1Security
Platform Updates

September 2026 Platform Update

Compliance readiness for eleven regulations measured from live tenant data, external sharing governed on the Domains screen, a third-party application inventory feeding both, a Security score, remediation with Microsoft-verified confirmation and true undo, license readiness, anomaly detection v3, organizations for partners, and an API playground - everything shipped between August and September 2026.

Platform Update - September 2026

This is our second consolidated platform update, covering everything that landed between 1 August and 20 September 2026 - more than eight hundred changes in seven weeks. The July release closed the loop from finding to fix; this one closes the loop from fix to proof: proof for a regulator, proof for an auditor, proof for a board, and proof - action by action - that a remediation really happened in Microsoft 365.

If you read one section, read Compliance below, together with Domains and the third-party application inventory that feed it. Between them they answer the question a customer is asked before any security programme exists: "show us where you stand" - and they answer it from data 1Security has already collected, before the organisation has changed a single setting.

Headlines

Compliance

Readiness for eleven regulations - EU AI Act, NIS2, GDPR, DORA, ISO 27001, ISO 42001, SOC 2, NIST CSF, HIPAA and both Polish acts - measured continuously from live tenant data, with attestations, weekly snapshots and a per-framework evidence pack.

Domains

Every external organisation your tenant exchanges data with - guests, shared files, mail - resolved to the real company behind the domain, reconciled against your configured sharing controls, and given a verdict that can be enforced.

Security score

Microsoft Secure Score side by side with the score 1Security measures from what actually happens in the tenant - one worklist ranked by points still on the table, with peer comparison and ninety days of history.

Verified remediation

Every action is now a ledger entry: confirmed against Microsoft after execution, witnessed by the audit log, revertible where a revert honestly exists - and refused, with a reason, where it does not.

License readiness

Which actions this tenant can actually run on its current Microsoft licensing - answered per tenant, badged on every action picker, and checkable from a licence export before 1Security is even connected.

Anomalies v3

Per-tenant adaptive calibration, incident detectors - impossible travel, password spray, content injection - a governance detector family, and curated containment actions one click from every episode.

Organizations

A multi-tenant access model built for partners and MSPs: organizations, tenant groups with cross-tenant views, per-tenant invitation grants and role templates - the substrate a many-tenant practice runs on.

Everything that writes remains opt-in. The core application is read-only; remediation still requires the separately consented write application. What changed this quarter is the other direction: every write is now confirmed against Microsoft after it runs, and the evidence is kept.

New: Compliance - show the regulator where you stand, from day one

Every framework conversation starts the same way: a spreadsheet, a questionnaire, and weeks of mapping controls to paragraphs by hand - repeated for every regulation separately. Compliance replaces that with something no spreadsheet can do: it measures readiness from the tenant itself, continuously, and maps one set of facts onto every framework at once.

  • Eleven frameworks, one evaluation. EU AI Act, NIS2, GDPR and DORA; the Polish KSC and KRiBSI acts; SOC 2, NIST CSF 2.0 and HIPAA; ISO/IEC 27001 and ISO/IEC 42001. The screen is built on a shared set of 15 requirements - things an organisation actually does, like "every AI agent has an accountable person" or "activity logs are retained six months". Each framework's articles cite the requirements that satisfy them, so a single fix - done once - moves every regulation that cites it. You never re-prove the same control fourteen different ways.
  • Eleven requirements are measured live by an evaluator that runs continuously against the tenant: agent ownership, log retention, restricted-data reachability, the third-party app inventory, the external-domain inventory, monitoring freshness, label protection, device compliance, dormant accounts, Conditional Access coverage, captured agent instructions. Four are attested - the documents a regulator expects (AI impact assessment, AI usage policy, incident response procedure, risk management) - recorded once by the compliance officer and counted in every framework that cites them.
  • Deliberately conservative statuses. Not evaluated means no data yet - it is never counted as a pass. A verdict that will be shown to an auditor must under-promise.
  • One worklist instead of eleven checklists. Every open requirement appears once, worst status first, ranked by how many articles in your scope it unlocks - with chips naming the frameworks it satisfies. "What should we fix next" becomes a sorted list.
  • Snapshots and evidence packs. The whole status document is captured automatically every Monday and on demand; the overview shows what changed since the last capture, and a per-framework evidence pack exports as a dated document - also served over the API. "What was our status on this date" has a real answer.
  • Frameworks you have not adopted are evaluated anyway and shown with their own readiness percentage - so how close you already are on, say, ISO 27001 is visible before anyone commits to it.

