Office 365 user monitoring

One account can reach 200,000 files. Know what it did with them.

In a typical tenant an ordinary account can open hundreds of thousands of files through groups, links and inheritance - and when that account resigns, gets phished or just starts behaving oddly, the answer to "what has it been doing?" is spread over sign-in logs, file reports, message trace and audit search, each with its own window. 1Security keeps every user's story in one place: what they can reach, what they did, from where, on which device, and whether today is normal for them.

The problem

A name lands on your desk. Now what?

An employee hands in notice. Defender flags a sign-in. HR asks a careful question about a contractor. Each time the request is the same: what has this account been doing lately, and does it matter? Answering it means stitching sign-in logs, file reports, message trace and audit search into one picture - each with its own export and its own time window - and doing it again for the next name.

The harder problem is context. 300 downloads might be that person's normal Tuesday or ten times their normal month. Sign-ins from two countries might be a holiday or a stolen token. A raw event log cannot tell you; only the account's own history can. And the number that matters most for the risk - how many files, sites and mailboxes this one credential can open - is not in any log at all.

1Security builds every user row from the permission graph and up to three years of activity: files, sites and groups reachable, the activity trend against the account's own 30-day baseline, every location and device it was seen from, and anomaly episodes that open only when today breaks the pattern. The story is assembled before anyone asks for it.

In practice

The leaver review, in one drawer, in fifteen minutes.

From name to verdict without a single export - the same flow works for a phishing suspicion or an insider-risk review.

  1. 01

    Open Users and start with reach

    The user drawer shows how many files, sites, groups and apps the account can open, and the access graph draws every path: direct grants, group inheritance, sharing links it created, its OneDrive, files that arrived by email. Every node clicks through to a filtered list. This is the blast radius one stolen password would have.

  2. 02

    Read the trend against the account's own baseline

    Activity over time, compared with the median of the account's previous 30 days. A spike shows as an anomaly episode with its peak tracked, so "340 downloads today" arrives already labelled as 28 times the usual 12 - no threshold to tune, no rule to write.

  3. 03

    Check where from and on what

    The travel tab lists every country, city and network the account was seen from, first-seen places flagged, Microsoft datacenter egress excluded, impossible-travel legs called out. Next to it, every device it used - including unregistered machines the directory has never met.

  4. 04

    Act from the same screen

    If the review finds something: revoke access with the blast radius shown per source, expire the links it created, disable the account, reclaim the license - each staged behind the review window and logged in Actions. If it finds nothing, you have the evidence for that too.

What makes it work

Three layers behind every user row.

User monitoring is what the platform's core layers look like when they meet on one identity.

  • Office 365 access management

    Effective access resolved through nesting, links and inheritance - the "what can it reach" half of every user story.

    Explore the feature
  • Impossible travel detection

    Every action located to country, city and network, first-seen origins flagged, Microsoft relay noise removed.

    Explore the feature
  • Shadow device detection

    The machines behind the account - registered, unregistered and shadow - with what each one touched.

    Explore the feature

FAQ

Common questions.

Is this employee surveillance?

No. It is the security record Microsoft 365 already produces, assembled per account: who did what, when, from where, on which device. 1Security keeps no browsable archive of message bodies or file contents, and values matched by sensitive-data scanning are never stored. It answers "is this account at risk or misused", not "what did this person write".

How do you know what is normal for an account?

Each active account learns its own baseline: today's activity is compared with the median of its previous 30 days, with the spread measured the same robust way. An anomaly episode opens only on a genuine spike, after a 14-day warm-up, and the sensitivity is a dial you can move and see the result on your real data immediately.

Which accounts should we look at first?

Sort Users by files reachable, descending - those are the accounts a compromise would hurt most. Then sort by last sign-in, ascending, with a license attached - those are the accounts that should not exist. Both cuts include SharePoint-only guests, so the review covers every identity that can open your files.

How far back can we look, and do we need E5?

Up to three years of activity on standard Microsoft 365 licensing - go from 180 days of history to three years. No E5, no Entra P2, no agent on the endpoint. The base connection is read-only; remediation is a separate module you enable when you want it.

Know the whole story before you need it.

Connect read-only and every user row starts assembling its history the same day - reach, activity, locations and devices in one place.

Or rebuild the next leaver review from four exports.