In an effort to make the reports for Admin log events more understandable, detailed, and precise, there are updates to some event names and types as well as reporting frequency and event conditions. Between now and August 2026, legacy and updated event names and types will be available. After August 2026, only the new event names and types will be available.
Saved investigations will continue to work, but they will be based on legacy events and will stop working after August 2026. After August 2026, custom charts in the security investigation tool will be based on old data.
What you need to do
- Review the changes listed on this page. If you're using or relying on any of the events listed on this page, you might need to make changes to your existing queries, alerts, reports, and rules.
- Between now and August 2026, rules that are affected will be automatically migrated and you might need to make changes to your rules. For details on updating any migrated rules, go to View and edit your activity rules.
Important: If you don't update rules that have changes to more than one event condition, you'll get increased alerts. Rules that have 2 conditions that are true will trigger an alert even if only one condition is true. For example, if a rule triggers an alert for a change to a specific Gmail setting, you will get an alert for all Gmail setting changes.
Changes to Admin log events
Account & security
| Admin console setting | Security & Audit and investigation tool | Reports API & Google SecOps | BigQuery Export |
|---|---|---|---|
| Account settings > Preferences > New features |
Toggle New App Features event name is renamed to Toggle New App Features Preference. Value for New Value changes from True or False to Rapid release or Scheduled release. Description value changes from New app features for your organization changed to value to The account setting of "New Features" was changed from value1 to value2. The Old Value attribute is introduced. Its values are Rapid release and Scheduled release. The New Features value is added to the Setting Category attribute. |
|
|
| Security > Access and data control > Google Cloud session control > Reauthentication policy |
New Value and Old Value attributes for Session Control Settings Change records values for reauthentication frequency, idle session timeout, and reauthentication method in separate log events. Previously, all 3 settings were recorded in one log event. If any of the settings are unchanged, no log event is recorded for that setting. |
If any of the settings are unchanged, no log event is recorded for that setting. |
If any of the settings are unchanged, no log event is recorded for that setting. |
App access control
Reports API & SecOps events[].name& BigQuery Export event_name |
Security & Audit and investigation tool event name |
New events[].name & event_name |
New Security & Audit and investigation tool event name |
|---|---|---|---|
| DISALLOW_SERVICE_FOR_ OAUTH2_ACCESS |
API Access Blocked | CHANGE_API_ACCESS | API Access Changed |
| ALLOW_SERVICE_FOR_ OAUTH2_ACCESS |
API Access Allowed | CHANGE_API_ACCESS | API Access Changed |
| ADD_TO_BLOCKED_OAUTH2 _APPS |
App Added to Blocked List | CHANGE_APP_ACCESS | App Configuration Changed |
| ADD_TO_LIMITED_OAUTH2 _APPS |
App Added to Limited List | CHANGE_APP_ACCESS | App Configuration Changed |
| ADD_TO_TRUSTED_OAUTH2 _APPS |
App Added to Trusted Allowlist | CHANGE_APP_ACCESS | App Configuration Changed |
| ADD_TO_TRUSTED_BY_ OAUTH_SCOPE_OAUTH2_ APPS |
App added to Trusted by OAuth Scope list | CHANGE_APP_ACCESS | App Configuration Changed |
| ADD_TO_CAA_EXEMPT _OAUTH2_APPS |
