Reference
User
All users registered in your tenant (internal, external)
Part of the Microsoft 365 inventory.
Scan settings
| Default scanning interval | Allowed scanning intervals | Data removal during incremental scan |
|---|---|---|
| Daily | Daily, Weekly, Bi-Weekly, Monthly, Never, Initial | Yes |
Properties
| Property | Type | Description | Automation placeholder |
|---|---|---|---|
| Account enabled | Boolean | True if the account is enabled; otherwise, false. This property is required when a user is created | {{User.AccountEnabled}} |
| City | String | The city in which the user is located | {{User.City}} |
| Company | String | The company name which the user is associated | {{User.Companyname}} |
| Copilot Credits Cost | Double | Microsoft 365 Copilot credit consumption (USD) attributed to this user. | {{User.CopilotCreditsCost}} |
| Copilot Studio Cost | Double | Copilot Studio (agent) credit consumption (USD) attributed to this user across all agents. | {{User.CopilotStudioUserCost}} |
| Country or region | String | The country/region in which the user is located | {{User.Country}} |
| Cowork Tasks | Double | Total Microsoft 365 Copilot Cowork tasks performed by this user. | {{User.CoworkTaskCount}} |
| Created | DateTime | The date and time the user was created | {{User.CreatedDateTime}} |
| Initially Scanned | DateTime | Shows when this object was initially found in a scan. | {{User.CreatedTime}} |
| Creation Type | String | Indicates whether the user account was created as a regular school or work account (null), an external account (Invitation), a local account for an Microsoft Entra ID B2C tenant (LocalAccount) or self-service sign-up using email verification (EmailVerified). | {{User.CreationType}} |
| Department | String | The name for the department in which the user works | {{User.Department}} |
| Disable Password Expiration | Boolean | If true password never expires | {{User.DisablePasswordExpiration}} |
| Disable Strong Password | Boolean | If true it allows weaker passwords than the default policy to be specified | {{User.DisableStrongPassword}} |
| Icon | String | Default scanning interval: Initial. | {{User.DisplayIcon}} |
| Display Name | String | {{User.DisplayName}} | |
| Extension Attribute 1 | String | This extension attribute is also known as Exchange custom attribute 1. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. Default scanning interval: Weekly. | {{User.ExtensionAttribute1}} |
| Extension Attribute 10 | String | This extension attribute is also known as Exchange custom attribute 10. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute10}} |
| Extension Attribute 11 | String | This extension attribute is also known as Exchange custom attribute 11. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute11}} |
| Extension Attribute 12 | String | This extension attribute is also known as Exchange custom attribute 12. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute12}} |
| Extension Attribute 13 | String | This extension attribute is also known as Exchange custom attribute 13. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute13}} |
| Extension Attribute 14 | String | This extension attribute is also known as Exchange custom attribute 14. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute14}} |
| Extension Attribute 15 | String | This extension attribute is also known as Exchange custom attribute 15. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute15}} |
| Extension Attribute 2 | String | This extension attribute is also known as Exchange custom attribute 2. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute2}} |
| Extension Attribute 3 | String | This extension attribute is also known as Exchange custom attribute 3. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute3}} |
| Extension Attribute 4 | String | This extension attribute is also known as Exchange custom attribute 4. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute4}} |
| Extension Attribute 5 | String | This extension attribute is also known as Exchange custom attribute 5. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute5}} |
| Extension Attribute 6 | String | This extension attribute is also known as Exchange custom attribute 6. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute6}} |
