1Security + Microsoft Entra Suite
The Suite secures the way in. 1Security maps what is inside.
Identity Protection, ID Governance, Private Access, Internet Access and Verified ID make up the strongest front door Microsoft has shipped - risk scored in real time, sessions conditioned, apps reached without a network. What that identity can then touch inside Microsoft 365 - which files, which mailboxes, which agents - is a different question, at a finer resolution. That resolution is 1Security.
- 70%of breaches exploit excessive permissions
- 98%of granted permissions are never needed
- 12h → 10 mina blast-radius investigation, before and after
Credit where due
What the Suite does brilliantly.
Five products sold as one control plane for how an identity gets in - and each of them is best-in-class at that job.
Risk that enforces itself
Entra ID Protection scores sign-in and user risk against Microsoft’s signal volume, and Conditional Access turns the score into a decision while the session is still being established - block it, step up authentication, force a credential reset. No analyst in the loop, no ticket queue.
Access to an app, not to a network
Entra Private Access and Internet Access replace legacy VPN with identity-centric, per-application access behind the same Conditional Access policies - on-premises apps and internet destinations alike. An identity gets one application, not a subnet.
Lifecycle and proof of who you are
Entra ID Governance automates joiners, movers and leavers with access packages and recurring reviews, while Verified ID adds cryptographically verifiable credentials for onboarding and helpdesk identity proofing - so the person on the phone is the person on the record.
The far side of the door
The Suite governs the session. Risk lives in what the session opens.
The Suite’s unit of work is the identity and its access: should this sign-in be allowed, under what conditions, to which application, for how long. That is exactly the right altitude for the front door, and it is engineered better than any alternative on the market.
Below the application, the question changes shape. Conditional Access can allow a session to SharePoint; it cannot say that the token behind it reaches 12,000 files it will never open, a finance site inherited through three nested groups, or a mailbox delegated years ago and never revoked. And some access paths never present a session to the door at all - an anonymous sharing link, a guest already sitting inside a site, an OAuth app or AI agent running on application permissions with no user attached.
Resolving access at the per-file, per-identity, per-action level was never the Suite’s design brief. It is 1Security’s entire product.
The complement
What 1Security adds behind the door.
1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did.
- 01
Every identity resolved to its reach
Direct grants, sharing links, group nesting, site inheritance - collapsed into one answer per identity: exactly which files, sites and mailboxes it can open. The thing a Conditional Access policy is ultimately protecting, finally visible.
- 02
Blast radius while the risk signal is still warm
A risky sign-in raised by ID Protection becomes a scoped answer in minutes: what that account could reach, what it actually touched, from which device and which location - with Microsoft’s own backend IPs filtered out so the anomalies are real ones.
- 03
The identities that never sign in
Service principals, OAuth apps and AI agents hold consented scopes and run without a user session, so they pass no front door at all. 1Security inventories them next to the humans, with the same reach map and the same activity history.
- 04
The trim, reversibly executed
Revoke access, expire links, remove stale guests - automations staged behind a review queue with a grace period, recorded in a ledger you can replay. Nothing irreversible happens without a human decision.
Joint architecture
The Suite conditions the session. 1Security accounts for what it opens.
Entra Suite remains the front door: risk scored, sessions conditioned, apps published per-identity, entitlements provisioned and recertified - including ID Governance, which has its own pairing page. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licences, and resolves the interior - every effective permission, every non-human identity, three years of activity history without a SIEM contract. Front-door decisions get made against evidence of what is behind it, and first findings land the same day.
NIS2, jointly
Access control you can enforce and evidence.
NIS2 - Directive (EU) 2022/2555 - obliges essential and important entities to implement access control policies, asset management and multi-factor authentication as part of their risk-management measures, with management personally accountable for them.
The Suite supplies the enforcement: MFA and risk-based Conditional Access on every sign-in, per-application access replacing broad network reach, entitlements provisioned through access packages and recertified on schedule, identity proofed at onboarding.
1Security supplies the evidence the same article implies but no front door can produce: which assets each identity effectively reaches inside Microsoft 365, which of those permissions were ever exercised across three years of activity, and reviewed, reversible automations to remove the ones that were not. Enforcement plus evidence is the answer; either alone is half of one.
Keep the door. Add the floor plan.
Read-only consent in the morning - by the end of the day, what every identity the Suite lets in can actually reach.
Or keep securing the entrance to rooms nobody has mapped.