Microsoft Defender XDR
Hunting and detection

CallActivityEvents table in the advanced hunting schema

In brief

The new table documents Microsoft Teams call activity details, including timestamps, call and participant identifiers, activity types, scheduling information, and join links. It is populated by Microsoft Defender for Office 365.

What Defender admins need to know

Admins can use the table when building advanced hunting queries. Queries return no results unless Defender for Office 365 is deployed in Defender.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

new file mode 100644

title: CallActivityEvents table in the advanced hunting schema titleSuffix: Microsoft Defender description: Learn about the CallActivityEvents table in the advanced hunting schema, which contains details about activities performed during Microsoft Teams calls. ms.service: defender-xdr ms.subservice: adv-hunting ms.author: pauloliveria author: poliveria ms.localizationpriority: medium ms.collection:

  • m365-security
  • tier3 ms.custom:
  • cx-ti
  • cx-ah appliesto:
    • Microsoft Defender XDR ms.topic: reference ms.date: 08/04/2026 ai-usage: ai-assisted

CallActivityEvents

[!INCLUDE Microsoft Defender XDR rebranding]

The CallActivityEvents table in the advanced hunting schema contains details about activities performed during Microsoft Teams calls in your organization.

This advanced hunting table is populated by records from Microsoft Defender for Office 365. If your organization hasn't deployed the service in Microsoft Defender, queries that use the table don't work or return any results. For more information about how to deploy Defender for Office 365 in the Defender portal, read Deploy supported services.

Schema

For information on other tables in the advanced hunting schema, see the advanced hunting reference.

Column nameData typeDescription
ActivityTimestampdatetimeDate and time when the activity was recorded
CallIdstringUnique identifier for the call, as generated by Microsoft 365
ActivityIdstringUnique identifier for the activity, as generated by Microsoft 365
ActivityInitiatorIdstringUnique identifier for the participant who initiated the activity
ActivityTypestringType of activity performed during the call
ThreadIdstringUnique identifier for the thread associated with the call
ActivityInitiatorUpnstringUser principal name of the participant who initiated the activity
ActivityInitiatorDisplayNamestringDisplay name of the participant who initiated the activity
CallSchedulingTypestringType of scheduling for the call, such as Adhoc, Scheduled, or Recurring
CallJoinUrlstringLink that participants use to join the call
OriginatorUserDisplayNamestringDisplay name of the caller who initiated the call
OriginatorUpnstringUser principal name of the caller who initiated the call

Related topics

[!INCLUDE Microsoft Defender XDR rebranding]