| Extension Attribute 7 | String | This extension attribute is also known as Exchange custom attribute 7. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute7}} |
| Extension Attribute 8 | String | This extension attribute is also known as Exchange custom attribute 8. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute8}} |
| Extension Attribute 9 | String | This extension attribute is also known as Exchange custom attribute 9. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{User.ExtensionAttribute9}} |
| External User State | String | For invited users, the state can be PendingAcceptance or Accepted, or null for all other users. | {{User.ExternalUserState}} |
| First Name | String | The given name (first name) of the user | {{User.FirstName}} |
| onPremises Sync Enabled | Boolean | true if this user object is currently being synced from an on-premises Active Directory (AD); otherwise the user isn't being synced and can be managed in Microsoft Entra ID. | {{User.InCloud}} |
| Is External | Boolean | Is user sign-in as guest | {{User.IsExternal}} |
| Title | String | The user's job title | {{User.JobTitle}} |
| Last scan update | DateTime | Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. | {{User.LastModifiedTime}} |
| Last Name | String | The user's surname | {{User.LastName}} |
| Last password change date | DateTime | The time when this Entra ID user last changed their password or when their password was created, whichever date the latest action was performed | {{User.LastPasswordChangeDateTime}} |
| Last Sign-In | DateTime | The last date a user has signed in to M365. This date can either be the last date a user actively signed in to M365 or when he last had a so called non-interactive sign-in (depending on what is more recent). Interactive sign-in happens by opening the browser and opening the url of an M365 resource (e.g. SharePoint Online). Non-interactive sign-in will happen when users use clients (e.g. Outlook Client) to access tenant resources rather than signing into your tenant directly. The timestamp represents date and time information using ISO 8601 format and is always in UTC time. Default scanning interval: Weekly. | {{User.LastSignIn}} |
| Last Sign-In (Interactive) | DateTime | The last date a user has signed in to M365 interactively. Interactive sign-in happens by opening the browser and opening the url of an M365 resource (e.g. SharePoint Online). The timestamp represents date and time information using ISO 8601 format and is always in UTC time. Default scanning interval: Weekly. | {{User.LastSignInInteractive}} |
| Last Sign-In (non-interactive) | DateTime | The last date a user has signed in to M365 non-interactively. Non-interactive sign-in will happen when users use clients (e.g. Outlook Client) to access tenant resources rather than signing into your tenant directly. The timestamp represents date and time information using ISO 8601 format and is always in UTC time. Default scanning interval: Weekly. | {{User.LastSignInNonInteractive}} |
| Last Successful Sign-In | DateTime | The date and time of the users most recent successful sign-in activity. The timestamp type represents date and time information using ISO 8601 format and is always in UTC. Default scanning interval: Weekly. | {{User.LastSuccessfulSignIn}} |
| Member Type | String | A String value that can be used to classify user membership types in your directory Allowed values: External Guest, External Member, Internal Guest, Internal Member. | {{User.MemberType}} |
| Office | String | The office location in the user's place of business | {{User.OfficeLocation}} |
| On-premises Distinguished Name | String | Contains the on-premises Active Directory distinguished name or DN. The property is only populated for customers who are synchronizing their on-premises directory to Microsoft Entra ID via Entra ID Connect. | {{User.OnPremisesDistinguishedName}} |
| On-premises sAMAccountName | String | Contains the on-premises sAMAccountName synchronized from the on-premises directory. The property is only populated for customers who are synchronizing their on-premises directory to Microsoft Entra ID via Entra ID Connect | {{User.OnPremisesSamAccountName}} |
| Preferred data location | String | The preferred data location for the user | {{User.PreferredDataLocation}} |
| Risk Score | Int32 | Stores risk score | {{User.RiskScore}} |