App allowlisted for exemption from API access blocks | CHANGE_APP_ACCESS | App Configuration Changed |
| REMOVE_FROM_TRUSTED _OAUTH2_APPS |
App Removed from Trusted Allowlist | CHANGE_APP_ACCESS | App Configuration Changed |
| REMOVE_FROM_CAA_ EXEMPT_OAUTH2_APPS |
App no longer allowlisted for exemption from API access blocks | CHANGE_APP_ACCESS | App Configuration Changed |
| REMOVE_FROM_BLOCKED _OAUTH2_APPS |
App Removed from Blocked List | CHANGE_APP_ACCESS | App Configuration Changed |
| REMOVE_FROM_LIMITED _OAUTH2_APPS |
App removed from Limited list | CHANGE_APP_ACCESS | App Configuration Changed |
| REMOVE_FROM_TRUSTED _BY_OAUTH_SCOPE_ OAUTH2_APPS |
App removed from Trusted by OAuth Scope list | CHANGE_APP_ACCESS | App Configuration Changed |
| BLOCK_ALL_THIRD_PARTY _API_ACCESS |
All third party API access blocked | CHANGE_ UNCONFIGURED_APPS _ACCESS |
Unconfigured Apps Access Changed |
| UNBLOCK_ALL_THIRD_ PARTY_API_ACCESS |
All third party API access unblocked | CHANGE_ UNCONFIGURED_APPS _ACCESS |
Unconfigured Apps Access Changed |
| SIGN_IN_ONLY_THIRD_ PARTY_API_ACCESS |
Allow Google Sign-in only third party API access | CHANGE_ UNCONFIGURED_APPS _ACCESS |
Unconfigured Apps Access Changed |
| UNDERAGE_BLOCK_ALL _THIRD_PARTY_API_ ACCESS |
All third party API access blocked | CHANGE_UNDERAGE _UNCONFIGURED_APPS _ACCESS |
Under 18 Unconfigured Apps Access Changed |
| UNDERAGE_SIGN_IN_ ONLY_THIRD_PARTY_ API_ACCESS |
Allow Google Sign-in only third party API access | CHANGE_UNDERAGE _UNCONFIGURED_APPS _ACCESS |
Under 18 Unconfigured Apps Access Changed |
Google Drive settings with inherited values
Previously, Google Drive settings that were overridden from an inherited value or reverted to an inherited value used the same log event identifiers, with INHERIT_FROM_PARENT in the old value and new value attributes:
- Security & Audit and investigation tool: The Change Drive Setting event name showed INHERIT_FROM_PARENT in Old value and New value
- Reports API & SecOps:
events[].type=DOCS_SETTINGS,events[].name=CHANGE_DOCS_SETTINGshowed INHERIT_FROM_PARENT inadmin.old_valueandadmin.new_value - BigQuery Export:
events_type=DOCS_SETTINGS,event_name=CHANGE_DOCS_SETTINGshowed INHERIT_FROM_PARENT inadmin.old_valueandadmin.new_value
| Tool | Override an inherited value | Change an existing value | Revert to an inherited value |
| Security & Audit and investigation tool | Event name: Create Application Setting |
Event name: Change Application Setting |
Event name: Delete Application Setting |
| Reports API & SecOps | Event type: APPLICATION_SETTINGS Event name: CREATE_APPLICATION_ SETTING |
Event type: APPLICATION_SETTINGS Event name: CHANGE_APPLICATION_ SETTING |
Event type: APPLICATION_SETTINGS Event name: DELETE_APPLICATION_ SETTING |
| BigQuery Export | Event type: APPLICATION_SETTINGS Event name: CREATE_APPLICATION_ SETTING |
Event type: APPLICATION_SETTINGS Event name: CHANGE_APPLICATION_ SETTING |
Event type: APPLICATION_SETTINGS Event name: DELETE_APPLICATION_ SETTING |
Drive settings
The following table lists updated log event information for the following Admin log event attributes and values:
- Security & Audit and investigation tool: Setting name, Old value, New value
- BigQuery Export:
admin.setting_name,admin.old_value,admin.new_value - Reports API & SecOps:
events[].parameters[].name=setting_name,events[].parameters[].name=OLD_VALUEorNEW_VALUE
|
Old event |
Updated event |
||
|
Setting name |
Old or new value |
Setting name |
Old or new value |
|
SHARING_OUTSIDE_ DOMAIN |
SHARING_NOT_ ALLOWED_BUT_MAY _RECEIVE_FILES |
ExternalSharing external_sharing_mode |
DISALLOWED |
|
ExternalSharing allow_receiving_external _files |
true |
||
|
SHARING_NOT_ ALLOWED |
