Skip to main content

Microsoft 365 | Users Active Last 30 Days Data

User “activity” within the last 30 days

Overview ✨

This article explains how Liongard determines Microsoft 365 user activity for the Users Active Last 30 Days metric and why results may differ from what you expect to see in Microsoft admin portals.

⭐️ Summary: This metric is based on Microsoft mailbox activity reporting, not a direct last-login value. A user may be counted as active when Microsoft reports mailbox activity within the last 30 days. If mailbox usage data is unavailable or cannot be matched to the user, the activity-related fields may appear blank and the user may be excluded from the count.


What this metric means

The Users Active Last 30 Days metric is intended to identify users whose Microsoft 365 mailbox activity indicates recent use within a 30-day window.

This value is derived from Microsoft reporting data returned by the mailbox usage reporting endpoint. Liongard evaluates the user’s Last Activity Date and determines whether that date falls within the last 30 days. If it does, the user is treated as active for this metric.

‼️ Important: This is not the same as last sign-in time and should not be interpreted as a direct authentication log. Microsoft measures this activity based on report data, which can reflect mailbox-related usage rather than a traditional user login event.


What counts as activity

For this metric, activity is tied to Microsoft mailbox usage reporting. In practical terms, this can include Exchange-related usage signals reflected in Microsoft’s reporting data, such as recent mailbox interaction.

Because the source is mailbox reporting, this metric is best understood as a mailbox activity indicator, not a universal measure of all Microsoft 365 service usage.


How the 30-day calculation works

Liongard checks the Microsoft-reported Last Activity Date for each applicable user record. If that value is within the previous 30 days, the user is included in the active count.

If the value is older than 30 days, the user is not included. If the value is missing, Liongard cannot confirm recent mailbox activity from this data source.

✅ Current behavior: The mailbox usage reporting window used for this data supports a 30-day period, which improves visibility for users whose most recent mailbox activity occurred between 8 and 30 days ago.


Why this may not match last login

It is common to compare this metric to sign-in information from Microsoft Entra ID, Azure AD, or other audit sources. Those values may not match, because they represent different activity signals.

  • Users Active Last 30 Days reflects mailbox usage reporting.

  • Last sign-in reflects authentication activity.

  • Non-interactive sign-in activity may include background token refreshes and service-driven access.

A user could sign in to Microsoft 365 and still show no recent mailbox activity in this metric. Likewise, a user could have mailbox activity reflected in reporting that does not align with the exact login behavior you expect.


When values may be blank or inconsistent

If Last Activity Date is blank or users are unexpectedly excluded from the Users Active Last 30 Days count, one of the most common causes is that Microsoft mailbox usage data is not being returned in a way that can be associated to specific users.

This can happen when the tenant is configured to conceal user identities in Microsoft 365 reports. In that case, Microsoft may return anonymized identifiers instead of usable user values, which prevents mailbox usage records from being matched correctly.

⚠️ Common cause of blank values: If Microsoft 365 report concealment is enabled, mailbox-related fields such as Last Activity Date may remain blank even when the user has activity. This is a tenant-side configuration issue, not necessarily a product defect.

For guidance on that specific condition, see Microsoft 365 | Obscured Mailbox Data.


What to check if the metric seems incorrect

What to review

Why it matters

What to expect

Last Activity Date

This is the source used for the 30-day calculation

If within the last 30 days, the user should be counted as active

Mailbox usage availability

The metric depends on Microsoft mailbox reporting data being returned

If mailbox data is unavailable, the activity signal may be blank

Microsoft report concealment setting

Concealed identities can prevent user matching

Blank mailbox-related fields and missing users from the count

Recent inspection results

Updated values appear only after a successful inspection

Run or review a fresh inspection before comparing results


How to interpret this metric correctly

Use Users Active Last 30 Days as a reporting signal for recent Microsoft mailbox activity. It is useful for spotting users with recent mailbox usage, but it should not be used as the sole authority for authentication history, licensing decisions, or account security reviews.

If you need to evaluate true authentication behavior, compare this data with Microsoft sign-in records and your organization’s identity reporting.

If you still see unexpected results

If the metric still does not align with your expectations after a fresh inspection, review whether user identity concealment is enabled in Microsoft 365 reports and confirm that mailbox usage data is being returned for the tenant.

If needed, contact support and include examples of affected users, the relevant inspection output, and whether the tenant is configured to display concealed names in reports.


References

Did this answer your question?