Complementary by design

1Security + CyberArk. The keys above, the doors below.

CyberArk owns the privileged tier: credentials vaulted and rotated, sessions isolated and recorded, standing privileges reduced to zero. 1Security maps the tier underneath - the everyday permissions inside Microsoft 365 that no vault was ever meant to hold. Together they answer both questions: who holds the keys, and what every identity can actually open.

  • 98%
    of granted permissions are never needed
  • 70%
    of breaches exploit excessive permissions
  • 12h → 10 min
    a blast-radius investigation, before and after

Credit where due

What CyberArk does well.

Privileged access is where one mistake ends companies - and CyberArk treats it that way.

  • The vault, done right

    Critical system-level accounts get automated credential vaulting and rotation. The password an attacker would most love to steal stops being worth stealing - it has already changed.

  • Sessions brokered and recorded

    Sensitive sessions across infrastructure and SaaS run isolated and recorded, with AI-generated summaries surfacing anomalous commands in real time. When an auditor asks what the admin did, there is a tape.

  • Zero standing privileges

    Ephemeral privileges are created when a task starts and destroyed when it ends - just-in-time entitlements scoped to the task, with agentless, brokered access to AWS, Azure, GCP and Kubernetes.

A different layer

The gap CyberArk isn’t designed to close.

CyberArk’s scope is deliberate: the privileged tier. Admin credentials, root sessions, the accounts that can take infrastructure down. Everything about the product - the vault, the broker, the recording - is shaped for access that is rare, powerful and worth ceremony.

Everyday access inside Microsoft 365 is the opposite shape. Sharing links minted in a click, group memberships that quietly inherit whole sites, OAuth consents granted on a Tuesday - millions of small permissions held by ordinary accounts. Nobody vaults a sharing link. Nobody brokers a session into a SharePoint folder. This layer is too broad and too fluid for ceremony - and 98% of it is never needed at all.

That’s not a flaw in the vault. It’s a different question, and it needs a different instrument: not a stronger lock, a map.

The map

What 1Security adds.

A permission-centric decision engine for Microsoft 365 - every identity, what it can reach, and what it actually did.

  1. 01

    Every identity, mapped

    Human, app, AI agent, device - 1Security maps what each one can reach and what it actually did. The everyday layer stops being a rumor and becomes a graph.

  2. 02

    Blast radius in minutes

    Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The question the privileged tier can’t see from above.

  3. 03

    Memory and baselines

    Three years of activity history without a SIEM contract, and per-identity behavior baselines that turn a number into an anomaly - episodes, with an alert line you position yourself.

  4. 04

    From found to fixed

    Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision.

Joint architecture

The vault above, the graph below.

CyberArk keeps holding the privileged tier - vaulted credentials, brokered and recorded sessions, zero standing privileges. 1Security connects to the Microsoft 365 tenant with read-only consent - no agents, standard Microsoft licenses, first findings the same day - and builds the permission graph underneath: every identity, every grant, every action, three years back. Neither touches the other’s layer; together they leave no layer unwatched.

NIS2 in practice

Access control you can evidence.

NIS2 Article 21(2)(i) obliges essential and important entities to run access control policies and asset management as part of their cyber-risk measures - and Article 23 gives them 24 hours to file an early warning once a significant incident is detected.

CyberArk evidences the privileged half: who could use the powerful accounts, when, and under which policy - with rotation and session recordings as proof. 1Security evidences the everyday half: which identities could reach which data across Microsoft 365, and what they actually did with it.

And when the 24-hour clock starts, the first question is scope. A blast-radius answer in ten minutes instead of twelve hours is the difference between an early warning written with facts and one written with adjectives.

Two layers of access. One picture.

Keep the vault on the keys. Put a map under the doors - every identity, every permission, every action in Microsoft 365.

Or keep the map of everyday access in your head.