Activities
Watch the extremes of your Microsoft 365 collaboration - the biggest activity spikes and the completely dormant - to catch threats, benchmark usage, and reclaim wasted spend, sometimes in as little as one hour.
Activities
Most dashboards show you an average. Averages hide the two things that actually matter: the resource that suddenly did far more than it should, and the resource that has done nothing for months. Activities are the top-and-bottom cuts of your Microsoft 365 collaboration - the user who downloaded 4,000 files this week, the agent nobody has used since it was built, the site that went quiet the day a project ended. Same permission-graph data as the rest of 1Security, viewed from its edges, where risk and waste both live.
An activity is one question - "who did the most of X in the last window?" or "what hasn't been touched in N days?" - answered as a ranked list with a trendline, refreshed continuously, and turnable into an alert with one click.
What You Can Achieve
Catch a spike before it becomes a breach
Top downloaders, sharers, and deleters over trailing windows as short as one hour - evaluated from raw activity, not day-late rollups. A dormant account that suddenly downloads thousands of files jumps to the top of the list while it's still happening.
Reclaim wasted Microsoft spend
Unused apps, unused AI agents, dormant users, and quiet sites - ranked by how long they've been idle. Every dormant licensed user and every abandoned app is money you can hand back, measured instead of guessed.
Govern AI adoption with real numbers
Top Copilot / AI users, the most-active agents, and the agents nobody uses - so 'how is AI actually being used here?' is a ranked list, not a hunch.
Benchmark collaboration over time
Most-active users, most-shared files, busiest sites and groups, most-active devices - each with a sparkline, so a suddenly-busy dormant resource is visible at a glance.
Two kinds of cut
Every activity is one of two shapes (as of now - more activity types almost done!):
- Top activity - the ranked leaders for an action over a window. Top downloaders this week. Most-shared files this month. Most-active agents. Top AI users. Busiest devices. The answer to "who / what is doing the most of this, right now?"
- Unused - resources with no activity for N or more days, ranked by how long they've been idle. Unused apps. Unused agents. Dormant users. Quiet sites. Idle devices. Files nobody has touched in a year. The answer to "what can I safely decommission or reclaim?"
The same eight resources you already know from the sidebar are all first-class types: users, files, sites, groups, emails, apps, agents, and devices - and both cuts apply to every one of them. Each type ranks by its own last-activity signal: sign-ins for devices, audit-log activity for users, sites, groups, apps, agents, and files - a file counts as active when anyone so much as views it, falling back to its last modification for history that predates your audit logs.
Scope every activity to a question
An activity is built from three choices, so a single mechanism covers dozens of classic security and cost cuts:
- Type - the resource being ranked (user, file, site, group, email, app, agent, device).
- Action - what counts as activity: created, viewed, downloaded, modified, shared, moved, deleted, permission changed, restored, authenticated, AI used, meeting, access blocked - or any activity for a raw volume ranking. Actions map onto real Microsoft 365 audit events (e.g. shared covers
SharingSet,AnonymousLinkCreated,SecureLinkCreated), so the cut lines up with what actually happened in the tenant. - Window - the trailing period the cut is measured over.
Windows run from near-real-time to all-time:
- 1 hour · 12 hours · 24 hours - true trailing windows evaluated directly from raw activity logs. This is prevention-grade detection: a mass download or mass share surfaces here while it's unfolding, not in tomorrow's report.
- 7 · 30 · 90 days - the standard reporting windows, served from daily rollups so even the largest tenants answer instantly.
- 1 year · all-time - for unused activities, where "how long has this been idle?" is the whole point. (File and email top-activity cuts stay within 90 days - those tables reach tens of millions of rows per window. Their unused cuts carry no such cap: finding a file untouched for a year is exactly the point.)
The sub-day windows are why Activities help stop threats in as little as one hour. A compromised account exfiltrating files, or an agent suddenly reaching far more than usual, rises to the top of a 1-hour cut in near real time - long before a daily digest would notice.
The board
Activities live on a customizable board of cards. Each card is one activity - its ranked rows, a value per row, and a sparkline of the trend across the window. Click view all on any card to open the full paginated list; click a row to jump straight into that user, file, agent, or device.
- Seeded to be useful on day one. A fresh tenant starts with the classic cuts already on the board: top downloaders, most-active and unused agents, most-shared files, top AI users, and most-active devices - so the board is worth reading before you've configured anything.
- Yours to shape. Add, remove, and arrange cards for the questions your team actually asks. Pick the type, action, window, and how many rows to show.
- Shareable. Mark an activity shared and it appears on every admin's board in the tenant (read-only for everyone but its owner) - the same model as saved views. One person curates "the numbers that matter," everyone sees them.
Turn any activity into an alert
An activity answers "what's happening now." An alert rule turns it into "tell me the moment it does." Any activity can become an alert rule with one click - it becomes a first-class policy alongside your trends and (soon) automations, and fires into the same alerts stream.
Thresholds follow the kind of cut:
- Top activity - alert when an entity crosses N actions within the window (e.g. any user who downloads more than 1,000 files in 24 hours).
- Unused - alert when an entity has had no activity for N or more days (e.g. any app idle for 90 days).
Each policy carries a severity, an evaluation cadence (hourly, daily, or weekly), and optional email recipients. Pair an hourly cadence with a 1-hour window and you have continuous, near-real-time detection for mass-download and mass-share abuse - defense while it's happening, not a post-incident autopsy.
Investigative patterns
The exfiltration tripwire: top downloaders, action downloaded, window 1 hour, alert threshold a few hundred. A departing employee or a compromised account draining a document library trips this while it's still draining.
- License reclaim - unused users over 1 year: dormant licensed accounts you can offboard or downgrade. Do the same for unused apps and unused agents to retire what nobody touches.
- Device reclaim - unused devices over 90 days: machines that still hold access but that nobody signs in from - revoke the access, get the hardware back.
- AI governance review - top AI users over 30 days next to unused agents: who is actually leaning on Copilot, and which agents you built and then abandoned.
- Insider-share watch - top sharers, action shared, window 24 hours: the accounts creating the most sharing links, where "anyone with the link" URLs are born.
- Site lifecycle - quiet sites over 90 days: project sites that went dormant and are candidates for archival before they become forgotten oversharing.
- Suspicious device surge - most-active devices over 24 hours: an unrecognized or rarely-used device doing an unusual volume of work.