1Security + One Identity Active Roles
Active Roles gets the grant right. 1Security shows what the grant can reach.
One Identity Active Roles runs your hybrid Microsoft directory the way it should be run - delegated without standing privilege, provisioned by policy, deprovisioned on time, every operation on the record. What it was never designed to map is the life of a grant after it lands: the files, sites and mailboxes it opens inside Microsoft 365, and what the account actually did there. That is where 1Security begins.
- 70%of breaches exploit excessive permissions
- 98%of granted permissions are never needed
- 12h → 10 mina blast-radius investigation, before and after
Credit where due
What Active Roles does brilliantly.
One console for Active Directory, Entra ID and Microsoft 365, with policy behind every change.
One console for the hybrid directory
Active Directory, Entra ID and Microsoft 365 administered from a single console - across domains, tenants and multi-forest environments. Workflow automation keeps every change inside consistent, enforced policy.
Delegation without standing privilege
Access Templates delegate fine-grained, role-based permissions precisely where they’re needed - and zero standing privilege takes the always-on admin rights off the table.
A lifecycle that ends cleanly
Immediate least privilege for every account, dynamic groups that follow attributes, and deprovisioning that actually finishes - membership removal, relocation, permanent deletion - with an audit trail of every operation performed or attempted.
The other half
A directory engine, by design.
Active Roles’ model is the change: the account created right, the group membership set by rule, the delegated permission scoped tight, the leaver deprovisioned on time. Enforcement lives at the moment of change, and the audit trail records every operation performed or attempted in the directory.
What happens between the changes is a different question. Once the account exists and the group is correct, that identity spends its working life inside SharePoint, Exchange and Teams - opening files, creating sharing links, accumulating reach through inheritance the directory never sees. Which of those permissions were ever used, from which device, what a compromised account could actually reach - those are questions about the workload, not the directory.
That layer was never Active Roles’ design brief. It is 1Security’s entire product.
The complement
What 1Security adds after the grant.
1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did.
- 01
The reach behind every grant
Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The directory object Active Roles provisioned becomes a map of everything it opens.
- 02
A memory the directory doesn’t keep
Three years of activity history without a SIEM contract, and a behavior baseline for every identity. When an account breaks its own norm, you get an anomaly episode with an alert line you position yourself - not a pile of raw events.
- 03
Findings that carry to their fix
Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision.
Joint architecture
Two layers, one identity.
Active Roles enforces at the directory layer - accounts, groups, delegation, deprovisioning - across Active Directory, Entra ID and Microsoft 365. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licenses, and resolves the workload layer: every identity, every permission, three years of activity. The directory says what an account holds; the graph says what it can reach and what it did. First findings land the same day.
NIS2, jointly
One directive, two halves of access control.
NIS2 - Directive (EU) 2022/2555 - makes access control policies an explicit risk-management measure under Article 21(2)(i), and expects you to prove they work in practice, not just on paper.
Active Roles covers the policy side: access granted by rule, delegated without standing privilege, removed on schedule, every directory operation in the audit trail. 1Security covers the practice side: the permission graph shows what those grants can actually reach inside Microsoft 365 and which of them were ever used - then trims the excess through reviewed, reversible automations.
When the auditor asks whether your access control policy matches reality, the answer is a report, not a project.
Active Roles gets the grant right. 1Security shows its reach.
Keep Active Roles running the directory - and put the permission graph after it.
Or keep assuming a well-made grant is a well-used one.