Microsoft 365 trend tracking

12,000 externally shared files. Up or down from last quarter?

A report gives you a number for today. It cannot tell you whether it was 4,000 six weeks ago or 28,000 before the cleanup started. 1Security turns any condition over your tenant - sites with sensitive data shared with anyone, users with no sign-in for 90 days, files Copilot can reach - into a series counted live, with a sparkline on the card and an alert the moment it crosses a line.

  • 50+
    trends pre-configured on day one - exposure, dormancy, AI reach, identity hygiene
  • 9
    resource types a trend can count: users, files, sites, groups, emails, apps, agents, devices, locations
  • 2
    ways a trend can alert: a threshold you set, or a deviation from its own baseline

The problem

A snapshot tells you how things are. Not which way they are going.

The number itself is rarely the interesting part. The direction is.

12,000 externally shared files is a fact with no meaning attached. 12,000, up from 4,000 in six weeks, is a finding you take to the CISO today. 12,000, down from 28,000 since the cleanup started, is proof that the programme is working. Any single report gives you the first reading only - a snapshot of now.

Teams that want the second and third reading export the same report every month and keep the spreadsheets. In our experience that discipline survives about two quarters, and the series breaks the first time someone changes a filter, because an export is a snapshot rather than a definition. When the auditor asks how exposure moved over the year, the honest answer is usually a shrug.

A trend in 1Security fixes the definition once - "sites containing sensitive information AND shared with anyone" - and keeps counting it against the live permission graph. The series stays comparable across quarters, the direction reads off the card, and the same object can alert or remediate without being redefined.

What you get

Any condition over your tenant, counted every day and kept.

Trends run on the permission graph, so a trend can count anything the graph can express - not a fixed catalog of reports.

  • 50+ trends ready on day one

    External users downloading files, sensitive data exposure to Copilot, dormant licensed accounts, guests with no sign-in for 90 days, anyone links on sensitive files. Turn on the ones you care about; the history starts building immediately.

  • Custom trends from the same builder as automations

    Pick a resource type - users, files, sites, groups, emails, apps, agents, devices, locations - and stack conditions: "sites with sensitive information AND external users AND no activity in a year". The count is live and matches what the Sites screen shows.

  • Three readings, not one

    Every card shows the current amount, the change over the window and the deviation from what the number normally does. "1,240 anyone links, +18% this month, well above its 90-day norm" is a decision; "1,240" is a row.

  • A board per person, one tenant

    Cards grouped into categories you name, colour and reorder. The security lead keeps exposure and identity on top; compliance keeps label coverage and GDPR data types. Same numbers, two boards, no disagreement.

  • Sparkline on every card

    The shape of the last weeks is on the card itself. Reading a board of 20 trends takes seconds; a spike or a plateau is visible before you click anything.

  • Alert on the same object

    Give a trend an instant trigger and it emails when the count crosses a threshold you set, or when it deviates from its own baseline. Digests collect the rest hourly, daily or weekly. No second tool to define the number in.

How deep it goes

Why "deviation from its own baseline" beats a fixed threshold.

Thresholds are easy to set and hard to set well. Two years of headcount change turns any fixed number into noise or silence.

"Alert me above 500 external shares" is a sensible rule in a 300-person tenant and permanent noise in a 5,000-person one. Inside a single organization it ages just as badly: the number that was alarming before the merger is Tuesday afterwards. Most alert fatigue comes from thresholds someone set once and nobody revisited.

A deviation trigger learns what a trend normally does and fires when today departs from that. It survives growth, seasonality and reorganisations without anyone touching the rule. Thresholds still exist for the cases where the requirement really is absolute - a regulator asked for "zero anyone links on files with card numbers", or a policy document names a limit.

A worked example: filter Sites to "contains sensitive information" plus "shared with anyone", save it as a trend, and watch it for a quarter. In a typical mid-size tenant that series starts in the low hundreds, drops sharply in the weeks after link cleanup, then creeps up at a few sites a week as people share. The creep is the number worth alerting on - and it is invisible in any single export.

In practice

The series most teams end up keeping.

Boards drift toward the same handful of trends, in roughly this order.

  1. 01

    Track exposure first

    Externally shared files, anyone links, sites with external users, sensitive files reachable by everyone. Turn on the exposure trends on day one; within two weeks you know whether the number is rising, holding or falling - typically it is rising until someone starts watching it.

