1Security
Platform Updates

July 2026 Platform Update

The first consolidated 1Security platform update - seven new modules (Agents, Automations, Anomalies, Activities, unified alerting, Devices, Locations), real-time evaluation across the product, a polished dark theme, and several hundred improvements shipped between May and July 2026.

Platform Update - July 2026

This is our first consolidated platform update, written for everyone who works in the product - the teams running 1Security day to day and the partners who look after them. It covers everything that landed between 1 May and 30 July 2026: seven new modules, a real-time evaluation path underneath all of them, a dark theme for the whole dashboard, and several hundred smaller improvements to the screens you already use every day.

If you read one section, read Automations and Unified alerting below: together they close the loop between "1Security found it" and "it is fixed, and we can prove it".

Headlines

Automations

26 suggested remediations counted against the live tenant, a grace period with a human review queue, and a full action catalog across sites, files, users, groups, apps, devices, email and licenses.

Anomalies

Not a black box: every deviation is recorded, and you decide where the alert line sits. Move the dial and the whole history re-classifies instantly - full visibility without the alert flood.

Activities

Top-and-bottom cuts of Microsoft 365 collaboration - top downloaders, unused agents, dormant licensed users - with trailing windows as short as one hour, evaluated from raw activity.

Unified alerting

Instant and digest alerting shared by trends, activities, automations and anomalies. The default rule needs no numbers from you: it watches deviation from the policy's own baseline.

Agents

Microsoft is turning every AI agent into an identity with permissions. One inventory for all of them - Entra, Copilot Studio, Azure AI Foundry and declarative Copilot agents - with what each can actually reach, what it is told to do, and what it did.

Devices

Identity attacks surface on the device layer first. Beyond what Intune can know: unregistered machines and persistent shadow devices using legitimate tokens, reconstructed from real activity, with per-action attribution.

Locations

If you operate in Europe, activity from Asia is a red flag before anything else is checked. Country, city and network resolved for every sign-in and data action, with Microsoft's own datacenter noise labelled out of the way.

Everything that writes is opt-in. 1Security's core application remains read-only. Remediation requires a second, separately consented write application - and even then, an automation with a review window stages proposals instead of acting. Nothing in this release changes your tenant without an explicit, revocable consent.

New: Automations - from findings to fixes

The gap every security product leaves open is the one between the finding and the fix. Automations closes it.

  • We show the number, not the promise. For every suggested automation, 1Security counts how many resources in this tenant it would fix right now - and shows that number on the card before anything is enabled. The catalog is 26 curated remediation policies in 13 groups across four themes (AI safety, oversharing, hygiene, cost), each counted against live data in your tenant. The first question stops being "what could this do?" and becomes "what did it find here, and do I want it fixed?".
  • Preview before enabling. Every suggestion opens onto the real list of affected resources, the conditions used, and the arguments the action would run with. Suggestions with illustrative defaults are flagged Review before enabling and left unchecked.
  • Review & customize opens the suggestion in the policy editor - conditions, arguments, name and severity - and the customization survives future catalog updates.
  • A grace period with a human review queue. Enable a suggestion and the default is a 72-hour window: the automation stages a proposal per resource instead of firing. Approve, reject (which snoozes the resource for 30 days), withdraw, or simply let the clock run out. Bulk review applies decisions by match rather than by a frozen id list, so proposals arriving mid-review are included.
  • A full action catalog covering sites (sharing capability, link defaults, external expiry, privacy, Copilot indexing, ownership), files (link removal by scope, permission revoke/downgrade, composite access revocation, deletion), users, groups, apps, devices, email and licenses.
  • Manual actions share the same catalog and the same ledger - run an action once from a list selection or a resource drawer, and it is recorded exactly like a policy-driven one.
  • Composite actions understand the permission graph. Revoke this user's access to these files resolves direct grants, links, group membership and site membership, removes what it safely can and asks for confirmation where the removal would affect other people, showing the blast radius per source.
  • Operational transparency: four counters (active, runs in 30 days, resources remediated in 30 days, open matches), an "engine live - last evaluation X ago" strip, an actions-performed chart from 1 hour to 1 year with click-through to the exact resources changed, per-automation firing stats, and pause/resume on any automation.

New: Anomalies - full visibility without the alert flood

Anomaly detection is normally a black box. The threshold was picked by somebody else, you cannot see it and you cannot move it, and anything that does not clear it is simply thrown away. It ends one of two ways: the system fires so often that nobody reads it after a week, or it stays quiet - and you have no way of telling whether it is quiet because nothing is happening, or because the threshold cut off exactly the thing that mattered. A critical anomaly disappears without a trace that it ever existed.

