A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Hello MrBee,
Your suspicion is good, not everyone has this!
For some services, the ClientIP in the audit log is the IP of a trusted Microsoft application for example Office on the web, calling the service on the user's behalf not the user's device. You can read it here:
For some services, the value displayed in this property might be the IP address for a trusted application (for example, Office on the web apps) calling into the service on behalf of a user and not the IP address of the device used by person who performed the activity.
To answer your subnet question, look the IP up in Microsoft's current Azure IP Ranges and Service Tags file which you can download here the file gets updated weekly. If it's in there, Microsoft uses it today and the Miami record you found is outdated.
Can you tell me which OfficeWorkload the event shows?
Best Regards
Alex