Every control you need for Microsoft 365
Tenant-wide threat protection, least-privilege governance, and end-to-end visibility - explore the 1Security feature set for Microsoft 365.
- Popularevery alert prints its receiptsan alert, with its working attached1 detectionMass download · 04:024,120 filesflaggedwhy?Baseline for this identity12 files / dayThe line you set500 / hr · crossed 04:02Deviceunregistered · first seen tonightthe line is yours - move it, history re-scoresre-classifiedSecurity
Microsoft 365 Alerts Tool
One alert model across policies, activity and anomalies - with the evidence attached and the alert threshold in your hands.
Explore - Popularevery number, tracked over timetrends · last 7 weeksmeasured daily20.9kFiles reachable by CopilotAI Safety+1↗ +3,154 since Jul 22LOWJun 10Jul 29115Groups with active edit linksPermission Management+1↗ +83 since Jul 22HIGHJun 10Jul 29Security
Microsoft 365 Monitoring Tool
Real-time monitoring that catches a mass download while it is unfolding - across users, files, apps, AI agents and devices.
Explore - Popularone inventory for all of themidentities in the tenant1284127361,024peopleapps · agents · service identitiesAI & Agents
Copilot Security Tool
Every AI agent's real blast radius - quantified before rollout, watched and constrained after.
Explore - Popularthe census starts at activity, not enrollmentdevices, reconstructed from activity3 classesaudit activitysign-insfile accessmailsessionsLAPTOP-FIN-014registeredcompliant · managed · corporate1 user · 6 apps · 2 IPsWindows · Chrome 126unregisteredseen in sign-ins · never enrolled4 users · 12 apps · 9 IPsfp:7c2e…a91shadowdata access · no sign-in of its own340 files · 2 accounts · 1 ASNdirectory · Intune · sees the first row onlySecurity
Shadow Device Detection
Every device touching your data, reconstructed from real activity - including the machines that never enrolled anywhere.
Explore - Populara location is an identity, not an IPone account · one hourtravel timeline09:12 · Warsaw · home ISP10:04 · Singapore · datacenterimpossible travel · 9,300 km in 52 minutesMicrosoft relay · labelled, not countedSecurity
Impossible Travel Detection
Locations as identities, not IPs: country, city and network for every action, first-seen origins, travel timelines with verdicts - no E5, no P2.
Explore - Popularanswered live · down to the filewho can reach Q4-Forecast.xlsx ?1,204People62Apps18AI agents18 unexpected
Q4-Forecast.xlsx
Finance · confidential
1,2841,3011,284identities can reach itGovernanceOffice 365 Access Management
Effective access, resolved - who can reach what, through which grant, and one place to take it away.
Explore - Popularno export, no ticket, no second toolone finding, three movessame screen“Anyone” link on /Finance · 412 files01Mapevery path to the file, down to one hop’s “why”02Watcha baseline per identity and an alert line you position03Fixcounted before you enable it, staged behind a reviewread-only until you say otherwiseGovernance
SharePoint Governance Tool
Every site ranked by exposure and abandonment - links, guests and Copilot access under control.
Explore - Popularno black boxes · every hop is a recordwhy is this file exposed?answered in fullQ4-Forecast.xlsx · Financesits in/Finance/Forecastspermission inheritance onshared withMarketing (group)added by an owner in Marchwhich containsguest@vendor.comexternal · last seen 2 days agoshown, not assertedevery hop is a record you can openVisibility
Microsoft 365 Audit Tool
Up to three years of searchable activity history - every action tied to an actor, device and location.
Explore - Popularone file, every doorway into it - on one screenxlsxQ4-Forecast.xlsxFinance / Forecasts / 2026modified 2 days ago · 1.8 MB · 14 versions18 card numbersConfidentialAccess1,284Links3Activity212Emails4who can reach it, and through whatFinance (group)site membership · inheritedMarketing (group)added by an owner in Marchk.nowak@vendor.comanyone link · no expiryCopilot · 3 agentstenant-wide readleft by email · 4× · last on TuesdayRemove accessData & Content
Microsoft 365 File Permissions
Who has access to any file, and why - people, links, apps and AI agents on one map, with the fix in the same place.