| Risk Score Update | DateTime | Stores risk score update | {{User.RiskScoreLastUpdate}} |
| Risk Score Value | String | Stores risk score value like Low_Low | {{User.RiskScoreValue}} |
| State or province | String | The state or province in the user's address | {{User.StateOrProvince}} |
| Type | String | A custom security attribute that is assigned to a directory object | {{User.Type}} |
| Usage location | String | A two letter country code (ISO standard 3166) | {{User.UsageLocation}} |
| User Email | String | The SMTP address for the user | {{User.UserEmail}} |
| User Email Domain | String | Email domain of the user. This will only be set if User Email is not empty. | {{User.UserEmailDomain}} |
| User Id | String | The unique identifier for the user | {{User.UserId}} |
| User Principal Name | String | The user principal name (UPN) of the user. The UPN is an Internet-style login name for the user based on the Internet standard RFC 822 | {{User.UserPrincipalName}} |
| User Type | String | A String value that can be used to classify user types in your directory | {{User.UserType}} |
Relations
| Relation | Service | Description |
|---|---|---|
| Resource Group | Azure | Azure resource groups in which the user is an owner |
| Application registration | Entra ID | Entra ID enterprise applications owned by the user |
| App Role Assignment | Entra ID | Entra ID App role assignments owned by the user |
| Device | Entra ID | Entra ID devices owned by user |
| Device | Entra ID | Entra ID devices used by the user |
| Directory Audits | AzureAD | All directory audit logs generated by Entra ID |
| Directory Role | Entra ID | Entra ID directory roles for which the user is a member (direct or via security group) |
| Enterprise Application | Entra ID | Entra ID App registrations owned by the user |
| OAuth2 Permission Grant | Entra ID | All OAuth permission grants in Entra ID |
| Risky Entra ID Sign-In | Entra ID | Shows Risky Entra ID Sign-Ins |
| Entra ID Sign-Ins | AzureAD | All sign-ins of users in your tenant |
| User Registration Credential | Entra ID | All Entra ID registration credentials of a user (MFA, Admin, Auth methods) |
| AI Agent | Azure AI Services | Azure AI projects are used to organize your work and save state while building customized AI apps |
| AI Agent | Azure AI Services | Azure AI projects are used to organize your work and save state while building customized AI apps |
| LLM Deployment | Azure AI Services | Azure AI Foundry supports deploying large language models (LLMs), flows, and web apps. Deploying an LLM or flow makes it available for use in a website, an application, or other production environments. |
| LLM Deployment | Azure AI Services | Azure AI Foundry supports deploying large language models (LLMs), flows, and web apps. Deploying an LLM or flow makes it available for use in a website, an application, or other production environments. |
| AI Hub | Azure AI Services | Azure AI hub which are the primary top-level Azure resources for Azure AI Foundry |
| AI Hub | Azure AI Services | Azure AI hub which are the primary top-level Azure resources for Azure AI Foundry |
| AI Project | Azure AI Services | AI projects in which user is an owner |
| AI Project | Azure AI Services | Azure AI projects are used to organize your work and save state while building customized AI apps |
| AI Project | Azure AI Services | Azure AI projects are used to organize your work and save state while building customized AI apps |
| AI Service | Azure AI Services | Cloud-based artificial intelligence (AI) services that help developers build cognitive intelligence into applications |
| AI Service | Azure AI Services | Cloud-based artificial intelligence (AI) services that help developers build cognitive intelligence into applications |
| Claude Organization | Anthropic | Organizations in which the user is a admin |
| Claude Organization | Anthropic | Organizations in which the user is a billing user |
| Claude Organization | Anthropic | Organizations in which the user is a Claude code user |
| Claude Organization | Anthropic | Organizations in which the user is a developer |
| Claude Organization | Anthropic | Organizations in which the user is a user |
| Claude User | Anthropic | All Claude users |
| M365 Copilot session | Copilot | All Microsoft 365 Copilot sessions. |
