Office 365 reporting
Who can open what: one click and one export. Not a day of work.
A "who has access to what" report usually means several exports merged into a spreadsheet that is stale on save - typically a day of work per question. In 1Security every screen is the report: filter, save the view, share the URL, export the CSV, or let the SOC pull the same numbers through a read-only API. Three years of history sit behind every row.
- 1filterable, exportable list per question - shareable as a URL, no merging
- 3 yearsof activity history behind every report row, on a standard licence
- 600/minAPI requests per key for pulling logs, detections and alerts into your SIEM
The problem
A report that needs five exports is not a report. It is a project.
The data exists. It is scattered across sources that were never built to answer one question together.
Sites in one export, sign-ins and guests in another, labels and audit in a third, mail flow in a fourth, and a script for the part no list shows. Each source returns a different shape, and by the time the spreadsheet is merged the tenant has moved on. A typical quarterly access review costs a mid-size IT team several days of exports.
The hardest questions never export at all. "Who can open this file, and through which group, link or inherited permission" is not a column in any export - it is a path through the permission graph that has to be resolved, not queried. So the report says "members of Finance-All", not "the 1,900 users, 12 guests and 3 apps that can actually open it".
1Security holds the resolved model - every user, group, site, file, link, app, agent, device and mailbox in one graph, with three years of activity attached. Reporting stops being an assembly job: ask the question on screen, save the view, share the URL, export the list. The same number is still true tomorrow, because it is recomputed, not pasted.
What you get
Every screen is the report.
Users, files, sites, groups, apps, agents, devices, emails, licences, locations - every list in the product filters, sorts and exports in full.
Live lists, full CSV exports
Any filtered list exports as it stands - no row caps, no "top 1,000". Filter Files to "contains card numbers AND anyone link", export, and the file is the evidence. The report is the live screen, not a snapshot someone made last month.
Saved and shared views
Name a filtered view, refine it, share it tenant-wide. "Externally shared, sensitive, no expiry" saved once opens current every quarter - a URL, not a ritual. Activity boards work the same way.
- GDPR · HIPAA · PCI-DSS
Sensitive data by framework
One row per sensitive information type - card numbers, IDs, health data, credentials - with how many files, emails, sites, users and apps can reach it. Filter by framework (GDPR, HIPAA, PCI-DSS, SOX, CCPA, FERPA) and by confidence, and quote high-confidence counts only.
Label coverage as a percentage
Sensitivity label coverage measured against where sensitive data actually sits, per site and per label. The difference between "we have a classification policy" and "68% of files with personal data carry a label, up from 41% in Q1".
Licence use per SKU
Purchased vs assigned vs available for every SKU, who holds each unit, guests and dormant accounts broken out. In a typical tenant 10-30% of paid seats sit on accounts that have not signed in for months - walk into the renewal with that number.
- 3 feeds
A read-only API for the rest
Normalized activity logs, your own policy detections and matched security alerts, per-tenant keys with scopes, cursor pagination, 600 requests a minute - with documented wiring for Microsoft Sentinel, Splunk, QRadar and Elastic.
In practice
The quarterly access review, in one sitting.
From opening the view to handing off the evidence - the way it runs once the views are saved.
- 01
Open the saved view
Files: externally shared, sensitive, no expiry - saved last quarter and shared with the team. It is current the moment it opens. Typical count in a mid-size tenant: a few hundred files, most of them on three or four sites.
- 02
Quote the number the auditor asked for
Sensitive info, high-confidence detections only, filtered to GDPR. "4,120 files with personal data, 310 of them reachable by anyone links" is reproducible on demand - not an estimate from a stale export.
- 03
Attach who touched it
Any row expands into who opened, downloaded or shared it, when, from where and on which device - up to three years back, on a standard licence.
- 04
Hand it off
Export the CSV for the audit file, share the view URL with the compliance lead, or let the SOC pull the same rows continuously through the API. One source, every consumer, same numbers.
The gap
Numbers that only exist once the model is joined.
Per-service reports describe each service on its own. These answers only exist where the model is joined.
