ExchangeMailboxAuditGroupActivity Class |
Namespace: Aspose.Email.Clients.Activity
The ExchangeMailboxAuditGroupActivity type exposes the following members.
Name | Description | |
---|---|---|
ExchangeMailboxAuditGroupActivity | Initializes a new instance of the ExchangeMailboxAuditGroupActivity class |
Name | Description | |
---|---|---|
AffectedItems |
Information about each item in the group.
| |
ClientIP |
The IP address of the device that was used when the activity was logged.
The IP address is displayed in either an IPv4 or IPv6 address format.
Mandatory: Yes
(Inherited from Content.) | |
CreationTime |
The date and time in Coordinated Universal Time (UTC) when the user performed the activity.
Mandatory: Yes
(Inherited from Content.) | |
CrossMailboxOperations |
Indicates if the operation involved more than one mailbox.
| |
DestFolder |
The destination folder, for operations such as Move.
| |
DestMailboxId |
Set only if the CrossMailboxOperations parameter is True. Specifies the target mailbox GUID.
| |
DestMailboxOwnerMasterAccountSid |
Set only if the CrossMailboxOperations parameter is True. Specifies the SID for the master account SID of the target mailbox owner.
| |
DestMailboxOwnerSid |
Set only if the CrossMailboxOperations parameter is True. Specifies the SID of the target mailbox.
| |
DestMailboxOwnerUPN |
Set only if the CrossMailboxOperations parameter is True. Specifies the UPN of the owner of the target mailbox.
| |
Folder |
The folder where a group of items is located.
| |
Folders |
Information about the source folders involved in an operation; for example, if folders are selected and then deleted.
| |
Id |
Unique identifier of an audit record.
Mandatory: Yes
(Inherited from Content.) | |
ObjectId |
For SharePoint and OneDrive for Business activity, the full path name of the file or folder accessed by the user.
For Exchange admin audit logging, the name of the object that was modified by the cmdlet.
Mandatory: No
(Inherited from Content.) | |
Operation |
The name of the user or admin activity.
For a description of the most common operations/activities, see Search the audit log in the Office 365 Protection Center.
For Exchange admin activity, this property identifies the name of the cmdlet that was run.
For Dlp events, this can be "DlpRuleMatch", "DlpRuleUndo" or "DlpInfo", which are described under "DLP schema" below.
Mandatory: Yes
(Inherited from Content.) | |
OrganizationId |
The GUID for your organization's Office 365 tenant.
This value will always be the same for your organization, regardless of the Office 365 service in which it occurs.
Mandatory: Yes
(Inherited from Content.) | |
RecordType |
The type of operation indicated by the record.
Mandatory: Yes
(Inherited from Content.) | |
ResultStatus |
Indicates whether the action (specified in the Operation property) was successful or not.
Possible values are Succeeded, PartiallySucceded, or Failed.
For Exchange admin activity, the value is either True or False.
Mandatory: No
(Inherited from Content.) | |
Scope |
Was this event created by a hosted O365 service or an on-premises server?
Possible values are online and onprem. Note that SharePoint is the only workload currently sending events from on-premises to O365.
Mandatory: No
(Inherited from Content.) | |
UserId |
The UPN (User Principal Name) of the user who performed the action (specified in the Operation property) that resulted in the record being logged;
for example, my_name@my_domain_name.
Note that records for activity performed by system accounts (such as SHAREPOINT\system or NT AUTHORITY\SYSTEM) are also included.
Mandatory: Yes
(Inherited from Content.) | |
UserKey |
An alternative ID for the user identified in the UserId property.
For example, this property is populated with the passport unique ID (PUID) for events performed by users in SharePoint, OneDrive for Business, and Exchange.
This property may also specify the same value as the UserID property for events occurring in other services and events performed by system accounts.
Mandatory: Yes
(Inherited from Content.) | |
UserType |
The type of user that performed the operation.
Mandatory: Yes
(Inherited from Content.) | |
Workload |
The Office 365 service where the activity occurred in the Workload string. The possible values for this property are:
Exchange
SharePoint
OneDrive
AzureActiveDirectory
SecurityComplianceCenter
Sway
ThreatIntelligence
Mandatory: No
(Inherited from Content.) |
Name | Description | |
---|---|---|
Equals | (Inherited from Object.) | |
Finalize | (Inherited from Object.) | |
GetHashCode | (Inherited from Object.) | |
GetType | (Inherited from Object.) | |
MemberwiseClone | (Inherited from Object.) | |
ToString | (Inherited from Object.) |