Microsoft 365 monitoring tool

A mass download takes 20 minutes. 1Security shows it in ten.

In a typical tenant the events that matter - a leaver pulling 3,000 files, an account signing in from a hosting network, an agent reading four times its usual - are over in under an hour. 1Security monitors Microsoft 365 with the current hour queryable, every action tied to a user, file, device and location, and new activity visible about ten minutes after it happens - on a 200-seat tenant and on one with 40 million files.

  • ~10 min
    from an action in Microsoft 365 to visible in 1Security, at any tenant size
  • 1 h
    the shortest activity window, read straight from raw audit logs
  • 8
    resource types watched: users, files, sites, groups, emails, apps, AI agents, devices

The problem

One incident, one row: account, device, location, files.

Sites live in one place, sign-ins in another, mail in a third, audit history in a fourth. The row an investigation needs - which account, on which device, from where, touched which files - has to be assembled from all of them.

The question in every incident is a join. Assembling it by hand means several exports, several formats and several delays, and by the time a daily report lands, the interesting hour is a day old.

Delay is not the only gap. Usage counts do not know that the account downloading 600 files usually downloads 12, that the device carrying the traffic has never authenticated, or that the network is a hosting provider in a country the user has never signed in from. Those are the facts that separate a busy afternoon from an exfiltration.

1Security reads the audit stream continuously, attributes every action to its user, resource, app, device and location, keeps the last hour as queryable as the last quarter, and holds up to three years of it - on standard licenses, with nothing to install.

What you get

Both ends of the activity range, on all eight resource types.

Risk lives at the top of the list (who did the most of something) and waste at the bottom (what has done nothing at all). Every screen shows both.

  • Top and unused, side by side

    Ranked "who did the most of X in the last window" and "what has done nothing for N days", each row with a sparkline. Both apply to users, files, sites, groups, emails, apps, AI agents and devices - top downloaders this hour, apps idle for 90 days, sites quiet for a year.

  • 1 h

    The current hour, queryable

    1, 12 and 24-hour windows are read directly from raw audit logs, so a download burst is visible while it runs. 7, 30 and 90-day windows come from daily rollups and answer instantly on the largest tenants.

  • 13

    13 action types mapped to real audit events

    Created, viewed, downloaded, modified, shared, moved, deleted, permission changed, restored, authenticated, AI used, meeting, access blocked - each mapped to the actual Microsoft 365 events behind it (SharingSet, AnonymousLinkCreated, SecureLinkCreated), not to a marketing category.

  • 5

    Country, city and network on every action

    Every event carries a location resolved locally - no third-party lookup sees your traffic - and a network class: standard, VPN, Tor, datacenter or Microsoft infrastructure. A first sign-in from a new country is flagged per user.

  • Devices, including the ones you never enrolled

    Activity is attributed to registered, unregistered and shadow devices - the last being machines seen accessing data with no authentication trail at all, discovered from the activity itself.

  • Any view becomes an alert in one click

    Turn a ranking into an alert rule with a threshold, a severity, hourly / daily / weekly cadence and recipients. Hourly cadence on the one-hour window is a standing mass-download tripwire.

Always on, provably

An engine that shows its own pulse.

Monitoring you cannot verify is monitoring you have to trust. 1Security keeps a liveness strip on the engine itself: "engine live - last evaluation 3 minutes ago", on screen, all the time.

Under the hood, each audit event re-evaluates only the policies and resources it touched, within minutes, with per-tenant coalescing so no event is dropped and a scheduled reconciliation pass as the floor under everything. Counts, trends and each account's anomaly baseline update while you watch - no nightly rebuild.

Scale is handled the unglamorous way: daily rollups answer the 30 and 90-day questions instantly on tenants past 40 million files, while the raw-log windows keep the current hour live. Top-activity cuts on files and emails stay within 90 days because those tables reach tens of millions of rows per window; unused cuts have no cap, since finding a file untouched for a year is the point.

In practice

Friday, 16:40: someone starts downloading.

A leaver's last week, as the monitoring sees it.

  1. 01

    16:40 - the window fills

    An account on notice starts pulling project files. About ten minutes later the downloads are in Activities at the top of the one-hour download ranking: 340 files, against a usual 12 a day.

