> For the complete documentation index, see [llms.txt](https://helpdesk.augmentt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://helpdesk.augmentt.com/modules/secure/alerts/monitored-alerts/m365-monitored-alerts.md).

# M365 Monitored Alerts

Sourced from the Microsoft 365 Unified Audit Log — these are events Augmentt's own logic collects and evaluates, not a separate Microsoft alerting product. Licensed at **Basic (non-P1)**, so every Microsoft 365 tenant can use this whole catalog regardless of add-on licensing.

{% hint style="info" %}
Reference: [Microsoft Entra audit log activity reference](https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities) — every row below corresponds to an activity Microsoft records in this audit log.
{% endhint %}

| Alert                                                                                                               | Category                     | Severity | What it alerts on                                                                    |
| ------------------------------------------------------------------------------------------------------------------- | ---------------------------- | -------- | ------------------------------------------------------------------------------------ |
| **Add Application** `add_application`                                                                               | Application Management       | Low      | An application was added to Azure.                                                   |
| **Add Owner** `add_owner`                                                                                           | Application Management       | Low      | An owner was added to the application.                                               |
| **Add Service Principal** `add_service_principal`                                                                   | Application Management       | Low      | A service principal was added.                                                       |
| **Add Service Principal Credentials** `add_service_principal_credentials`                                           | Application Management       | Medium   | Service principal credentials were added.                                            |
| **Consent To Application** `consent_to_application`                                                                 | Application Management       | Medium   | A user or admin consented to an application.                                         |
| **Remove Delegated Permission Grant** `remove_delegated_permission_grant`                                           | Application Management       | Low      | A delegated permission grant was removed.                                            |
| **Update Application** `update_application`                                                                         | Application Management       | Low      | An application was updated.                                                          |
| **Update Application Certificates And Secrets Management** `update_application_certificates_and_secrets_management` | Application Management       | Medium   | Application certificates and secrets management were updated.                        |
| **Update Service Principal** `update_service_principal`                                                             | Application Management       | Low      | A service principal was updated.                                                     |
| **Add A Partner To Cross Tenant Access Setting** `add_a_partner_to_cross_tenant_access_setting`                     | Cross Tenant Access Settings | High     | A partner was added to cross-tenant access settings.                                 |
| **Add Device** `add_device`                                                                                         | Device                       | Low      | A device was added.                                                                  |
| **Device No Longer Compliant** `device_no_longer_compliant`                                                         | Device                       | Low      | A device is no longer compliant.                                                     |
| **Device No Longer Managed** `device_no_longer_managed`                                                             | Device                       | Medium   | A device is no longer managed.                                                       |
| **Register Device** `register_device`                                                                               | Device                       | Low      | A device was registered.                                                             |
| **Remove Member From Group** `remove_member_from_group`                                                             | Group Management             | Low      | A member was removed from a group.                                                   |
| **Remove Owner From Group** `remove_owner_from_group`                                                               | Group Management             | Low      | An owner was removed from a group.                                                   |
| **Update Policy** `update_policy`                                                                                   | Policy                       | Low      | A policy was updated.                                                                |
| **Delete Conditional Access Policy** `delete_conditional_access_policy`                                             | Policy                       | High     | A Conditional Access policy was deleted.                                             |
| **Delete Policy** `delete_policy`                                                                                   | Policy                       | Medium   | A policy was deleted.                                                                |
| **Update Conditional Access Policy** `update_conditional_access_policy`                                             | Policy                       | Medium   | A Conditional Access policy was updated.                                             |
| **Update Authorization Policy** `update_authorization_policy`                                                       | Policy                       | Medium   | An authorization policy was updated.                                                 |
| **Add Member To Role Outside of PIM** `add_member_to_role_outside_of_pim`                                           | Resource Management          | High     | A member was added to a role permanently, outside of Privileged Identity Management. |
| **Triggered PIM Alert** `triggered_pim_alert`                                                                       | Resource Management          | High     | A Privileged Identity Management alert was triggered.                                |
| **Update Role** `update_role`                                                                                       | Role Management              | Medium   | A role was updated.                                                                  |
| **Add User** `add_user`                                                                                             | User Management              | Low      | A new user was added.                                                                |
| **Admin Deleted Security Info** `admin_deleted_security_info`                                                       | User Management              | High     | An admin deleted a user's security info (MFA methods).                               |
| **Admin Registered Security Info** `admin_registered_security_info`                                                 | User Management              | Low      | An admin registered security info on a user's behalf.                                |
| **Change Password Self-Service** `change_password_selfservice`                                                      | User Management              | Low      | A self-service password change was initiated.                                        |
| **Change User License** `change_user_license`                                                                       | User Management              | Low      | A user's license was changed.                                                        |
| **Change User Password** `change_user_password`                                                                     | User Management              | Low      | A user changed their password.                                                       |
| **Enable Account** `enable_account`                                                                                 | User Management              | Low      | An account was enabled.                                                              |
| **Disable Account** `disable_account`                                                                               | User Management              | Low      | An account was disabled.                                                             |
| **Invite External User** `invite_external_user`                                                                     | User Management              | Low      | An external user was invited.                                                        |
| **Redeem External User Invite** `redeem_external_user_invite`                                                       | User Management              | Low      | An external user redeemed their invitation.                                          |
| **Reset Password by Admin** `reset_password_by_admin`                                                               | User Management              | Medium   | A password was reset by an admin.                                                    |
| **Reset Password Self-Service** `reset_password_selfservice`                                                        | User Management              | Low      | A password was reset via self-service password reset.                                |
| **Reset User Password** `reset_user_password`                                                                       | User Management              | Low      | A user's password was reset.                                                         |
| **User Changed Default Security Info** `user_changed_default_security_info`                                         | User Management              | Low      | A user changed their default security info method.                                   |
| **User Deleted Security Info** `user_deleted_security_info`                                                         | User Management              | Low      | A user deleted their own security info.                                              |
| **Disable Strong Authentication** `disable_strong_authentication`                                                   | User Management              | High     | Strong authentication (MFA) was disabled for a user.                                 |
| **Set Verified Publisher** `set_verified_publisher`                                                                 | User Management              | Low      | A verified publisher was set on an application.                                      |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://helpdesk.augmentt.com/modules/secure/alerts/monitored-alerts/m365-monitored-alerts.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
