DeviceLogonEvents
DeviceLogonEvents contains sign-in and authentication events on devices reported by Microsoft Defender for Endpoint.
tablesCurrent
Relationships
Microsoft Defender for Endpoint
Source productproductMicrosoft Defender for Endpoint P2
Required licenselicenseMicrosoft Graph Security API
API accessapiMicrosoft Defender for Endpoint APIs
API accessapiLegacy Microsoft Defender XDR APIs
API accessapiDeviceEvents
Related tabletableDeviceInfo
Related tabletableDeviceNetworkEvents
Related tabletable
Source productproductMicrosoft Defender for Endpoint P2
Required licenselicenseMicrosoft Graph Security API
API accessapiMicrosoft Defender for Endpoint APIs
API accessapiLegacy Microsoft Defender XDR APIs
API accessapiDeviceEvents
Related tabletableDeviceInfo
Related tabletableDeviceNetworkEvents
Related tabletable
Schema
| Field | Type | Description | Copy |
|---|---|---|---|
Timestamp | datetime | Date and time when the event was recorded. | |
DeviceId | string | Unique identifier for the device in the service. | |
DeviceName | string | Fully qualified domain name of the device. | |
ActionType | string | Type of logon activity that triggered the event. | |
LogonType | string | Type of logon session. | |
AccountName | string | User name of the account that attempted or completed logon. | |
AccountDomain | string | Domain of the account that attempted or completed logon. | |
AccountSid | string | Security identifier of the account that attempted or completed logon. | |
RemoteIP | string | Remote IP address associated with the logon event, when available. | |
FailureReason | string | Information explaining why the recorded logon action failed. |