Microsoft 365 audit and investigation

"What did this account touch?" Answered in minutes, not weekends.

Most Microsoft 365 investigations still mean stitching sign-ins, file events and mailbox traces into one timeline by hand - a day of work per account, and only while the events are still inside the retention window. 1Security keeps up to three years of history behind every account, already attributed to the file, the device and the location, so the answer to "what did they touch, from where, and how far could they have gone" is a filter, not a project.

The problem

The tip arrives late. The log has already moved on.

A departing employee downloaded "a lot" in their last two weeks. A contractor account behaved oddly before the contract ended. A phishing click from Tuesday reached the SOC on Friday. Every real investigation starts with a lead that is days or months old - which is why 1Security takes you from 180 days of audit history on standard licenses to three years, switched on the day you connect rather than the day after you needed it.

Even inside the window, one account means sign-in, file, mailbox and device records that each tell part of the story. Correlating one afternoon of one user across them by hand is an afternoon of your own, and it still does not tell you what the account could have reached but did not touch - which is the number management asks for first.

In a typical tenant an ordinary account can reach hundreds of thousands of files through groups, sharing links and inherited site permissions, and nobody has ever seen that number written down. So the impact section of the report becomes an estimate, and the timeline has gaps exactly where the interesting week was.

In practice

One account, taken apart in four steps.

How an investigation runs in 1Security - departing employee, suspected insider or a compromised login, the path is the same.

  1. 01

    Open the account and read its reach

    Open the user in Users. The drawer shows what the account can reach right now - sites, files, groups, mailboxes, links - resolved through every nested group and inheritance, plus its devices, its sign-in locations and its activity trend against its own baseline. The blast radius that used to take a day of scripting is one drawer, typically counted in the tens or hundreds of thousands of files.

  2. 02

    Replay the window that matters

    Switch to Activity logs and filter to the account and the date range - last week or last year, up to three years back. Every event names the file, the action, the app, the device (managed or not) and the country and city it came from, with the raw audit record one click away. Sort by severity to see the 40 downloads and the mailbox rule before the 4,000 file opens.

  3. 03

    Read what sat below your alert line

    Anomalies keeps every deviation down to two sigma above the account's own 30-day baseline as an info-tier episode - never mailed, never thrown away. Lower the sensitivity dial and the quiet Tuesday nobody alerted on shows up as "downloads 8x normal", without a rescan or a tuning period.

  4. 04

    Check the origin, then close the loop

    The travel trail says whether the account ever appeared somewhere its owner could not have been - two countries 900 km apart within an hour, a datacenter or Tor exit - and on which device. Findings become staged actions: expire the links, revoke the sessions, disable the account, each one logged in Actions with who approved it and when.

What makes it work

Memory, attribution and a baseline.

Three parts of the platform turn an audit export into an investigation you can finish before lunch.

  • Three years of audit history

    Searchable, attributed activity - from 180 days to three years of retention on a standard license, with occurred-at and discovered-at timestamps kept apart.

    Explore the audit tool
  • Locations with verdicts

    Every event resolved to a country, city and network type. First-seen countries flagged, datacenter egress recognised for what it is, impossible travel called out on the timeline.

    Explore travel detection
  • Alerts that keep receipts

    Episodes instead of event spam, a sensitivity dial you set yourself, and an info tier that preserves everything down to two sigma for the day you need hindsight.

    Explore the alerts tool

FAQ

Common questions.

How far back can an investigation reach?

Up to three years of activity, on a standard Microsoft 365 license - three years of subscription builds three years of history, taking you from 180 days of standard audit retention to three years without a premium add-on. The audit history available at the moment you connect is backfilled; from then on nothing expires.

Do we need a premium license or an agent on the machines?

No. Retention, attribution, locations and anomalies all run on standard licensing with a read-only connection. There is nothing to install on endpoints; device attribution comes from the sign-in and audit records themselves.

Can we investigate quietly?

Yes. Investigating is read-only browsing of data 1Security already holds - filters, drawers and timelines. Nothing is sent, changed or announced unless you explicitly stage an action, and staged actions wait in their own review window.

What if the suspicious activity never triggered an alert?

That is what the info tier is for. Everything down to two sigma above the account's own baseline is stored and filterable even though nobody was mailed. Lowering the alert line reclassifies history at read time, so hindsight is a filter change, not a forensics job.

The next "did we miss something?" deserves an answer.

Connect read-only and the history starts building the same day - so the next departing employee, odd contractor or late phishing report is a ten-minute lookup instead of a lost weekend.

Or keep stitching the timeline by hand.