Microsoft 365 unified audit log
Your unified audit log, three years deep, one search box.
The unified audit log is the right source for "who did what, when, from where, and on which device". 1Security keeps it up to three years on standard licenses, in one searchable timeline with the action in plain language and country, city and device on every row - so a question about last year is a filter, not a project.
- 3 yearsof retained activity on a standard license - from 180 days to three years
- 0scripts or exports needed to answer a question - filter, read, save the view
- 5attributions on every row: user, resource, app, device, location
The problem
The trail expires before the question arrives.
Incidents surface months after the event. Default audit retention does not last that long, and what does survive is hard to read.
Incidents surface months after the event, and standard audit retention runs 180 days. An investigation that opens in March about something that happened in August needs a longer memory - 1Security extends yours to three years on the license you already have.
Retention is only half of it. Raw audit rows are operation names split across SharePoint, Exchange, Entra and Teams, and the two attributes an investigator reaches for first - where the action came from and which device it came from - have to be joined in from elsewhere. Rebuilding that by hand for every question is why most questions never get asked.
1Security keeps the trail up to three years, attributes every event, and puts action, user, resource, app, device and location on the same row - with the raw Microsoft record one click away.
What you get
Raw audit events turned into readable rows.
Every action carries the attributes an investigation actually needs, in one Activity logs screen.
What happened
The action in plain language with an icon for its type - "downloaded 61 files", "created an anyone link" - instead of FileDownloaded and AnonymousLinkCreated from the raw record. Filter by any of 13 action types.
Who did it
The user, app or AI agent behind the action, clickable straight through to its profile - groups, licenses, reach and its own activity baseline.
What it touched
The file, site, mailbox, group or other resource affected, with a count when one action touched many at once, and the sensitive-info count next to it.
From where
Country and city, plus the network type: ordinary connection, VPN, Tor, datacenter or Microsoft service traffic - filterable, with location novelty as its own filter.
On which device
The device behind the action, managed or unmanaged, including devices that were never enrolled.
Severity, saved views and the raw record
Risky events stand out in the list, any filter combination saves as a named view you can share and rerun, and the full source record is one click away when an auditor wants the original.
How deep it goes
Location novelty is the cheapest high-signal filter you own.
Alongside severity, actor type, source, action and date, the timeline narrows by country, network type and location novelty.
Location novelty separates the first time a user was ever seen somewhere from places they have been before. It is a lightweight indicator with a very high hit rate: a genuinely new location on an account that has worked from one city for two years is either travel somebody can confirm in a minute or something worth an hour. In a typical tenant the filter returns a handful of rows a day, not hundreds.
Network type is the companion filter. Many Microsoft 365 events carry the address of a Microsoft datacenter rather than the user's, and a naive tool raises a foreign-datacenter alarm on all of them. Those are labelled Microsoft service traffic instead, which keeps genuine sign-ins from another country visible rather than buried under false positives.
And the pivot: open a user or device, read the Locations tab as a travel timeline, click any location, and land on exactly the events that came from it, already filtered. "I see activity from a city this person does not work in - show me which events" is one click, not an afternoon of exports.
In practice
Four questions the timeline answers in minutes.
Logs on their own are data. The value is how fast a question turns into a list.
- 01
Incident root cause
Open Activity logs, type the account, and read back through up to three years of history. Sort by severity: the mailbox rule at 03:14 and the 600 downloads at 03:20 come first.
- 02
Compliance evidence
Save the filter as a named view, export the rows to CSV, and hand the auditor a trail with the raw record attached - the same list every quarter, one click.
- 03
The abnormal pattern
Filter to after-hours downloads, sign-ins from a first-seen country, or activity through VPN, Tor or a datacenter. These stand out only when history and location sit on the same row.
- 04
AI and app oversight
Filter the actor to AI agents or apps and see how Copilot, declarative agents and connected applications actually touch your data - in the same timeline as human activity.
The difference
What you get on top of the audit log.
Same source data, kept longer, joined to everything else, and readable at a glance.
- Up to three years of retention on a standard license - from 180 days to three years, no premium add-on
- One filterable list, exportable in full - no scripts, no paging, no export ceilings
- Country, city and network type on every event row
- Microsoft datacenter addresses labelled as service traffic instead of raising foreign-datacenter alarms
- Location novelty as a filter, separating first-ever locations from familiar ones
- Managed versus unmanaged device shown per action, including devices that were never enrolled
- AI agents treated as actors alongside people and apps
- A travel timeline per user or device, with one-click pivots into the events, and the raw record still underneath
Scale
Retention is a storage problem, not a feature flag.
Three years of activity for a large tenant is a very large table, which is why retention here is built on daily rollups and partitioned history rather than on keeping a search index warm. Production tenants past 40 million files answer 30- and 90-day questions instantly; the 1, 12 and 24-hour windows read the raw log.
- 3 yearsof history accumulates as the platform runs
- 500M+files in the largest tenants the timeline serves
- 5network types told apart: ordinary, VPN, Tor, datacenter, Microsoft service traffic
Related
Where this fits.
The timeline is the raw material. Locations, devices and anomalies are the three lenses most often applied to it, and each one links back here for the underlying events.
Sign-in locations
Every sign-in with the city, the device and the Conditional Access policy that let it in - and the share no policy governed.
See locations →Shadow device detection
The devices behind the events, including the ones that were never enrolled.
See devices →Anomaly detection
The same activity measured against each account's own 30-day baseline - 40 downloads is routine for one user and an incident for another.
See anomalies →
FAQ
Questions teams ask first.
Do I need a premium license for three years of retention?
No. Retention is part of the platform, so it works on standard licenses from Business Basic up. The history accumulates as the platform runs: three years of subscription builds three years of trail, and historical backfill imports the audit history still available on the day you connect.
Where does the location on each event come from?
From the network context on the event, resolved to country, city and network type (ASN). Events carrying Microsoft datacenter addresses are recognised and labelled as service traffic rather than treated as foreign activity.
Can I still see the raw audit record?
Yes. Every row opens to the full event including the original Microsoft record, which matters when an auditor wants the unedited evidence rather than a rendered summary.
Does it cover AI agent activity?
Yes. Agents appear as actors alongside people and applications, which is what makes "what did this agent read last quarter" answerable at all.
Can the log feed a SIEM?
Yes. A read-only REST API pulls activity into a SOC or SIEM pipeline with cursor pagination and occurredAt separated from discoveredAt, so late-arriving events are never missed. No agent, no log forwarder.
Keep the audit log longer than the questions take to arrive.
Connect read-only and the timeline starts building the same day - with location and device attached from the first event.
Or keep answering last year's questions with this year's exports.