1Security + Microsoft Purview
Purview knows what your data is. 1Security knows who can reach it.
Microsoft Purview classifies, labels and protects your sensitive data - brilliantly, across every app and service it touches. What it was never designed to map is the other half of the risk: the permissions, sharing links and group memberships that decide who can reach that data. That is where 1Security begins.
- 70%of breaches exploit excessive permissions
- 98%of granted permissions are never needed
- 12h → 10 mina blast-radius investigation, before and after
Credit where due
What Purview does brilliantly.
One platform for data security, governance and compliance - built into the Microsoft 365 you already run.
Labels that never let go
Sensitivity labels classify and protect content with encryption and markings, and because the label lives in the file’s metadata, it stays with the data wherever it’s saved or sent. Labels protect whole containers too - Teams, Microsoft 365 Groups and SharePoint sites.
DLP that acts in the moment
Purview DLP runs deep content analysis - not a simple text scan - across Exchange, SharePoint, OneDrive, Teams, endpoints and on-premises shares. When a sensitive item is about to leave, it warns, blocks or quarantines, right inside the apps people already use.
Compliance machinery at platform scale
Audit, eDiscovery, Compliance Manager, Records Management - a full compliance suite in one portal. And in the Copilot era the labels carry over: Copilot honors label permissions and returns data only to users granted the right to extract it.
The other half
A content engine, by design.
Purview’s whole model is the item: classify the file, label the email, block the sensitive upload. That focus is exactly why it works so well - the policy travels with the content, and every decision is anchored to what the data is.
The standing access around that content is a different question. Which identities can reach a Highly Confidential library - through direct grants, sharing links, nested groups, inheritance? Which of those permissions has ever been used? What else could the account behind a DLP alert have reached? Those are questions about the graph of access, not about any single item.
That graph was never Purview’s design brief. It is 1Security’s entire product.
The complement
What 1Security adds around the label.
1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did.
- 01
The reach behind every account
Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. When Purview marks a document Highly Confidential, the permission graph tells you exactly how far the accounts around it extend.
- 02
A memory that predates the incident
Three years of activity history without a SIEM contract, and a behavior baseline for every identity. When something breaks the norm, you get an anomaly episode with an alert line you position yourself - not a pile of raw events.
- 03
Findings that carry to their fix
Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision.
Joint architecture
Two layers, one tenant.
Purview enforces at the content layer - labels, encryption, DLP - inside the Microsoft 365 services where your data lives. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licenses, and resolves the access layer: every identity, every permission, three years of activity. The label says what the data is; the graph says who can reach it and what they did with it. First findings land the same day.
NIS2, jointly
One directive, two obligations, one pair.
NIS2 - Directive (EU) 2022/2555 - makes access control policies and asset management an explicit risk-management measure under Article 21(2)(i), and expects you to prove both.
Purview covers the asset side: sensitive data is discovered, classified and labeled, and DLP enforces how it may move. 1Security covers the access side: the permission graph shows which identities can reach that data and which of those permissions were ever used - then trims the excess through reviewed, reversible automations.
When the auditor asks who can access your critical data and why, the answer is a report, not a project.
Purview labels it. 1Security maps who can reach it.
Keep Purview doing what it does best - and put the permission graph around it.
Or keep guessing who can open the files you just labeled.