Reference

User

All users registered in your tenant (internal, external)

Part of the Microsoft 365 inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
DailyDaily, Weekly, Bi-Weekly, Monthly, Never, InitialYes

Properties

Property Type Description Automation placeholder
Account enabled Boolean True if the account is enabled; otherwise, false. This property is required when a user is created {{User.AccountEnabled}}
City String The city in which the user is located {{User.City}}
Company String The company name which the user is associated {{User.Companyname}}
Copilot Credits Cost Double Microsoft 365 Copilot credit consumption (USD) attributed to this user. {{User.CopilotCreditsCost}}
Copilot Studio Cost Double Copilot Studio (agent) credit consumption (USD) attributed to this user across all agents. {{User.CopilotStudioUserCost}}
Country or region String The country/region in which the user is located {{User.Country}}
Cowork Tasks Double Total Microsoft 365 Copilot Cowork tasks performed by this user. {{User.CoworkTaskCount}}
Created DateTime The date and time the user was created {{User.CreatedDateTime}}
Initially Scanned DateTime Shows when this object was initially found in a scan. {{User.CreatedTime}}
Creation Type String Indicates whether the user account was created as a regular school or work account (null), an external account (Invitation), a local account for an Microsoft Entra ID B2C tenant (LocalAccount) or self-service sign-up using email verification (EmailVerified). {{User.CreationType}}
Department String The name for the department in which the user works {{User.Department}}
Disable Password Expiration Boolean If true password never expires {{User.DisablePasswordExpiration}}
Disable Strong Password Boolean If true it allows weaker passwords than the default policy to be specified {{User.DisableStrongPassword}}
Icon String Default scanning interval: Initial. {{User.DisplayIcon}}
Display Name String {{User.DisplayName}}
Extension Attribute 1 String This extension attribute is also known as Exchange custom attribute 1. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. Default scanning interval: Weekly. {{User.ExtensionAttribute1}}
Extension Attribute 10 String This extension attribute is also known as Exchange custom attribute 10. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute10}}
Extension Attribute 11 String This extension attribute is also known as Exchange custom attribute 11. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute11}}
Extension Attribute 12 String This extension attribute is also known as Exchange custom attribute 12. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute12}}
Extension Attribute 13 String This extension attribute is also known as Exchange custom attribute 13. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute13}}
Extension Attribute 14 String This extension attribute is also known as Exchange custom attribute 14. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute14}}
Extension Attribute 15 String This extension attribute is also known as Exchange custom attribute 15. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute15}}
Extension Attribute 2 String This extension attribute is also known as Exchange custom attribute 2. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute2}}
Extension Attribute 3 String This extension attribute is also known as Exchange custom attribute 3. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute3}}
Extension Attribute 4 String This extension attribute is also known as Exchange custom attribute 4. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute4}}
Extension Attribute 5 String This extension attribute is also known as Exchange custom attribute 5. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute5}}
Extension Attribute 6 String This extension attribute is also known as Exchange custom attribute 6. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute6}}
Extension Attribute 7 String This extension attribute is also known as Exchange custom attribute 7. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute7}}
Extension Attribute 8 String This extension attribute is also known as Exchange custom attribute 8. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute8}}
Extension Attribute 9 String This extension attribute is also known as Exchange custom attribute 9. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. {{User.ExtensionAttribute9}}
External User State String For invited users, the state can be PendingAcceptance or Accepted, or null for all other users. {{User.ExternalUserState}}
