Understand the advanced hunting schema
In brief
The schema reference now lists CallActivityEvents, corrects the FileMaliciousContentInfo link, and standardizes the GraphAPIAuditEvents name.
What Defender admins need to know
Administrators can use the updated table entries and links when referencing advanced hunting schemas. No action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Understand the advanced hunting schema
| AlertInfo | Alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity, including severity information and threat categorization |
| BehaviorEntities (Preview) | Entities (file, process, device, user, and others) that are involved in a behavior in Microsoft Defender for Cloud Apps (not available for GCC) and User and Entity Behavior Analytics (UEBA) |
| BehaviorInfo (Preview) | Behaviors from Microsoft Defender for Cloud Apps (not available for GCC) and User and Entity Behavior Analytics (UEBA) |
| CallActivityEvents | Activities performed during Microsoft Teams calls in your organization |
| CampaignInfo (Preview) | Email campaigns identified by Microsoft Defender for Office 365 |
| CloudAppEvents | Events involving accounts and objects in Office 365 and other cloud apps and services |
| CloudAuditEvents | Cloud audit events for various cloud platforms protected by the organization's Microsoft Defender for Cloud |
| EntraIdSpnSignInEvents | Microsoft Entra service principal and managed identity sign-ins |
| ExposureGraphEdges | Microsoft Security Exposure Management exposure graph edge information provides visibility into relationships between entities and assets in the graph |
| ExposureGraphNodes | Microsoft Security Exposure Management exposure graph node information, about organizational entities and their properties |
| FileMaliciousContentInfoFileMaliciousContentInfo (Preview) | Files that were processed by Microsoft Defender for Office 365 in SharePoint Online, OneDrive, and Microsoft Teams. |
| GraphAPIAuditEvents | Microsoft Entra ID API requests made to Microsoft Graph API for resources in the tenant |
| IdentityAccountInfo | Account information from various sources, including Microsoft Entra ID. This table also includes information and link to the identity that owns the account. |
| IdentityDirectoryEvents | Events involving an on-premises domain controller running Active Directory (AD). This table covers a range of identity-related events and system events on the domain controller. |
| IdentityEvents (Preview) | Information about identity events obtained from other cloud identity service providers |
@@ -12,11 +12,13 @@ ms.collection: ms.custom: - cx-ti - cx-ah+- msecd-doc-authoring-1018 appliesto: - Microsoft Defender XDR - Microsoft Sentinel in the Microsoft Defender portal ms.topic: reference-ms.date: 04/13/2026+ms.date: 07/27/2026+ai-usage: ai-assisted --- # Understand the advanced hunting schema@@ -59,6 +61,7 @@ The following reference lists all the tables in the schema. Each table name link | **[AlertInfo](advanced-hunting-alertinfo-table.md)** | Alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity, including severity information and threat categorization | | **[BehaviorEntities](advanced-hunting-behaviorentities-table.md)** (Preview) | Entities (file, process, device, user, and others) that are involved in a behavior in Microsoft Defender for Cloud Apps (not available for GCC) and User and Entity Behavior Analytics (UEBA) | | **[BehaviorInfo](advanced-hunting-behaviorinfo-table.md)** (Preview) | Behaviors from Microsoft Defender for Cloud Apps (not available for GCC) and User and Entity Behavior Analytics (UEBA) | +| **[CallActivityEvents](advanced-hunting-callactivityevents-table.md)** | Activities performed during Microsoft Teams calls in your organization | | **[CampaignInfo](advanced-hunting-campaigninfo-table.md)** (Preview) | Email campaigns identified by Microsoft Defender for Office 365 | | **[CloudAppEvents](advanced-hunting-cloudappevents-table.md)** | Events involving accounts and objects in Office 365 and other cloud apps and services | | **[CloudAuditEvents](advanced-hunting-cloudauditevents-table.md)** | Cloud audit events for various cloud platforms protected by the organization's Microsoft Defender for Cloud | @@ -102,8 +105,8 @@ The following reference lists all the tables in the schema. Each table name link | **[EntraIdSpnSignInEvents](advanced-hunting-entraidspnsigninevents-table.md)** | Microsoft Entra service principal and managed identity sign-ins | | **[ExposureGraphEdges](advanced-hunting-exposuregraphedges-table.md)** | Microsoft Security Exposure Management exposure graph edge information provides visibility into relationships between entities and assets in the graph | | **[ExposureGraphNodes](advanced-hunting-exposuregraphnodes-table.md)** | Microsoft Security Exposure Management exposure graph node information, about organizational entities and their properties | -| **[FileMaliciousContentInfo](advanced-hunting-emailurlinfo-table.md)** (Preview) | Files that were processed by Microsoft Defender for Office 365 in SharePoint Online, OneDrive, and Microsoft Teams. | -| **[GraphApiAuditEvents](advanced-hunting-graphapiauditevents-table.md)** | Microsoft Entra ID API requests made to Microsoft Graph API for resources in the tenant | +| **[FileMaliciousContentInfo](advanced-hunting-filemaliciouscontentinfo-table.md)** (Preview) | Files that were processed by Microsoft Defender for Office 365 in SharePoint Online, OneDrive, and Microsoft Teams. |+| **[GraphAPIAuditEvents](advanced-hunting-graphapiauditevents-table.md)** | Microsoft Entra ID API requests made to Microsoft Graph API for resources in the tenant | | **[IdentityAccountInfo](advanced-hunting-identityaccountinfo-table.md)** | Account information from various sources, including Microsoft Entra ID. This table also includes information and link to the identity that owns the account. | | **[IdentityDirectoryEvents](advanced-hunting-identitydirectoryevents-table.md)** | Events involving an on-premises domain controller running Active Directory (AD). This table covers a range of identity-related events and system events on the domain controller. | | **[IdentityEvents](advanced-hunting-identityevents-table.md)** (Preview) | Information about identity events obtained from other cloud identity service providers | 