  2. 02

    17:00 - the tripwire fires

    The hourly alert on the one-hour download window crosses its threshold and emails the team: the account, the count, the device, and a network first seen today in another country.

  3. 03

    17:05 - the account on one screen

    One click opens the user: what it can reach (typically hundreds of thousands of files for an ordinary account), what it touched this week against its own baseline, which device carried the traffic and whether that device is managed.

  4. 04

    17:10 - the response is recorded

    Sharing links expired, access removed, account disabled - staged behind the review window and written to Actions, so "what did we do about it" is already answered when the post-mortem starts.

The difference

What one model of activity, permissions, devices and locations gives you.

These exist here because activity, permissions, devices and locations sit in one model.

  • The current hour, queryable - 1, 12 and 24-hour windows read from raw audit logs, not from yesterday's rollup
  • Dormant lists on every resource type: users, sites, groups, apps, agents and devices idle for 90 days or a year, each one click from an alert
  • AI usage as an action type - who used which agent, how often, against which sites
  • Shadow devices reconstructed from activity alone: access with no observed authentication, discovered without any enrollment
  • First-seen locations flagged per user - the first time an account appears in a new country is a signal, not a row
  • Microsoft service and relay traffic recognised and labelled, so datacenter noise stops looking like phantom foreign logins
  • Up to three years of history under every sparkline - from 180 days to three years
  • A liveness strip on the engine: when it last evaluated, in the open

Deployment

Watching by this afternoon.

One read-only consent connects the tenant; the audit stream starts flowing the same day and the first ranked lists are useful immediately. No agents on endpoints, no log forwarder, no premium sign-in add-on. Location and device attribution are included on standard licenses from Business Basic up.

  • Same day
    from read-only consent to live activity rankings
  • 0
    agents, appliances or log forwarders to deploy
  • 3 years
    of retained, attributed activity - no premium license, no add-on

Use cases

The same monitoring, three different payoffs.

Exfiltration, interrupted: an hourly alert on the one-hour download or share window catches mass movement while it is unfolding. The alert names the account, the device and the origin, so the response starts with facts, not with log collection.

Spend, reclaimed: the dormant lists show accounts that have not signed in for a year and still hold licenses, devices nobody signs in from, and groups that receive mail nobody reads. In a typical tenant that is 10-30% of paid seats.

AI, measured: top AI users, most-active agents and the agents nobody has used since they were built, in the same ranked views - adoption and governance read from the same numbers.

  • Real time monitoring

    A mass download takes 20 minutes. Your nightly report finds it tomorrow. The one-hour tripwire, end to end.

    See the use case
  • Activity report

    Who downloaded the most last month? Answered in one click, not one day - live, exportable, mailed on schedule.

    See the use case
  • User monitoring

    One account can reach 200,000 files. Know what it did with them - against its own baseline, with device and location.

    See the use case

FAQ

Questions teams ask about monitoring.

How fresh is the data, really?

New resources and activity appear in about ten minutes, and that holds at every tenant size - the same pipeline serves tenants past 40 million files. The 1, 12 and 24-hour windows are read from raw audit logs, so the current hour is queryable while it is happening. We say near real time because Microsoft's own audit pipeline adds minutes before we see the event.

Do we need a premium license for this?

No. Monitoring, activity windows, device attribution and location intelligence run on standard Microsoft 365 licenses, Business Basic upward. Location enrichment runs inside 1Security, so there is no premium sign-in log add-on and no third-party IP service.

Does it monitor AI activity too?

Yes. AI agents are one of the eight resource types, "AI used" is one of the thirteen action types, and every agent gets its own activity baseline - so "the finance agent read four times its usual number of files today" is a detection, not a guess.

What about devices we never enrolled?

They are the point. 1Security reconstructs devices from real activity, keyed by a stable fingerprint, and classifies them as registered, unregistered or shadow - the last being devices seen accessing data with no observed authentication at all, which is what a stolen token looks like in use.

Can monitoring become alerting without extra setup?

One click. Any ranking converts to an alert rule with a threshold, hourly, daily or weekly cadence and your choice of recipients. Hourly cadence on the one-hour window gives you a standing mass-download tripwire.

Watch the hour that matters.

Connect read-only and see your tenant's live activity rankings the same day. The first "idle for a year" list usually pays for the exercise on its own.

Or keep reading yesterday's report about last week's incident.