1Security

Requirements

Exactly what 1Security needs before you connect - which Microsoft 365 licenses count, which admin roles are used and when, every permission requested per module, and what stays optional.

Requirements

Everything 1Security needs from your tenant, in one place: the license check that runs at connect time, the admin roles involved, the exact permissions each module requests, and the handful of things that genuinely need a premium Microsoft SKU.

The headline: 1Security runs on a standard Microsoft 365 license. There is no agent to install, no appliance, no log forwarder, and no E5 requirement for the core product.

Microsoft 365 licensing

The one hard requirement

Your tenant needs at least one user with a license that includes SharePoint Online. That is the whole check. 1Security verifies it at connect time and blocks with "Your tenant does not have the required license" if no qualifying subscription is found.

Any of these qualify (the list is matched on subscription SKU, so equivalents and regional variants count too):

FamilyPlans that qualify
BusinessBusiness Basic, Business Standard, Business Premium
EnterpriseOffice 365 E1 / E3 / E5, Microsoft 365 E3 / E5
FrontlineMicrosoft 365 F1 / F3 (including the EEA "no Teams" variants)
Standalone SharePointSharePoint Online Plan 1, Plan 2, Office for the web
Developer & GovernmentE3 / E5 Developer, GCC High and DoD variants of E3 / E5

The license is checked at the tenant level, not per seat. 1Security does not need a license for every user it maps - it needs the tenant to have SharePoint Online, because that is what makes the Microsoft Graph endpoints 1Security reads available at all.

What needs nothing extra

These all work on Business Basic - no E5, no add-ons, no premium sign-in logs:

  • The full permission graph - users, groups, sites, files, apps, agents, devices.
  • Sensitivity scanning with 1Security's own engine (300+ detectors, OCR included).
  • Up to three years of activity history, well past Microsoft's default retention.
  • Location intelligence - enrichment runs locally, no premium sign-in log add-on.
  • Devices, including unregistered and shadow devices. 1Security reads the Entra device directory, not Intune - Intune is never required. (If you do run Intune, it fills in the compliance and managed-state columns; without it they stay empty.)
  • Automations and the whole remediation layer: file and link remediation, group and site membership, disabling users, apps and agent identities, revoking app consent grants, assigning and removing licenses - including removing a Copilot license. The only exceptions are the two Copilot search-exclusion actions listed below.
  • Agents discovered through Entra Agent ID - agent identities and blueprints are readable on every Entra tenant, no license attached.

What needs a premium Microsoft SKU

A handful of features depend on something Microsoft itself puts behind a higher tier. Each one degrades on its own - the rest of the platform is unaffected, and 1Security detects the missing tier and skips cleanly rather than erroring.

FeatureWhat it needsWithout it
Purview SIT detectionsMicrosoft Purview Content Explorer - Microsoft 365 E5, E5 Compliance, or the Information Protection & Governance add-on1Security's own sensitivity engine still classifies everything - you lose the Microsoft second opinion, not the finding. See Sensitivity.
Sensitivity labelsMicrosoft Purview Information Protection - Microsoft 365 E3 / E5 or Business Premium (labels have to exist in the tenant before there is anything to read)The Sensitivity Labels screen stays empty. 1Security's own classification is unaffected.
Sign-in-level detailEntra ID P1 - included in Microsoft 365 E3 / E5, Business Premium and EMS, not in Office 365 E1 / E3 / E5Activity keeps flowing in full from the unified audit log. What stays empty: per-user last sign-in time, per-sign-in Conditional Access attribution, and the Conditional Access policy inventory. 1Security detects the missing tier on the first call and skips that branch permanently.
Native security alertsMicrosoft Defender (any workload that emits alerts)Defender's alerts and incidents don't flow in. 1Security's own anomaly detection is unaffected.
Copilot search exclusionBoth of the things Microsoft requires for Restricted Content Discovery: a base subscription - Office 365 E1 / E3 / E5 / A5 or Microsoft 365 E3 / E5 / A5 - and one advanced management route: a Microsoft 365 Copilot license assigned to at least one user (seats you own but have assigned to nobody do not count), Microsoft 365 E7, or the SharePoint Advanced Management Plan 1 add-onThe two actions that exclude a site from Copilot and org-wide search (Site_BlockCopilotOrgWideSearch / Site_AllowCopilotOrgWideSearch) fail cleanly. Every other site-settings action works on any SharePoint plan. Once you connect, the Action readiness screen reads your subscriptions and says which of the two parts is missing, beside the action.
Copilot agent catalogMicrosoft Agent 365 on the one admin who connects the tenant (~$15/user standalone, or bundled in E7)Entra-backend agents are still scanned in full; declarative Copilot agents look like ordinary enterprise apps. Details in Agents.
Historical audit backfillThe AuditLogsQuery.Read.All permission granted on the read app. Depth follows Microsoft's audit retention: 180 days on every plan, 365 days with E5, up to 10 years with the 10-Year Audit Log Retention add-onForward audit-log polling keeps running - only the backfill of history from before you connected stays dormant.
Automatic audit-log enablementEntra ID P2 - the audit module grants itself Exchange Administrator as a time-boxed (2 hour) PIM assignment, and PIM is a P2 featureAudit ingestion itself is unaffected. Only the convenience of 1Security checking and turning on the unified audit log for you is lost - flip it on once yourself, see Tenant settings.

