logo
search
Others

What Is a GATFR Token in Microsoft 365 Audit Logs? Explained

WPS EditorWPS Editor Sep 28, 2026 868 views

Question details

The user needs to understand the meaning of the 'Issued GATFR token' entry in the Microsoft 365 unified audit log and whether it indicates administrator activity.

What Is a GATFR Token in Microsoft 365 Audit Logs?
Product
Microsoft 365
Device & OS
not provided
Scenario
Reviewing unified audit logs in Microsoft 365 and encountering unfamiliar GATFRTokenIssue entries.
Observed behavior
An audit log entry titled 'Issued GATFR token' or 'GATFRTokenIssue' is generated during standard Exchange operations.
Before you start

Ensure you have the necessary compliance or security administrator privileges in your Microsoft 365 tenant to access and view the unified audit logs.

Solution 1Recommended

Analyze and Interpret the GATFRTokenIssue Log Entry

Use this information to understand the source of the GATFR token entry and verify the user type associated with the internal Exchange operation.

GATFR stands for 'Get Access Token For Resource.' It is not a distinct security token type but an internal Exchange or Outlook Web Access (OWA) procedure.

This procedure is typically called to obtain an access token for another resource, such as Microsoft Graph. A common scenario that triggers this log is when a user attaches a OneDrive or SharePoint file to an email.

1
Locate the operation in the audit log

Search your unified audit log for the operation named 'GATFRTokenIssue'. This specific operation uses record type 275.

2
Identify the workload source

Verify the workload field in the log details. You will see it is categorized under the Exchange workload, indicating it is an internal system call.

3
Check the UserType value

Review the 'UserType' parameter within the audit record. A UserType value of 0 indicates that the action was performed as the standard user (e.g., the user attaching a file), not by an administrator.

Analyze and Interpret the GATFRTokenIssue Log Entry
Normal System Behavior: The GATFRTokenIssue operation generally represents standard internal Exchange communication and does not indicate unauthorized administrative activity.
Free Microsoft Office alternative

Looking for a Simpler Office Solution? Try WPS Office

While Microsoft 365 involves complex enterprise logging and backend token management, individual users and small teams often just need a reliable, hassle-free document editor. WPS Office provides a lightweight, free alternative to Microsoft Office without the steep learning curve or enterprise administrative overhead.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button.
  2. 2. Install WPS Office: Run the downloaded setup file and follow the quick installation prompts.
  3. 3. Open Your Files: Launch WPS Office and instantly open your existing Microsoft Office documents without formatting loss.
Fully compatible with Microsoft Word, Excel, and PowerPoint file formats.Lightweight application that requires minimal system resources.Free to download with a familiar, easy-to-navigate user interface.Seamless offline document editing without complex cloud token syncing issues.
QA img-9

Frequently Asked Questions

What does GATFR stand for in Microsoft Exchange?

GATFR stands for 'Get Access Token For Resource.' It is a background procedure used by Microsoft Exchange and Outlook Web Access to securely request access to external resources like Microsoft Graph.

Does a GATFRTokenIssue log mean an administrator accessed my account?

No. The GATFRTokenIssue operation is an internal Exchange call. If the log displays a UserType value of 0, it confirms the operation was triggered by the normal user's actions, not an administrator.

What user actions trigger a GATFR token issuance?

A very common user action that triggers this token issuance is attaching a cloud file (like a document stored in OneDrive or SharePoint) to an email while using Outlook Web Access.