First Name String The given name (first name) of the user {{User.FirstName}}
onPremises Sync Enabled Boolean true if this user object is currently being synced from an on-premises Active Directory (AD); otherwise the user isn't being synced and can be managed in Microsoft Entra ID. {{User.InCloud}}
Is External Boolean Is user sign-in as guest {{User.IsExternal}}
Title String The user's job title {{User.JobTitle}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{User.LastModifiedTime}}
Last Name String The user's surname {{User.LastName}}
Last password change date DateTime The time when this Entra ID user last changed their password or when their password was created, whichever date the latest action was performed {{User.LastPasswordChangeDateTime}}
Last Sign-In DateTime The last date a user has signed in to M365. This date can either be the last date a user actively signed in to M365 or when he last had a so called non-interactive sign-in (depending on what is more recent). Interactive sign-in happens by opening the browser and opening the url of an M365 resource (e.g. SharePoint Online). Non-interactive sign-in will happen when users use clients (e.g. Outlook Client) to access tenant resources rather than signing into your tenant directly. The timestamp represents date and time information using ISO 8601 format and is always in UTC time. Default scanning interval: Weekly. {{User.LastSignIn}}
Last Sign-In (Interactive) DateTime The last date a user has signed in to M365 interactively. Interactive sign-in happens by opening the browser and opening the url of an M365 resource (e.g. SharePoint Online). The timestamp represents date and time information using ISO 8601 format and is always in UTC time. Default scanning interval: Weekly. {{User.LastSignInInteractive}}
Last Sign-In (non-interactive) DateTime The last date a user has signed in to M365 non-interactively. Non-interactive sign-in will happen when users use clients (e.g. Outlook Client) to access tenant resources rather than signing into your tenant directly. The timestamp represents date and time information using ISO 8601 format and is always in UTC time. Default scanning interval: Weekly. {{User.LastSignInNonInteractive}}
Last Successful Sign-In DateTime The date and time of the users most recent successful sign-in activity. The timestamp type represents date and time information using ISO 8601 format and is always in UTC. Default scanning interval: Weekly. {{User.LastSuccessfulSignIn}}
Member Type String A String value that can be used to classify user membership types in your directory Allowed values: External Guest, External Member, Internal Guest, Internal Member. {{User.MemberType}}
Office String The office location in the user's place of business {{User.OfficeLocation}}
On-premises Distinguished Name String Contains the on-premises Active Directory distinguished name or DN. The property is only populated for customers who are synchronizing their on-premises directory to Microsoft Entra ID via Entra ID Connect. {{User.OnPremisesDistinguishedName}}
On-premises sAMAccountName String Contains the on-premises sAMAccountName synchronized from the on-premises directory. The property is only populated for customers who are synchronizing their on-premises directory to Microsoft Entra ID via Entra ID Connect {{User.OnPremisesSamAccountName}}
Preferred data location String The preferred data location for the user {{User.PreferredDataLocation}}
Risk Score Int32 Stores risk score {{User.RiskScore}}
Risk Score Update DateTime Stores risk score update {{User.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{User.RiskScoreValue}}
State or province String The state or province in the user's address {{User.StateOrProvince}}
Type String A custom security attribute that is assigned to a directory object {{User.Type}}
Usage location String A two letter country code (ISO standard 3166) {{User.UsageLocation}}
User Email String The SMTP address for the user {{User.UserEmail}}
User Email Domain String Email domain of the user. This will only be set if User Email is not empty. {{User.UserEmailDomain}}
User Id String The unique identifier for the user {{User.UserId}}
User Principal Name String The user principal name (UPN) of the user. The UPN is an Internet-style login name for the user based on the Internet standard RFC 822 {{User.UserPrincipalName}}
User Type String A String value that can be used to classify user types in your directory {{User.UserType}}