The part that matters commercially: all of this is computed from data 1Security already collects. There is nothing to configure, no questionnaire to fill in and no project to run first. An organisation connects its tenant, and before it has remediated anything at all it can put a dated, honest readiness picture in front of a regulator - here is our scope, here is our status, here is what changed since last month. The product delivers its first audit answer before the customer has done anything beyond showing it.

Supply chain, covered from both ends

Every major framework carries a supply-chain control - NIS2 21(2)(d), DORA 28, GDPR 28, ISO 27001 A.5.19/5.23, SOC 2 CC9.2 and their peers - and they all ask the same two questions: who has access to us, and who do we hand data to? Two surfaces in this release answer them, and Compliance reads both.

New: Domains - every external organisation, named and governed

A guest appears in a group, a file goes to an outside address, a partner's people show up in the audit log - each is a relationship with an external organisation, and until now those relationships had no screen. Domains is that screen:

  • One row per counterparty. Every domain observed anywhere in the tenant - mail flow, guest accounts, shared files, audit-log actors - becomes one row carrying the whole relationship: guests, correspondents, messages exchanged, files reachable, sensitivity exposure, when it began and when it was last active.
  • Domains become companies. Each domain is resolved against Microsoft Entra's tenant directory, so instead of a bare string you see the organisation's real name and identity - or learn that it is freemail, or that no organisation stands behind it at all.
  • Configuration meets reality. Microsoft ships several trusted-domain mechanisms in different admin centers, keyed differently, and they do not cross-check each other. 1Security reads the ones it can reach - SharePoint sharing lists, cross-tenant access partners, the mail allow/block lists - and puts each domain's configured standing next to its observed activity. The contradictions surface as drift flags: blocked but active, trusted but unused, active but ungoverned, conflicting lists - each shipping as a ready-made detection, so drift raises an alert instead of waiting to be browsed.
  • A verdict that sticks. Each organisation gets a decision - trusted, watched or blocked - with a full who/when/why history, and blocking can be enforced straight into the tenant's SharePoint sharing lists, working within whatever restriction mode is already configured. The screen is equally clear about what a block does not do: existing guests and links survive it, and the blocked but active flag keeps watching exactly that.

Improved: Apps - the third-party inventory you can trust

The Apps screen - every OAuth consent, add-in, vendor integration and managed identity with a foothold in the tenant - got the reliability work that makes an inventory citable:

  • Publisher-based discovery replaced the undocumented tag the inventory previously leaned on, and a nightly refresh sweep keeps every app's portrait current - which is what lets the Compliance screen treat "third-party apps inventoried with their reach" as a measured requirement rather than a best effort.
  • Unified access channels. How an app reaches data - tenant-wide grant, admin-consented delegation, a single user's consent click, licensing, an explicit grant - is classified consistently everywhere, with the consenting admin recorded, so accountability survives staff turnover.
  • Severity that understands toxic combinations. Tenant-wide file access, admin consent for all users, an unverified publisher and reach into sensitive data lift an app's anomaly severity, with the reasons printed in the notification mail.

Together, Domains and Apps are the two halves of the supply-chain answer - data going out, software coming in - and both flow into the same compliance articles automatically.

New: Security score - both halves of the truth

Security score gives the organisation the one number every board asks for - built honestly, from two sources:

  • Microsoft Secure Score, exactly as the Defender portal reports it, with Microsoft's own remediation guidance, comparative averages for your size band and industry, and deep links into the portal.
  • The 1Security score, measured from what actually happens - sensitive data actually reachable, agents actually lacking an accountable owner, accounts actually dormant, sign-ins actually uncovered. Configuration and observed reality are deliberately kept as separate controls even where they measure the same fact, because a policy that is configured but not covering real sign-ins is precisely the insight one merged number would hide.
  • One worklist, ranked by points still on the table, with an "if you only have five minutes" shortlist - so even the shortest security session starts with the highest-value fix.
  • Categories of our own: AI & agents, observed data exposure, and monitoring & response - measured by 1Security and cross-referenced to the compliance articles they satisfy, so fixing a control shows which ISO 27001, NIS2 or EU AI Act articles move with it.
  • Waivers with a note for controls that genuinely do not apply, ninety days of daily history for both halves, and the score served over the REST API and MCP.