| Copilot credits consumption | Copilot | Per-user Microsoft 365 Copilot credit consumption, imported from the Copilot credits / consumption-by-user export. |
| Copilot user activity (Report) | Copilot | Get the most recent activity data for enabled users of Microsoft 365 Copilot apps. |
| Copilot Cowork usage | Copilot | Per-user Microsoft 365 Copilot Cowork activity (tasks, active days), imported from the CoworkUserDetails export. |
| AI Builder consumption | Copilot Studio | AI Builder credit consumption per day/user/environment, imported from the AI Builder consumption report. |
| Action | Copilot Studio | Actions used by Copilot Agent |
| Action | Copilot Studio | Actions used by Copilot Agent |
| Agent Flow | Copilot Studio | Agent Flows created inside Copilot Studio. |
| Agent Flow | Copilot Studio | Agent Flows created inside Copilot Studio. |
| Agent Flow | Copilot Studio | Agent Flows created inside Copilot Studio. |
| Knowledge | Copilot Studio | Used knowledge in Copliot Agent |
| Knowledge | Copilot Studio | Used knowledge in Copliot Agent |
| Pay-as-you-go Plan | Copilot Studio | A pay-as-you-go plan is a group of one or more environments that you can configure to bill to Azure. |
| Pay-as-you-go Plan | Copilot Studio | A pay-as-you-go plan is a group of one or more environments that you can configure to bill to Azure. |
| Copilot Studio user consumption | Copilot Studio | Per-user Copilot credit consumption per agent, imported from the User-Level Credit Consumption export. |
| Topic | Copilot Studio | Topics of Copilot Agent |
| Topic | Copilot Studio | Topics of Copilot Agent |
| Trigger | Copilot Studio | Triggers that start a Copilot agent |
| Trigger | Copilot Studio | Triggers that start a Copilot agent |
| Copilot Agent | Copilot Studio | Agents to which the user has access |
| Copilot Agent | Copilot Studio | Agents created inside Copilot Studio. |
| Copilot Agent | Copilot Studio | Agents created inside Copilot Studio. |
| Copilot Agent | Copilot Studio | Agents created inside Copilot Studio. |
| Copilot Agent | Copilot Studio | Agents created inside Copilot Studio. |
| Calendar Permission | Exchange | Permissions configured on Exchange mailbox calendars (sharing and delegation). |
| Exchange Audit Event | Exchange | Exchange administrative and mailbox audit events ingested from the Office 365 Management Activity API. |
| Exchange Role Group | Exchange | |
| Exchange Role Group | Exchange | |
| Mail User | Exchange | Mail-enabled users that route to an external SMTP address. Common offboarding-leak signal. |
| Mailbox Audit Bypass | Exchange | Accounts excluded from mailbox audit logging. Bypassed service accounts can read mail invisibly — high-signal finding most products miss. |
| Mailbox Delegate | Exchange | Mailbox delegations: Full Access, Send-As, and Send-on-Behalf permissions on user mailboxes. |
| Mailbox Delegate | Exchange | Mailbox delegations: Full Access, Send-As, and Send-on-Behalf permissions on user mailboxes. |
| Mailbox Folder Permission | Exchange | Per-folder ACLs on user mailboxes (Calendar, Inbox, Top of Information Store). Anonymous calendar sharing is a silent data leak no admin UI surfaces. |
| Redirect Rule | Exchange | All registered Exchange mailbox redirect rules |
| Mobile Device | Exchange | Exchange ActiveSync mobile device partnerships. |
| Mailbox | Exchange | All Exchange mailboxes of your users, rooms & equipment |
| Intune Managed Devices M365 User | Intune | Devices enrolled and managed through Microsoft Intune, including compliance status and hardware details |
| Intune Managed Devices M365 User Name | Intune | Devices enrolled and managed through Microsoft Intune, including compliance status and hardware details |
| Agent Blueprint | Microsoft Agent 365 | Agent blueprint the user owns. |
| Agent Blueprint | Microsoft Agent 365 | Agent blueprint the user sponsors. |
| Agent Blueprint Principal | Microsoft Agent 365 | Agent identity blueprint principal the user owns. |
| Agent Blueprint Principal | Microsoft Agent 365 | Agent identity blueprint principal the user sponsors. |
| Agent Identity | Microsoft Agent 365 | Agent identity the user owns. |
| Agent Identity | Microsoft Agent 365 | Agent identity the user sponsors. |
| Agent User | Microsoft Agent 365 | Agent user being managed. |
| Agent User | Microsoft Agent 365 | Agent user being sponsored. |
