Case study - Medical University of Warsaw

Full visibility and control over the Microsoft 365 data of 24,000 students and academics.

A leading Polish medical university deployed a comprehensive solution for access governance, cost optimisation and protection of sensitive data across a rich Microsoft 365 ecosystem.

  • 24,000+ users
  • 11 million files
  • 67 TB in the cloud
  • 18,000 OneDrive accounts
  • 6,700 SharePoint sites

The organisation

A university hospital’s data estate, run by a handful of people.

The Medical University of Warsaw educates thousands of medical students and handles sensitive patient data for teaching and research. The university set out to deploy a new solution that would improve control over access across its extensive Microsoft 365 ecosystem.

Rapid student turnover, access to medical data and a small IT team called for something that combined security with operational efficiency.

The scale of the Microsoft 365 estate

  • 24,000+
    students, academics and administrative staff
  • 11M
    files
  • 67 TB
    of data in the cloud
  • 6,700
    SharePoint sites

Plus 18,000 OneDrive accounts, thousands of Teams teams, and sensitive personal data that requires particular care under GDPR and health-sector regulation.

Outcomes

What the 1Security rollout delivered.

  • Full visibility of the data of more than 24,000 people across SharePoint, OneDrive, Teams and Entra ID.
  • Sensitive medical and personal data located across 67 TB - and its exposure measured rather than guessed at.
  • Oversharing reduced: the widest-open sites, links and group memberships found, prioritised and cleaned up.
  • Unused Microsoft 365 licences and resources identified and reduced, freeing up IT budget.
  • Continuous monitoring of access changes for thousands of active users.
  • Stronger compliance with the requirements governing medical data.

The challenges

A vast estate, a population in constant motion, a small team.

Each of the following was true of the environment before the rollout - and any one of them would justify the project on its own.

No complete picture of access in a constantly changing ecosystem

A medical university has exceptionally high user turnover. Every year hundreds of students graduate and new ones enrol. Academics collaborate with outside research institutions, and access is granted inside teaching and research projects.

Despite the advanced administrative capabilities built into Microsoft 365, the data sat spread across separate services - SharePoint, OneDrive, Teams - and the IT team had no tooling that brought ongoing monitoring into one place.

The risk of exposing sensitive medical data

Medical universities process particularly sensitive data: patient information used for teaching, research data and medical records. Any breach can mean a violation of medical confidentiality, heavy financial penalties (tens of thousands of złoty for a single breach in the medical sector) and lasting damage to the institution’s reputation.

At the same time, the IT team had no way to automatically identify where in 67 TB of data the sensitive medical information actually sits - the places security effort should be concentrated on. Manual review does not scale to that volume.

An unusually large risk surface against limited IT capacity

The Medical University of Warsaw manages 18,000 OneDrive accounts and 6,700 SharePoint sites used by tens of thousands of people. That entire environment is administered by an IT team of a few.

Licences and cloud resources used below their potential

Research shows that educational institutions can cut Microsoft 365 costs by 14-30% through better licence management alone. What was missing was the tooling to identify:

  • inactive licences left behind by graduates and former employees
  • premium licences whose advanced M365 capabilities are never used
  • duplicate and overlapping licences
  • excessive consumption of storage space

The overhead of compliance and audit

On top of that, medical universities answer to several regulatory regimes at once:

  • GDPR and personal-data protection
  • Poland’s National Cybersecurity System Act (KSC) - the university’s clinical centre, UCK WUM, is designated a provider of an essential service
  • medical confidentiality obligations
  • ISO 27001 standards

Producing compliance reports and access audits by hand in Microsoft 365 is slow and error-prone. The reporting built into that environment requires lengthy processing, so answering auditors and regulators quickly is not realistic in practice.

“We needed a solution that would let our small IT team manage a huge, constantly changing Microsoft 365 environment. 1Security gives us the full visibility and control we simply did not have before. We can now manage security proactively instead of only reacting to incidents.”
Marcin Wszendyrowny — Medical University of Warsaw

The solution

1Security as one platform for access governance across Microsoft 365.

The Medical University of Warsaw chose 1Security as its partner for a comprehensive system to govern, monitor and optimise its Microsoft 365 environment - one that extends the administrative capabilities already available in M365.

How the rollout ran

  1. 01

    Proof of concept - complete visibility of access

    • 1Security connected to the university’s Microsoft 365 cloud environment
    • every resource, user and permission scanned and mapped
    • an interactive dashboard built to show the complete access picture
  2. 02

    Analysis of sensitive data and its exposure

    • data exposure mapped in the context of users and teams
    • 1Security’s sensitive-data detection deployed across the estate
    • potential security gaps identified
  3. 03

    Reduction and optimisation

    • oversharing worked down from the top: the widest-open sites, links and groups first
    • unused resources, dormant accounts and premium licences surfaced for review and cleanup
    • third-party and AI application access brought under review
    • automated remediation available in the platform for whenever the university chooses to switch it on

In daily use

The capabilities the university runs on.

Three of the platform’s capabilities carry the day-to-day work of the WUM IT team.

One control panel for the whole estate

Administrators moved to a single central control panel that presents all data in SharePoint, Teams, OneDrive and Entra ID (part of Microsoft 365) visually and intuitively. In real time, the IT team can see:

  • who has access to which Microsoft 365 resources, and on what basis
  • where data sits in the M365 ecosystem and how it is being used
  • which Teams teams and SharePoint sites are active, and which are unused

Automatic analysis of licence and resource usage

Administrators also started using automatic analysis of Microsoft 365 licence and resource usage, which includes identifying inactive users and unused premium M365 subscriptions. This capability could deliver savings of 14-30% of licence spend.


Sensitive-data detection, deployed

The algorithm that detects medical, personal and other sensitive data is deployed and running on the university’s content. It answers the question manual review could not: where, inside 67 TB, the sensitive material actually sits - and it scores the exposure and risk of each area of the environment, so the small IT team can put its effort where the consequences are highest.

Results

Security, efficiency and savings.

Security and compliance

  • 24,000+ people

    Full visibility of the data estate

    For the first time, the WUM IT team has a complete picture of all data in Microsoft 365, where it sits and who can reach it.

  • 43-52%

    Proactive identification of threats

    The system monitors permission changes, so potential security gaps surface before an incident. In healthcare, where 43-52% of data breaches involve Microsoft 365 misconfiguration, being proactive is decisive.

  • GDPR

    Compliance with medical regulation

    Sensitive medical and personal data is located, and continuous monitoring of who can reach it significantly reduces the risk of financial penalties for data-protection breaches.

Operational efficiency

  • Days → minutes

    IT team time returned

    Because the estate is mapped continuously, work that used to take days - preparing audit reports, analysing permissions - now takes minutes.

  • 14-30%

    Unused licences identified

    WUM has begun a licence review that could yield savings of 14-30% of Microsoft 365 cost by removing inactive and unused licences and third-party applications.

  • Hundreds of thousands of złoty

    Storage space under management

    Identifying and archiving unused data optimises Microsoft 365 cloud storage cost. Combined with the licence savings, this could add up to hundreds of thousands of złoty over the next three years.

What the rollout shows

The 1Security rollout at the Medical University of Warsaw shows how a comprehensive approach to Microsoft 365 access governance can transform the way medical universities manage security, compliance and the cost of IT services.

See the same picture of your own tenant.

Connect 1Security and get the complete access map of your Microsoft 365 - users, files, sites, teams and applications - in days, not quarters.