---
title: Activity Logs
description: A unified, three-year audit trail of who did what, when, from where, and on which device - across all of Microsoft 365, without premium licenses.
icon: Activity
---

# Activity Logs

The Activity Logs screen is your organization's memory. It brings every action across your connected Microsoft 365 environment - files, email, Teams, SharePoint, sign-ins, AI agents, third-party apps - into one searchable, long-term timeline that answers **"who did what, when, from where, and on which device?"**

## What You Can Achieve

<Cards>
  <Card
    title="Investigate incidents with confidence"
    description="Trace any file, user, app, or agent back through years of history to find the root cause of an incident - not just the last 30 days Microsoft keeps by default."
  />
  <Card
    title="Prove compliance"
    description="A complete, retained audit trail is evidence. Show auditors exactly what happened, when, and who was responsible."
  />
  <Card
    title="Spot the abnormal"
    description="After-hours mass downloads, a sign-in from a brand-new country, activity from a VPN or datacenter - patterns that only stand out when you can see location and history together."
  />
  <Card
    title="Oversee AI and third-party apps"
    description="Understand how Copilot, other AI agents, and connected apps are actually being used across your data."
  />
</Cards>

## Three Years of Retention, Out of the Box

Microsoft's default audit retention is short - often just 90 days - and extending it usually means expensive E5 or add-on licenses. 1Security retains your activity for **up to three years** as part of the platform (three years of usage builds up three years of history), on a standard license. When an incident surfaces months later, the trail is still there.

## Every Event, Attributed

The log table turns raw, cryptic audit events into readable rows. For each action you see:

- **What happened** - the action and a plain-language description, with an icon for the action type.
- **When** - when it occurred, and when 1Security discovered it.
- **Who** - the actor (user, app, or AI agent), clickable to their full profile.
- **On what** - the file, site, group, or other resource affected (and a count when one action touched many).
- **Through what** - the application or AI agent used.
- **From what device** - with an indicator for managed vs. unmanaged.
- **Its severity** - so the risky events stand out.

Click any row to open the full event, including the raw source record.

## Location Intelligence in Your Logs

Every event now also tells you **where it came from**. Two columns bring this to the surface:

- **Location** - the country and city behind the action.
- **Infrastructure** - the type of network: an ordinary connection, or a **VPN**, **Tor**, or **datacenter** (the risky ones are highlighted), or **Microsoft**'s own backend.

<Callout type="info">
  Many Microsoft 365 events carry Microsoft's datacenter IP rather than the
  user's real one. 1Security recognises this and labels it **Microsoft** instead
  of raising a false "foreign datacenter" alarm - while keeping genuine foreign
  sign-ins fully visible. See [Location Intelligence](/en/docs/location).
</Callout>

### Filtering by Location

Alongside the usual filters (severity, actor type, source, action, and date), you can now narrow the timeline by:

- **Country** - everything from a specific country.
- **Infrastructure type** - e.g. show only Tor / VPN / datacenter activity.
- **Location novelty** - the _first time_ a user was ever seen at a location versus places they've been before. First-time locations are a lightweight, high-signal indicator of a new or suspicious session.

### The Locations Tab and One-Click Pivots

When you open a user's or device's drawer, the **Locations** tab lists everywhere that identity has been active - a travel timeline. **Click any location and you jump straight to the exact log events that came from it**, already filtered.

So an investigation like _"I see activity attributed to Delhi, but this user works in Warsaw - show me precisely which events those were"_ takes a single click.

## Why This Matters

Logs on their own are just data. The value is in the questions you can answer quickly: _Did this account do anything it never has before? From a place it never has? On a device we don't manage?_ By unifying action, actor, resource, device, and location in one retained timeline, the Activity Logs screen turns raw events into answers.
