Inquiry About 'File Deleted' Logs in Microsoft Defender Console

David Chung 0 평판 포인트
2026-09-18T00:53:31.3033333+00:00

Hello,

The information below is an activity log extracted through the Microsoft Defender Console. The log records deletion activity that occurred in OneDrive. For privacy reasons, the user's name has been redacted.

As shown below, there is a log entry with "File Deleted" in the Description field.

If a folder in OneDrive is deleted, would the activity also be recorded as "File Deleted" in the Microsoft Defender Console, as shown below?

If multiple files within a single folder are deleted at the same time as part of a single deletion action, would Microsoft Defender record this as one "File Deleted" log entry, or would it generate separate "File Deleted" log entries for each individual file?

Thank you for your assistance and clarification.

Best regards,

image

Microsoft 365 및 Office | OneDrive | 기업용 | Windows
댓글 0개 설명 없음

답변 1개

정렬 기준: 등록순
  1. Austin-H 8,385 평판 포인트 Microsoft 외부 직원 중재자
    2026-09-18T02:54:04.85+00:00

    Disclaimer: This thread was originally created under the Korean (ko-KR) locale, despite English being used as the primary language of the inquiry. Accordingly, the response below has been provided in English based on the language of the original question. For future inquiries, please consider posting in the forum section that corresponds to your preferred language to help ensure more efficient assistance and communication.

    Hello David Chung
    Thank you for posting question to Microsoft Q&A Forum.
    Yes, OneDrive for Business deletion activity can surface in Microsoft Defender activity views.

    Audit log activities | Microsoft Learn

    • Folder deletion: A folder is normally represented by a folder-specific operation—such as FolderRecycled when moved to the recycle bin or FolderDeleted when deleted. FileRecycled and FileDeleted apply to file/document objects. Therefore, the FileDeleted entries in the screenshot most directly indicate deleted file items; they should not, by themselves, be treated as the audit record for the parent folder.
    • Multiple-file deletion: When deletion records are generated for multiple files, the expected pattern is separate item-level events, rather than one aggregate FileDeleted event. The SharePoint/OneDrive audit schema assigns each audit record a unique ID and identifies a single object through properties such as ObjectId and SourceFileName; Microsoft’s Defender hunting content likewise evaluates deletion volume by counting individual CloudAppEvents records.

    To specially fetch information of deleted items with a folder being deleted advance hunting may required

    CloudAppEvents table in the advanced hunting schema - Microsoft Defender XDR | Microsoft Learn

    1. Open Advanced Hunting

    Go to:

    Microsoft Defender portal > Hunting > Advanced hunting

    1. Run the following query

    Replace the user, folder name, and approximate deletion time

    Please let me know if you have any further questions.


    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    이 대답이 도움이 되었나요?


답변

질문 작성자는 답변을 '승인됨'으로 표시하고, 중재자는 답변을 '추천됨'으로 표시할 수 있습니다. 이를 통해 사용자는 해당 답변이 작성자의 문제를 해결했다는 것을 알 수 있습니다.