Microsoft 365 audit tool
Three years of audit history, one search box. Answers in ten minutes.
Most audit questions reach further back than six months, and by then the trail has usually gone cold. 1Security keeps up to three years of Microsoft 365 activity, searchable, with the user, file, app, device and location on every row - so "what did this account touch, and from where?" takes ten minutes instead of a forensics engagement.
- 3 yearsof searchable activity on a standard license - from 180 days to three years
- 10 minto answer "was this account compromised?" - instead of a 12-hour reconstruction
- 5attributions on every event: user, resource, app, device, location
The problem
An audit answer is a chain of five joins. 1Security does the joining for you.
The Unified Audit Log stores events. An auditor asks about people, files and consequences - the distance between the two is where audit weeks go.
A raw audit row is an operation name, a GUID and a timestamp. Turning it into "a contractor's unmanaged laptop downloaded 61 files with financial data at 22:10, from a network we had never seen" means joining sign-in logs, device records, IP intelligence and file metadata - for every event, by hand.
Retention adds a second problem. The questions that matter - when did this start, was it happening before we noticed - routinely reach further back than six months, and in a typical tenant the honest answer to "show me last spring" is that the evidence is gone. 1Security takes your audit memory from 180 days to three years on the license you already have.
1Security does the joining continuously and keeps the result: one timeline where every event arrives already attributed, filterable by anything, with the raw Microsoft record one click away.
Capabilities
A record that answers in sentences, not GUIDs.
Every action across files, email, Teams, SharePoint, sign-ins, AI agents and third-party apps, in one searchable place.
- 3 years
Three-year searchable timeline
Retained out of the box on a standard license - no log-storage bill, no premium add-on. Open Activity logs, type an email address, and read three years back.
Five attributions on every row
User, resource, app, device (managed or not) and location on each event, with severity and a plain-language description. The raw source record stays one click away for the sceptic.
Location and novelty filters
Filter by country, by network type - VPN, Tor, datacenter, Microsoft service traffic - or by location novelty: only events from places this user has never been seen before. The fastest breach question there is.
The Actions list
Every fix, automated or manual, is recorded with who approved it, when it ran and what changed. "We found it" and "we fixed it" become one exportable trail.
- 12
Instant at 500M+ files
Daily rollups across 12 action groups make the 30- and 90-day questions instant even on tenants past 40 million files. The 1, 12 and 24-hour windows read raw logs. Scale never shows up in the query time.
A feed your SIEM can trust
The read-only REST API separates occurredAt from discoveredAt, because audit events can arrive minutes or hours after they occurred - a SIEM polling on ingestion time never loses a late arrival. Deterministic ordering, cursor pagination.
Regulated clocks
Built for the 24-hour, 72-hour and one-month questions.
NIS2 gives you 24 hours for an early warning, 72 for a notification with an initial assessment, and a month for the final report - and makes management personally accountable. GDPR gives you 72 hours to notify.
The 24-hour warning needs one look: the timeline with location on every row separates a genuine sign-in from another country from routine service traffic at a glance. The 72-hour assessment needs blast radius on demand: what the affected account could reach, whether regulated data was in scope, which device carried it - "could reach 214,000 files, 3,100 of them with personal data" instead of "potentially affected".
The final report reaches backwards: three years of retained history reconstructs entry points that are months old, and the Actions list is the response evidence. The same trail serves ISO 27001 and SOC 2 as continuous evidence instead of an annual scramble.
In practice
Tuesday, 08:12: "was this account compromised?"
An investigation, timed.
- 01
08:12 - one search
Open Activity logs and type the account's email. Its full history is one filtered timeline: sign-ins, files, mail, agents, permission changes - reaching back as far as three years.
- 02
08:15 - the origin check
The location column tells the story: two years of activity from two cities and one home ISP. Then, Thursday night, a first-seen datacenter origin - flagged as novel automatically.
- 03
08:20 - scope in numbers
Filter to the novel origin: 34 downloads, one unmanaged device, two hours. Every file named, with the sensitive-info count next to it. The "what did they reach" section of the report writes itself.
- 04
08:25 - evidence, exported
Save the view, export the rows, attach the remediation trail from Actions. What used to be a 12-hour reconstruction is finished with the first coffee.
The difference
What you get on top of the audit log.
Same source data, kept longer and joined to everything else.
- Up to three years of retention on a standard license - from 180 days to three years, no premium add-on
- Location novelty as a filter: only events from places this user has never been seen before
- Microsoft service and relay traffic labelled, so the timeline reads clean instead of full of phantom datacenter logins
- AI agent activity, device activity and blocked-access events as filterable log types of their own
- Unmapped events kept in an explicit "other" bucket - nothing silently dropped
- 1Security's own service activity filtered out of your logs by default
- Saved views you can name, share and rerun - a recurring audit question becomes a link
- occurredAt vs discoveredAt on the API, so downstream systems never miss late-arriving events
Deployment
Evidence collection that starts today.
Connect read-only and the timeline starts accumulating the same day; historical backfill imports the audit history still available at connection time. No agents, no log forwarder, no storage bill scaled to your event volume, no premium license prerequisite for any of it.
- 1 dayfrom read-only consent to a live, searchable timeline
- 180 d → 3 yrwhat happens to your audit memory
- 0agents, log forwarders or premium licenses required
Use cases
The same record, three audiences.
For the auditor: recurring evidence requests become saved views. Access history, permission changes and remediation records export from one place, with plain-language descriptions an assessor can read without a Graph API glossary.
For the responder: entry points that are months old are still in the record. Three years of attributed history means "when did this actually start" has an answer even when the honest answer is "last spring".
For the regulated: run the 72-hour drill before the incident. Pick a user, start the clock, and practise producing the early warning, the scope assessment and the evidence pack from one screen.
Microsoft 365 alerts
Detections built on this record: instant, digest, and an anomaly line scored against each account's own baseline.
See alerts →Microsoft 365 monitoring
The live one-hour windows that catch a mass download while it is still running.
See monitoring →Access management
The permission graph that turns "what happened" into "what could they reach" - hundreds of thousands of files for an ordinary account.
See access management →
FAQ
Questions auditors and responders ask first.
How is three-year retention possible without a huge storage bill?
Retention is part of the product, not a metered log-storage line item. 1Security stores attributed security metadata - who did what, when, from where, on which device - not a second copy of your documents or mailboxes, so the economics are nothing like a SIEM's ingest pricing.
Does it backfill history from before we connected?
Yes. Historical backfill imports the audit history still available at connection time - typically the last 180 days - and from that point forward 1Security's own retention takes over. Three years of subscription gives you three years of history.
Can auditors work in it directly?
That is the intended use. Every event carries a plain-language description, views can be saved, named and shared, full lists export to CSV, and the raw source record stays one click away when the auditor wants the primary evidence.
How does this help with NIS2 and GDPR deadlines?
The 24-hour early warning, the 72-hour notification and the one-month final report each map to the record: location on every row separates real foreign activity from routine service traffic in one look, blast radius comes from the permission graph on demand, and three years of history plus the Actions list carry the final report.
Do we need a premium license?
No. The audit timeline, retention, location intelligence and exports all run on standard licenses from Business Basic up, over a read-only connection with no agent to install. Premium Microsoft SKUs only matter for optional extras like ingesting Defender alerts or syncing Purview labels.
Give your tenant a three-year memory.
Connect read-only and the timeline starts building today - three years of attributed history, ten-minute answers, and an evidence trail your auditor can hold.
Or hope the next question stays inside the last six months.