ExternalSharing external_sharing_mode |
DISALLOWED |
|
|
ExternalSharing allow_receiving_external _files |
false |
||
|
TRUSTED_DOMAINS_ ALLOWED_WITH_ WARNING_MAY_ RECEIVE _FILES_ FROM_ ANYONE |
ExternalSharing external_sharing_mode |
ALLOWLISTED_ DOMAINS |
|
|
ExternalSharing warn_for_sharing_ outside_allowlisted_ domains |
true |
||
|
ExternalSharing allow_receiving_files_ outside_allowlisted_ domains changed |
true |
||
|
TRUSTED_DOMAINS_ ALLOWED_WITH_ WARNING |
ExternalSharing external_sharing_mode |
ALLOWLISTED_ DOMAINS |
|
|
ExternalSharing warn_for _sharing_outside_ allowlisted_domains |
true |
||
|
ExternalSharing allow_ receiving_files_outside_ allowlisted_domains changed |
false |
||
|
TRUSTED_DOMAINS_ ALLOWED_AND_MAY_ RECEIVE_FILES_FROM _ANYONE |
ExternalSharing external_sharing_mode |
ALLOWLISTED_ DOMAINS |
|
|
ExternalSharing warn_ for_sharing_outside_ allowlisted_domains |
false |
||
|
ExternalSharing allow_ receiving_files_outside_ allowlisted_domains changed |
true |
||
|
TRUSTED_DOMAINS_ ALLOWED |
ExternalSharing external_sharing_mode |
ALLOWLISTED_ DOMAINS |
|
|
ExternalSharing warn_for_sharing _outside_allowlisted_ domains |
false |
||
|
ExternalSharing allow_receiving_files _outside_allowlisted_ domains changed |
false |
||
|
SHARING_ALLOWED_ WITH_WARNING |
ExternalSharing external_sharing_mode |
ALLOWED |
|
|
ExternalSharing warn_for_external_ sharing |
true |
||
|
SHARING_ALLOWED |
ExternalSharing external_sharing_mode |
ALLOWED |
|
|
ExternalSharing warn_for_external_ sharing |
false |
||
|
SHARING_INVITES_TO_ NON_GOOGLE_ ACCOUNTS |
NOT_ALLOWED |
ExternalSharing allow_non_google_ invites |
false |
|
ANONYMOUS_ PREVIEW |
ExternalSharing allow_non_google_ invites |
true |
|
|
PUBLISHING_TO_WEB |
NOT_ALLOWED |
ExternalSharing allow_publishing_files |
false |
|
ALLOWED |
true |
||
|
SHARING_ACCESS_ CHECKER_OPTIONS |
NAMED_PARTIES_ ONLY |
ExternalSharing access_checker_ suggestions |
RECIPIENTS_ONLY |
|
DOMAIN_OR_NAMED _PARTIES |
RECIPIENTS_OR_ AUDIENCE |
||
|
ALL |
RECIPIENTS_OR_ AUDIENCE_OR_ PUBLIC |
||
|
SHARING_TEAM_DRIVE _CROSS_DOMAIN_ OPTIONS |
CROSS_DOMAIN_ FROM_INTERNAL_OR _EXTERNAL |
ExternalSharing allowed_parties _for_distributing_ content |
ALL_ELIGIBLE_ USERS |
|
CROSS_DOMAIN_ FROM_INTERNAL_ ONLY |
ELIGIBLE_INTERNAL _USERS |
||
|
CROSS_DOMAIN_ MOVES_BLOCKED |
NONE |
||
|
DEFAULT_LINK_ SHARING_FOR_NEW _DOCS |
PRIVATE |
GeneralAccessDefault default_file_access |
PRIVATE_TO_OWNER |
|
PEOPLE_WITH_LINK |
PRIMARY_ AUDIENCE_WITH_ LINK |
||
|
PUBLIC |
PRIMARY_ AUDIENCE_WITH_ LINK_OR _SEARCH |
||
|
DOCS_OFFLINE_ ENABLED |
false |
DocsOffline enable_docs_offline |
false |
|
true |
true |
||
|
ENABLE_DRIVE_APPS |
false |
DriveSdk enable_drive_sdk_api _access |
false |
|
true |
true |
||
Gmail settings
For all affected settings in Reports API & SecOps:
events[].typeEMAIL_SETTINGS is renamed to APPLICATION_SETTINGSevents[].parameters[].name=USER_DEFINED_SETTING_NAME is moved toevents[].parameters[].name=SETTING_METADATA.USER_DEFINED_NAME
For all affected settings in BigQuery Export:
event_typeEMAIL_SETTINGS is renamed to APPLICATION_SETTINGS- admin.user_defined_setting_name is moved to admin.setting_metadata.user_defined_name
|
Gmail setting |
Security & Audit and investigation tool |
Reports API & SecOps | BigQuery Export |
|---|---|---|---|
|
Mail delegation |
Change Email Setting is renamed to Change Application Setting ENABLE_SENDER_ ATTRIBUTION is renamed to MailDelegation sender_attribution_ desired |
|
|
|
Image URL proxy allowlist |
Change Email Setting is renamed to Change Application Setting NUMBER_OF_EMAIL _IMAGE_URL_ WHITELIST _PATTERNS is renamed to MailImage Proxy external _image_bypass_ pattern |
