Microsoft 365
Microsoft 365
Hal reads your clients’ Microsoft 365 audit activity through the Microsoft 365 Management Activity API, over read-only credentials you grant and can revoke at any time. He never writes to the tenant.
What’s collected:
- The unified audit log across workloads — Exchange, SharePoint, OneDrive, Teams
- Mailbox operations, file and sharing activity, and admin actions
- The result and the acting account for each event
Events are polled every few minutes and retained for 365 days, searchable across every connected tenant.
Prerequisite: the tenant must have Unified Audit Logging enabled before Hal
can read it. See Audit Logging Prerequisites.
Connect it: any of the three methods in Getting Started — Hal-assisted (chat), script, or manual — produce the same read-only credentials.
Sign-in and identity activity comes from Entra ID, a separate feed.