| Shadow AI Detection | Microsoft Agent 365 | A detection of a shadow AI agent on a specific managed device, linked to the device's Microsoft 365 user. |
| Group | Microsoft 365 | Groups where the user is a member |
| Group | Microsoft 365 | Groups where the user is an owner |
| Subscription | Microsoft 365 | Microsoft 365 subscriptions licensed to the user |
| Rooms & Equipment | Microsoft 365 | Rooms or Equipment assigned to the user account |
| Service Assignment | Microsoft 365 | Details when a service or app has been assigned to the user |
| App | Microsoft 365 | Microsoft 365 apps licensed to the user |
| User Activity | Microsoft 365 | Details when a Microsoft 365 service has been used the last time by a specific user |
| User | Microsoft 365 | Manager of the user (directly reporting to) |
| OneDrive | OneDrive | All of your users OneDrives in your tenant |
| File | OneDrive | All OneDrive files stored in a library of a OneDrive |
| File | OneDrive | All OneDrive files stored in a library of a OneDrive |
| Folder | OneDrive | All OneDrive folders stored in a library of a OneDrive |
| Folder | OneDrive | All OneDrive folders stored in a library of a OneDrive |
| File Sharing | OneDrive | OneDrive files shared by the user |
| File Sharing | OneDrive | OneDrive files shared with the user (direct or via security group) |
| File Sharing | OneDrive | OneDrive file sharings modified by the user |
| OpenAI Audit Log | OpenAI | A log of a user action or configuration change within this organization. Needs to be enabled at https://platform.openai.com/settings/organization/data-controls/data-retention |
| OpenAI ChatKit Thread | OpenAI | Represents a conversation thread in ChatKit. |
| OpenAI Completion | OpenAI | The aggregated completions usage details |
| OpenAI Organization | OpenAI | Organizations in which the user is an owner |
| OpenAI Organization | OpenAI | Organizations in which the user is reader |
| OpenAI Project | OpenAI | Projects in which the user is a member |
| OpenAI Project | OpenAI | Projects in which the user is an owner |
| OpenAI User | OpenAI | Represents an individual user within an organization |
| Plan | Planner | Plans where the user is a member |
| Plan | Planner | Plans where the user is an owner |
| Plan | Planner | All Planner plans |
| Plan | Planner | Plans which are shared with the user |
| Power App (Canvas App) | Power Apps | Power Apps co-owned by the user (direct or via security group) |
| Power App (Canvas App) | Power Apps | Power Apps created by the user |
| Power App (Canvas App) | Power Apps | Power Apps that were last modified by the user |
| Power App (Canvas App) | Power Apps | Power Apps owned by the user |
| Power App (Canvas App) | Power Apps | Power Apps co-owned by the user (direct or via security group) |
| Power App (Canvas App) | Power Apps | Power Apps that were last published by the user |
| Power App (Canvas App) | Power Apps | Power Apps that the user is allowed to use (direct or via security group) |
| Power App (Canvas App) | Power Apps | Power Apps that the user is allowed to use (direct or via security group) |
| Environment | Power Apps | Power Platform environments created by the user |
| Environment | Power Apps | Power Platform environments last modified by the user |
| Connection | Power Automate | Flow Connections authenticated by the user |
| Connection | Power Automate | Flow Connections created by the user |
| Flow | Power Automate | Flows owned by the user (direct or via security group) |
| Flow | Power Automate | Flows owned by the user (direct or via security group) |
| Flow | Power Automate | Flows that the user is allowed to use (direct or via security group) |
| Flow | Power Automate | All Power Automate Flows in your tenant |
| Flow | Power Automate | Flows which the user is allowed to use (direct) |
| Activity Event | Power BI | Lists activity events for PowerBI |
| App | Power BI | Apps in PowerBI |
| Artifacts published to Web | Power BI | Lists artifacts published to Web for PowerBI |
| Dashboard | Power BI | Dashboards for which user is owner |
| Dashboard | Power BI | Dashboards for which user has read access |
| Dashboard | Power BI | Dashboards for which user has read and copy access |
| Dashboard | Power BI | Dashboards for which user has read and reshare access |
