1Security + Defender XDR

Defender stops the attack. 1Security shrinks what the next one can reach.

Microsoft Defender XDR is the incident machine: it correlates signals across endpoints, identities, email and apps into one attack story, disrupts the attack at machine speed, and heals what was hit. The standing permissions that decide how far any attack could travel exist before the first alert - and that layer is 1Security’s.

  • 600M/day
    identity attacks (Microsoft, 2024)
  • 70%
    of breaches exploit excessive permissions
  • 12h → 10 min
    a blast-radius investigation, before and after

Credit where due

What Defender XDR does brilliantly.

A unified pre- and post-breach defense suite that natively coordinates detection, prevention, investigation and response across endpoints, identities, email and applications.

  • One incident, the whole story

    Correlation engines stitch alerts from Defender for Endpoint, Office 365, Identity and Cloud Apps into a single incident: the timeline, the tactics, every impacted user, device and mailbox, and a visual map of how they interact. The full attack story, not a queue of fragments.

  • Disruption at machine speed

    Automatic attack disruption correlates millions of signals to spot active ransomware and BEC campaigns, then contains compromised assets in real time - device contained, user disabled, sessions revoked - at a maintained confidence of 99% or higher. Every action can be undone by your team.

  • Self-healing after the fight

    AI-powered automatic actions and playbooks remediate impacted mailboxes, endpoints and identities back to a secure state. For everything else there’s advanced hunting: KQL over the raw signal and alert data, in one portal.

Before and after

Built for the attack in progress.

Defender XDR’s unit of work is the incident. It begins when threat signals correlate and ends when the impacted assets are remediated - and that focus is exactly why disruption at 99% confidence is possible at all. An incident machine should be judged on incidents, and this one is superb.

Two questions live outside that model, by design. Before the alert: the standing permission sprawl that decides how far any compromised account could travel - nothing malicious has happened yet, so there is no signal to correlate. And after the disruption: the account is disabled, the device contained - but which of its permissions should ever come back, and what did it quietly touch over the past year? Hunting is scoped to 30 days of raw signals, the right window for incident work - not for a question that spans quarters.

Both are questions about the permission layer, not the threat layer. That layer is 1Security’s entire product.

The complement

What 1Security adds around the incident.

1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did.

  1. 01

    Blast radius, mid-incident

    Every file, site and mailbox a compromised account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The impact question your incident report needs answered while Defender is still disrupting, not a week later.

  2. 02

    Memory beyond the hunting window

    Three years of activity history without a SIEM contract, and a behavior baseline per identity with anomaly episodes and an alert line you position yourself. What the account touched last spring is a query, not an archaeology project.

  3. 03

    A smaller surface for the next one

    Revoke access, expire links, sever sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. 98% of granted permissions are never needed; trimming them is how the next incident starts smaller.

Joint architecture

The threat lane and the permission lane.

Defender XDR owns the threat lane: detect, correlate, disrupt, heal. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licenses, and owns the permission lane: before the incident it maps and trims what every identity can reach, during it it answers blast radius in minutes, and after it it decides - with a human in the loop - which access should never come back. First findings land the same day.

NIS2, jointly

Seventy-two hours is not long.

NIS2 - Directive (EU) 2022/2555 - puts incident handling on the clock under Article 23: an early warning within 24 hours of a significant incident, a notification within 72 hours including an initial assessment of its severity and impact, and a final report within a month.

Defender XDR carries the detection half: the incident, the attack story, the disruption timeline - what happened and what was contained, ready when the clock starts. 1Security carries the impact half: what the compromised account could reach, resolved in minutes instead of a 12-hour log hunt, and what it actually did across three years of activity memory - the severity and impact assessment the 72-hour notification demands.

One pair, one report, inside the deadline.

Stop the attack. Then shrink the next one.

Keep Defender XDR on the incident - and put the permission graph around everything the incident could have reached.

Or keep meeting every incident with 98% of your permissions still granted.