1Security
Screens

Activity Logs

A unified, three-year audit trail of who did what, when, from where, and on which device - across all of Microsoft 365, without premium licenses.

Activity Logs

The Activity Logs screen is your organization's memory. It brings every action across your connected Microsoft 365 environment - files, email, Teams, SharePoint, sign-ins, AI agents, third-party apps - into one searchable, long-term timeline that answers "who did what, when, from where, and on which device?"

What You Can Achieve

Investigate incidents with confidence

Trace any file, user, app, or agent back through years of history to find the root cause of an incident - not just the last 30 days Microsoft keeps by default.

Prove compliance

A complete, retained audit trail is evidence. Show auditors exactly what happened, when, and who was responsible.

Spot the abnormal

After-hours mass downloads, a sign-in from a brand-new country, activity from a VPN or datacenter - patterns that only stand out when you can see location and history together.

Oversee AI and third-party apps

Understand how Copilot, other AI agents, and connected apps are actually being used across your data.

Three Years of Retention, Out of the Box

Microsoft's default audit retention is short - often just 90 days - and extending it usually means expensive E5 or add-on licenses. 1Security retains your activity for up to three years as part of the platform (three years of usage builds up three years of history), on a standard license. When an incident surfaces months later, the trail is still there.

Every Event, Attributed

The log table turns raw, cryptic audit events into readable rows. For each action you see:

  • What happened - the action and a plain-language description, with an icon for the action type.
  • When - when it occurred, and when 1Security discovered it.
  • Who - the actor (user, app, or AI agent), clickable to their full profile.
  • On what - the file, site, group, or other resource affected (and a count when one action touched many).
  • Through what - the application or AI agent used.
  • From what device - with an indicator for managed vs. unmanaged.
  • Its severity - so the risky events stand out.

Click any row to open the full event, including the raw source record.

Location Intelligence in Your Logs

Every event now also tells you where it came from. Two columns bring this to the surface:

  • Location - the country and city behind the action.
  • Infrastructure - the type of network: an ordinary connection, or a VPN, Tor, or datacenter (the risky ones are highlighted), or Microsoft's own backend.

Many Microsoft 365 events carry Microsoft's datacenter IP rather than the user's real one. 1Security recognises this and labels it Microsoft instead of raising a false "foreign datacenter" alarm - while keeping genuine foreign sign-ins fully visible. See Location Intelligence.

Filtering by Location

Alongside the usual filters (severity, actor type, source, action, and date), you can now narrow the timeline by:

  • Country - everything from a specific country.
  • Infrastructure type - e.g. show only Tor / VPN / datacenter activity.
  • Location novelty - the first time a user was ever seen at a location versus places they've been before. First-time locations are a lightweight, high-signal indicator of a new or suspicious session.

The Locations Tab and One-Click Pivots

When you open a user's or device's drawer, the Locations tab lists everywhere that identity has been active - a travel timeline. Click any location and you jump straight to the exact log events that came from it, already filtered.

So an investigation like "I see activity attributed to Delhi, but this user works in Warsaw - show me precisely which events those were" takes a single click.

Why This Matters

Logs on their own are just data. The value is in the questions you can answer quickly: Did this account do anything it never has before? From a place it never has? On a device we don't manage? By unifying action, actor, resource, device, and location in one retained timeline, the Activity Logs screen turns raw events into answers.

On this page