---
title: Activities
description: Watch the extremes of your Microsoft 365 collaboration - the biggest activity spikes and the completely dormant - to catch threats, benchmark usage, and reclaim wasted spend, sometimes in as little as one hour.
icon: Activity
---

# Activities

Most dashboards show you an average. Averages hide the two things that actually matter: the resource that suddenly did far **more** than it should, and the resource that has done **nothing** for months. Activities are the top-and-bottom cuts of your Microsoft 365 collaboration - the user who downloaded 4,000 files this week, the agent nobody has used since it was built, the site that went quiet the day a project ended. Same permission-graph data as the rest of 1Security, viewed from its edges, where risk and waste both live.

An activity is one question - _"who did the most of X in the last window?"_ or _"what hasn't been touched in N days?"_ - answered as a ranked list with a trendline, refreshed continuously, and turnable into an alert with one click.

## What You Can Achieve

<Cards>
  <Card
    title="Catch a spike before it becomes a breach"
    description="Top downloaders, sharers, and deleters over trailing windows as short as one hour - evaluated from raw activity, not day-late rollups. A dormant account that suddenly downloads thousands of files jumps to the top of the list while it's still happening."
  />
  <Card
    title="Reclaim wasted Microsoft spend"
    description="Unused apps, unused AI agents, dormant users, and quiet sites - ranked by how long they've been idle. Every dormant licensed user and every abandoned app is money you can hand back, measured instead of guessed."
  />
  <Card
    title="Govern AI adoption with real numbers"
    description="Top Copilot / AI users, the most-active agents, and the agents nobody uses - so 'how is AI actually being used here?' is a ranked list, not a hunch."
  />
  <Card
    title="Benchmark collaboration over time"
    description="Most-active users, most-shared files, busiest sites and groups, most-active devices - each with a sparkline, so a suddenly-busy dormant resource is visible at a glance."
  />
</Cards>

## Two kinds of cut

Every activity is one of two shapes (as of now - more activity types almost done!):

- **Top activity** - the ranked leaders for an action over a window. _Top downloaders this week. Most-shared files this month. Most-active agents. Top AI users. Busiest devices._ The answer to "who / what is doing the most of this, right now?"
- **Unused** - resources with no activity for N or more days, ranked by how long they've been idle. _Unused apps. Unused agents. Dormant users. Quiet sites. Idle devices. Files nobody has touched in a year._ The answer to "what can I safely decommission or reclaim?"

The same eight resources you already know from the sidebar are all first-class types: **users, files, sites, groups, emails, apps, agents, and devices** - and both cuts apply to every one of them. Each type ranks by its own last-activity signal: sign-ins for devices, audit-log activity for users, sites, groups, apps, agents, and files - a file counts as active when anyone so much as views it, falling back to its last modification for history that predates your audit logs.

## Scope every activity to a question

An activity is built from three choices, so a single mechanism covers dozens of classic security and cost cuts:

- **Type** - the resource being ranked (user, file, site, group, email, app, agent, device).
- **Action** - what counts as activity: _created, viewed, downloaded, modified, shared, moved, deleted, permission changed, restored, authenticated, AI used, meeting, access blocked_ - or **any activity** for a raw volume ranking. Actions map onto real Microsoft 365 audit events (e.g. _shared_ covers `SharingSet`, `AnonymousLinkCreated`, `SecureLinkCreated`), so the cut lines up with what actually happened in the tenant.
- **Window** - the trailing period the cut is measured over.

Windows run from **near-real-time to all-time**:

- **1 hour · 12 hours · 24 hours** - true trailing windows evaluated directly from raw activity logs. This is prevention-grade detection: a mass download or mass share surfaces here while it's unfolding, not in tomorrow's report.
- **7 · 30 · 90 days** - the standard reporting windows, served from daily rollups so even the largest tenants answer instantly.
- **1 year · all-time** - for unused activities, where "how long has this been idle?" is the whole point. (File and email **top-activity** cuts stay within 90 days - those tables reach tens of millions of rows per window. Their unused cuts carry no such cap: finding a file untouched for a year is exactly the point.)

<Callout type="info">
  The sub-day windows are why Activities help stop threats **in as little as one
  hour**. A compromised account exfiltrating files, or an agent suddenly
  reaching far more than usual, rises to the top of a 1-hour cut in near real
  time - long before a daily digest would notice.
</Callout>

## The board

Activities live on a customizable board of cards. Each card is one activity - its ranked rows, a value per row, and a sparkline of the trend across the window. Click **view all** on any card to open the full paginated list; click a row to jump straight into that user, file, agent, or device.

- **Seeded to be useful on day one.** A fresh tenant starts with the classic cuts already on the board: top downloaders, most-active and unused agents, most-shared files, top AI users, and most-active devices - so the board is worth reading before you've configured anything.
- **Yours to shape.** Add, remove, and arrange cards for the questions your team actually asks. Pick the type, action, window, and how many rows to show.
- **Shareable.** Mark an activity **shared** and it appears on every admin's board in the tenant (read-only for everyone but its owner) - the same model as [saved views](/en/docs/screens/activity-logs). One person curates "the numbers that matter," everyone sees them.

## Turn any activity into an alert

An activity answers "what's happening now." An **alert rule** turns it into "tell me the moment it does." Any activity can become an alert rule with one click - it becomes a first-class [policy](/en/docs/screens/trends) alongside your trends and (soon) automations, and fires into the same alerts stream.

Thresholds follow the kind of cut:

- **Top activity** - alert when an entity crosses **N actions within the window** (e.g. _any user who downloads more than 1,000 files in 24 hours_).
- **Unused** - alert when an entity has had **no activity for N or more days** (e.g. _any app idle for 90 days_).

Each policy carries a severity, an evaluation cadence (**hourly, daily, or weekly**), and optional email recipients. Pair an hourly cadence with a 1-hour window and you have continuous, near-real-time detection for mass-download and mass-share abuse - defense while it's happening, not a post-incident autopsy.

## Investigative patterns

<Callout type="info">
  **The exfiltration tripwire**: _top downloaders_, action **downloaded**,
  window **1 hour**, alert threshold a few hundred. A departing employee or a
  compromised account draining a document library trips this while it's still
  draining.
</Callout>

- **License reclaim** - _unused users_ over **1 year**: dormant licensed accounts you can offboard or downgrade. Do the same for _unused apps_ and _unused agents_ to retire what nobody touches.
- **Device reclaim** - _unused devices_ over **90 days**: machines that still hold access but that nobody signs in from - revoke the access, get the hardware back.
- **AI governance review** - _top AI users_ over **30 days** next to _unused agents_: who is actually leaning on Copilot, and which agents you built and then abandoned.
- **Insider-share watch** - _top sharers_, action **shared**, window **24 hours**: the accounts creating the most sharing links, where "anyone with the link" URLs are born.
- **Site lifecycle** - _quiet sites_ over **90 days**: project sites that went dormant and are candidates for archival before they become forgotten oversharing.
- **Suspicious device surge** - _most-active devices_ over **24 hours**: an unrecognized or rarely-used device doing an unusual volume of work.
