1Security + Defender XDR
Defender XDR stops the attack. 1Security shows how far it could have gone.
Defender XDR correlates signals across endpoints, identities, email and apps into one incident, disrupts the attack automatically and heals what was hit. 1Security answers the questions around that incident: what the compromised account could reach - in a typical tenant, 200,000 files - what it actually touched over the last three years, and which of that access should never come back. Every Defender alert lands in 1Security already linked to the account, its reach and its baseline, so triage takes minutes.
- 200,000files an ordinary account can open in a typical tenant
- 3 yearsof activity history behind every alert
- 10 minto a blast-radius answer during the incident
What Defender XDR does
One incident, the whole story, disrupted at machine speed.
Defender XDR coordinates detection, prevention, investigation and response across endpoints, identities, email and applications, before and after a breach.
One incident, the whole story
Alerts from Defender for Endpoint, Office 365, Identity and Cloud Apps are correlated into a single incident: the timeline, the tactics, every impacted user, device and mailbox, and a map of how they connect. The attack story, not a queue of fragments.
Automatic attack disruption
Millions of signals are correlated to spot active ransomware and business email compromise campaigns, and compromised assets are contained in real time - device isolated, user disabled, sessions revoked - with every action reversible by your team.
Self-healing and hunting
Automatic actions and playbooks bring impacted mailboxes, endpoints and identities back to a secure state. Advanced hunting adds KQL over the raw signal and alert data, all in one portal.
The question this pairing answers
The alert names an account. What could that account reach?
Defender XDR works on the incident: it starts when signals correlate and ends when the impacted assets are remediated. That focus is what makes automatic disruption possible, and it is exactly what an incident tool should do.
Two questions sit around every incident. Before the alert: how much can any single account reach if it is ever compromised - in a typical tenant, hundreds of thousands of files through groups, links and inheritance, long before anything malicious happens. After the disruption: the account is disabled and the device contained, but which of its permissions should ever come back, and what did it quietly open over the past year?
Both are questions about permissions and history rather than about the threat itself. 1Security answers them next to the alert: what the account could open, what it did open, three years back, and a reviewed way to trim it.
What 1Security adds
Context around every Defender alert.
1Security maps every identity in Microsoft 365 - person, guest, app, AI agent, device - to what it can open and what it actually did, and shows your Defender alerts inside that map.
- 01
Blast radius while the incident is live
Every file, site and mailbox the compromised account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The impact section of the incident report gets a number while Defender is still disrupting, not a week later.
- 02
Three years of history behind the alert
Up to three years of activity per identity on standard licenses, each account scored against its own baseline. "340 downloads today, usual 12" arrives with the alert, and what the account touched last spring is a filter in Activity logs, not an archaeology project.
- 03
A smaller blast radius for the next one
Remove access, expire links, revoke sessions - staged as per-resource proposals behind a 72-hour window (instant, 24 hours and 7 days also available), owner review optional, every action logged. Nothing irreversible happens without a person deciding.
How the two fit
Defender handles the threat. 1Security handles the permissions.
Defender XDR detects, correlates, disrupts and heals. 1Security connects to the same tenant read-only, with no agents and on standard Microsoft licenses, and adds the permission layer: before an incident it maps and trims what every identity can reach, during one it answers blast radius in minutes, and afterwards it helps decide, with a person in the loop, which access should not come back. Defender and Sentinel alerts appear in 1Security linked to the users, mailboxes and apps they concern. First findings land the same day you connect.
NIS2, together
Seventy-two hours is not long.
NIS2 - Directive (EU) 2022/2555 - puts incident handling on the clock under Article 23: an early warning within 24 hours of a significant incident, a notification within 72 hours including an initial assessment of severity and impact, and a final report within a month.
Defender XDR carries the detection half: the incident, the attack story, the disruption timeline - what happened and what was contained, ready when the clock starts. 1Security carries the impact half: what the compromised account could reach, resolved in minutes, and what it actually did across three years of activity - the severity and impact assessment the 72-hour notification asks for.
One pairing, one report, inside the deadline.
Give every Defender alert its context.
Keep Defender XDR on the incident. Connect 1Security read-only and the next alert arrives with the account, what it can reach, its baseline and three years of history one click away.
Or keep answering "how bad is it?" a week after the incident.