Backup Policy Started or Stopped

Sent when a backup policy execution starts or is stopped before it completes.

General Information

Event ID: vdc.workload_v0.tenant_v0.audit_v0.microsoft.backup.execution_v0

Event message details: Sent with data.audit.action set to Backup Policy Started or Backup Policy Stopped.

Severity: Varies depending on data.audit.action.

General Information

data.audit.action

Severity

Backup Policy Started

Info

Backup Policy Stopped

Low

Workloads: Veeam Data Cloud for Microsoft 365

Parameters

The parameter set is the same for every source that sends this event.

Parameters

Parameter Name

Description

Example

specversion

Event schema version.

20250815

source

System that sent the event. Possible values: CONTROLPLANE, M365.

M365

timestamp

Time when the event happened, in RFC3339Nano format and the UTC time zone.

2026-08-04T09:18:42Z

type

Event ID.

vdc.workload_v0.tenant_v0.audit_v0.microsoft.backup.execution_v0

actor.kind

Actor type that triggered the event. Possible values: user, system, service_account.

system

organizationReference.workloadTenantId

Workload tenant ID.

tenant_12345

data.audit.action

Action that represents the event.

Backup Policy Started

data.audit.actionGroup

High-level classification of the action category. Possible values: DATA_ACCESS, ACCESS_MANAGEMENT, DATA_MANAGEMENT, PROTECTION_MANAGEMENT.

PROTECTION_MANAGEMENT

data.audit.targetDisplayName

Display name of the target of this event. If the target is unknown or not applicable, the value is Unknown or N/A.

Daily Logs Backup

data.execution.policyId

Backup policy ID.

f67d6448-6e96-47e5-8924-8141d6e9d5a7

data.execution.policyName

Backup policy name. Duplicates targetDisplayName.

Daily Logs Backup

data.execution.policyType

Policy type.

Express - Exchange Online

data.execution.backupType

Scope of data the policy covers. Possible values: Entire Organization, Selected Items.

Entire Organization

data.tenant.id

Tenant ID.

tenant_12345

data.workload.type

Workload type.

M365

Event Example

Backup Policy Started

{
  "specversion": "20250815",
  "source": "M365",
  "timestamp": "2026-08-04T09:18:42Z",
  "type": "vdc.workload_v0.tenant_v0.audit_v0.microsoft.backup.execution_v0",
  "actor": {
    "kind": "system"
  },
  "organizationReference": {
    "workloadTenantId": "tenant_12345"
  },
  "data": {
    "audit": {
      "action": "Backup Policy Started",
      "actionGroup": "PROTECTION_MANAGEMENT",
      "targetDisplayName": "Daily Logs Backup"
    },
    "execution": {
      "policyId": "f67d6448-6e96-47e5-8924-8141d6e9d5a7",
      "policyName": "Daily Logs Backup",
      "policyType": "Express - Exchange Online",
      "backupType": "Entire Organization"
    },
    "tenant": {
      "id": "tenant_12345"
    },
    "workload": {
      "type": "M365"
    }
  }
}

Backup Policy Stopped

{
  "specversion": "20250815",
  "source": "M365",
  "timestamp": "2026-08-04T09:18:42Z",
  "type": "vdc.workload_v0.tenant_v0.audit_v0.microsoft.backup.execution_v0",
  "actor": {
    "kind": "system"
  },
  "organizationReference": {
    "workloadTenantId": "tenant_12345"
  },
  "data": {
    "audit": {
      "action": "Backup Policy Stopped",
      "actionGroup": "PROTECTION_MANAGEMENT",
      "targetDisplayName": "Daily Logs Backup"
    },
    "execution": {
      "policyId": "f67d6448-6e96-47e5-8924-8141d6e9d5a7",
      "policyName": "Daily Logs Backup",
      "policyType": "Express - Exchange Online",
      "backupType": "Entire Organization"
    },
    "tenant": {
      "id": "tenant_12345"
    },
    "workload": {
      "type": "M365"
    }
  }
}