Uredi

CallActivityEvents

The CallActivityEvents table in the advanced hunting schema contains details about activities performed during Microsoft Teams calls in your organization.

This advanced hunting table is populated by records from Microsoft Defender for Office 365. If your organization hasn't deployed the service in Microsoft Defender, queries that use the table don't work or return any results. For more information about how to deploy Defender for Office 365 in the Defender portal, read Deploy supported services.

Note

Support for the event streaming API, Microsoft Sentinel integration, and more attributes is planned for the coming weeks.

Schema

For information on other tables in the advanced hunting schema, see the advanced hunting reference.

Column name Data type Description
ActivityTimestamp datetime Date and time when the activity was recorded
CallId string Unique identifier for the call, as generated by Microsoft 365
ActivityId string Unique identifier for the activity, as generated by Microsoft 365
ActivityInitiatorId string Unique identifier for the participant who initiated the activity
ActivityType string Type of activity performed during the call
ThreadId string Unique identifier for the thread associated with the call
ActivityInitiatorUpn string User principal name of the participant who initiated the activity
ActivityInitiatorDisplayName string Display name of the participant who initiated the activity
CallSchedulingType string Type of scheduling for the call, such as Adhoc, Scheduled, or Recurring
CallJoinUrl string Link that participants use to join the call
OriginatorUserDisplayName string Display name of the caller who initiated the call
OriginatorUpn string User principal name of the caller who initiated the call

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender XDR Tech Community.