The Copilot row follows Microsoft's SharePoint Advanced Management prerequisites page, which lists no Business plan. On Business Basic / Standard / Premium with Copilot, 1Security reports the two actions as not ready even though they will very likely run - buy nothing on the strength of that verdict alone.

Check your tenant before you connect

This section is for Microsoft 365 administrators: the check below reads your tenant's subscriptions, which takes a role that can see Billing in the Microsoft 365 admin center - Global Administrator, Billing Administrator or License Administrator. Without one of those you will hit a permissions wall at the first step.

It is advisory. It compares the licenses your tenant holds against the same bundle table 1Security uses after you connect, and it assumes your base subscription is active - a lapsed or cancelled subscription still appears in the list for a while, and no prompt can see that. Microsoft decides what runs; this tells you what to expect. The check 1Security runs after you connect also matches subscriptions by their GUID, so it can only be more generous than this page, never less.

Check your licenses before you connect

Export Billing > Your products to CSV and drop it on the check page: which of the two parts you hold, how many 1Security actions run on them, and what would unlock the rest. Nothing is stored.

Open the license checkNo sign-in, no consent

Admin roles

WhenWho has to do itWhy
Initial consent, and each extension moduleGlobal AdministratorMicrosoft requires a Global Admin to grant tenant-wide application permissions.
Purview moduleAn admin who can edit Purview role groupsThe 1Security service principal must be added to the Content Explorer List Viewer role group before Purview detections can be read.
Day-to-day useNo Microsoft admin role at allAnalysts work inside 1Security. Access there is governed by 1Security's own roles.

Consent is a one-time action per module. If you are not a Global Admin, ask one to complete the consent flow - you can still own day-to-day operations afterwards.

Directory roles 1Security assigns to itself

Two modules need a Microsoft role on their own service principal, because the underlying API is Exchange-based rather than Graph-based. This is why those modules request RoleManagement.ReadWrite.Directory - it is used to make exactly one assignment, to 1Security's own application:

  • Audit module - assigns Exchange Administrator to the audit app's service principal, so it can read the unified audit log configuration through Exchange Online PowerShell. The assignment is deliberately time-boxed to 2 hours through Privileged Identity Management, which means it needs Entra ID P2 - on tenants without P2 the assignment doesn't complete, audit ingestion still runs in full, and the only loss is that 1Security cannot check or enable the unified audit log for you.
  • Purview module - the same permission pattern as a standing assignment (no PIM, no P2), paired with the Content Explorer List Viewer role-group membership above.

Tenant settings

  • Unified audit log must be turned on. It is on by default in most tenants. 1Security checks its status and, once the audit module is connected, can turn it on for you - or you can do it yourself first, see Microsoft's guide. Without it, Microsoft records no activity for anyone to read, so the Activity Logs screen stays empty.
  • No other tenant configuration is required. No mail flow rules, no conditional access exceptions, no service accounts, no mailbox impersonation.