  2. 02

    Add AI reach

    Files reachable by Copilot, sites with sensitive data that Copilot indexes, agents with reach into user data. New enough that the direction matters more than the level: a flat 30,000 files is a fact, a 30,000 that doubled since the licence rollout is a decision.

  3. 03

    Add identity hygiene

    Dormant licensed accounts, guests with no sign-in for 90 days, accounts without MFA, unused paid apps. Slow-moving series where the trend is the whole signal - and where a step down is money returned to the licence pool.

  4. 04

    Pick the board number

    One trend per quarter that leadership recognises - "files with personal data reachable by anyone", "guests with access to sensitive sites" - with its history attached. The improvement is a line on a chart, not a claim in a slide.

The difference

What a monthly export cannot give you.

A report is a snapshot. A trend is a definition that keeps measuring.

  • Sharing links counted every day for a year, so you see where the number bent, not only where it stands today
  • "Licensed users with no sign-in for 90 days" kept as a series, so you know whether offboarding is keeping up
  • A condition can cross resource types - sites with sensitive info AND external users AND no owner - in one definition
  • Change and deviation are calculated for you; nobody keeps 12 monthly spreadsheets and diffs them by hand
  • Trends for devices, AI agents and sign-in locations sit on the same board as files and users
  • Per-user boards over one tenant, so security and compliance arrange the same numbers differently without either being wrong
  • A sparkline on the card, so a spike is visible without opening 20 reports
  • The same policy object can measure, alert and remediate - a trend you watched last quarter becomes an automation this one, unchanged

Design

One policy engine, three surfaces.

A trend measures, an activity ranks, an automation acts. All three are policies evaluated on the same permission graph, re-checked within minutes of the events that touch them, and rolled up daily so the largest tenants - 40 million files and more - answer instantly. That is why a trend count and the matching screen filter never disagree.

  • 9
    resource types: users, files, sites, groups, emails, apps, agents, devices, locations
  • 10 min
    typical freshness for new activity at any tenant size; touched policies re-evaluate within minutes
  • 3 years
    of history kept behind every trend on standard licensing, so last year is still on the chart

Related

Where this fits.

Trends are the measuring surface of the same engine that ranks activity and runs remediation. Most teams arrive here from one of those two, or from a report they are tired of rebuilding.

  • Activity analytics

    The extremes rather than the totals: who downloaded the most in the last hour, which app nobody has used in 90 days.

    See activities
  • Remediation automation

    The same conditions with an action attached and a 72-hour review window in front of it.

    See automations
  • Reporting

    Saved views, CSV exports and the read-only REST API for taking the numbers to auditors and the SIEM.

    See reporting

FAQ

Questions teams ask first.

What can a trend measure?

Anything the permission graph can express as a condition, across users, files, sites, groups, emails, apps, AI agents, devices and sign-in locations - "sites with sensitive info shared with anyone", "guests with no sign-in for 90 days", "files with card numbers reachable by everyone", "devices nobody signed in from for a month". Sensitivity detections, labels, sharing links, group nesting and activity are all available as conditions.

Do I have to build them myself?

No. More than 50 trends are pre-configured - exposure, dormancy, AI reach, identity hygiene, licence waste. Most teams keep five to ten of those and add two or three of their own for the questions only they would ask.

Threshold or deviation - which should I use?

Deviation for anything that scales with the organization, because a fixed number ages badly as headcount changes. Threshold when the requirement really is absolute - a regulator asked for zero, or a policy document names the limit. Both fire into the same alert stream, by email, with cooldowns so one spike is one message.

How far back does the history go?

From the day you turn a trend on, and it is kept for up to three years on standard Microsoft 365 licensing. Activity-based trends also draw on the activity history 1Security retains - up to three years - so last year is still on the chart.

How does this relate to automations?

A trend and an automation are the same policy, one without an action and one with. A number you have been watching becomes a staged fix without being redefined, and the fix reports against the series you were already tracking - so you can see the count drop after the automation runs.

Start the series today. Read the direction next month.

Connect read-only and the 50+ ready trends start counting the same day. The first useful comparison - up, down or holding - arrives within weeks, with the history kept for three years.

Or keep 12 monthly exports and diff them by hand.