Microsoft 365 activity analytics

One user downloaded 4,000 files this week. The tenant average says +11%.

Averages hide the two things an admin needs: the account that suddenly did far more than it should, and the 10-30% of licensed users, apps and agents that have done nothing for months. 1Security ranks both ends of your tenant - by user, file, site, group, mailbox, app, AI agent and device - over windows from one hour to all-time, and turns any ranking into an alert with one click.

  • 1 h
    the shortest window, read from raw audit logs so a mass download shows while it is running
  • 8
    resource types ranked: users, files, sites, groups, emails, apps, AI agents, devices
  • 13
    action types mapped to real Microsoft 365 audit events

The problem

Averages describe the middle. Nobody was ever breached by the median user.

Averages say activity is up or down for the population. That is useless for both jobs an admin has: finding the account draining a library and finding the licenses paying for nothing.

The two facts that matter live at the edges. On one edge, a departing employee pulls a document library in an afternoon - typically a few thousand files in under an hour. On the other, in a typical tenant 10-30% of paid licenses sit on accounts that have not signed in for months, dozens of consented apps have zero users, and half of the AI agents built last year have never been used. An average cannot show either.

Latency makes it worse. Daily rollups mean the earliest a download burst can be seen is tomorrow. For an exfiltration that is an autopsy. And averages do not know the account's normal - 600 downloads means nothing until you know it usually does 12.

Activities in 1Security are the top-and-bottom rankings of the same activity data the rest of the platform uses. Sub-day windows are read from raw audit logs, so the answer arrives while the event is happening; long windows come from rollups, so the largest tenants answer instantly.

What you get

One mechanism, every classic security and cost cut.

An activity is three choices: which resource, what counts as activity, and over what window. That covers dozens of questions admins actually ask.

  • Top activity rankings

    The leaders for an action over a window: top downloaders this week, most-shared files this month, most-active agents, top AI users, busiest devices - each row with a value and a sparkline, one click into the user, file, agent or device.

  • Unused rankings

    Resources with no activity for N days, ranked by how long they have been idle: unused apps, unused agents, dormant users, quiet sites, devices nobody signs in from, files nobody has opened in a year.

  • 13 real audit actions

    Created, viewed, downloaded, modified, shared, moved, deleted, permission changed, restored, authenticated, AI used, meeting, access blocked - each mapped to actual audit events (shared = SharingSet, AnonymousLinkCreated, SecureLinkCreated), so the ranking matches what happened.

  • Windows from one hour to all-time

    1, 12 and 24 hours read raw logs for detection while it happens; 7, 30 and 90 days come from daily rollups; 1 year and all-time exist for unused rankings, where "how long idle" is the whole point.

  • A board seeded on day one

    A fresh tenant starts with the rankings that matter already on the board - top downloaders, most-active and unused agents, most-shared files, top AI users, most-active devices - then you add the cards for the questions your team asks.

  • Shared with every admin

    Mark an activity shared and it appears on every admin's board in the tenant, read-only for everyone but its owner. One person curates the numbers, the whole team reads the same list.

How deep it goes

From a ranking to a tripwire in one click.

A ranking tells you what is happening now. An alert rule on it tells you the moment it happens again.

Top-activity rules fire when an entity crosses N actions inside the window - "any user who downloads more than 1,000 files in 24 hours", or a few hundred in one hour. Unused rules fire when an entity has had no activity for N or more days - "any app idle for 90 days", "any licensed user with no sign-in for a year".

Each rule carries a severity, an evaluation cadence of hourly, daily or weekly, and optional email recipients. Hourly cadence on the one-hour window is continuous, near-real-time detection of mass download and mass share - defence while it is happening, not a post-incident report.

The rules are ordinary policies, so they land in the same alert stream as trends and anomalies, with one severity model and one place to tune the threshold. There is no separate console to watch.

In practice

The four rankings that stay on every board.

These survive contact with real tenants and tend to be the ones admins keep.

