1Security + Microsoft Purview

Purview tells you what a file is. 1Security tells you who can open it.

Purview classifies, labels and protects the content. 1Security takes those labels and detections and puts them next to the other half of the question: which users, guests, apps and AI agents can reach the file today, and what they did with it over the last three years. Same tenant, read-only connection, first results the same day.

  • 200,000
    files an ordinary account can open in a typical tenant
  • 20-40%
    of files with sensitive content that carry no label yet
  • 10 min
    from a labeled file to the full list of who can reach it

What Purview does

Purview is the standard for classifying and protecting content.

One platform for data security, governance and compliance, built into the Microsoft 365 you already run.

  • Labels that travel with the file

    Sensitivity labels classify and protect content with encryption and markings. The label lives in the file metadata, so it stays with the document wherever it is saved or sent. Labels can protect whole Teams, Microsoft 365 Groups and SharePoint sites as well.

  • DLP that acts as the data moves

    Purview DLP inspects content across Exchange, SharePoint, OneDrive, Teams, endpoints and on-premises shares. When a sensitive item is about to leave, it warns, blocks or quarantines, inside the apps people already use.

  • A full compliance toolkit

    Audit, eDiscovery, Compliance Manager, Records Management, sensitive information types. In the Copilot era the labels keep working: Copilot honours label permissions and returns protected content only to users allowed to extract it.

The question that comes next

Once a file is labeled, who can open it?

A label answers what the file is. The next question every auditor, CISO and Copilot rollout asks is who can reach it: through direct grants, sharing links, nested groups and site inheritance. In a typical tenant an ordinary account can open around 200,000 files, and 20-40% of files with card numbers, IDs or health data carry no label yet.

That is a question about the permission graph, not about any single file. Which accounts and apps can reach a Highly Confidential library? Which of those permissions has ever been used? What else could the account behind a DLP alert have opened?

1Security answers exactly that, and shows the answer next to your Purview labels and sensitive information types, so the two views sit in one row: what the file is, and who can open it.

What 1Security adds

Your labels, plus who can reach the data and what they did.

1Security connects read-only to the same tenant and resolves every identity in it - people, guests, apps, AI agents, devices - to what it can open and what it actually did.

  1. 01

    Labels and detections in one list

    Purview sensitivity labels and sensitive information type matches are imported and shown next to 1Security's own 300+ detectors and OCR. Filter Files to "labeled Highly Confidential" or "card numbers detected, no label" and get a list, not a project. Label coverage per site is a column.

  2. 02

    Who can open each labeled file

    Every user, guest, app and AI agent that can reach a file, resolved through direct grants, sharing links, groups and inheritance, in about ten minutes. Sort a Highly Confidential library by how many people can open it and the cleanup order writes itself.

  3. 03

    Three years of who did what, and a fix behind a review window

    Up to three years of activity on every labeled file, on standard licenses. When a DLP alert names an account, one click shows what else it opened. Expire the links, remove the access, revoke the sessions - staged as proposals behind a 72-hour review window, so nothing changes without a person deciding.

How the two fit together

Purview protects the content. 1Security shows the access around it.

Purview enforces at the content level - labels, encryption, DLP - inside the Microsoft 365 services where the data lives. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licenses, imports the labels and detections, and resolves the access level: every identity, every effective permission, three years of activity. First findings land the same day.

NIS2, together

One directive, two obligations, covered by the pair.

NIS2 - Directive (EU) 2022/2555 - names access control policies and asset management as explicit risk-management measures under Article 21(2)(i), and expects you to evidence both.

Purview covers the asset side: sensitive data is discovered, classified and labeled, and DLP governs how it may move. 1Security covers the access side: which identities can reach that data, which of those permissions were ever used, and a reviewed, reversible cleanup for the excess.

When the auditor asks who can access your critical data and why, the answer is an export from one screen, with the labels on it.

Integration status

Where the integration stands.

The Purview arm of 1Security is read-only and pull-based: the sensitivity label taxonomy and per-file assignments come in through Microsoft Graph and stay current from the audit log, and Sensitive Information Type detections import through a dedicated Purview connection you consent to separately. Every imported detection keeps its provenance - detected by Purview, by 1Security, or by both - so the two engines confirm rather than overwrite each other. Tenants without Purview get the same screens from 1Security's own 300+ detectors and OCR on standard licenses; connecting Purview later adds Microsoft's detections next to them, with nothing to migrate.

Put "who can open it" next to every label.

Connect read-only in the morning. By the end of the day you have your labeled and unlabeled sensitive files, ranked by how many people can reach them.

Or keep guessing who can open the files you just labeled.