Microsoft 365 Unified Audit Logs connector

Important

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Microsoft 365 Unified Audit Logs from the Previews page. See Manage Azure Databricks previews.

The managed Microsoft 365 Unified Audit Logs connector in Lakeflow Connect ingests unified audit events from Microsoft Entra ID, Exchange, SharePoint, and other Microsoft 365 workloads into Azure Databricks.

The connector uses the Microsoft 365 Management Activity API to ingest append-only audit events. It doesn't ingest Outlook messages or SharePoint files.

Feature availability

Feature Availability
UI-based pipeline authoring Red X icon Not supported
API-based pipeline authoring Green check icon Supported
Declarative Automation Bundles Green check icon Supported
Incremental ingestion Green check icon Supported
Unity Catalog governance Green check icon Supported
Orchestration using Databricks Workflows Green check icon Supported
API-based column selection and deselection Green check icon Supported
API-based row filtering Red X icon Not supported
SCD Type 2 Red X icon Not supported
Microsoft 365 unified audit events are append-only.
Automated schema evolution: New and deleted columns Green check icon Supported
Automated schema evolution: Data type changes Red X icon Not supported
Automated schema evolution: Column renames Green check icon Supported
Treated as a new column (new name) and deleted column (old name).

Authentication methods

Authentication method Availability
OAuth U2M Red X icon Not supported
OAuth M2M Green check icon Supported
A Microsoft Entra application with a client ID, client secret, and Office 365 Management API application permissions.
Basic authentication (username/password) Red X icon Not supported

What to know before you start

Start ingesting from Microsoft 365

  1. Configure Microsoft 365 for ingestion (Microsoft 365 and Entra admins). Enable unified auditing and create a Microsoft Entra application for Azure Databricks.
  2. Create a Unity Catalog connection (Admins). Create a connection in Catalog Explorer so pipeline authors don't need direct access to the credentials.
  3. Create an ingestion pipeline (Admins or non-admins). Use Declarative Automation Bundles or a Azure Databricks notebook to create a pipeline from an existing connection.