8801a0 4a72c235-a50d-4870-b598-fd88fd1fa074
DisplayText Read audit logs data from OneDrive workload Read audit logs data from OneDrive workload
Description Allows the app to read and query audit logs from OneDrive workload, without a signed-in user Allows the app to read and query audit logs from OneDrive workload, on behalf of a signed-in user.
AdminConsentRequired Yes Yes

Graph Methods

Resources

Granting this permission allows the calling application to access (and/or update) the following information in your tenant.

Graph reference: auditLogQuery

Property Type Description
administrativeUnitIdFilters String collection The collection of administrative unit IDs to filter on.
approximateReturnedRecordCount Int64 The approximate number of records retrieved by the query. This value can be higher or lower than recordCountLimit due to distributed counting. Read-only.
displayName String The display name of the audit log query.
filterEndDateTime DateTimeOffset The end date and time of the audit log query filter.
filterStartDateTime DateTimeOffset The start date and time of the audit log query filter.
id String The unique identifier for the audit log query. Inherited from entity.
ipAddressFilters String collection The collection of IP addresses to filter on.
isRecordCountLimitExceeded Boolean Indicates whether the query exceeded the per-search record-count limit. The default value is false. A value of true is authoritative and isn't derived from approximateReturnedRecordCount. Read-only.
keywordFilter String Free text to match against the non-indexed content of each record: the workload-specific properties inside auditData, including its AppAccessContext object. The indexed common-schema properties, such as the operation name, aren't matched by keyword; use their own filters, such as operationFilters, for those.
objectIdFilters String collection The collection of object IDs to filter on.
operationFilters String collection The collection of operations to filter on.
recordCountLimit Int64 The record-count threshold used to limit query result retrieval. Read-only.
recordTypeFilters microsoft.graph.security.auditLogRecordType collection The collection of record types to filter on.
serviceFilters String collection The collection of services to filter on.
status microsoft.graph.security.auditLogQueryStatus The status of the audit log query. Possible values are: notStarted, running, succeeded, failed, cancelled, unknownFutureValue.
userPrincipalNameFilters String collection The collection of user principal names to filter on.