1Security + Entra ID Governance
Governance models the access you intend. 1Security maps the access you actually have.
Microsoft Entra ID Governance is how a modern tenant decides who should have access: packages, approvals, reviews, lifecycle automation. What sits beneath every one of those entitlements - the files, sites and mailboxes a single membership really unlocks, and whether anyone ever touched them - is a finer resolution of the same question. That resolution is 1Security.
- 98%of granted permissions are never needed
- 70%of breaches exploit excessive permissions
- 12h → 10 mina blast-radius investigation, before and after
Credit where due
What ID Governance does brilliantly.
Four questions, answered as process: which identities should have access, what are they doing with it, are controls in place, and can auditors verify them.
Entitlements as products
Access packages bundle the groups, Teams, apps and SharePoint sites a role needs - requested through multi-stage approval, time-limited by policy. External partners get invited as B2B guests on approval and removed automatically when access expires.
A lifecycle that runs itself
Lifecycle workflows automate joiner, mover and leaver events straight from HR sources like Workday and SuccessFactors, and provisioning connectors reach hundreds of cloud and on-premises applications. Day one access on day one, and clean exits when people leave.
Recertification and privileged control
Recurring access reviews put group memberships, application access and role assignments in front of the people who can judge them - with AI-powered suggestions. Privileged Identity Management adds just-in-time elevation and role-change alerting on top.
The resolution limit
Governance works at the entitlement. Risk lives at the item.
ID Governance’s unit of work is the entitlement: a group, a role, an access package. That’s the right altitude for deciding intent - model the access, route the approval, expire what isn’t renewed. It’s governance done as engineering, and it works.
Inside Microsoft 365, each entitlement then fans out. One group membership cascades through nested groups and site inheritance into thousands of individual files. And access also gets created outside the model entirely - an ad-hoc sharing link never passes through an access package or an approval stage. So when a reviewer certifies a membership, the honest questions underneath are: what does this membership actually reach, and has any of it ever been used?
Answering at that per-file, per-action resolution was never ID Governance’s design brief. It is 1Security’s entire product.
The complement
What 1Security adds beneath the entitlement.
1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did.
- 01
Entitlements resolved to reach
Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The membership you’re asked to certify stops being a name and becomes a map.
- 02
Evidence instead of instinct
Three years of activity history without a SIEM contract, with a behavior baseline per identity. 98% of granted permissions are never needed - now a reviewer can see which 98%, before clicking approve.
- 03
The trim, safely executed
Revoke access, expire links, sever sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision.
Joint architecture
Intent upstream, evidence downstream.
Entra ID Governance stays the system of intent: it decides, provisions and recertifies access at the entitlement level. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licenses, and resolves the effective layer beneath it - every identity, every permission, three years of activity. Governance decisions get made on evidence of reach and use instead of on names; first findings land the same day.
DORA, jointly
Least privilege you can demonstrate.
DORA - Regulation (EU) 2022/2554 - requires financial entities to restrict access to ICT assets and data to what legitimate functions actually need, and to keep that restriction demonstrable as part of ICT risk management under Article 9.
ID Governance supplies the control machinery: entitlements modelled as access packages, approvals recorded, access recertified on schedule, privileged roles elevated just-in-time. 1Security supplies the evidence: what each entitlement effectively reaches inside Microsoft 365, which of those permissions were used across three years of activity - and reviewed, reversible automations to trim what wasn’t.
Control plus evidence is what the regulator is actually asking for. Either alone is half an answer.
Intended access, meet actual access.
Keep ID Governance deciding who should have access - and put the map of what that access really reaches underneath it.
Or keep certifying memberships nobody has seen the bottom of.