Backup Data Browsed

Sent when a user browses backed-up data.

General Information

Event ID: vdc.workload_v0.tenant_v0.audit_v0.microsoft.browse_v0

Event message details: Sent with data.audit.action set to Backup Data Browsed.

Severity: Info

Workloads: Veeam Data Cloud for Microsoft 365

Parameters

Parameters

Parameter Name

Description

Example

specversion

Event schema version.

20250815

source

System that sent the event. Possible values: CONTROLPLANE, M365.

M365

timestamp

Time when the event happened, in RFC3339Nano format and the UTC time zone.

2026-08-04T09:18:42Z

type

Event ID.

vdc.workload_v0.tenant_v0.audit_v0.microsoft.browse_v0

actor.kind

Actor type that triggered the event. Possible values: user, system, service_account.

user

actor.identifier

Actor identifier.

alice@example.com

organizationReference.workloadTenantId

Workload tenant ID.

tenant_12345

data.audit.action

Action that represents the event.

Backup Data Browsed

data.audit.actionGroup

High-level classification of the action category. Possible values: DATA_ACCESS, ACCESS_MANAGEMENT, DATA_MANAGEMENT, PROTECTION_MANAGEMENT.

DATA_ACCESS

data.audit.targetDisplayName

Display name of the target of this event. If the target is unknown or not applicable, the value is Unknown or N/A.

Inbox

data.browse.application

Microsoft 365 application that was browsed. Possible values: OUTLOOK, SHAREPOINT, ONEDRIVE, TEAMS.

OUTLOOK

data.browse.outlook

Label for the Outlook (mailbox) data that was browsed. Populated only when data.browse.application is OUTLOOK.

(browse items) Inbox / Subfolder

data.browse.sharePoint

Label for the SharePoint data that was browsed. Populated only when data.browse.application is SHAREPOINT.

(browse sites) Marketing / Documents

data.browse.oneDrive

Label for the OneDrive data that was browsed. Populated only when data.browse.application is ONEDRIVE.

(browse files) alice@contoso.com / Documents

data.browse.teams

Label for the Microsoft Teams data that was browsed. Populated only when data.browse.application is TEAMS.

(browse channels) Engineering / General

data.tenant.id

Tenant ID.

tenant_12345

data.workload.type

Workload type.

M365

Event Example

{
  "specversion": "20250815",
  "source": "M365",
  "timestamp": "2026-08-04T09:18:42Z",
  "type": "vdc.workload_v0.tenant_v0.audit_v0.microsoft.browse_v0",
  "actor": {
    "identifier": "alice@example.com",
    "kind": "user"
  },
  "organizationReference": {
    "workloadTenantId": "tenant_12345"
  },
  "data": {
    "audit": {
      "action": "Backup Data Browsed",
      "actionGroup": "DATA_ACCESS",
      "targetDisplayName": "Inbox"
    },
    "browse": {
      "application": "OUTLOOK",
      "outlook": {
        "key": "browse.outlook",
        "value": "(browse items) Inbox / Subfolder"
      }
    },
    "tenant": {
      "id": "tenant_12345"
    },
    "workload": {
      "type": "M365"
    }
  }
}