New: Actions - remediation you can prove

The July release shipped automations that fix things. This release makes every fix provable. An action is no longer a fire-and-forget API call - it is a ledger entry with a life of its own:

  • Confirmation against Microsoft. After an action executes, a probe re-reads the tenant and verifies the change actually holds before calling it applied - and the evidence is kept: the state before, the write receipt, the state after.
  • A second, independent witness. Microsoft's own audit log entry for the change is attached to the action's detail page - so "1Security says it did it" is corroborated by "Microsoft recorded it happening".
  • A real undo. Reverting is itself an action, with the same confirmation semantics - and where a revert honestly does not exist, the product says so instead of pretending. The same honesty runs through the whole engine: no-op actions are refused with a reason, an app restriction shows who would lose access before it is confirmed, and a write that partially failed reports exactly which sites were refused.
  • Approval, contention and a ledger-driven notification bell - two automations cannot fight over the same setting, manual actions can require confirmation, and every state an action passes through is named after a fact about the tenant.
  • First live families: SharePoint site, configuration and sharing actions, and application restrict/allow - the latter behind its own, separately consented write scope. The remaining families are visible in the product as coming soon, with the full action catalog - what each action does, whether it reverts, how it confirms - published in the documentation.

New: License readiness - what can this tenant actually run?

Microsoft gates many remediation capabilities behind specific SKUs, and finding out which is normally an archaeology project. Now it is a product surface:

  • A requirement map and bundle catalog. Every action is mapped to the Microsoft licensing it needs, and every Microsoft bundle to what it contains - so "what can we run in this tenant" is answered from the tenant's actual assigned licenses, seat counts included.
  • Badged where decisions are made. Every action picker, every automation row and every policy shows a missing license badge when the tenant's licensing does not cover it - including policies that outlived a license they once had.
  • Checkable before you buy - or connect. The public requirements page now carries a licence checker: a prospect exports their Your products list from the Microsoft admin center and gets the same readiness evaluation the product runs - before 1Security is connected at all.

1Security's own insights still require no premium Microsoft licensing; what this work does is make the boundary honest and visible, action by action.

Improved: Anomalies - v3, calibrated per tenant

The anomaly engine had its biggest quarter since it shipped:

  • Adaptive per-tenant calibration, always on. Detection floors are calibrated to each tenant's own scale at worker boot and nightly - so a 40-person company and a 40,000-person one both get sensible verdicts without anyone touching a dial. A sustained false-positive pass rode along: dismissed days count as normal, cold-start artefacts are dismissed, floored metrics are calibrated per rule.
  • Incidents, distinguished from anomalies. Some detections are not "unusual for this user" - they are bad on their face. Impossible travel, password spray, risky sign-ins and scan-driven content-injection detection on files and mail now land as incidents that always alert, while the tenant's alert line continues to govern behavioural anomalies. Correlated ranking lifts episodes that co-occur.
  • A governance detector family. Seven new detectors watch the identity and governance layer - the changes to roles, apps and directory state that precede most real incidents.
  • Severity you can operate. Effective severity combines the measured score with per-detector defaults, rule overrides and a manual verdict - editable in place, everywhere severity is shown. A detector that is real-but-known can be set to tracked: logged, visible, never notifying.
  • From episode to response. Every anomaly carries up to three curated containment actions - the proportionate next step, one click away, running through the same verified action ledger as everything else.
  • Per-entity detection from day one, gated on collected log depth rather than a fixed warm-up, with metric-level drill-through from any episode to the exact logs behind it.

