Holds enriched activity from Office 365 and connected SaaS apps for advanced hunting. Data arrives only through Defender for Cloud Apps and its Microsoft 365 connector; Purview Audit by itself doesn't fill it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains CloudAppEvents in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft 365
Formerly Office 365, Microsoft's software-as-a-service productivity suite. A Microsoft Entra tenant provides its identity, and its data is not governed by Azure RBAC.
- SaaS
A cloud model in which you consume a finished application that the provider operates, Microsoft 365 for instance. Nearly everything is the provider's job; you look after your data, users and devices.
- Advanced hunting
Threat-hunting feature of the Microsoft Defender portal that runs KQL over 30 days of raw Defender XDR data, plus onboarded Sentinel data, and supports custom detections. It finds activity after it happens rather than blocking it.
- Microsoft Purview Audit
Searches the unified audit log for admin and user activity across Microsoft services. The Standard tier keeps records for 180 days, while Premium adds longer retention and intelligent insights.