How can I get a Upload/Download log of Onedrive
Hey guys, the old System Admin sharing group is gone, the newly created one still has few members and posts. I really hope a long and practical post like this will bring a fresh breeze of energy to everyone.
There have been many posts about internal data security before, you guys can search and read to dig deeper. This article is in the spirit of synthesizing, correcting, and providing the latest 2026 update for newbie Admins just getting familiar with the Microsoft ecosystem. Hope you guys support it.
Let's get started..
Basically, the workflow goes like this:
ACCESS MICROSOFT DEFENDER – OPEN ACTIVITY LOG – FILTER UPLOAD/DOWNLOAD EVENTS – TRACE THE DATA
Once you master this tool flow, you can control thousands of data in/out activities every single day.
However, unlike older monitoring tools, the current system update has some changes:
Returned data is much deeper and more detailed than before.
Requires proper Admin privileges to avoid access hurdles.
The filter fields are also way more diverse.
So how do we execute this? Read to the end and you'll see.
WHY DO WE NEED TO DO THIS?
If you've decided to make a living as a System Admin, you definitely have to make internal Data Leakage Prevention your ultimate survival goal.
The reason is that internal data leakage risks are 10 – 15 times more dangerous than external hackers.
On average, employees handle thousands of files a day. But imagine, out of nowhere, an employee quietly downloads a massive amount of highly sensitive company files right in the middle of the night? That is a huge "Red flag"!
If you don't have an Activity Log to monitor this, you won't even know where to start looking when the data evaporates.
STEP 1: ACCESS THE SYSTEM
A good management system must first be designed for easy Admin observation. After many Microsoft updates, the Security portal remains the #1 choice.
For those with Server administration experience, it probably only takes a few minutes to access and set things up perfectly to get right to work.
For the newbies who know nothing, here is a simple direction for you:
Open your browser and head straight to: security.microsoft.com
You MUST log in with an account that has Admin privileges.
Look at the left-hand navigation pane, scroll down a bit to find Cloud apps, then click on Activity log.
STEP 2: ANALYZE THE ACTIVITY LOG TABLE
This is probably the hurdle that stops many from becoming professional Admins because seeing a massive chunk of data is overwhelming, but it's really not that hard.
Once the screen loads, you get a comprehensive bird's-eye view of everything going on in your environment. Draw your attention to the table right in the center:
On the left: The specific list of Users. One look and you know exactly who is performing the action. No denying it.
Next to it: The exact timestamp down to the second. Super critical if you are trying to trace a timeline.
The best part: The column showing geographical locations and IP addresses. For example, if your company only has an office in Vietnam, and suddenly there's a file download from a bizarre country. At this point, your passion for investigation will trigger your curiosity to click and check immediately, instead of ignoring it.
STEP 3: USE FILTERS TO TRACK DOWNLOAD HISTORY
People often say, modern IT is split into two halves: one half mindlessly scrolling through lines of logs manually, and the other half knowing how to use tools. Anything done purely manually will just go from bad to worse.
Solve the problem smartly and simply using the Filter feature. By default, the system stores data for 6 months.
To check downloaded files:
Click on the Activity Type Filter box.
Type and select "Download".
Instantly, the system pulls up a whole list of events. Click on the details, and you'll see all the info: What the exact file name is (e.g., an .xlsx report), who downloaded it, exact date and time, source IP, and the device used (e.g., an iOS mobile device). One page displays up to like 250 events.
It's that simple. Don't work hard, work smart.

Comments
Post a Comment