Microsoft 365 inventory tool
Your tenant has 3-5x more sites than IT thinks. We count all of them.
Ask an admin how many sites, guests, consented apps or devices the tenant has and the answer is low by a multiple - private channel sites, personal OneDrives, SharePoint-only guests and unenrolled devices never made it onto any list. 1Security keeps eight live inventories - users, files, sites, groups, emails, apps, AI agents, devices - built from what actually happens in the tenant, refreshed within about ten minutes, with "what can it reach?" answered on every row.
- 8live inventories on one permission graph
- 500M+files inventoried in the largest production tenants
- ~10 minfor a new site, user, app or device to appear
The problem
Several exports later, still no count.
Most tenants hold several times more sites than IT believes they have. Guests, apps and devices are counted no better.
Every Team ever created left a site. Every private and shared channel made another site with its own membership. Every user carries a personal OneDrive. Every "let me just try this app" click left a service principal with standing permissions. In a mid-size tenant that adds up to thousands of sites, 30-50 consented apps with zero users and hundreds of guests nobody has reviewed - and none of it is in one place.
Exports get you part of the way: one snapshot per source, stale on arrival, and silent about anything that never registered in a directory. The laptop that was never enrolled. The guest who only ever got a SharePoint link and never became a directory object. The add-in an admin approved in 2022 and then left the company.
1Security builds the inventory from the tenant itself and from its activity, then keeps it alive. Not a quarterly census - a running count with the permission graph underneath, so every row also answers "and what can it reach?"
What gets counted
Every kind of thing in the tenant, with its own screen.
Each inventory has the same depth: reach, sensitive data in scope, activity trend, and orphaned filters that say "review me first".
Sites - all of them
Every SharePoint site, subsite and hub, every Teams-connected site including private and shared channel sites, and every personal OneDrive as a site of its own - with storage, owners, external users, links and last activity as columns.
- 6 access channels
Apps and integrations
Every OAuth consent, add-in, vendor integration and managed identity, with six access channels classified and the first consenting admin recorded - so "who let this in?" has a name even after that admin left.
Devices - including shadow ones
Registered, unregistered and shadow devices reconstructed from real activity with stable fingerprints. A device that was never enrolled still shows up here, with the files it touched.
AI agents, across ecosystems
Copilot and Copilot Studio agents, Entra Agent ID agents and Azure AI Foundry in one inventory, with the files, sites, users and emails each agent can actually reach counted.
Identities - all three kinds
Members, Entra guests and SharePoint-only guests - external identities that never became directory objects and slip past directory-based reviews - each with reach, last real activity, MFA state and license.
Licenses as a reclaim list
Per SKU: purchased vs assigned vs available units, holders with guests broken out, subscription status - and the dormant accounts still holding paid seats.
The method
Built from activity, not copied from the directory.
A directory lists what was registered. An inventory built from behavior lists what exists.
Shadow devices are the clearest example: a machine observed accessing data with no observed authentication at all sits outside any enrollment-based inventory by definition. 1Security keys these devices by stable fingerprint and stitches sessions onto them, so an odd event last Tuesday becomes "this machine, these documents, these accounts".
The same logic runs everywhere. Last-seen comes from actual activity logs, current to about ten minutes. Sites are marked abandoned by what stopped happening on them - typically more than half of all files sit in sites with no activity for a year. Apps are flagged orphaned when nothing has used them for a month or a year. The inventory does not just count the tenant - it tells you which parts are dead weight with live access.
In practice
The quarterly review, done in four sorted lists.
Four passes that used to be four separate projects - now four filters over the same graph.
- 01
Sites nobody owns
Open Sites, filter to no activity in a year and external users still attached. The list is usually a few dozen rows and every one of them is a site nobody inside touches but someone outside can still enter.
- 02
Apps nobody uses
Open Apps, filter to no users or no activity for a year. In a typical tenant that is 30-50 consents, each with the admin who approved it - so "can we remove this?" has a name attached.
- 03
Devices nobody manages
Open Devices, filter unmanaged plus personal - the BYOD set nobody controls. Shadow devices on top of it are where token theft first becomes visible.
- 04
Licenses nobody holds
Open Licenses, sort available units descending, review the guest holders, cross dormant accounts with their paid seats. Ten minutes, and typically 10-30% of paid seats turn out to be idle.
The difference
What only an activity-built inventory can count.
Not hidden settings - things that only show up when the count is built from what actually happens.
- Shadow devices: machines touching data with no authentication trail, keyed by persistent fingerprint
- SharePoint-only guests: external access that lives outside the directory, counted anyway
- Private and shared channel sites and personal OneDrives counted as sites - the 3-5x gap
- The first admin who consented to each app, kept after that admin leaves
- Per-agent AI reach: the files, sites, users and emails each agent can actually touch
- Last-seen from real activity, current to about ten minutes
- Orphaned everything: no owners, no members, no activity for a year - as filters, not archaeology
- Every count sits on the permission graph, so each row answers "what can it reach?"
Deployment
Counted the same day you connect.
One read-only consent, no agents, no appliances. The inventory starts filling within minutes and new resources keep appearing about 10 minutes after they exist. Standard Microsoft licensing from Business Basic up. No E5, and no Intune requirement for 1Security's own device insights. Each customer tenant lives in its own dedicated database.
- 1 dayfrom consent to a browsable inventory
- 0 writesread-only by default - write is a separate consent
- 0 Intunelicenses required for device visibility
Use cases
Where the count pays for itself.
Copilot readiness: before AI reads the tenant, know the tenant. The pre-rollout list is a filter - Copilot-enabled sites with sensitive data, sorted by detections - not a discovery project.
Offboarding without leftovers: a leaver's OneDrive, their sharing links, their app consents and their license are all rows in the same inventory, so nothing orphaned survives the exit.
M&A and consolidation: two tenants counted the same way, on the same graph, before anyone promises a migration date.
Office 365 Access Management
The graph underneath the inventory: who can reach each counted thing.
See access management →SharePoint Governance Tool
The site inventory turned into ranked cleanup with a review window.
See SharePoint governance →Copilot Security Tool
The AI agent inventory with what each agent can read.
See Copilot security →
FAQ
Common questions.
How is this different from the admin center exports?
Each export lists what was registered with one source, separately. 1Security builds one inventory across all of them, adds what registration alone does not capture (shadow devices, SharePoint-only guests, abandoned sites), and puts the permission graph underneath so every row also answers what it can reach.
How long does the initial inventory take?
Browsable the same day. A tenant under 100K files completes its full scan in one to two hours, around 1M files takes 6 to 12 hours, and the largest 500M+ file tenants take weeks - with the inventory usable throughout and new resources appearing within about 10 minutes.
Do I need Intune for the device inventory?
No. Device posture (compliance, management state, ownership) is read from Entra and Intune where present, but 1Security's own insights - shadow devices, per-device activity, distinct users and locations - come from activity reconstruction and need no Intune license.
Does the AI agent inventory need extra Microsoft licenses?
Everything Entra-backed scans with no extra license. Only the declarative Copilot agent catalog needs Agent 365 - and exactly one license, on the single admin account that connects the tenant. Without it, that one tab shows a banner; nothing else fails.
Is any of this writing to my tenant?
No. The inventory is built entirely from the read-only connection. Cleanup actions (site ownership, app disable, license reclaim) live in the separately consented Automations module and stage behind a 72-hour review window before anything changes.
Count the tenant. Then govern it.
One read-only consent and the inventory starts filling the same day - sites, apps, devices, agents, guests and licenses, with what each can reach attached.
Or keep believing the number of sites IT wrote down in 2022.








