Exposing the secret Office 365 detailed activity logs and forensics tool
lmgsecurity.com
lmgsecurity.com
"Burden" is an understatement. Any API Microsoft documents becomes part of their ongoing commitment to eternal backward-compatibility. (Heck, even some things they never document at all still end up forced into that commitment, like the internal registry hives in Windows 95.)
So Microsoft do everything they can to only document what they're absolutely sure they have in a good, stable, "won't regret later that we didn't fix it some more before setting it in stone" state.
My guess is that it's due to one of the following:
* The API isn't considered beta yet. * This was created as somewhat of a side project and hasn't been formalized yet. * Documenting it is on the backlog. * It's meant for internal use in that they may be building in tools in the Security and Compliance center that will be calling it.
I respect that fact that CrowdStrike and others have spent the time with the api and made life a lot easier for others. As someone who has spent more time than he wanted with the Office 365 API I am a fan of people who make my life easier. That being said I am not buying the drama that these API's have been hidden.
Because your right to make money is equivalent to other people's right to remain alive.
All that video said was "the API you seek is called Activities". Am I missing the joke, or is the name of the API literally the only thing that they needed to get this working?
I'm at a loss for words, really.
As someone who relies very heavily on logs to debug issues in immature and/or fast-moving products, I would be surprised if they didn't log everything. It's sysadmin 101.
Perhaps corporations with a history of abusive tactics and legal shenanigans, would prefer to follow a different path?
<sigh>