Skip to content

Microsoft 365

Microsoft 365

Hal reads your clients’ Microsoft 365 audit activity through the Microsoft 365 Management Activity API, over read-only credentials you grant and can revoke at any time. He never writes to the tenant.

What’s collected:

  • The unified audit log across workloads — Exchange, SharePoint, OneDrive, Teams
  • Mailbox operations, file and sharing activity, and admin actions
  • The result and the acting account for each event

Events are polled every few minutes and retained for 365 days, searchable across every connected tenant.

Prerequisite: the tenant must have Unified Audit Logging enabled before Hal can read it. See Audit Logging Prerequisites.

Connect it: any of the three methods in Getting Started — Hal-assisted (chat), script, or manual — produce the same read-only credentials.

Sign-in and identity activity comes from Entra ID, a separate feed.