- Who can open a specific file, and through which grant, link or group - as an exportable list of users, guests and apps
- Sensitive data counts by framework you can filter by confidence and quote to a regulator, with reach next to each detection type
- Label coverage measured against where sensitive data is, per site, trending quarter over quarter
- Three years of who-did-what on a standard licence - from 180 days of history to three years
- Licence units purchased vs assigned vs idle, with dormant holders and guests broken out per SKU
- A shareable URL that is the report, recomputed on open - not a PDF from March
- The same rows flowing to Sentinel or Splunk through a pull API, without a log-storage bill for being prepared
Deployment
First exportable answers the same afternoon.
One read-only consent, no agent, no appliance. The first scan lists your users, sites, files, groups and apps within hours for most tenants; saved views, exports and the API are available as soon as it lands. Activity history starts building from day one and is kept for up to three years - all on standard Microsoft 365 licensing.
- Same dayfrom read-only consent to the first filtered, exportable answers
- 0E5, Entra P2 or premium audit add-ons required - Business Basic upward
- 1×API secrets are shown once and stored only as a hash; nobody, including support, can recover them
Use cases
The audit, the board, the SOC.
Three audiences, three formats, one set of numbers that never disagree.
Audit prep: the evidence assembles itself. Who had access, what changed, when and from where - answered from the resolved model with three years of memory, exported with the same filters the auditor watched you apply. A review that used to cost days of exports takes one sitting.
Board reporting: trend boards turn posture into numbers that move - externally shared files, label coverage, guests with access to sensitive sites - each with a sparkline and its history. A board is a shareable URL, so the same picture reaches leadership every quarter without a slide-building week.
The SOC feed: some events arrive late, so the API separates when something happened from when it was ingested; your SIEM polls on ingestion time and never drops a late event. The policy-detections feed exports what your own 1Security rules found - "anyone link created on a file with card numbers" - and that data exists nowhere else.
Keep exploring
Where the numbers come from.
Microsoft 365 audit tool
The three-year activity history behind every report row: every action attributed to a user, file, device and location, searchable in seconds.
See the audit tool →Access management
The permission graph that turns "who can open this" from a day-long project into a filter - nested groups, links and inheritance resolved.
See access management →Microsoft 365 alerts
When a number you report on starts moving, an email arrives before the next quarterly review does.
See the alerts tool →
FAQ
Reporting questions, answered straight.
Can reports be scheduled or shared with the team?
Saved views are named, editable and shareable tenant-wide, and any filtered screen is a shareable URL. For push delivery, digest alerts email summaries hourly, daily or weekly to the recipients you choose - top downloaders this week, new anyone links on sensitive files, guests added to sensitive sites.
How far back does the data go?
Activity history is kept for up to three years on a standard licence, so you go from 180 days of audit history to three. Historical audit backfill can extend coverage further back where your Microsoft licensing allows it. Permission and inventory data is always the live state.
Are the sensitive-data numbers defensible in front of an auditor?
Detections come from 300+ deterministic detectors plus OCR and Purview SIT import, each with a confidence level, so you can quote high-confidence matches only. What is stored is the detection type, count and confidence - never the matched values themselves - which tends to satisfy the same auditors who asked for the numbers.
Can non-technical stakeholders use it?
Yes. Access paths are explained in plain language ("can open via Finance-All > Finance-Managers"), saved views open pre-filtered screens, and nobody needs a script or a query language. The people who ask the questions can read the answers themselves.
How do we pull the data into our SIEM?
Through the read-only REST API: three feeds (activity logs, policy detections, security alerts), per-tenant keys with scopes, 600 requests a minute, cursor pagination, and documented integrations for Microsoft Sentinel, Splunk, QRadar and Elastic. It is pull-based, so no inbound connectivity to your network is required, and one poll per feed per minute stays comfortably inside the limit.
Stop assembling reports. Start exporting answers.
Connect read-only in the morning and hand someone a live, filtered, exportable answer in the afternoon. Save the view, and next quarter takes one click.
Or keep merging five exports every quarter.