  1. 01

    Set the exfiltration tripwire

    Users, action downloaded, window 1 hour, alert threshold a few hundred, cadence hourly. A leaver or a compromised account draining a library trips it while it is still draining - typically within 20 minutes of the first download.

  2. 02

    Run the license reclaim list

    Users, unused, window 1 year - dormant accounts still holding licenses. Then the same for unused apps and unused agents. In a typical tenant this list is 10-30% of paid seats plus 30-50 apps nobody has opened.

  3. 03

    Watch the sharers

    Users, action shared, window 24 hours. These are the accounts creating the most sharing links, which is where "anyone with the link" URLs are born - and where an insider-share pattern shows first.

  4. 04

    Read AI adoption from numbers

    Top AI users over 30 days next to unused agents. Who is actually leaning on Copilot, which agents are busiest, and which were built and then abandoned - a governance review from data, not from a survey.

The difference

What ranking the extremes gives you.

Usage counts describe the population. This ranks the extremes across the tenant and lets you alert on them.

  • Trailing windows as short as one hour, read from raw audit logs instead of yesterday's rollup
  • The same top and unused rankings on all eight resource types, including AI agents and devices
  • Files counted as active when anyone views them, not only when they are modified
  • Dormancy measured in days idle, not as a yes/no flag - so you can sort by how long
  • AI usage ranked as an action, for people and for agents
  • Any ranking convertible into an alert rule with a threshold, a severity and a cadence
  • A sparkline per row, so a dormant resource that suddenly wakes up is obvious
  • Boards shared across the admin team, so everyone reads the same numbers

Scale

Short windows on very large tables.

Sub-day rankings read raw logs; the 7, 30 and 90-day windows come from daily rollups. That split is what lets a tenant with tens of millions of events per window answer instantly and still show a download burst inside the hour. Top-activity rankings on files and emails stay within 90 days because those tables reach tens of millions of rows per window; unused rankings on the same resources have no cap.

  • 1 h
    shortest window, served from raw audit logs
  • 90 days
    longest top-activity window on files and emails, from rollups
  • 500M+
    files in the largest tenants the same rankings run on

Related

Where this fits.

Activities rank the extremes. Anomalies compare each account to its own baseline, and trends follow a number over time. The three answer different questions and are usually read together.

  • Anomaly detection

    Deviation from an account's own baseline instead of a fixed threshold - 600 downloads matters when the usual is 12.

    See anomalies
  • Trend tracking

    The same numbers followed week over week, with change and deviation.

    See trends
  • License optimization

    Where the dormant-user and unused-app lists turn into reclaimed spend.

    See licenses

FAQ

Questions teams ask first.

How fast can this actually detect a mass download?

Within the hour. The one-hour window is read from raw audit logs rather than daily rollups, and an hourly alert cadence on top means the email arrives while the download is still in progress. Audit events reach us a few minutes after they happen, which is why we say near real time.

What counts as activity for a file?

Any view counts, not only a modification. For history older than your audit log retention the last modification is used as a fallback, so very old files do not look artificially dormant.

Are there limits on the longest windows?

Top-activity rankings on files and emails stay within 90 days, because those tables reach tens of millions of rows per window. Unused rankings on the same resources carry no cap - finding a file untouched for a year is the point.

Do I have to configure it before it is useful?

No. A fresh tenant starts with the classic rankings already on the board - top downloaders, most-active and unused agents, most-shared files, top AI users, most-active devices - so it is worth reading before anyone has configured anything.

Do we need a premium license or a SIEM for this?

No. Activities run on standard Microsoft 365 licenses over the read-only connection, with no agent to install. History is kept for up to three years - from 180 days to three years.

Look at the edges of your tenant.

Connect read-only and the board seeds itself with the rankings that matter the same day. The unused lists - dormant users, idle apps, abandoned agents - usually pay for the exercise on their own.

Or keep reading averages.