How to detect a mouse jiggler in remote work
Published 20 August 2026 · Phitalys
An employee shows as "Available" on Teams from morning to evening, and yet deliverables are late and messages go unanswered. Before drawing any conclusion, one question must be asked: is the presence signal reliable? Detecting a mouse jiggler in remote work, in the approach described here, is not about employee surveillance — it is about verifying the reliability of an indicator that many organisations already use, in practice, as a reference point. It is also a matter of fairness: when an activity simulator distorts the presence data, it is the people who actually work who lose out.
What is a mouse jiggler?
A mouse jiggler (or "activity simulator") artificially keeps a computer in an "active" state. There are two families.
The software jiggler: a program or script that moves the cursor a few pixels at regular intervals, or simulates keystrokes. Some are legitimate utilities diverted from their purpose; others are applications built precisely to "stay green".
The hardware jiggler: a small USB device that presents itself to the system as a genuine mouse and sends micro-movements, or a mechanical pad you place the mouse on. The computer sees an authentic peripheral: no software installed, almost nothing to detect on the device side.
In both cases the effect is the same: the Teams status stays green and the screen never locks, whatever the actual activity.
Why a green status proves nothing
The Microsoft 365 presence status reflects one simple thing: the system registered a recent input (mouse, keyboard, foreground application). It indicates that a session is active, not that work is being done. The reverse is equally true: an "Away" status does not prove inactivity — an employee in a physical meeting, on the phone or deep in reading can turn orange.
Managing on status colour alone is therefore doubly unfair: it penalises those who work without touching their keyboard, and it rewards a simple USB device. If the status is going to serve as a reference point, its reliability has to be verified first. That is where objective signatures come in.
Detecting a mouse jiggler: three reliable signatures
Human activity is irregular; a simulator's is mechanical. Three signatures, observable without ever reading anyone's content, qualify the signal.
1. A mechanically regular cadence. A real working day alternates peaks and troughs: meetings, breaks, focus, moving around. A jiggler produces metronomic activity — the same micro-event, at the same interval, for hours. This perfect regularity resembles no human behaviour: it is the most characteristic signature.
2. Presence without output. A workstation "active" all day that generates no trace of production — not one email sent, not one message, not one document opened or edited — is a measurable anomaly. This is strictly about volumes, never content: we count, we do not read.
3. A status frozen without transitions. A human Teams status lives: it moves from "Available" to "Busy" during a meeting, to "Away" at a break, then back. A status locked on "Available" for hours, with no transition at all, is an indicator of artificially maintained presence. The same reasoning applies to fake Teams meetings that simulate presence through the calendar — a different trick, the same convergence-based detection.
Taken in isolation, each of these signals can have a legitimate explanation. It is their dated, documented convergence that constitutes a serious reference point — a starting point for a conversation, never proof in itself.
Detecting a hardware mouse jiggler: why USB changes nothing
The selling point of hardware jigglers is their invisibility: the workstation sees an authentic mouse, and conventional endpoint security struggles to tell the difference. That is largely true — at the device level.
But a USB device does not write emails, does not open documents and does not answer messages. Nor does it reproduce the natural transitions of a human status, or the irregularity of real activity. In other words, a hardware jiggler fools the computer, not the usage data. The three signatures above — mechanical cadence, presence without output, frozen status — remain fully observable on the Microsoft 365 side, without installing anything on the devices. Detection does not happen at the peripheral level; it happens at the signal level.
How it works
Phitalys' Microsoft 365 presence analysis is agentless: nothing is installed on workstations, no screenshots, no recording. Reading happens on the Microsoft 365 side, through the Graph API, read-only and with the tenant administrator's consent.
The tool observes the signals described above — status transitions, activity cadence, output volumes (emails, messages, documents), recurring meetings where the organiser is alone with no camera or microphone, out-of-hours activity with no associated output — and turns them into dated, explainable reference points: this period, this pattern, and the reason this signal stands out. The full list is on the detection section of our homepage.
The result is never an automated verdict. A flagged pattern may reflect an activity simulator, but also an overload, a misconfigured tool or a personal difficulty. It is up to the manager and HR to open the conversation, with dated facts rather than impressions.
The fair method: transparency, works council, proportionality
Activity monitoring of this kind cannot be improvised. In France, the Labour Code sets two established obligations: informing employees beforehand about any system collecting data that concerns them personally (Article L1222-4), and consulting the works council (CSE), where one exists, before deploying any means of monitoring employee activity (Article L2312-38). Comparable transparency and consultation requirements exist across much of Europe.
Beyond that, GDPR and data-protection authorities call for data minimisation and for the system to be proportionate to its purpose — and courts tend to dismiss evidence obtained through a system employees were not told about. Phitalys is built in that spirit: only volumes are processed, never content; aggregates over small groups (fewer than five people by default) are masked; every individual-level access is logged; and detection modules are off by default — they are only enabled after an explicit decision by the organisation, once information and consultation have taken place. The details are on our security and compliance page.
One essential point to close: no tool can guarantee that a finding will be legally admissible in a given context. Before any disciplinary use, legal advice specific to your situation (employment lawyer, DPO) remains necessary.
FAQ
Is a hardware mouse jiggler really undetectable?
It is very hard to detect at the workstation level, which sees an authentic mouse. But it produces no emails, no messages, no documents, and no natural status transitions: on the Microsoft 365 side, the signatures of artificial presence remain observable.
Can an employee be sanctioned on the basis of these signals?
That is not what they are for. The reference points produced are a factual starting point for a conversation, not proof of misconduct. Any disciplinary follow-up would require a fair framework (prior information, works-council consultation) and legal advice suited to the context; nothing guarantees in advance that a judge would accept a given element.
Do employees have to be informed about the system?
Yes. Prior information of employees and, where employee representation exists, its consultation are required before any deployment — in France under Articles L1222-4 and L2312-38 of the Labour Code. It is also a condition of the system's effectiveness: a transparent framework is generally dissuasive and preserves trust.