---
title: Sensitivity Scanning
description: Find sensitive data across Microsoft 365 with 1Security's own 300-detector scanning engine - including OCR for scans and screenshots - on a standard license, no E5 or Purview required.
icon: ShieldAlert
---

# Sensitivity Scanning

Sensitivity scanning answers a question Microsoft puts behind its most expensive licenses: **"Where is our sensitive data - and who can reach it?"** 1Security ships its own scanning engine that reads file and email content, detects over 300 types of sensitive information - credit card numbers, personal identifiers, financial records - and connects every detection to the permission graph. It runs on a **standard Microsoft 365 Business Basic license**.

## What You Can Achieve

<Cards>
  <Card
    title="Classify without premium licensing"
    description="Deep data discovery without E5 or a Purview deployment. The engine is 1Security's own - organizations with no Microsoft classification investment get full coverage from day one."
  />
  <Card
    title="Read what attackers actually read"
    description="Card numbers live in scanned contracts, screenshots, and photographed documents - not just spreadsheets. Built-in OCR reads text inside images, where text-only scanners are blind."
  />
  <Card
    title="See exposure, not just existence"
    description="A detection isn't a row in a report - it's flagged in the permission graph. The question instantly becomes 'who can access this?' instead of 'somewhere we have credit cards.'"
  />
  <Card
    title="Verify Purview instead of trusting it"
    description="If you run Microsoft Purview, 1Security syncs its detections alongside its own - an independent second engine that shows where the two disagree."
  />
</Cards>

## How the Scan Works

1. **Extraction** - text is securely extracted from documents, spreadsheets, presentations, and emails.
2. **OCR** - for images and scanned documents, built-in optical character recognition reads the text inside the pixels.
3. **Pattern matching** - extracted text is evaluated against the library of 300+ sensitive information patterns, each detection carrying a confidence level.
4. **Risk assessment** - files and emails with detections are flagged in the permission graph and across every screen, so exposure analysis starts immediately.

## Supported Formats and Limitations

The scanner focuses on the formats where business data actually lives:

- **Documents**: `.txt`, `.csv`, `.docx`, `.pdf`, `.xlsx`, `.pptx`
- **Images (OCR)**: `.jpg`, `.jpeg`, `.png`, `.gif`, `.bmp`, `.tif`, `.tiff`, `.webp`
- **Emails**: message bodies are enriched and scanned.

**Performance limits:**

- **File size** - files up to **50 MB** are scanned; larger files are skipped to keep the system responsive.
- **PDF depth** - the **first 5 pages** of each PDF are processed, capturing the most relevant context.
- **Embedded images** - up to **10 embedded images** per document (e.g. `.docx`) go through OCR.

## Where Detections Land

- The [Sensitive Info screen](/en/docs/screens/sensitive-info) rolls every detection type into an estate-wide map: which files, emails, sites, groups, users, and apps each type touches, filterable by compliance framework (GDPR, HIPAA, PCI-DSS, and more).
- The [Files](/en/docs/screens/files) and [Emails](/en/docs/screens/email) screens filter by sensitive info presence, specific types, minimum counts, and confidence - and combine those with sharing and exposure filters.
- The [Sensitivity Labels screen](/en/docs/screens/sensitivity-labels) closes the loop: compare what the scan _found_ against what Purview labels _cover_, and measure your real protection gap.

## Licensing Requirements

You do not need premium Microsoft licenses for deep security visibility. **Nearly every functionality in 1Security works with a standard Microsoft 365 Business Basic license.**

The only exceptions that require advanced Microsoft licenses are:

- **Security Alerts** - requires **Microsoft Defender** to pull native security alerts into 1Security.
- **Sensitivity Labels** - requires **Microsoft Purview** if you want to sync and display Purview's native labels alongside 1Security's findings.

<Callout type="info">
  Even without Microsoft Purview, 1Security's independent sensitivity engine
  fully classifies and analyzes your sensitive data - Purview adds a second
  opinion, not the first one.
</Callout>
