A group of Microsoft Products and technologies used for sharing and managing content, knowledge, and applications.
Dear tech_fc,
- It's likely indicating these user agents do not correspond to typical browser or Office client software. The interaction with the file was by a service or background process rather than a direct user action.
- When the audit logs show the platform as “Service,” it's likely indicating a service account or background process accessed the file, as opposed to “WinDesktop,” which suggests a user on a Windows desktop application.
- "OAuth" in the authentication type column suggests that the access token used for authentication was obtained through the OAuth protocol, which is a common method for service-to-service authentication. "FormsCookieAuth" would typically represent interactive user authentication via a web form where a cookie is used for maintaining the session.
- If the Application display name in the logs is "Media Analysis and Transformation Service," it likely means the activity was performed by a background service that processes media files for analysis and transformation purposes.
- SharePoint audit logs do provide information on the device and user type, but there might be limitations regarding the granularity of the details for unmanaged devices or background processes. The user type for a background process could be listed as a service account or system account, or it might not be specified at all.
- If the logs are generated by background processes, certain fields like user agent, browser name, and version might indeed be blank or contain generic identifiers that represent the service rather than specific browser details.
Sincerely,
Jazlyn | Microsoft Community Moderator