Export Microsoft 365 unified audit logs at scale using the Office 365 Management Activity API

domain: learn.microsoft.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Confirm unified audit logging is turned on for the tenant before subscribing, since the API returns nothing without it.
  2. Register a Microsoft Entra ID app with the Office 365 Management APIs ActivityFeed.Read permission and obtain an OAuth2 token for the tenant.
  3. Create a subscription per content type (e.g. Audit.Exchange, Audit.SharePoint, Audit.AzureActiveDirectory) via the subscription start endpoint.
  4. Poll the subscription content endpoint on a schedule (or register a webhook notification endpoint) to discover new content blob URIs, then fetch each blob URI to download the actual audit records.
  5. Normalize and forward parsed records into a SIEM, respecting the tenant's baseline throttling allocation (around 2,000 requests per minute) with backoff on throttling responses.

Known gotchas

Related routes

Export Google Workspace admin, login, and Drive audit activity via the Admin SDK Reports API for SIEM ingestion
developers.google.com · 5 steps · unrated
Automate SOC 2 evidence collection by exporting audit logs and access reviews from cloud provider APIs
aicpa.org/soc2 · 5 steps · unrated
Export expense reports from Expensify using the Expensify Integrations API
expensify · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans