Better together
1Security + Microsoft Defender for Cloud Apps.
Defender for Cloud Apps watches behavior in motion: which cloud apps your people use, what happens inside the live session, which OAuth grants deserve a second look. 1Security resolves the access at rest - every file, site and mailbox each identity in your Microsoft 365 tenant can reach, and whether it ever needed to. One instrument for the session, one for the standing grant.
Credit where due
What Defender for Cloud Apps does well.
A CASB, an SSPM layer and OAuth app governance in one product, wired straight into Microsoft Defender.
Shadow IT, discovered and scored
Cloud discovery analyzes your traffic logs against a catalog of over 31,000 cloud apps, each ranked on more than 90 risk factors. You see what your organization really uses - on the corporate network and off it - and you sanction, unsanction and block from one screen.
Sessions controlled in real time
Conditional Access app control puts policy inside the live session: monitor low-trust sessions, block downloads of sensitive data to unmanaged or risky devices, watch collaboration with external users as it happens.
OAuth apps under governance
App governance closes the app-to-app gap: the OAuth apps your users consent to, their permissions, unused apps and expired credentials - all monitored, with every signal correlated at incident level inside Microsoft Defender.
The design boundary
Built for the session, not the standing grant.
Defender for Cloud Apps is deliberately session-shaped. Its raw material is behavior in motion - the traffic log, the live session, the OAuth consent - and inside that scope it is the strongest answer in the Microsoft stack. That focus is a design decision, and for a CASB it’s the right one.
Standing access is a different material. Inside Microsoft 365, an identity’s real reach is assembled from direct grants, sharing links, group memberships and inheritance - permissions that exist and keep working whether or not any session touches them. 70% of breaches exploit excessive permissions, and 98% of granted permissions are never needed at all.
That reach isn’t a session artifact, so no session control is meant to render it. It’s a different question - and it takes a different instrument to answer.
The other instrument
What 1Security adds.
1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did.
- 01
The permission graph
Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. A blast-radius investigation that used to take 12 hours now takes 10 minutes.
- 02
Memory that outlasts the session
Three years of activity history, per-identity behavior baselines, and anomaly episodes with an alert line you position yourself. When a session raises a question, the answer is already on file.
- 03
Devices and origins, reconstructed
Shadow devices rebuilt from real activity by a stable fingerprint - no Intune enrollment required. Every action enriched with location and ASN, Microsoft’s own datacenter noise labelled out.
- 04
Findings that end in a fix
Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision.
Joint architecture
Two lenses on one tenant.
Defender for Cloud Apps sits with your sessions and app traffic - discovery, session policy, OAuth governance - and correlates its signal inside Microsoft Defender. 1Security connects to the same Microsoft 365 tenant with read-only consent - no agents, standard Microsoft licenses, first findings the same day - and resolves the layer beneath: who can reach what, who actually did, and which permissions should never have existed. When a Defender for Cloud Apps alert names an identity, 1Security tells you what that identity could touch.
- Same dayfrom read-only consent to first findings
- 12h → 10 mina blast-radius investigation, before and after
- StandardMicrosoft licenses - no E5 prerequisite
Joint use case
NIS2 wants proof, not policy documents.
NIS2 Article 21 obliges essential and important entities to run risk-management measures that include access-control policies - and to demonstrate they work. A policy PDF doesn’t demonstrate anything; the regulator’s question is concrete: who can access what, why, and what happens when that access is abused.
Together the two products answer it end to end. Defender for Cloud Apps enforces the in-session half: sensitive downloads blocked on unmanaged devices, external collaboration monitored in real time, risky OAuth grants governed. 1Security supplies the evidence half: the resolved permission graph as the current access-control state of the tenant, three years of activity memory behind every identity, and remediation - revoke, expire, sever - with review queues that record the human decision.
When the auditor asks who could reach the finance site on the day of the incident, that’s a lookup, not a project.
Keep the session covered. Add the map beneath it.
Defender for Cloud Apps already watches your apps in motion. See what it looks like with the standing access resolved underneath - every identity, every permission, every action.
Or keep answering “who has access to what” by hand.