Microsoft Exchange Online: Introducing ActorInfoString in Exchange Online audit logs
Microsoft Exchange Online is introducing the ActorInfoString field in audit logs to improve accuracy and visibility. Rolling out in late May 2025, this field records the true user agent for each audited event, enhancing security, compliance, and investigation capabilities. No action is required before rollout. Existing audit data remains unchanged. Coming soon: ActorInfoString, a new audit log field in Microsoft Exchange Online (EXO) designed to improve the accuracy, clarity, and depth of your audit logs. ActorInfoString records the true user agent responsible for each audited event, giving security and compliance teams increased visibility into actions performed in your Exchange Online environment. This update builds on the existing audit schema by capturing more granular information about clients, devices, and applications involved in audited operations. When this will happen: General Availability (Worldwide, GCC, GCC High, DoD): We will begin rolling out late May 2025 and expect to complete by late May 2025. How this will affect your organization: Once enabled, ActorInfoString will appear as a new field in your Exchange Online audit logs, alongside existing fields such as ClientInfoString. This addition provides an unambiguous record of which client, device, or application performed a given operation, supporting better investigation of incidents, improved detection of suspicious activity, and strengthened compliance reporting. Existing audit schema fields, records, and integrations will remain unchanged, ensuring a seamless transition without service impact or data loss. After this rollout, change administrators will see these key improvements: Clarity: Easily reveal the true user agent behind every action in your logs. Better security: Accelerate investigation and threat detection by tracing the actual source of actions. Compliance: Enhance your audit trails to more effectively meet regulatory standards. Future-readiness: Prepare your monitoring and log analysis for evolving audit needs. Use these instructions to find the new field: Log into the Exchange Online admin center. Go to the Security & Compliance section. Select Audit logs from the menu. In the Audit logs section, look for the ActorInfoString field under the detailed log entries. Example of how ActorInfoString should appear for admins: ee33-4930-9efd-2b7f2c8183b7","RecordType" : 50, “Resultstatus" : "Succeeded","UserKey":"1c6b6 ActorInfoString" : “Client-REST ;Client-RESTSystem;UserAgent-NoUserAgent Appld-1c6b689d-1 What you […]
The post Microsoft Exchange Online: Introducing ActorInfoString in Exchange Online audit logs appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Exchange Online: Introducing ActorInfoString in Exchange Online audit logs
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Cross-post SharePoint News to Engage
SharePoint News can now be cross-posted to Viva Engage communities with full fidelity and synchronized conversations across platforms. Rolling...
Call Quality Dashboard Custom Detailed Reports
Call Quality Dashboard will get a refreshed interface with enhanced accessibility and features like dark mode. Public preview starts mid-Augus...
Microsoft Copilot Pages: Access existing Pages from the “/” menu in chat
Starting late August 2026, users can access existing Pages via the “/” menu in Copilot chat, while the “Edit in Pages”...
Microsoft Teams: Collect information with List Form in Workflows
Microsoft Teams Workflows will add a new trigger, “A form is submitted,” for automating actions based on SharePoint list–backed fo...
Microsoft Viva Engage: Reducing reply notification volume in email
Microsoft Viva Engage will reduce email reply notifications by only sending alerts for direct replies, @mentions, and new posts, cutting down ...
Microsoft Teams: Lobby visibility will align with the “Who can admit from lobby” meeting option
Microsoft Teams will align lobby visibility with the “Who can admit from lobby” setting, so only users allowed to admit participan...
Microsoft Word: Similarity Checker retirement
Microsoft Word’s Similarity Checker will be retired on October 3, 2026, and removed from Microsoft Editor. Other writing and editing fea...
Microsoft Secure Score: New AI-readiness recommendations for device security
Microsoft Secure Score will add four new AI-readiness recommendations for device security in Microsoft Defender for Endpoint, focusing on TPM ...
Dynamics 365 Contact Center- Use data masking to protect customer data
We are announcing the ability to use data masking to protect customer data in Dynamics 365 Contact Center. This feature will reach general ava...
Microsoft Teams: QR code protection in Teams messaging
Microsoft Teams will provide additional protection for QR codes shared by external users in messages. Images containing QR codes from external...