Microsoft 365 security log
One security log, three years deep, on the licenses you already have.
The question usually arrives in month seven: a departing employee's activity from last quarter, a compromise found months after the first sign-in, an auditor sampling last year. 1Security ingests the audit stream continuously and keeps it as one searchable log for up to three years - files, mail, Teams, sign-ins, AI agents and third-party apps in a single timeline, every event already tied to the user, the file, the app, the device and the country it came from. On standard licenses, with no SIEM bill and no log forwarder.
The problem
The question arrives in month seven. Make sure the log is still there.
A departing employee's activity from last quarter. A compromise found four months after the first sign-in. An auditor sampling a date range from last year. Security questions do not respect retention windows. With 1Security you go from 180 days of audit history on standard licenses to three years - retention that starts the day you connect, not the day after the incident.
Even inside the window, 'what did this account do that afternoon' spans sign-in, file, mailbox and device records that each speak their own language, and correlating them by hand is an afternoon of your own. One timeline, with every event already tied to its user, file, device and location, turns that question into a filter.
And the raw events do not name things. A typical tenant produces hundreds of thousands of audit records a week, keyed by GUIDs and site URLs, and requests often arrive through a datacenter egress rather than the user's real network. Shipping all of that to a SIEM makes it searchable and makes it expensive - most teams end up keeping 30 days and hoping.
In practice
From a vague question to an exact list of events.
How a typical search runs in Activity logs - one screen, one query, any date range up to three years.
- 01
Filter by anything that matters
Open Activity logs and narrow by user, file, site, app, AI agent, device, country, network type or action group - the same filters work across file, mail, Teams, sign-in and agent events. "Everything this contractor downloaded from the finance site in March" is three chips, and the answer is a list, typically a few dozen rows out of millions.
- 02
Read events as sentences, not GUIDs
Every row is a plain-language description with the actor, the resource, the app, the device (managed or unmanaged), the location and a severity. Datacenter egress is labelled for what it is instead of raising a false "foreign datacenter" alarm; VPN, Tor and hosting egress are flagged. The raw Microsoft record stays one click away for the skeptics.
- 03
Go back three years, not six months
Up to three years of history means last year's date range is a filter, not a lost cause. 7, 30 and 90-day questions are served from precomputed rollups and answer instantly even on tenants with tens of millions of files; long windows over hundreds of millions of events still return in seconds.
- 04
Save it, schedule it, or feed the SOC
Save the filter as a view, schedule it as a digest, export it, or let Sentinel, Splunk, QRadar or Elastic pull the same normalised log through the read-only REST API - polling on the discovered-at timestamp so late-arriving events are never lost. You keep the SIEM for correlation and stop paying it for storage.
What makes it work
A log is only as good as what each line carries.
Three parts of the platform turn raw audit events into a security log you can actually search.
Three years of audit history
From 180 days to three years of retention, searchable in place, with an explicit unclassified bucket instead of silently dropped events.
Explore the audit tool →Near real-time ingestion
New activity is visible in about ten minutes at any tenant size, so the log is a live surface you can watch during an incident, not a nightly batch.
Explore monitoring →Answers and exports
Saved views, scheduled digests and full exports on the same data - plus the REST API when the log belongs in your SIEM.
Explore reporting →
FAQ
Common questions.
Does this replace the Microsoft unified audit log?
It builds on it. 1Security reads the same audit stream, normalises it, attaches the user, device and location to every event, and keeps it for up to three years. The raw Microsoft record stays attached to each event, so nothing is lost in translation - and you can still run Search-UnifiedAuditLog whenever you want a second opinion.
Do we need a premium license or add-on for this?
No. Three-year retention, enrichment and search run on standard Microsoft 365 licenses - Business Basic upward - with a read-only connection and nothing to install. The audit history available at the moment you connect is backfilled; history accumulates from there.
How does the log get into our SIEM?
Pull-based, through the read-only REST API: per-tenant keys, 600 requests a minute, cursor pagination, and documented wiring for Sentinel, Splunk, QRadar and Elastic. Polling on the discovered-at timestamp keeps the drain deterministic even when events surface hours late.
How fast does new activity show up?
About ten minutes from the action to a searchable row, at any tenant size. During a live incident you can filter to the account and watch the log fill in.
Keep the answer past day 180.
Connect read-only and the log starts accumulating today - searchable, attributed, and yours for three years. Backfill covers the audit history available when you connect.
Or hope the next question is about something recent.