| Dashboard | Power BI | Dashboards for which user has read and write access |
| Dashboard | Power BI | Dashboards which are subscribed by the user |
| Dataflow | Power BI | Lists dataflows for PowerBI |
| Dataflow | Power BI | Lists dataflows for PowerBI |
| Dataset | Power BI | Lists datasets for PowerBI |
| Datamart | Power BI | Lists datamarts for PowerBI |
| Datamart | Power BI | Lists datamarts for PowerBI |
| Pipeline | Power BI | Lists pipelines for PowerBI |
| Pipeline | Power BI | Lists pipelines for PowerBI |
| Report | Power BI | Reports for which user is owner |
| Report | Power BI | Reports for which user has read access |
| Report | Power BI | Reports for which user has read and copy access |
| Report | Power BI | Reports for which user has read and reshare access |
| Report | Power BI | Reports for which user has read and write access |
| Report | Power BI | Lists reports for PowerBI |
| Report | Power BI | Lists reports for PowerBI |
| Report | Power BI | Lists reports for PowerBI |
| Report | Power BI | Reports which are subscribed by the user |
| Workspace | Power BI | Workspaces in which user is admin |
| Workspace | Power BI | Workspaces in which user is contributor |
| Workspace | Power BI | Workspaces in which user is member |
| Workspace | Power BI | Workspaces in which user is viewer |
| SharePoint Group | SharePoint | SharePoint Group with an access |
| SharePoint Agent | SharePoint | SharePoint agents inside a list |
| SharePoint Agent | SharePoint | SharePoint agents inside a list |
| File Sharing | SharePoint | SharePoint files shared by the user |
| File Sharing | SharePoint | SharePoint files shared with the user (direct or via security group) |
| File Sharing | SharePoint | SharePoint file sharings modified by the user |
| List/Library | SharePoint | Lists in which user has access to (direct or via security group) |
| File | SharePoint | File in which user has access to (direct or via security group) |
| File | SharePoint | All SharePoint files stored in a library of a SharePoint site |
| File | SharePoint | All SharePoint files stored in a library of a SharePoint site |
| Folder | SharePoint | Folder in which user has access to (direct or via security group) |
| Folder | SharePoint | All SharePoint folders stored in a library of a SharePoint site |
| Folder | SharePoint | All SharePoint folders stored in a library of a SharePoint site |
| Site Collection | SharePoint | Site which user has access to |
| Site Collection | SharePoint | Site collections in which user is admin (direct or via security group) |
| Site Collection | SharePoint | Site collections in which user is member (direct or via security group) |
| Site Collection | SharePoint | Site collections in which user is owner (direct or via security group) |
| Site Collection | SharePoint | Site collections in which user is visitor (direct or via security group) |
| SharePoint Special Group | SharePoint | Special groups which related to user |
| Site | SharePoint | Sites in which user is admin (direct or via security group) |
| Site | SharePoint | Sites in which user is member (direct or via security group) |
| Site | SharePoint | Sites in which user is owner (direct or via security group) |
| Site | SharePoint | Sites in which user is visitor (direct or via security group) |
| Site | SharePoint | Web which user has access to |
| Audit Eventss | Teams | Audit log events of the user in Teams |
| Channel | Teams | Private Teams channels where the user is member |
| Channel | Teams | Shared Channels in which user is member |
| Channel | Teams | Shared Channels in which user is owner |
| Channel | Teams | Channels in which user is owner |
| Team | Teams | Teams in which the user is a member or a guest (for external users) |
| Team | Teams | Teams in which the user is an owner |
| User Activity | Teams | Details about the activity of the user in Teams |
| Device Usage | Teams | Details which devices the user uses to access Teams |
| Community | Viva Engage | Community in which the user is a member |
| Community | Viva Engage | Community in which the user is an owner |
Segments
| Segment | Description |
|---|---|
| External Users | Shows all external users |
| Internal Users | Shows all internal users |
| Disabled Accounts | Shows all disabled users |
| Users creating custom agents | Unique users which are creating agents in last 30 days |