Relations

Relation Service Description
Resource Group Azure Azure resource groups in which the user is an owner
Application registration Entra ID Entra ID enterprise applications owned by the user
App Role Assignment Entra ID Entra ID App role assignments owned by the user
Device Entra ID Entra ID devices owned by user
Device Entra ID Entra ID devices used by the user
Directory Audits AzureAD All directory audit logs generated by Entra ID
Directory Role Entra ID Entra ID directory roles for which the user is a member (direct or via security group)
Enterprise Application Entra ID Entra ID App registrations owned by the user
OAuth2 Permission Grant Entra ID All OAuth permission grants in Entra ID
Risky Entra ID Sign-In Entra ID Shows Risky Entra ID Sign-Ins
Entra ID Sign-Ins AzureAD All sign-ins of users in your tenant
User Registration Credential Entra ID All Entra ID registration credentials of a user (MFA, Admin, Auth methods)
AI Agent Azure AI Services Azure AI projects are used to organize your work and save state while building customized AI apps
AI Agent Azure AI Services Azure AI projects are used to organize your work and save state while building customized AI apps
LLM Deployment Azure AI Services Azure AI Foundry supports deploying large language models (LLMs), flows, and web apps. Deploying an LLM or flow makes it available for use in a website, an application, or other production environments.
LLM Deployment Azure AI Services Azure AI Foundry supports deploying large language models (LLMs), flows, and web apps. Deploying an LLM or flow makes it available for use in a website, an application, or other production environments.
AI Hub Azure AI Services Azure AI hub which are the primary top-level Azure resources for Azure AI Foundry
AI Hub Azure AI Services Azure AI hub which are the primary top-level Azure resources for Azure AI Foundry
AI Project Azure AI Services AI projects in which user is an owner
AI Project Azure AI Services Azure AI projects are used to organize your work and save state while building customized AI apps
AI Project Azure AI Services Azure AI projects are used to organize your work and save state while building customized AI apps
AI Service Azure AI Services Cloud-based artificial intelligence (AI) services that help developers build cognitive intelligence into applications
AI Service Azure AI Services Cloud-based artificial intelligence (AI) services that help developers build cognitive intelligence into applications
Claude Organization Anthropic Organizations in which the user is a admin
Claude Organization Anthropic Organizations in which the user is a billing user
Claude Organization Anthropic Organizations in which the user is a Claude code user
Claude Organization Anthropic Organizations in which the user is a developer
Claude Organization Anthropic Organizations in which the user is a user
Claude User Anthropic All Claude users
M365 Copilot session Copilot All Microsoft 365 Copilot sessions.
Copilot credits consumption Copilot Per-user Microsoft 365 Copilot credit consumption, imported from the Copilot credits / consumption-by-user export.
Copilot user activity (Report) Copilot Get the most recent activity data for enabled users of Microsoft 365 Copilot apps.
Copilot Cowork usage Copilot Per-user Microsoft 365 Copilot Cowork activity (tasks, active days), imported from the CoworkUserDetails export.
AI Builder consumption Copilot Studio AI Builder credit consumption per day/user/environment, imported from the AI Builder consumption report.
Action Copilot Studio Actions used by Copilot Agent
Action Copilot Studio Actions used by Copilot Agent
Agent Flow Copilot Studio Agent Flows created inside Copilot Studio.
Agent Flow Copilot Studio Agent Flows created inside Copilot Studio.
Agent Flow Copilot Studio Agent Flows created inside Copilot Studio.
Knowledge Copilot Studio Used knowledge in Copliot Agent
Knowledge Copilot Studio Used knowledge in Copliot Agent
Pay-as-you-go Plan Copilot Studio A pay-as-you-go plan is a group of one or more environments that you can configure to bill to Azure.
Pay-as-you-go Plan Copilot Studio A pay-as-you-go plan is a group of one or more environments that you can configure to bill to Azure.
Copilot Studio user consumption Copilot Studio Per-user Copilot credit consumption per agent, imported from the User-Level Credit Consumption export.
Topic Copilot Studio Topics of Copilot Agent
Topic Copilot Studio Topics of Copilot Agent
Trigger Copilot Studio Triggers that start a Copilot agent
Trigger Copilot Studio Triggers that start a Copilot agent
Copilot Agent Copilot Studio Agents to which the user has access
Copilot Agent Copilot Studio Agents created inside Copilot Studio.
Copilot Agent Copilot Studio Agents created inside Copilot Studio.
Copilot Agent Copilot Studio Agents created inside Copilot Studio.
