Microsoft 365 unified audit log

Your unified audit log, three years deep, one search box.

The unified audit log is the right source for "who did what, when, from where, and on which device". 1Security keeps it up to three years on standard licenses, in one searchable timeline with the action in plain language and country, city and device on every row - so a question about last year is a filter, not a project.

  • 3 years
    of retained activity on a standard license - from 180 days to three years
  • 0
    scripts or exports needed to answer a question - filter, read, save the view
  • 5
    attributions on every row: user, resource, app, device, location

The problem

The trail expires before the question arrives.

Incidents surface months after the event. Default audit retention does not last that long, and what does survive is hard to read.

Incidents surface months after the event, and standard audit retention runs 180 days. An investigation that opens in March about something that happened in August needs a longer memory - 1Security extends yours to three years on the license you already have.

Retention is only half of it. Raw audit rows are operation names split across SharePoint, Exchange, Entra and Teams, and the two attributes an investigator reaches for first - where the action came from and which device it came from - have to be joined in from elsewhere. Rebuilding that by hand for every question is why most questions never get asked.

1Security keeps the trail up to three years, attributes every event, and puts action, user, resource, app, device and location on the same row - with the raw Microsoft record one click away.

What you get

Raw audit events turned into readable rows.

Every action carries the attributes an investigation actually needs, in one Activity logs screen.

  • What happened

    The action in plain language with an icon for its type - "downloaded 61 files", "created an anyone link" - instead of FileDownloaded and AnonymousLinkCreated from the raw record. Filter by any of 13 action types.

  • Who did it

    The user, app or AI agent behind the action, clickable straight through to its profile - groups, licenses, reach and its own activity baseline.

  • What it touched

    The file, site, mailbox, group or other resource affected, with a count when one action touched many at once, and the sensitive-info count next to it.

  • From where

    Country and city, plus the network type: ordinary connection, VPN, Tor, datacenter or Microsoft service traffic - filterable, with location novelty as its own filter.

  • On which device

    The device behind the action, managed or unmanaged, including devices that were never enrolled.

  • Severity, saved views and the raw record

    Risky events stand out in the list, any filter combination saves as a named view you can share and rerun, and the full source record is one click away when an auditor wants the original.

How deep it goes

Location novelty is the cheapest high-signal filter you own.

Alongside severity, actor type, source, action and date, the timeline narrows by country, network type and location novelty.

Location novelty separates the first time a user was ever seen somewhere from places they have been before. It is a lightweight indicator with a very high hit rate: a genuinely new location on an account that has worked from one city for two years is either travel somebody can confirm in a minute or something worth an hour. In a typical tenant the filter returns a handful of rows a day, not hundreds.

Network type is the companion filter. Many Microsoft 365 events carry the address of a Microsoft datacenter rather than the user's, and a naive tool raises a foreign-datacenter alarm on all of them. Those are labelled Microsoft service traffic instead, which keeps genuine sign-ins from another country visible rather than buried under false positives.

And the pivot: open a user or device, read the Locations tab as a travel timeline, click any location, and land on exactly the events that came from it, already filtered. "I see activity from a city this person does not work in - show me which events" is one click, not an afternoon of exports.

In practice

Four questions the timeline answers in minutes.

Logs on their own are data. The value is how fast a question turns into a list.

  1. 01

    Incident root cause

    Open Activity logs, type the account, and read back through up to three years of history. Sort by severity: the mailbox rule at 03:14 and the 600 downloads at 03:20 come first.

  2. 02

    Compliance evidence

    Save the filter as a named view, export the rows to CSV, and hand the auditor a trail with the raw record attached - the same list every quarter, one click.

  3. 03

    The abnormal pattern

    Filter to after-hours downloads, sign-ins from a first-seen country, or activity through VPN, Tor or a datacenter. These stand out only when history and location sit on the same row.

  4. 04

    AI and app oversight

    Filter the actor to AI agents or apps and see how Copilot, declarative agents and connected applications actually touch your data - in the same timeline as human activity.

The difference

What you get on top of the audit log.

Same source data, kept longer, joined to everything else, and readable at a glance.

  • Up to three years of retention on a standard license - from 180 days to three years, no premium add-on
  • One filterable list, exportable in full - no scripts, no paging, no export ceilings
  • Country, city and network type on every event row
  • Microsoft datacenter addresses labelled as service traffic instead of raising foreign-datacenter alarms
  • Location novelty as a filter, separating first-ever locations from familiar ones
  • Managed versus unmanaged device shown per action, including devices that were never enrolled
  • AI agents treated as actors alongside people and apps
  • A travel timeline per user or device, with one-click pivots into the events, and the raw record still underneath

Scale

Retention is a storage problem, not a feature flag.

Three years of activity for a large tenant is a very large table, which is why retention here is built on daily rollups and partitioned history rather than on keeping a search index warm. Production tenants past 40 million files answer 30- and 90-day questions instantly; the 1, 12 and 24-hour windows read the raw log.

  • 3 years
    of history accumulates as the platform runs
  • 500M+
    files in the largest tenants the timeline serves
  • 5
    network types told apart: ordinary, VPN, Tor, datacenter, Microsoft service traffic

Related

Where this fits.

The timeline is the raw material. Locations, devices and anomalies are the three lenses most often applied to it, and each one links back here for the underlying events.

  • Sign-in locations

    Every sign-in with the city, the device and the Conditional Access policy that let it in - and the share no policy governed.

    See locations
  • Shadow device detection

    The devices behind the events, including the ones that were never enrolled.

    See devices
  • Anomaly detection

    The same activity measured against each account's own 30-day baseline - 40 downloads is routine for one user and an incident for another.

    See anomalies

FAQ

Questions teams ask first.

Do I need a premium license for three years of retention?

No. Retention is part of the platform, so it works on standard licenses from Business Basic up. The history accumulates as the platform runs: three years of subscription builds three years of trail, and historical backfill imports the audit history still available on the day you connect.

Where does the location on each event come from?

From the network context on the event, resolved to country, city and network type (ASN). Events carrying Microsoft datacenter addresses are recognised and labelled as service traffic rather than treated as foreign activity.

Can I still see the raw audit record?

Yes. Every row opens to the full event including the original Microsoft record, which matters when an auditor wants the unedited evidence rather than a rendered summary.

Does it cover AI agent activity?

Yes. Agents appear as actors alongside people and applications, which is what makes "what did this agent read last quarter" answerable at all.

Can the log feed a SIEM?

Yes. A read-only REST API pulls activity into a SOC or SIEM pipeline with cursor pagination and occurredAt separated from discoveredAt, so late-arriving events are never missed. No agent, no log forwarder.

Keep the audit log longer than the questions take to arrive.

Connect read-only and the timeline starts building the same day - with location and device attached from the first event.

Or keep answering last year's questions with this year's exports.