diff --git a/office-365-management-api/office-365-management-activity-api-schema.md b/office-365-management-api/office-365-management-activity-api-schema.md index 2796382..ae0627e 100644 --- a/office-365-management-api/office-365-management-activity-api-schema.md +++ b/office-365-management-api/office-365-management-activity-api-schema.md @@ -1432,7 +1432,7 @@ The UserId and UserKey of these events are always SecurityComplianceAlerts. Ther ## Microsoft Defender for Office 365 and Threat Investigation and Response schema -[Microsoft Defender for Office 365](/defender-office-365/mdo-about) events are available for Microsoft 365 customers who have Defender for Office 365, ether included or as an add-on subscription. For example, Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, and Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2. +[Microsoft Defender for Office 365](/defender-office-365/mdo-about) events are available for Microsoft 365 customers who have Defender for Office 365, either included or as an add-on subscription. For example, Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, and Microsoft 365 A5/E5/G5 includes Defender for Office 365 Plan 2. [Threat Investigation and Response](/defender-office-365/office-365-ti) events are available only to customers with Defender for Office 365 Plan 2. @@ -3149,3 +3149,4 @@ The DataScanClassification audit schema is designed to capture and log activitie +