Better together

1Security + Microsoft Sentinel.

Sentinel remembers everything you send it: every source, normalized, correlated, hunted and answered with a playbook - a cloud-native SIEM doing exactly what a SIEM should. 1Security adds the one thing no log stream carries: the standing permissions of your Microsoft 365 tenant - who can reach what, through which grant, and whether they ever needed to.

Credit where due

What Sentinel does well.

A cloud-native SIEM built for multicloud, multiplatform scale - detection, investigation, response and proactive hunting on one query surface.

  • Every source, one surface

    Data connectors ship packaged in solutions: Microsoft sources integrate in real time, and Syslog, CEF and REST APIs bring in the rest of the ecosystem. ASIM normalization translates it all into one uniform view you can actually query.

  • Alerts become incidents

    Analytics combine low-fidelity alerts about different entities into high-fidelity incidents, mapped against MITRE ATT&CK and enriched with threat intelligence. The analyst starts from a case, not a haystack.

  • Response as workflow

    Automation rules coordinate incident handling centrally; playbooks built on Azure Logic Apps carry the response into ServiceNow, Jira and the rest of your stack. Hunting queries and notebooks extend the reach beyond what any rule anticipated.

The design boundary

An archive, not a witness.

A SIEM’s contract is the record: ingest it, normalize it, correlate it, keep it immutable. Sentinel honors that contract at cloud scale, and everything a SOC does - detection, forensics, compliance - stands on it. The contract is the point.

But permissions are state, not events. A sharing link created in 2023 emits nothing tonight. A nested group quietly extends reach to a site nobody mentions in any log. An identity’s real blast radius inside Microsoft 365 is assembled from direct grants, links, group memberships and inheritance - and none of that assembly travels in a log stream, so no query against the stream can return it. 70% of breaches exploit excessive permissions; 98% of granted permissions are never needed at all.

Sentinel answers “what happened” better than anything else you run. “What could happen - who can reach what, right now” is a different question, held in a different structure. A SIEM stores records; understanding permissions was never its assignment.

The witness

What 1Security adds.

1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did.

  1. 01

    The permission graph

    Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. A blast-radius investigation that used to take 12 hours now takes 10 minutes.

  2. 02

    Identity-shaped memory

    Per-identity behavior baselines over three years of activity history, with anomaly episodes and an alert line you position yourself. When an incident names an account, its normal is already established.

  3. 03

    Devices and origins, reconstructed

    Shadow devices rebuilt from real activity by a stable fingerprint - no Intune enrollment required. Every action enriched with location and ASN, Microsoft’s own datacenter noise labelled out.

  4. 04

    Findings that end in a fix

    Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision.

Joint architecture

The record and the map.

Sentinel stays exactly where it is: the organization-wide record, the incidents, the hunting surface, the playbooks. 1Security connects to your Microsoft 365 tenant with read-only consent - no agents, standard Microsoft licenses, first findings the same day - and holds the map the record can’t carry: the resolved permission graph and per-identity baselines. When a Sentinel incident names an account, the analyst pivots to 1Security for its blast radius and its history, then closes the loop with remediation that queues for human review. The archive states the facts; the witness explains what they touch.

  • Same day
    from read-only consent to first findings
  • 12h → 10 min
    a blast-radius investigation, before and after
  • Standard
    Microsoft licenses - no E5 prerequisite

Joint use case

DORA asks how far it could spread.

DORA requires financial entities to classify ICT-related incidents and report the major ones on fixed deadlines - initial notification, intermediate report, final report - with a defensible assessment of impact. The clock starts before the investigation ends.

Together the two products keep that clock honest. Sentinel establishes what happened and when: the incident, its timeline, the correlated evidence across every source you ingest. 1Security establishes how far it could spread: every file, site and mailbox the affected identity could reach, resolved in minutes instead of a day of log stitching - and what it actually touched, against three years of its own baseline.

The impact section of the report stops being an estimate. It becomes a lookup - and the remediation that follows is queued, reviewed and recorded.

Keep the record. Add the witness.

Sentinel already remembers everything that happened. See what changes when the permissions underneath it are resolved - every identity, every grant, every blast radius on demand.

Or keep reconstructing blast radius from queries, one incident at a time.