Forum Discussion
Acessos pastas SharePoint / SharePoint folder access
Use Microsoft Purview Audit to investigate the files in that SharePoint folder, but treat this as file activity rather than a definitive “folder opened” report. Search the incident window for FileAccessed and FileDownloaded, then filter or export by SiteUrl, SourceRelativeUrl, SourceFileName, and ObjectId. Preserve UserId, ClientIP, UserAgent, ApplicationDisplayName, and EventData for correlation.
The value app@sharepoint is not a normal employee account. Microsoft documents it as an application presenting SharePoint App-Only authentication, sometimes for Microsoft 365 or compliance services acting on behalf of a user, administrator, or service. That field alone therefore cannot identify the person who caused the action. Check ApplicationDisplayName and EventData, then compare nearby audit events, Entra sign-ins, sharing events, and app permissions.
Because this concerns leaked information, preserve exported audit data before changing access, restrict affected sharing, and involve your security and legal response process. Avoid attributing a download until the records correlate.