Warning The following list shows the default configuration and is subject to the configuration set by the solution’s deployer, and must be updated accordingly by the deployer.
| information | example of reporting | treatment | reason | scope |
|---|---|---|---|---|
| END-USER | — | — | — | — |
| endpoint username | j.smith | stored | control efficacy, incident response | |
| browser profile username | j.smith@company.com | stored | control efficacy, incident response | |
| USAGE | — | — | — | — |
| web application use | 'teams.microsoft.com' received 14 interactions on 2025-09-18 | stored | control efficacy, situational awareness | only websites with authentication are tracked |
| application usernames | password for account 'j.smith@company.com' of 'login.microsoftonline.com' has 2 issues | stored | control efficacy, situational awareness | only accounts of protected applications are tracked |
| application passwords | N/A | processed | control efficacy, situational awareness | only hash and quality metadata is stored, only locally, and only of protected accounts |
| metadata about downloading | completed download of 'https://drive.com/SDjchTVAfbjAQXPxoY' to '/Users/j.smith/Downloads/budget 2025.docx' | stored | situational awareness, incident response | includes url, file size, path and type |
| metadata about uploading / printing | user selected file "Business case feedback.png" | stored | situational awareness, incident response | includes file size, path and mtime |
| security events | browser error net::ERR_CERT_DATE_INVALID [WARN] for navigate to https://login.application.com/login | stored | incident detection, situational awareness, incident response | |
| web navigations | navigation to https://a7436388/b24b8947?f23b6e6b | stored (locally) | incident response | heavily hashed, only stored on endpoint |
| web requests | N/A | processed | all | used for MFA- and blacklist detection |
| ENDPOINT | — | — | — | — |
| IP address | 185.34.22.17 | stored | situational awareness | |
| installed extensions | installed extension 'laankejkbhbdhmipfmgcngd' (Grammarly) with risk 4.9 | stored | incident detection, situational awareness, incident response | |
| compliance status | control ForbiddenApplications = PASSING | stored | control efficacy, incident response | |
| security configuration | N/A | processed | control efficacy | only control state is stored (see above) |
| installed & running applications | N/A | processed | control efficacy | only control state is stored (see above) |
| stored documents | N/A | processed | control efficacy | only control state is stored (see above) |
| camera | N/A | N/A | N/A | |
| microphone | N/A | N/A | N/A | |
| Do Not Disturb status | N/A | processed | N/A | |
| Contents of clipboard and selected / dropped files | found AWS API key during clipboard-paste | processed | control efficacy, incident detection, situational awareness | only type of secret is logged, the actual secret is never stored |