logo
search
Compliance Problems

Understanding RequestType in Microsoft 365 Unified Audit Logs

Amos GikundaAmos Gikunda Oct 1, 2026 868 views

Question details

The user needs to understand the meaning and context of various RequestType values found in Microsoft 365 and Microsoft Entra ID Unified Audit Logs.

Understanding RequestType in Microsoft 365 Unified Audit Logs
Product
Microsoft 365
Device & OS
not provided
Scenario
Reviewing unified audit logs for compliance, security monitoring, and authentication tracking.
Observed behavior
Encountering varying RequestType or EndpointCall values (such as Login, OAuth2, SAML2, MFA-related requests, and Windows authentication) that require official definition and interpretation.
Before you start

Ensure you have the necessary administrative privileges (such as Global Reader, Security Reader, or Compliance Administrator) in your Microsoft 365 tenant to access and view Microsoft Entra ID Unified Audit Logs.

Solution 1Recommended

Consult the Microsoft Q&A Community for Entra ID

Because audit log schemas and endpoint request types are frequently updated, the most accurate interpretations of specific RequestType values are found via specialized Microsoft channels.

Microsoft continuously updates its identity platforms, which can introduce new RequestType and EndpointCall values into your audit logs. Standard documentation may not always reflect these changes immediately.

1
Navigate to Microsoft Q&A

Open your web browser and go to the official Microsoft Q&A platform.

2
Locate the Entra ID section

Search for the "Microsoft Entra ID" tag to ensure your query reaches the appropriate identity, access management, and audit-log experts.

3
Post your specific RequestType

Create a new question detailing the exact RequestType or EndpointCall values you are observing in your logs (e.g., specific OAuth2 or SAML2 strings) and ask for the official definitions.

Consult the Microsoft Q&A Community for Entra ID
Expert Assistance: Specialized identity experts on the platform can clarify undocumented values and provide links to the most current documentation regarding authentication endpoints.
Free Microsoft Office alternative

Try WPS Office for Your Documentation and Log Analysis Needs

While resolving complex compliance logs in Microsoft 365 requires specialized Microsoft tools, you don't need expensive software to document your findings. WPS Office is a lightweight, free alternative to Microsoft Office, perfect for compiling audit reports, analyzing large CSV log exports in Spreadsheets, and sharing security protocols securely.

  1. 1. Download WPS Office: Visit the official WPS website and download the free installation package for your operating system.
  2. 2. Install the Software: Run the installer and follow the simple on-screen instructions to set up WPS Office on your computer.
  3. 3. Analyze Audit Logs: Open your exported Entra ID audit log CSV files using WPS Spreadsheet to easily filter and analyze RequestType data.
Highly compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Open and analyze large audit log CSV exports quickly in WPS Spreadsheet.Lightweight installation and familiar user interface for seamless migration.Built-in PDF toolkit for securing, signing, and sharing compliance reports.
microsoft office alternative - wps office

Frequently Asked Questions

What does RequestType mean in Microsoft 365 audit logs?

The RequestType column identifies the specific protocol or type of endpoint request made during an authentication event. Examples include standard Logins, OAuth2 token requests, SAML2 authentication, and MFA prompts.

Where can I export the Unified Audit Logs in Microsoft 365?

You can export the Unified Audit Logs from the Microsoft Purview compliance portal under the "Audit" solution, or by running PowerShell cmdlets such as Search-UnifiedAuditLog.

Why am I seeing unknown RequestType values in my Entra ID logs?

Microsoft continuously updates its identity platforms and backend endpoints. If you encounter an undocumented RequestType, it is highly recommended to ask on the Microsoft Q&A Microsoft Entra ID section for clarification from specialized identity experts.

Can I filter my audit logs by RequestType?

Yes. When analyzing exported audit logs in a spreadsheet application or querying them via PowerShell, you can filter the records by the RequestType column to isolate specific authentication protocols or endpoint calls.