Understanding RequestType in Microsoft 365 Unified Audit Logs
Question details
The user needs to understand the meaning and context of various RequestType values found in Microsoft 365 and Microsoft Entra ID Unified Audit Logs.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Reviewing unified audit logs for compliance, security monitoring, and authentication tracking.
- Observed behavior
- Encountering varying RequestType or EndpointCall values (such as Login, OAuth2, SAML2, MFA-related requests, and Windows authentication) that require official definition and interpretation.
Ensure you have the necessary administrative privileges (such as Global Reader, Security Reader, or Compliance Administrator) in your Microsoft 365 tenant to access and view Microsoft Entra ID Unified Audit Logs.
Consult the Microsoft Q&A Community for Entra ID
Because audit log schemas and endpoint request types are frequently updated, the most accurate interpretations of specific RequestType values are found via specialized Microsoft channels.
Microsoft continuously updates its identity platforms, which can introduce new RequestType and EndpointCall values into your audit logs. Standard documentation may not always reflect these changes immediately.
Open your web browser and go to the official Microsoft Q&A platform.
Search for the "Microsoft Entra ID" tag to ensure your query reaches the appropriate identity, access management, and audit-log experts.
Create a new question detailing the exact RequestType or EndpointCall values you are observing in your logs (e.g., specific OAuth2 or SAML2 strings) and ask for the official definitions.

Review the Microsoft Entra Audit Log Schema Documentation
Check the baseline Microsoft Entra ID documentation for common authentication request types before posting on forums.
Try WPS Office for Your Documentation and Log Analysis Needs
While resolving complex compliance logs in Microsoft 365 requires specialized Microsoft tools, you don't need expensive software to document your findings. WPS Office is a lightweight, free alternative to Microsoft Office, perfect for compiling audit reports, analyzing large CSV log exports in Spreadsheets, and sharing security protocols securely.
- 1. Download WPS Office: Visit the official WPS website and download the free installation package for your operating system.
- 2. Install the Software: Run the installer and follow the simple on-screen instructions to set up WPS Office on your computer.
- 3. Analyze Audit Logs: Open your exported Entra ID audit log CSV files using WPS Spreadsheet to easily filter and analyze RequestType data.

Frequently Asked Questions
What does RequestType mean in Microsoft 365 audit logs?
The RequestType column identifies the specific protocol or type of endpoint request made during an authentication event. Examples include standard Logins, OAuth2 token requests, SAML2 authentication, and MFA prompts.
Where can I export the Unified Audit Logs in Microsoft 365?
You can export the Unified Audit Logs from the Microsoft Purview compliance portal under the "Audit" solution, or by running PowerShell cmdlets such as Search-UnifiedAuditLog.
Why am I seeing unknown RequestType values in my Entra ID logs?
Microsoft continuously updates its identity platforms and backend endpoints. If you encounter an undocumented RequestType, it is highly recommended to ask on the Microsoft Q&A Microsoft Entra ID section for clarification from specialized identity experts.
Can I filter my audit logs by RequestType?
Yes. When analyzing exported audit logs in a spreadsheet application or querying them via PowerShell, you can filter the records by the RequestType column to isolate specific authentication protocols or endpoint calls.