Tuning is not safe in those tools either. A new threshold only applies from tomorrow, so you never find out what it would have caught yesterday, and every move of the slider is a bet: either you get flooded, or you silence something you did not know was there. So nobody touches it, and everyone lives with a setting no one consciously chose.

Anomalies splits the decision that other tools merge into one:

  • What is unusual is measured and always recorded. Every meaningful deviation - down to 2 sigma - is kept as Info: visible on the screen, filterable, part of the history, and never mailed to anyone.
  • What is worth an alert is a line you set. Above it an anomaly is Alerted and notifies its recipients. Below it nothing is lost - it simply is not shouting at you.

Because nothing is discarded, the dial is safe to move in either direction, and it answers immediately: let go of the slider and your existing history is re-classified at read time. You see what a stricter or a looser setting would have caught, on real activity from your own tenant, with no tuning period, no shadow mode and no quarter of waiting to find out whether the number was right.

  • A bank, hospital or law firm drags the line down. Everything the detector ever found noteworthy becomes Alerted, retroactively - and the audit question "would we have seen it?" is answered by looking, not by hoping.
  • A 30-person company or an agency pushes it the other way. The queue shrinks to the handful of episodes worth a human's attention, and everything else stays recorded for the day it becomes relevant.
  • Same tenant, same data, same detector. A regulated organisation and a relaxed one are not running different products, or different tiers - the dial is simply in a different place.

Underneath the dial:

  • A baseline per policy, per user, per app and per AI agent - "anomalous" always means anomalous for this one, in this tenant. Today is compared against the median of the trailing 30 days, and an episode opens when it spikes above it.
  • Robust statistics. Median and median absolute deviation, today excluded from its own baseline, with a Poisson tail test for rare events and a percentage jump for high-volume ones, so every episode lands on one comparable score - which is what makes a single dial meaningful across policies of wildly different sizes.
  • Episodes, not events - open / acknowledged / dismissed triage, peak tracking, one notification per episode, and a 14-day warm-up before detection says anything at all.
  • Tenant-level alerting with instant and digest channels, spike / drop / silence switches, and a quiet period that sends nothing rather than a "nothing happened" mail.

Worth doing on your first day with the screen: drag the sensitivity down and watch the Info tier turn into Alerted episodes. It shows two things at once - that everything has been recorded since detection started, and that where the alert line sits is your decision rather than a vendor's.

New: Activities - the extremes of collaboration

Activities ranks the top and the completely dormant across all eight resource types - users, files, sites, groups, emails, apps, agents and devices.

  • Two cuts: top activity (who did the most of X in the window) and unused (what has done nothing for N days).
  • Windows from one hour to all-time. The 1 / 12 / 24-hour windows are evaluated directly from raw activity logs - prevention-grade detection while a mass download is still unfolding - while 7 / 30 / 90-day windows are served from rollups so the largest tenants answer instantly.
  • A customizable, shareable board seeded with the classic cuts on day one; mark an activity shared and it appears on every admin's board.
  • One click turns any activity into an alert rule with its own threshold, severity, cadence and recipients.

New: Unified alerting - one mechanism everywhere

Trends, activities, automations and anomalies now share a single alerting model with two deliberately separate channels:

  • Digest - the reporting cadence you already know (interval + recipients).
  • Instant - evaluated on the real-time path and mailed the moment a line is crossed, with a cooldown so a jumpy policy cannot mail hourly.

What makes it a one-click feature is the default: deviation from the policy's own baseline (+50%), which needs no number from you. Thresholds remain available for teams that know their number. Deviation is three independent switches rather than a direction - spike (on by default), drop (off, because holidays and conference weeks depress nearly every policy at once) and silence (off; a count hitting zero usually means something broke, not that the team was away).

All platform mail is now in-house. Alert summaries, instant alerts, anomaly notifications and transactional mail all go out through Microsoft Graph from a dedicated mailer application, with a shared branded layout and attachment support.

New: Agents - one source of truth for the agentic tenant

Microsoft is rebuilding Microsoft 365 around agents, and the security consequence is easy to state: every agent is a new identity with its own permissions, its own data reach and its own activity - created by people who do not think of themselves as granting access. An employee builds a Copilot agent in an afternoon, a vendor ships one with a product you licensed, a platform team spins one up in Azure AI Foundry, and each of them quietly acquires a slice of the tenant. Nothing in the Microsoft admin surface puts those three in the same list.

Agents is that list - a domain of its own, not a filter over applications, because agents have structure applications do not.