Copilot Agent Copilot Studio Agents created inside Copilot Studio.
Calendar Permission Exchange Permissions configured on Exchange mailbox calendars (sharing and delegation).
Exchange Audit Event Exchange Exchange administrative and mailbox audit events ingested from the Office 365 Management Activity API.
Exchange Role Group Exchange
Exchange Role Group Exchange
Mail User Exchange Mail-enabled users that route to an external SMTP address. Common offboarding-leak signal.
Mailbox Audit Bypass Exchange Accounts excluded from mailbox audit logging. Bypassed service accounts can read mail invisibly — high-signal finding most products miss.
Mailbox Delegate Exchange Mailbox delegations: Full Access, Send-As, and Send-on-Behalf permissions on user mailboxes.
Mailbox Delegate Exchange Mailbox delegations: Full Access, Send-As, and Send-on-Behalf permissions on user mailboxes.
Mailbox Folder Permission Exchange Per-folder ACLs on user mailboxes (Calendar, Inbox, Top of Information Store). Anonymous calendar sharing is a silent data leak no admin UI surfaces.
Redirect Rule Exchange All registered Exchange mailbox redirect rules
Mobile Device Exchange Exchange ActiveSync mobile device partnerships.
Mailbox Exchange All Exchange mailboxes of your users, rooms & equipment
Intune Managed Devices M365 User Intune Devices enrolled and managed through Microsoft Intune, including compliance status and hardware details
Intune Managed Devices M365 User Name Intune Devices enrolled and managed through Microsoft Intune, including compliance status and hardware details
Agent Blueprint Microsoft Agent 365 Agent blueprint the user owns.
Agent Blueprint Microsoft Agent 365 Agent blueprint the user sponsors.
Agent Blueprint Principal Microsoft Agent 365 Agent identity blueprint principal the user owns.
Agent Blueprint Principal Microsoft Agent 365 Agent identity blueprint principal the user sponsors.
Agent Identity Microsoft Agent 365 Agent identity the user owns.
Agent Identity Microsoft Agent 365 Agent identity the user sponsors.
Agent User Microsoft Agent 365 Agent user being managed.
Agent User Microsoft Agent 365 Agent user being sponsored.
Shadow AI Detection Microsoft Agent 365 A detection of a shadow AI agent on a specific managed device, linked to the device's Microsoft 365 user.
Group Microsoft 365 Groups where the user is a member
Group Microsoft 365 Groups where the user is an owner
Subscription Microsoft 365 Microsoft 365 subscriptions licensed to the user
Rooms & Equipment Microsoft 365 Rooms or Equipment assigned to the user account
Service Assignment Microsoft 365 Details when a service or app has been assigned to the user
App Microsoft 365 Microsoft 365 apps licensed to the user
User Activity Microsoft 365 Details when a Microsoft 365 service has been used the last time by a specific user
User Microsoft 365 Manager of the user (directly reporting to)
OneDrive OneDrive All of your users OneDrives in your tenant
File OneDrive All OneDrive files stored in a library of a OneDrive
File OneDrive All OneDrive files stored in a library of a OneDrive
Folder OneDrive All OneDrive folders stored in a library of a OneDrive
Folder OneDrive All OneDrive folders stored in a library of a OneDrive
File Sharing OneDrive OneDrive files shared by the user
File Sharing OneDrive OneDrive files shared with the user (direct or via security group)
File Sharing OneDrive OneDrive file sharings modified by the user
OpenAI Audit Log OpenAI A log of a user action or configuration change within this organization. Needs to be enabled at https://platform.openai.com/settings/organization/data-controls/data-retention
OpenAI ChatKit Thread OpenAI Represents a conversation thread in ChatKit.
OpenAI Completion OpenAI The aggregated completions usage details
OpenAI Organization OpenAI Organizations in which the user is an owner
OpenAI Organization OpenAI Organizations in which the user is reader
OpenAI Project OpenAI Projects in which the user is a member
OpenAI Project OpenAI Projects in which the user is an owner
OpenAI User OpenAI Represents an individual user within an organization
Plan Planner Plans where the user is a member
Plan Planner Plans where the user is an owner
Plan Planner All Planner plans
Plan Planner Plans which are shared with the user
Power App (Canvas App) Power Apps Power Apps co-owned by the user (direct or via security group)
Power App (Canvas App) Power Apps Power Apps created by the user
Power App (Canvas App) Power Apps Power Apps that were last modified by the user
Power App (Canvas App) Power Apps Power Apps owned by the user
Power App (Canvas App) Power Apps Power Apps co-owned by the user (direct or via security group)
Power App (Canvas App) Power Apps Power Apps that were last published by the user
Power App (Canvas App) Power Apps Power Apps that the user is allowed to use (direct or via security group)