Permissions, module by module

1Security follows least privilege literally: the base install is read-only, and every capability that needs more permission is a separate consent you grant only if you want the feature. Write access exists in exactly two modules, both opt-in.

Core visibility - read-only, granted at install

Microsoft Graph:

User.Read.All                      Group.Read.All
GroupMember.Read.All               Directory.Read.All
Files.Read.All                     Sites.Read.All
Organization.Read.All              Application.Read.All
Team.ReadBasic.All                 Reports.Read.All
Insights-UserMetric.Read.All       UserAuthenticationMethod.Read.All
AuditLog.Read.All                  SecurityAlert.Read.All
SecurityIncident.Read.All          Sites.FullControl.All
AuditLogsQuery.Read.All            (optional - historical audit backfill only)
Policy.Read.All                    (optional - Conditional Access inventory only)

SharePoint:

Sites.Read.All
User.Read.All
Sites.FullControl.All

Why Sites.FullControl.All appears in a read-only module. SharePoint's own API offers no read-only scope that exposes site-collection sharing settings and permission inheritance - the data the permission graph is built from. The visibility module only ever issues read calls with it. Nothing in 1Security writes to your tenant until you enable the Automations or Mailbox Management module below.

Audit log

Office 365 Management API:  ActivityFeed.Read, ActivityFeed.ReadDlp
Microsoft Graph:            RoleManagement.ReadWrite.Directory

The Graph permission is used only for the Exchange Administrator self-assignment described above.

Purview

Microsoft Graph:  RoleManagement.ReadWrite.Directory

Plus membership of the Content Explorer List Viewer role group in Purview.

Email visibility

Mail.Read
Domain.Read.All

Read-only access to mailbox contents. Message bodies and attachments are read during analysis, not stored.

Mailbox management (optional, write)

Mail.ReadWrite

Granted separately from email visibility - you can read mailboxes without ever allowing changes. Lets an automation quarantine or flag a message rather than only alerting on it. No permanent deletion.

Automations (optional, write)

Microsoft Graph:  Files.ReadWrite.All, Group.ReadWrite.All,
                  GroupMember.ReadWrite.All, User.ReadWrite.All
SharePoint:       Sites.FullControl.All

Optional (each unlocks only its own actions):
                  Application.ReadWrite.All            (app & agent enable / disable,
                                                        assignment requirement)
                  DelegatedPermissionGrant.ReadWrite.All  (revoke app consent grants)
                  AppRoleAssignment.ReadWrite.All         (remove app role assignments)

The only module that can change anything in your tenant. Actions are staged behind review queues and grace periods - see Automations.

Copilot agents (optional)

CopilotPackages.Read.All   (delegated, on the read app)

Delegated rather than application permission, which is why Microsoft validates the license of the single admin who connected the tenant rather than every user. See Agents.

Clients and network

  • Browser - Chrome, Edge, Firefox or Safari, last two major versions. Nothing to install: no extension, no desktop agent, no endpoint software.
  • Cloud (SaaS) - nothing to open on your side. 1Security calls Microsoft, not your network. Users' browsers need outbound HTTPS (443) to app.1security.ai and api.1security.ai - the full hostname list, and what to do when a web filter classifies 1Security as an AI site and blocks it, is in Network Requirements.
  • BYOC and On-Premise - the deployment needs outbound HTTPS (443) to the Microsoft endpoints 1Security calls: login.microsoftonline.com, graph.microsoft.com, manage.office.com, <tenant>.sharepoint.com and <tenant>-my.sharepoint.com, plus the Exchange Online and Security & Compliance PowerShell endpoints (outlook.office365.com, *.compliance.protection.outlook.com) used by the audit and Purview modules. Hardware and Azure resource sizing is in Installation.

When a prerequisite is missing

Next: pick a deployment model in Installation, then see what the first scan does with the access you granted.

On this page