Louie Mayor I realize this is not SLA help forums, but perhaps you can suggest where I can read more about enabling each specific type of schemas? In this test tenant MTP is enabled (under https://security.microsoft.com/settings/mtp_settings/mtp_consent + sign-in for previews is on) and all other E5 features are switched on and configured including MCAS but we are missing some tables. Note: Azure ATP with on-prem agents not used - because this is Azure only tenant with no on-prem AD. Does IdentityLogonEvents source events from Azure ATP or Azure AD?
Present: DeviceEvents
Missing: EmailEvents and IdentityLogonEvents.
Should I ask this question to MDATP support? I failed to find any details on troubleshooting issues with not getting EmailEvents and IdentityLogonEvents with my google-foo...
Assuming integration is triggered, should the new schema/table exist even where there is not a single event yet arrived, or is it only created on first event arrival? Perhaps I can put my questions as documentation feedback under https://docs.microsoft.com/en-us/microsoft-365/security/mtp/mtp-enable-faq