Explore - Popularthe directory stops - the activity doesn’twhat the activity gives back4 signalsUsersGroupsLicencesthe directorywhere the admin center stopsShadow devicestouching data with no sign-in of their ownrebuiltLocations as identitiescountry, city and network per actionrebuiltAgent reach, resolvedthe files an agent can actually openrebuiltEvidence of deletionthreads whose parent is missingrebuiltData & Content
Sensitive Data Discovery
Where regulated data lives and everything that can reach it - two detection engines, no premium licence required.
Explore - Popularthe agent is new · the access is nota new agent, built Tuesdayapproved by nobodyMarek · Financehere 9 years · access nobody has reviewed since 2019builds an agent in an afternoonInvoice Assistantruns on Marek’s permissions, not its owninherits everything20.9kfiles232sites46mailboxeswhat it can reach on day oneAI & Agents
AI Agent Inventory
Every agent in the tenant with its real reach counted, its blueprint reviewed, and guardrails you can verify.
Explore - Popularattackers do not break in - they log inj.miller@ · three sessions todayall with a valid tokensame account · same permissions · every log line legitimate08:52looks like herLAPTOP-JM-02Warsaw · office11 files13:20looks like herLAPTOP-JM-02Warsaw · home ISP4 files03:14fp:7c2e…a91datacenter · first seen340 filesnot the ownernew device + first-seen origin + 03:14 + 340 filesGovernance
Microsoft 365 User Access Review
Every identity with what it can reach, what it did, and whether it should still exist - including SharePoint-only guests that live outside the directory.
Explore - Popularstaged → reviewed → recordedautomationsreview · 24h gracegateRevoke external links×1,284Remove stale guests×316Unshare finance folders×48Reclaim unused licenses×6124,812 staged · all reversibleloggedGovernance
Remediation Automation
Findings become fixes at tenant scale, counted before you enable them and staged behind a review window.
Explore - the portal shows the rules - not the doorconditional access · declared vs observedlast 24hyou declaredyour tenant didtrustednamedpartly coveredno policy applied31%29%34%31%of sign-ins no policy governedOffice not trustedFrankfurt egress · 4 of 9 addresses in rangeTrusted, but riskynamed range now resolves to a hosting ASNNo enforcement1,204 sign-ins completed with no policy in forceVisibility
Conditional Access Monitoring
Declared Conditional Access compared against observed sign-ins: coverage verdicts, ungoverned traffic share, and the ranges your offices outgrew.
Explore - connected before lunch · risks nothingday oneread-only09:00Read-only consentno agents installed09:05Scan runninglicenses you already own11:40First findingsbefore lunchno SIEM contract · no E5 upsellread-onlyGovernance
Office 365 User Provisioning
Lifecycle access from day one to offboarding - reach, dormant accounts and license reclaim in one flow.
Explore - not an export - a living graphhow deep the map goesone tenantSites232Files20.9kPermissions1.2MActivity logs274kactivity keptnative retention · 90 days1Security · 3 yearsVisibility
Microsoft 365 Inventory Tool
Eight live inventories on one permission graph - including the sites, devices and AI agents that were never registered anywhere.
Explore - numbers a board can act onboard report · Q3same tenant, measured twiceFiles exposed outside the company−64%24,8108,940Licences paid for, never used−77%$412k$96kTime to shut down risky access−91%9 days19 hoursAprilJulyVisibility
Office 365 Reporting
Answers, not exports - regulator-grade numbers, saved views and a read-only API for your SOC.
Explore - what a successful phish looks like - as a shapeone conversation, drawn6 messagesreplied back outfrombilling@acme-inv.coRE: RE: Invoice batch - Marchreply chain inferredsend-on-behalftoap@ (shared)tom.zielinskicarries3Invoice_2291.pdfIBAN · 2 hitsunique uploadparent missingData & Content
Office 365 Email Monitoring
Outbound sensitive content, delegated-send abuse and whole-thread evidence that survives deletion.