  • Every agent ecosystem in one inventory. Entra Agent ID agents (the three-tier blueprint model), service principals tagged by Copilot Studio and Azure AI Foundry, and - once an admin connects it - the declarative Copilot agents from the Microsoft 365 agent catalog. Discovered by the regular tenant scan, correlated so a Copilot package and the Entra identity behind it are recognised as one thing.
  • Blueprints are first-class. Agents are stamped out of templates, so the templates get their own tab: publisher, verification status, declared permissions, how much cascades down and how many instances exist. One unverified blueprint can be the parent of fifty agents - review it once instead of chasing every copy.
  • Permissions, atom by atom. Each permission is shown with its source (granted directly on the agent, inherited from the blueprint, or merely declared), its kind (application or delegated), and Microsoft's own blocked-for-agents flag - the same treatment files get for user permissions. "This agent is over-permissioned" stops being a feeling and becomes a list.
  • Reach, quantified. For every agent: how many files, sites, users and emails it can actually get to, resolved through its knowledge sources rather than assumed from a manifest - a SharePoint source resolved to the real site, a mailbox source resolved to the real user, tenant-wide access recognised as tenant-wide. Each is a tab you can open and page through.
  • The settings a reviewer actually asks about. The agent's instructions (its system prompt), suggested prompts, disclaimer, knowledge sources and capabilities - including which capabilities can write rather than read. What the agent is told to do, next to what it is allowed to touch.
  • Activity per agent. Every action an agent took, with breakdowns by action type and the same trend and hourly charts the rest of the platform uses - answered from rollups, so it stays instant on large tenants.
  • Agents are first-class everywhere else too. They are a resource type in Activities (most-active agents, unused agents), a per-entity subject in Anomalies (an agent reading four times its usual number of files today), and a target type in policies - so agent risk lives in the same detection and alerting machinery as everything else, rather than in a separate console.

Licensing, plainly. Entra-backed agents - Agent ID, Copilot Studio and Azure AI Foundry identities - need nothing beyond the standard read consent. The declarative Copilot agent catalog is delegated-only on Microsoft's side and needs a single Agent 365 seat on the admin who connects it; without it, everything else on the screen still works, and the screen says so instead of quietly showing an empty list.

New: Devices - where identity attacks become visible

Attackers do not break in any more, they log in. Once they hold a valid token, the account behaves like the account: every log line is legitimate, because the credential is legitimate. The machine using it is the part of the story that does not fit - which is why the device layer is where most identity attacks first become visible, and why securing devices stopped being an IT hygiene task and became a security control.

"We manage our devices in Intune" is only half of the answer. Intune's model starts at enrollment, so anything that never enrolled is invisible to it by definition - and that is precisely where an attacker prefers to operate. Devices reconstructs every machine touching your data from real activity rather than from the directory, and classifies what it finds:

  • Registered - enrolled in Entra ID / Intune, with posture read natively from Microsoft.
  • Unregistered - not in the directory at all, discovered from sign-ins or from data activity. Unmanaged access you were otherwise blind to: personal laptops, contractor machines, a phone nobody enrolled.
  • Shadow - the riskiest class: a device seen accessing data with no observed authentication at all. A sensitive document opened from a machine that never signed in the normal way is the signature of a legitimate token being used somewhere it should not be - a stolen or replayed session, a device that authenticated once and simply kept going.

Shadow and unregistered devices are not one-off log lines. They are persistent identities: each is keyed by a stable fingerprint, sessions are stitched back onto it, and the same machine keeps accumulating history - so you can follow it across days, see every file it touched, which accounts it acted as, and where from. That is the difference between "an odd event last Tuesday" and "this machine, these 340 documents, these two accounts, this ASN".

  • A real last-seen signal. Reconstructed from activity, not Entra's roughly two-week activity timestamp.
  • Per-action attribution - which files, users, apps, IP addresses and locations a device touched.
  • Session mapping - SharePoint and Exchange activity carries a session id but no device id; mapping sessions onto devices is what lets that traffic be attributed at all, and a repair job reconciles fingerprinted devices as more evidence arrives.
  • Posture stays Microsoft's - compliance, management state, ownership and trust type are read natively from Entra ID and Intune, so what you see always agrees with the MDM. Device enable/disable is available as an automation action, within Microsoft's own constraints.
  • Quick filters for the attack surface - shadow, unregistered, stale, orphaned, disabled and personal devices, each with a live count.

The investigation this unlocks: whenever an account is suspected of compromise, filter Devices to shadow over the incident window. Machines that touched data without ever authenticating are the shortest path from "we think a token was stolen" to the actual blast radius - what was opened, downloaded and shared, and from which origin.