Power App (Canvas App) Power Apps Power Apps that the user is allowed to use (direct or via security group)
Environment Power Apps Power Platform environments created by the user
Environment Power Apps Power Platform environments last modified by the user
Connection Power Automate Flow Connections authenticated by the user
Connection Power Automate Flow Connections created by the user
Flow Power Automate Flows owned by the user (direct or via security group)
Flow Power Automate Flows owned by the user (direct or via security group)
Flow Power Automate Flows that the user is allowed to use (direct or via security group)
Flow Power Automate All Power Automate Flows in your tenant
Flow Power Automate Flows which the user is allowed to use (direct)
Activity Event Power BI Lists activity events for PowerBI
App Power BI Apps in PowerBI
Artifacts published to Web Power BI Lists artifacts published to Web for PowerBI
Dashboard Power BI Dashboards for which user is owner
Dashboard Power BI Dashboards for which user has read access
Dashboard Power BI Dashboards for which user has read and copy access
Dashboard Power BI Dashboards for which user has read and reshare access
Dashboard Power BI Dashboards for which user has read and write access
Dashboard Power BI Dashboards which are subscribed by the user
Dataflow Power BI Lists dataflows for PowerBI
Dataflow Power BI Lists dataflows for PowerBI
Dataset Power BI Lists datasets for PowerBI
Datamart Power BI Lists datamarts for PowerBI
Datamart Power BI Lists datamarts for PowerBI
Pipeline Power BI Lists pipelines for PowerBI
Pipeline Power BI Lists pipelines for PowerBI
Report Power BI Reports for which user is owner
Report Power BI Reports for which user has read access
Report Power BI Reports for which user has read and copy access
Report Power BI Reports for which user has read and reshare access
Report Power BI Reports for which user has read and write access
Report Power BI Lists reports for PowerBI
Report Power BI Lists reports for PowerBI
Report Power BI Lists reports for PowerBI
Report Power BI Reports which are subscribed by the user
Workspace Power BI Workspaces in which user is admin
Workspace Power BI Workspaces in which user is contributor
Workspace Power BI Workspaces in which user is member
Workspace Power BI Workspaces in which user is viewer
SharePoint Group SharePoint SharePoint Group with an access
SharePoint Agent SharePoint SharePoint agents inside a list
SharePoint Agent SharePoint SharePoint agents inside a list
File Sharing SharePoint SharePoint files shared by the user
File Sharing SharePoint SharePoint files shared with the user (direct or via security group)
File Sharing SharePoint SharePoint file sharings modified by the user
List/Library SharePoint Lists in which user has access to (direct or via security group)
File SharePoint File in which user has access to (direct or via security group)
File SharePoint All SharePoint files stored in a library of a SharePoint site
File SharePoint All SharePoint files stored in a library of a SharePoint site
Folder SharePoint Folder in which user has access to (direct or via security group)
Folder SharePoint All SharePoint folders stored in a library of a SharePoint site
Folder SharePoint All SharePoint folders stored in a library of a SharePoint site
Site Collection SharePoint Site which user has access to
Site Collection SharePoint Site collections in which user is admin (direct or via security group)
Site Collection SharePoint Site collections in which user is member (direct or via security group)
Site Collection SharePoint Site collections in which user is owner (direct or via security group)
Site Collection SharePoint Site collections in which user is visitor (direct or via security group)
SharePoint Special Group SharePoint Special groups which related to user
Site SharePoint Sites in which user is admin (direct or via security group)
Site SharePoint Sites in which user is member (direct or via security group)
Site SharePoint Sites in which user is owner (direct or via security group)
Site SharePoint Sites in which user is visitor (direct or via security group)
Site SharePoint Web which user has access to
Audit Eventss Teams Audit log events of the user in Teams
Channel Teams Private Teams channels where the user is member
Channel Teams Shared Channels in which user is member
Channel Teams Shared Channels in which user is owner
Channel Teams Channels in which user is owner
Team Teams Teams in which the user is a member or a guest (for external users)
Team Teams Teams in which the user is an owner
User Activity Teams Details about the activity of the user in Teams
Device Usage Teams Details which devices the user uses to access Teams
Community Viva Engage Community in which the user is a member
Community Viva Engage Community in which the user is an owner