Explore - a policy is a document - coverage is a numbersensitive files · labelled vs found300+ detectorsCredit card numbers1,980 / 4,120gapNational IDs610 / 2,760gapHealth records1,140 / 1,330API keys & secrets70 / 890gapfiles with sensitive infoof them labelled31%34%38%41%label coveragemeasured weekly · trending upData & Content
Purview Label Coverage
What your sensitivity labels actually cover, and which of them protect anything at all.
Explore - one group added - twelve hundred people reachedone membership, resolved4 levels deepa.kowalskaFinanceAll-Staff-EUBoardIntranetHR-FilesBoard-Packs4 guests12direct members12864121,204effective reachGovernance
Group Access Analysis
What membership in a group actually unlocks - nesting resolved, external members surfaced, blast radius counted.
Explore - not a gap in the tools - the gap between themwhat each tool covers3 of 3 working correctlyeverything an identity attack touchesWho can reach what - covered by none of themGovernance
App and OAuth Consent Governance
Every app with a foothold in the tenant: how it got in, who let it in, and what it can actually read.
Explore - numbers a board can act onboard report · Q3same tenant, measured twiceFiles exposed outside the company−64%24,8108,940Licences paid for, never used−77%$412k$96kTime to shut down risky access−91%9 days19 hoursAprilJulyGovernance
Microsoft 365 Licence Optimization
The seats you pay for and nobody uses - unassigned units, licences on guests, and dormant accounts still billing.
Explore - spikes only · today vs its own 30-day medianfiles read · finance-agentmedian 12 / day3.5σ · alert line2σ · kept as infoepisode openedtoday · 4× its usual · one mailown baselinethe line is yoursmove it - history reclassifies at read timeSecurity
Microsoft 365 Anomaly Detection
Every policy, user, app and agent measured against its own baseline - with an alert line you move and see the answer to at once.
Explore - a location is an identity, not an IPone account · one hourtravel timeline09:12 · Warsaw · home ISP10:04 · Singapore · datacenterimpossible travel · 9,300 km in 52 minutesMicrosoft relay · labelled, not countedSecurity
Office 365 Sign-in Locations
Every place your tenant is reached from, with your Conditional Access configuration laid over observed reality.
Explore - not an export - a living graphhow deep the map goesone tenantSites232Files20.9kPermissions1.2MActivity logs274kactivity keptnative retention · 90 days1Security · 3 yearsVisibility
Microsoft 365 Unified Audit Log
Who did what, when, from where and on which device - retained up to three years on a standard licence.
Explore - kept live - not an exportyour tenant, as one graph5 branchesIdentity & Access1,204 users · 196 devicesData & Content20.9k files · 232 sitesApps & AI88 apps · 46 agentsDetections12k alerts · 48 anomaliesActivity & Trends274k activity logsVisibility
SharePoint Site Inventory
Every site, channel site and OneDrive in one list, ranked by external reach, abandonment and what Copilot can read.
Explore - read from raw logs - fresh in about 10 minutesdownloads · one-hour windows · todayraw audit log14:00 - 15:00340 filesin one hourcontractorunregistered devicefirst-seen originwhat leftClient-list-2026.xlsxPricing-model-v7.xlsxBoard-minutes-Mar.docxContract-template.docx+ 336 morecaught while unfoldingVisibility
Microsoft 365 Activity Analytics
The extremes rather than the averages - a mass download inside the hour, and everything nobody has touched in a year.
Explore - every number, tracked over timetrends · last 7 weeksmeasured daily20.9kFiles reachable by CopilotAI Safety+1↗ +3,154 since Jul 22LOWJun 10Jul 29115Groups with active edit linksPermission Management+1↗ +83 since Jul 22HIGHJun 10Jul 29Visibility
Microsoft 365 Trend Tracking
Any number in the tenant followed over time, with the change and the deviation attached - and alerting on the same object.
Explore
Need different features?
For teams with advanced security, control and support needs - let's tailor 1Security to your stack.

Gain visibility. Ensure compliance. Boost productivity.
Stop guessing who has access to your sensitive data. With 1Security, you gain the visibility, automation, and confidence needed to protect your Microsoft 365 environment.