|
|
|
Compliance > Restrict delivery |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting RESTRICT_DELIVERY is renamed to RestrictDelivery rules walled_garden_info or RuleState rule_state enabled |
|
|
|
Compliance > Comprehensive mail storage |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting COMPREHENSIVE_ MAIL _STORAGE is renamed to RuleState rule_state enabled |
|
|
|
Spam, phishing, and malware > Inbound gateway |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting INBOUND_GATEWAY is renamed to RuleState rule_state enabled or InboundGateway {field} |
|
|
|
Routing > Email forwarding using recipient address map |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting ALIAS_TABLE is renamed to AliasTable rules alias_table_info or RuleState rule_state enabled |
|
|
|
Compliance > Content compliance |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting CONTENT_ COMPLIANCE is renamed to ContentCompliance rules content _compliance _info or RuleState rule_state enabled |
|
admin.setting_nameCONTENT_ COMPLIANCE is renamed to ContentCompliance rules content_compliance _info or RuleState rule_state enabled |
|
Default Routing > Default Routing |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting DOMAIN_DEFAULT is renamed to DomainDefault rules domain_default_info or RuleState rule_state enabled |
|
|
|
Routing > Routing |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting UNIFIED_MAIL_ ROUTING is renamed to Routing rules routing_info or RuleState rule_state enabled |
|
|
|
Routing > Inbound email journal acceptance in Vault |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting INBOUND_EMAIL_ JOURNAL_ ACCEPTANCE is renamed to RuleState rule_state enabled or ExchangeJournal Ingestion {field} |
|
|
|
Blocked senders |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting BLOCKED_SENDERS is renamed to BlockedSenders rules blocked_senders_info or RuleState rule_state enabled |
|
|
|
Routing > Third-party email archiving |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting OUTBOUND_EMAIL_ JOURNAL_ GENERATION is renamed to ExchangeJournal Generation rules exchange_journal_ generation _info or RuleState rule_state enabled |
|
|
|
Routing > Non-Gmail mailbox |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting QUARANTINE_ SUMMARY is renamed to NonGmail Mailbox rules quarantine _summary _info or RuleState rule_state enabled |
|
|
|
Routing > SMTP relay service |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting OUTBOUND_RELAY is renamed to RuleState rule_state enabled |
|
|
|
Spam, phishing, and malware > Security sandbox rules |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting SECURITY_SANDBOX_ RULE is renamed to DeepScanning rules deep_scanning_info or RuleState rule_state enabled |
|
|
|
Compliance > Secure transport (TLS) compliance |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting TLS_COMPLIANCE is renamed to TlsCompliance rules tls_compliance_info or RuleState rule_state enabled |
|
|
|
Spam, phishing, and malware > Spam |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting SPAM_CONTROL is renamed to SpamOverride rules spam_override_info or RuleState rule_state enabled |
|
|
|
Compliance > Objectable content |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting OBJECTIONABLE_ CONTENT is renamed to Objectionable Content rules objectionable_content _info or RuleState rule_state enabled |
|
|
|
Routing > Alternate secure route |
Change/Delete/Create Gmail Setting is renamed to Change/Delete/Create Application Setting ALTERNATE_SECURE _ROUTE is renamed to AlternateSecureRoute alternate_route_id or RuleState rule_state enabled |
|
|