Segments

Segment Description
External Users Shows all external users
Internal Users Shows all internal users
Disabled Accounts Shows all disabled users
Users creating custom agents Unique users which are creating agents in last 30 days

Actions

  • Add or remove a SharePoint Site Collection Administrator
  • Add or remove member to/from a Community
  • Add or remove owner to/from a Community
  • Delete User Account
  • Disable User Account
  • Enable User Account
  • Add or remove owner user to/from a Flow
  • Add or remove run-only user to/from a Flow
  • Add member user to a group
  • Add owner user to a group
  • Add or remove owner user to/from a Power App
  • Add or remove run-only user to/from a Power App
  • Add or remove admin user to/from a Workspace
  • Add or remove contributor user to/from a Workspace
  • Add or remove member user to/from a Workspace
  • Add or remove viewer user to/from a Workspace
  • Add or remove user to/from a SharePoint File with a specified permission
  • Add or remove user to/from a SharePoint File Sharing
  • Add or remove user to/from a SharePoint Folder with a specified permission
  • Add or remove user to/from a SharePoint List with a specified permission
  • Add or remove user to/from a SharePoint Site with a specified permission
  • Add or remove user to/from a SharePoint Site Collection with a specified permission
  • Add or remove member to/from a Team
  • Add or remove member to/from a Team Channel
  • Add or remove owner to/from a Team
  • Add or remove owner to/from a Team Channel
  • Add subscriptions for a user
  • Add user to a group
  • Add user to a SharePoint Site
  • Add user to a Team
  • Remove user from a group
  • Remove user from a SharePoint Site
  • Remove user from a SharePoint Site Collection
  • Remove user from a Team
  • Remove subscriptions for a user
Policy Severity Description
Copilot Adoption Opportunity - E3/E5 Users Medium Identifies E3/E5 licensed users eligible for Copilot, helping prioritize rollout to users with necessary prerequisites.
Copilot License Assigned to Disabled Account High Flags disabled accounts retaining active Copilot licenses, enabling immediate cost recovery through license reassignment.
Inactive Copilot Users - 30 Days Medium Reports on users with unused Copilot licenses for 30+ days, enabling proactive engagement or license reallocation. This policy only works correctly with non-anonymized data.
Excessive Draft Agent Creation Pattern Medium Flags users creating 5+ unpublished agents, indicating potential training needs or cleanup requirements
External users Information Shows external users (users with user type 'Guest')
External Users with pending acceptance Low External users which have not accepted invitation to your tenant
Users with Power Platform Premium License Information Users with assigned Premium License for Power Platform (per user plan)
Users with E3 license not using Outlook in last 12 month Low Show Users with E3 license not using Outlook in last 12 month.
Users with passwords not changed in last 6 months Medium Shows users that have not changed their password for more than 6 months
Disabled user accounts Medium Shows all disabled user accounts
Admin accounts with an Office 365 E3 license assigned Medium Admin accounts with an Office 365 E3 license assigned (Note: please adjust the email address, prefix or postfix to your company settings)
Administrators without MFA High Shows administrators that have not activated multi factor authentication
External users invited 3 month ago with pending acceptance Low Shows external users invited more than 3 month ago that have not accepted invitation to the tenant
Disabled user accounts with assigned licenses High Shows disabled user accounts which have any licenses assigned
Global administrators without MFA High Shows global administrators that have not activated multi factor authentication
Guest users with a Dynamics license assigned Medium Guest users with a Dynamics license assigned
Inactive external users Medium Shows external users that have not signed in for more than 6 month
Inactive internal users Medium Shows internal users that have not signed in for more than 6 month
Over-licensed user Accounts High User accounts that have more than one License assigned with overlapping apps.
Users who are creating Microsoft Loop Teams Components Medium A list of users that are creating Microsoft Loop components in their OneDrive

Last updated: 7/19/2026