Office 365 activity report
Who downloaded the most last month? Answer in one click, not one day.
A typical activity request - top downloaders, what left the tenant, which sites went quiet - costs an admin half a day of exports and scripting, and the spreadsheet is stale before it is mailed. 1Security keeps the Office 365 activity report as a live screen: filter, sort, export, save the view, and have it mailed every Monday. With up to three years of history behind every number.
The problem
Monday morning: management wants the numbers. Again.
Someone asks for last month's activity: who was most active, how many files were downloaded, what was shared outside, which sites nobody touched. The answer is spread across audit search, usage reports, sign-in logs and message trace - each with its own export format and its own window. Half a day later there is a spreadsheet describing a tenant that has already changed.
Next month the same request comes back slightly different, the spreadsheet is rebuilt by hand, and the numbers do not match the previous one. Nobody can say why, because each export was a one-off with its own filters. Meanwhile the events that mattered - the account that downloaded 4,000 files in a week, the site that went silent the day a project ended - are buried in the averages.
And the trail needs to be long. With 1Security you go from 180 days of activity history to up to three years on the licenses you already have, so a question about last spring still has data behind it and the report you build today runs on the same data next year.
In practice
From a one-off export to a report that runs itself.
What replacing manual activity reporting looks like in the first week.
- 01
Ask the question once, on the Activities board
Open Activities and pick the cut: top downloaders, top sharers, most-shared files, most-active devices, unused sites - over 24 hours, 7, 30 or 90 days, or a year. Each card is a ranked list with a sparkline: "top 20 downloaders in the last 30 days" is one click, and the number one row is often a surprise.
- 02
Save the view and share it
Filter Activity logs to the exact slice management asked for - time window, action types, resource - and save it under a name. Saved views are visible tenant-wide, so the next admin opens the same definition instead of rebuilding it. Export gives you exactly the rows on screen, not a mystery CSV.
- 03
Schedule the digest
Turn the cut into a policy and attach a digest: hourly, daily or weekly, to the recipients who asked. The Monday report now mails itself, computed at send time. Add an instant alert on top - "any user downloading more than 1,000 files in 24 hours" - and the report doubles as a tripwire.
- 04
Feed the people who want raw data
Where a SIEM, MSSP or a BI team wants the feed rather than the screen, the read-only REST API serves logs and alerts with cursor pagination - the same data, pulled on their schedule. One source of numbers instead of four exports.
What makes it work
Live data underneath, not exports.
Three parts of the platform carry this use case - each goes deeper than reporting alone.
Office 365 reporting
Numbers an auditor accepts, saved and shared views, full-list exports and the read-only API - answers instead of attachments.
Explore the feature →Microsoft 365 audit tool
Up to three years of searchable history behind every number, each event tied to a user, app, device and location.
Explore the feature →Microsoft 365 monitoring tool
The live layer the reports read from: new activity visible within about ten minutes, at any tenant size.
Explore the feature →
FAQ
Common questions.
Can the report be scheduled and emailed automatically?
Yes. Digests run hourly, daily or weekly to the recipients you choose, and instant alerts mail the moment a threshold is crossed. Mail is sent through Microsoft Graph from a dedicated mailer app, so it arrives from your own tenant.
How far back does the data go?
Up to three years of activity history on a standard Microsoft 365 license - go from 180 days to three years without a premium add-on. Long windows are served from daily rollups, so a 90-day question answers instantly even on tenants with tens of millions of files.
How is this different from the usage reports we already have?
It complements them. Usage reports answer adoption per workload; 1Security answers the people questions - named users, files, sites, devices and apps ranked by what they did, cross-filtered with who can access what. It needs no E5, no agent and no log forwarder.
Can our SIEM pull these numbers?
Yes. The read-only REST API exposes logs, monitoring alerts and security alerts with per-tenant keys and cursor pagination, with documented wiring for Sentinel, Splunk, QRadar and Elastic.
Stop rebuilding the same spreadsheet.
Connect read-only, save the views your team keeps asking for and let the digests deliver themselves. First numbers the same day.
Or export it all again next month, cell by cell.