Office 365 real time monitoring

A mass download takes 20 minutes. Your nightly report finds it tomorrow.

The moment that matters in a tenant is short: a leaver pulling 3,000 files from a finance library, an anyone link created on a payroll folder, a mailbox rule forwarding outside. 1Security reads Microsoft 365 audit activity continuously, re-evaluates only what each event touched, and alerts within minutes - so you interrupt the download instead of reading about it.

The problem

"Real time" usually means a refresh interval.

Plenty of dashboards say real time and mean recomputed tonight. The gap costs nothing 364 days a year and everything on the one afternoon a departing employee starts downloading a whole document library. By the time the 2 AM job runs, the files are on a USB stick.

Watching audit search by hand does not scale past one resource, and a fixed threshold gives you a row, not a verdict. What you need next to the row is context: who the account is, what else it can reach, and whether 3,000 downloads is normal for it - and that context is not in any single log.

On a large tenant the naive fix does not work either: re-scoring 40 million files because one changed is how monitoring products fall over. The only workable answer is scope - react to the event, re-evaluate the slice it touched, and prove the engine is alive so silence means nothing happened, not that nothing was checked.

In practice

A mass download, minute by minute.

What happens in 1Security between the first download and the alert in your inbox.

  1. 01

    Events land and get attributed

    Audit-log activity streams in continuously. Every event is tied to a user, file, site, app, device and location - so a download is never just "FileDownloaded", it is "this account, this device, this city, this file". Per-tenant coalescing means no event is dropped, and new activity shows in Activity logs about ten minutes after it happens at any tenant size.

  2. 02

    Only the affected slice re-evaluates

    The policies an event touches re-check just the changed resources, within minutes. Counts, trends and the account's own anomaly baseline update while you watch - no nightly rebuild, no full-tenant recomputation.

  3. 03

    The one-hour tripwire fires

    Activities support 1, 12 and 24-hour windows read straight from raw audit logs. "More than 500 downloads by one user in an hour" or "an anyone link created on a site with sensitive info" fires during the incident, and an instant alert mails you the moment the line is crossed - with cooldowns, so one incident is one email, not fifty.

  4. 04

    Verdict with the alert, not after it

    The alert opens on the account's page: today's activity against its normal, the files it reached, the device and location, and three years of history one click away. Most alerts close in minutes as benign; the one that is not gets an interruption while it is still happening.

What makes it work

Scoped reaction, honest windows, proof of life.

Three design choices separate real time monitoring from a refresh interval.

  • The monitoring engine

    Eight resource types, thirteen action types mapped to real Microsoft 365 audit events, about ten-minute freshness at any tenant size, and instant answers on 7, 30 and 90-day windows from rollups.

    Explore the monitoring tool
  • Alerts on the same clock

    Instant alerts ride the real-time path and email the moment a threshold or a deviation from the account's baseline is crossed. Digests collect the rest on your schedule.

    Explore the alerts tool
  • History behind every spike

    When the tripwire fires, up to three years of attributed activity is one click away - so the interruption arrives with its investigation attached.

    Explore the audit tool

FAQ

Common questions.

How fresh is "real time" here, concretely?

New activity is visible in about ten minutes at every tenant size, and the policies an event touches are re-evaluated within minutes of the event. The 1, 12 and 24-hour windows read straight from raw audit logs, not from precomputed aggregates. We say near real time because audit events take a few minutes to be published before we can read them, and we would rather be honest than round down.

Does this hold up on very large tenants?

Yes - that is the reason the pipeline re-evaluates only the affected slice. Production tenants with more than 40 million files run on it; long-window questions answer instantly from rollups while the short windows stay raw.

How do we know the engine is actually running?

A liveness strip shows the last evaluation time on screen, and the actions chart shows what the engine did across any window from an hour to a year. A quiet week is verifiably quiet, not assumed to be.

Do we need E5, Defender or a SIEM for this?

No. Real time monitoring runs on standard Microsoft 365 licensing over the read-only connection, with no agent to install. It complements Defender rather than replacing it - Defender alerts show up on the same account page with the same context.

Put a one-hour tripwire on the thing you fear most.

Connect read-only and the pattern you worry about - mass download, anyone link on sensitive data, forwarding rule - is armed the same afternoon, with an email the moment it trips.

Or read about it in tomorrow's digest.