Actions
- Add or remove a SharePoint Site Collection Administrator
- Add or remove member to/from a Community
- Add or remove owner to/from a Community
- Delete User Account
- Disable User Account
- Enable User Account
- Add or remove owner user to/from a Flow
- Add or remove run-only user to/from a Flow
- Add member user to a group
- Add owner user to a group
- Add or remove owner user to/from a Power App
- Add or remove run-only user to/from a Power App
- Add or remove admin user to/from a Workspace
- Add or remove contributor user to/from a Workspace
- Add or remove member user to/from a Workspace
- Add or remove viewer user to/from a Workspace
- Add or remove user to/from a SharePoint File with a specified permission
- Add or remove user to/from a SharePoint File Sharing
- Add or remove user to/from a SharePoint Folder with a specified permission
- Add or remove user to/from a SharePoint List with a specified permission
- Add or remove user to/from a SharePoint Site with a specified permission
- Add or remove user to/from a SharePoint Site Collection with a specified permission
- Add or remove member to/from a Team
- Add or remove member to/from a Team Channel
- Add or remove owner to/from a Team
- Add or remove owner to/from a Team Channel
- Add subscriptions for a user
- Add user to a group
- Add user to a SharePoint Site
- Add user to a Team
- Remove user from a group
- Remove user from a SharePoint Site
- Remove user from a SharePoint Site Collection
- Remove user from a Team
- Remove subscriptions for a user
Policies that check this object
| Policy | Severity | Description |
|---|---|---|
| Copilot Adoption Opportunity - E3/E5 Users | Medium | Identifies E3/E5 licensed users eligible for Copilot, helping prioritize rollout to users with necessary prerequisites. |
| Copilot License Assigned to Disabled Account | High | Flags disabled accounts retaining active Copilot licenses, enabling immediate cost recovery through license reassignment. |
| Inactive Copilot Users - 30 Days | Medium | Reports on users with unused Copilot licenses for 30+ days, enabling proactive engagement or license reallocation. This policy only works correctly with non-anonymized data. |
| Excessive Draft Agent Creation Pattern | Medium | Flags users creating 5+ unpublished agents, indicating potential training needs or cleanup requirements |
| External users | Information | Shows external users (users with user type 'Guest') |
| External Users with pending acceptance | Low | External users which have not accepted invitation to your tenant |
| Users with Power Platform Premium License | Information | Users with assigned Premium License for Power Platform (per user plan) |
| Users with E3 license not using Outlook in last 12 month | Low | Show Users with E3 license not using Outlook in last 12 month. |
| Users with passwords not changed in last 6 months | Medium | Shows users that have not changed their password for more than 6 months |
| Disabled user accounts | Medium | Shows all disabled user accounts |
| Admin accounts with an Office 365 E3 license assigned | Medium | Admin accounts with an Office 365 E3 license assigned (Note: please adjust the email address, prefix or postfix to your company settings) |
| Administrators without MFA | High | Shows administrators that have not activated multi factor authentication |
| External users invited 3 month ago with pending acceptance | Low | Shows external users invited more than 3 month ago that have not accepted invitation to the tenant |
| Disabled user accounts with assigned licenses | High | Shows disabled user accounts which have any licenses assigned |
| Global administrators without MFA | High | Shows global administrators that have not activated multi factor authentication |
| Guest users with a Dynamics license assigned | Medium | Guest users with a Dynamics license assigned |
| Inactive external users | Medium | Shows external users that have not signed in for more than 6 month |
| Inactive internal users | Medium | Shows internal users that have not signed in for more than 6 month |
| Over-licensed user Accounts | High | User accounts that have more than one License assigned with overlapping apps. |
| Users who are creating Microsoft Loop Teams Components | Medium | A list of users that are creating Microsoft Loop components in their OneDrive |