New: Locations - the cheapest high-signal question in identity security

Where an action came from is one of the strongest available signals that an identity is still in the right hands - and the cheapest to check. A company that operates in Europe has no business watching its finance director download a document library from Asia at three in the morning, and you need no behavioural modelling to know that. Geography answers "should I be worried?" before anything else does, which is exactly what you want at the start of an investigation.

Microsoft does carry the IP address in its logs, and three things make it unusable as it stands: raw IPs are disposable, nothing resolves them into something a human can read, and Microsoft's own backend traffic pollutes the picture until half the tenant appears to be working from a US datacenter.

Locations fixes all three:

  • A location is an identity, not an IP. Country + city + network (ASN) collapse hundreds of fleeting addresses into one stable "Warsaw, Poland - home ISP".
  • Microsoft's own traffic is recognised and labelled, so a foreign origin actually means something instead of being the fourth false alarm this week.
  • The network matters as much as the country. A home ISP, a corporate network, a mobile carrier, a hosting provider and an anonymity service all look identical in Microsoft's logs; here they are distinguishable - which is what makes Tor, VPN and hosting-provider access visible.
  • Attached to everything. Every log line, and every user and device, carries the locations it was seen at - so "who worked from outside Europe this week" and "where does this identity normally operate" are one filter, and a suspicious origin leads straight to what was touched.
  • Enriched locally. IP-to-location and IP-to-network resolution happens inside the platform - no third-party geolocation service, and nothing about your tenant leaving the platform.

Locations and Devices are strongest together: a previously unseen origin plus a shadow device on the same account, in the same window, is about as close to a definitive "this token is not with its owner" signal as passive telemetry gets - and both are visible without deploying anything on the endpoint.

New: a dark theme, and one worth using

The dashboard now has a System / Light / Dark control in the account menu, and dark is not an inverted light theme. It was authored as its own palette on a semantic colour-token layer, with charts, graphs, tooltips, toasts, badges and scrims tuned individually across several rounds of visual QA - because "dark mode" that washes out a graph or drops a legend to unreadable grey is worse than no dark mode at all. The theme is applied before the first paint, so there is no white flash on load.

It matters more than a preference: security teams live in dark interfaces, incident work happens at night, and a product that exists only in bright white reads as an admin console rather than a security tool. In the same pass the last legacy MUI components were removed from the client, so the entire dashboard now renders as one coherent design system.

Renamed: the policy family

If you have used the platform before, the naming has been rationalised. All four are now first-class members of one policy family, evaluated by one engine and alerting through one mechanism:

BeforeNowWhat it is
MonitoringsTrendsState of the tenant over time, from the permission graph
newActivitiesTop-and-bottom activity cuts over trailing windows
newAutomationsPolicies that remediate, with review and grace periods
newAnomaliesBaseline deviation per policy and per entity

Trends got the same treatment as automations, plus a round of polish across the whole screen.

  • Suggested trends carry live counts. The template library shows, for each ready-made trend, how many resources in the tenant match it right now - counted live while you browse, with more than 50 trends available out of the box. Choosing what to monitor becomes a decision made on your own numbers rather than on template names.
  • A board you arrange yourself. Cards are drag-and-drop ordered per user, and the categories they sit in - names, icons and colours - are editable tenant-wide, so the board can be phrased the way your team talks about its own risks.
  • Charts that read properly. One sparkline component everywhere, density-aware points and area fill, every day in the range drawn rather than only the days with data, and the table view available again next to the cards.
  • Filters that behave. A two-column filter drawer, and category and tag selections carried in the URL - a filtered board is now a link you can send to a colleague.

Also new

  • Email threads and Conversations - messages are grouped into threads with an explicit thread role and a missing-parent signal (a strong deletion indicator), plus a conversations view with counts and filters.
  • Saved views - save, name, edit and share filter/column configurations; public views are visible to the whole tenant, and "set view as" applies one anywhere the resource type matches.
  • Interactive organisation graph - the dashboard graph is now a d3 renderer with real pan and zoom, expand/collapse-all and search-driven narrowing.
  • Manual remediation on files and email - run actions modal with write-app consent gating, an in-drawer manage-access modal, per-item succeeded/failed reporting and optimistic list updates.
  • Scoped administrators - admins can be granted limited access rather than full tenant visibility.
  • A new documentation site (the one you are reading) in English and Polish, with search, structured navigation, per-page actions and condition-level help text for every policy field.