New: Organizations - built for partners

Serving one tenant and serving forty are different products. This quarter shipped the difference:

  • Organizations as the access boundary. Accounts, invitations and tenant bindings are organization-scoped, with cross-organization access attempts handled explicitly.
  • Tenant groups with an all-tenants view and a per-tenant group scope - member pickers, tenant columns on licenses and activities, scoped invitations - so an MSP analyst sees their portfolio, and only their portfolio.
  • Invitations v2. Per-tenant advanced grants, admin role templates with provenance, identity-mismatch detection with one-click re-issue, expiring invites that soft-mark instead of vanishing, and a weekly inviter digest.
  • Seat counting and directory events - a monthly seat snapshot per tenant and a directory-event stream fed from both scans and the audit path - the substrate usage-based commercial models sit on.

New: take 1Security with you - API keys, playground, MCP

The REST API grew into a first-class product surface this quarter:

  • API keys - per-tenant and organization-wide, read-only by scope, managed from the dashboard.
  • An in-app playground - every endpoint, its parameters and a live response, inside the product, so a SOC engineer can go from "can we pull detections?" to a working query without leaving the page.
  • New endpoints for the quarter's features - security score, compliance status and snapshots, the evidence pack, the actions ledger, users - and the same coverage mirrored as MCP tools, so an AI assistant with a key can ask the tenant questions directly.
  • A SIEM integration guide and full API reference, published in English, Polish and German.

Also new

  • Security cases - a one-time scan of a frozen resource set as a first-class object: scope it, run it, review it, keep it as the record of an investigation. A per-case review board and an owner-review flow (resource owners reviewing their own items) shipped alongside.
  • Broken permission inheritance detection - sites, libraries and items whose permissions have quietly diverged from their parent, detected from the permission walk and refreshed from audit events.
  • Exports that behave - raw activity-log export, and a download flow with progress, cancel and switch-to-email for large exports. Download counting was also made honest: page renders are no longer counted as user downloads.
  • Purview and sensitivity hardening - scan restore and throttling, SIT deduplication on mail, and local resolution of file URLs before Graph is asked.
  • Self-hosted / BYOC deployment - a click-by-click Entra portal guide for the current Azure UI, an Azure deployment guide with verification steps, and a production runbook - the path for customers whose data cannot leave their own cloud.
  • A proactive hardening pass across authentication, authorization and dependencies.
  • Trends onboarding - a template explorer for the first-run experience, and sorting by trend and by activity across lists.

Improvements

Scale

The scan and ingestion layer was rebuilt for the largest tenants: parallel, restart-safe tenant scans with selective permission fetches; the SharePoint unique-permission walk persisted and parallelised; Graph traffic prioritised and throttling attributed per tenant; precompute moved off the scan workers; mailbox backfill parallelised, with truncated Graph responses salvaged instead of dropped; policy membership evaluated in SQL instead of materialising id lists; scan concurrency sized by seats; and two watchdogs - a heartbeat alarm for a scan that is alive but not advancing, and a freshness alarm for audit ingestion.

Languages

The dashboard now ships in seven languages - English, Polish, German, French, Spanish, Ukrainian and Russian - and the documentation in English, Polish and German. Every action, detector and invitation flow added this quarter landed with all locales in the same commit.

Website and content

A German landing page and German dashboard for the DACH market; dedicated landing pages for Agents and Anomalies; a blog with its first posts and public patch notes; a customer case study; the File sharing module renamed to Data sharing to match what it now covers; and a repositioning pass that puts the AI-governance story - agents, Copilot, third-party AI - at the front of the site.

Interface

Dark mode is now the default, after a contrast and interactivity pass across charts, alerts and drawers. Quick filter chips, a columns view, better file navigation, and the interactive access graph extended to users.

Worth knowing

  • The compliance picture costs the customer nothing to produce. It is computed from data the platform already collects; scope selection and the four attestations are the only human input, and neither is required for the screen to be useful on day one.
  • Nothing acts without consent, and now nothing claims without proof. Reads stay on the read-only application; writes require the separate write consent, can be held behind review windows - and are confirmed against Microsoft after they run, with the evidence retained.
  • No premium Microsoft licensing is required for 1Security's own insights - and where Microsoft licensing does gate a remediation, the product now says so upfront, per action, per tenant, and even pre-sale from a licence export.

On this page