Improvements

Lists and tables

  • The first column now stays pinned while you scroll horizontally on every list, so you never lose track of which row you are reading.
  • Column reordering, saved per user across main lists, drawer tables, logs and security alerts - with a drag handle, a "customized columns" pill and a clear reset.
  • Tooltips on column headers. Any column can carry a description that appears on hover, so an unfamiliar heading explains itself in place instead of sending someone to the documentation - and it is separate from the "click and hold to drag" hint on the grip, so the two never collide.
  • Sortable headers extended to the remaining columns, including agents and managed-identity apps.
  • Capped auto-fill row selection with a selected/max badge, so bulk actions on huge lists stay bounded.
  • Lists no longer blank out when a drawer opens; nested rows no longer show meaningless checkboxes; long text truncates sensibly in both narrow and wide cells.
  • Row links open resources in a new tab where that is the natural move.
  • Drawer-specific filters (including alert filters inside resource drawers) and a two-column filter drawer.

Real-time

  • Real-time policy engine v2. Audit-log activity re-evaluates only the affected slice of the affected policies within minutes, with per-tenant coalescing so no event is dropped, and a reconciliation pass as the floor. In practice: counts, trends, anomalies and automation proposals now update while you watch, instead of on a nightly cadence.
  • Real-time detection extended to group changes and file delete / move / rename.
  • Live counting on suggestion and template cards while the daily engine warms up, with an explicit "counting live" state rather than a misleading zero.
  • Engine liveness is shown on screen ("last evaluation X ago") rather than assumed.

Activity logs

  • Richer log insights, with the resources involved in each event surfaced inline.
  • Copilot and AI agent activity, device activity, and blocked-access events are first-class log types.
  • Actor search by email, action-group filter chips, and an explicit "other / unclassified" bucket instead of silently dropping unmapped events.
  • Daily rollups for 12 action groups plus breakdown counts, which is what makes 7/30/90-day questions answer instantly on large tenants.
  • 1Security's own service activity is filtered out of your logs.

Charts

  • Interactive graphs throughout, including hourly resolution and drill-down from a point to the underlying rows.
  • Graphs draw every day in the range rather than only days that happen to have data - a gap is now visible as a gap.
  • Multi-line activity trend with per-action toggles, filter pills doubling as the legend, and range pills.
  • Refreshed data visualisation across line, sankey and tree charts, plus trend sparklines on cards.

Performance and reliability

  • Hardened Microsoft Graph 429/503 throttling handling across sensitivity scanning, precompute and audit-log ingestion.
  • Tenant scans resume at drive granularity with per-site "fully scanned" marking, so an interrupted multi-week scan restarts where it stopped.
  • Per-entity precompute fast paths (sites, apps, groups, files, users), no-op heap rewrites skipped, and precompute lock ownership checkpoints that survive worker restarts.
  • Differential policy-resource synchronisation and chunked junction deletes with statement timeouts, replacing statements that could stall the largest tenants.
  • Reduced main-database load from the sensitivity scheduler and the auth pipeline.
  • Log ingestion no longer degrades high-traffic tenants; log and rollup backfills are substantially faster.
  • Background work is split across dedicated worker processes, so user traffic is never behind a scan.
  • Every background failure is recorded to a structured process-error table - support questions are answered from data, not from log grepping.

Accounts and access

  • Limited-access (scoped) administrators.
  • Invitations work through inherited roles, plus a first-admin invitation type for new tenants.
  • Refresh-token grace period and improved session handling - fewer surprise logouts.
  • The last selected tenant is remembered across sessions.

Email

  • Mail actions (delete, move to junk, move to deleted items, mark read/unread) with consent gating, all-recipient risk escalation and partial-success reporting.
  • Fail-safe attachment scanning with error logging, and a reset-resilient historical backfill.

Marketing site and documentation

  • Documentation search, sidebar sections and icons, sitemap and OG metadata.
  • /features and /use-cases listing pages, a resources dropdown in the header and a docs link in the footer.
  • Condition descriptions and tooltips for every policy field, in English and Polish, wherever conditions are displayed or picked.
  • Schedule-a-call widget, responsive scheduling page and a safer live-demo entry point.

Worth knowing

  • Nothing acts without consent. Detection, counting and previews run on the read-only application. Remediation requires the separate write consent, and can additionally be held behind a review window and manual approval.
  • No premium Microsoft licensing is required for 1Security's own insights - device discovery, activity statistics, locations, the permission graph and our own sensitivity engine work on Business Basic. Intune and Purview licences enrich what you see; they are not a prerequisite.
  • Real-time is real-time. Where the platform previously waited for a nightly cycle, activity now flows through within minutes - which changes what an investigation feels like: you are watching the tenant, not yesterday's report.

On this page