1Security + Microsoft Entra Suite

Entra Suite decides who gets in. We show what they can open once inside.

Identity Protection, Conditional Access, Private and Internet Access, ID Governance and Verified ID govern the sign-in: who, from where, on what terms. Once a permitted identity is inside Microsoft 365, an ordinary account can open around 200,000 files through groups, links and inheritance. 1Security resolves that for every user, guest, app and AI agent, shows what was actually opened over three years, and trims what nobody needs - behind a review window.

  • 200,000
    files an ordinary account can open in a typical tenant
  • 10 min
    from a risky sign-in to its blast radius
  • 3 years
    of activity behind every identity

What Entra Suite does

The strongest identity front door in Microsoft 365.

Five products working as one layer over how an identity signs in: risk, conditions, network access, lifecycle and proof of identity.

  • Risk that turns into a decision

    Identity Protection scores sign-in and user risk on Microsoft-scale signal, and Conditional Access acts on it while the session is being set up: block, step up authentication, force a password reset. No ticket, no analyst in the loop.

  • Access to an app, not to a network

    Private Access and Internet Access replace broad VPN reach with per-application access under the same Conditional Access policies, for on-premises apps and internet destinations alike.

  • Lifecycle and proof of who you are

    ID Governance automates joiners, movers and leavers with access packages and recurring access reviews. Verified ID adds cryptographically verifiable credentials for onboarding and helpdesk identity checks.

What you still need to know

The sign-in is governed. What that identity can open is the next question.

Conditional Access answers "should this sign-in be allowed, and on what terms". That is exactly the right question at the front door. Behind it, a permitted session to SharePoint carries whatever the account has accumulated: sites inherited through nested groups, files shared years ago, a mailbox delegated and never revoked. In a typical tenant that adds up to hundreds of thousands of files per ordinary account.

Some access never presents a sign-in at all: an anyone link, a guest already inside a site, an OAuth app or AI agent running on application permissions with no user attached. Those paths sit outside the session model by design - and they are exactly where oversharing hides.

So the question on top of the Suite is: for every identity it lets in, and every one that never signs in, what exactly can it open, what did it actually touch, and how do we take back the part nobody uses.

What 1Security adds

Every identity resolved to what it can open, and what it opened.

1Security maps every identity in Microsoft 365 - user, guest, app, AI agent, device - to the files, sites and mailboxes it can reach and the actions it took, and stages the cleanup.

  1. 01

    Effective access per identity

    Direct grants, sharing links, group nesting and site inheritance collapsed into one answer per identity: which files, sites and mailboxes it can open, and through which path. The thing a Conditional Access policy is protecting, made visible.

  2. 02

    Blast radius while the risk signal is fresh

    A risky sign-in flagged by Identity Protection becomes a scoped answer in about ten minutes: what that account could reach, what it actually touched, from which device and location. Datacenter relay addresses are labelled, so the anomalies you see are real ones.

  3. 03

    The identities that never sign in

    Service principals, OAuth apps and AI agents hold consented scopes and run without a user session. 1Security lists them next to the humans, with the same access map and the same activity history.

  4. 04

    Cleanup behind a review window

    Revoke access, expire links, remove idle guests - staged as per-resource proposals with a 72-hour review window by default, owner review available, every executed action logged. Nothing irreversible happens without a person deciding.

How the two work together

Entra Suite governs the sign-in. 1Security governs what it opens.

Entra Suite stays the front door: risk scored, sessions conditioned, apps published per identity, entitlements provisioned and recertified (ID Governance has its own pairing page). 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft 365 licenses, and resolves the inside: every effective permission, every non-human identity, up to three years of activity. Front-door policy gets written against evidence of what is behind it, and first findings land the same day.

NIS2, jointly

Access control you can enforce, and prove.

NIS2 (Directive (EU) 2022/2555) requires essential and important entities to run access control, asset management and multi-factor authentication as part of their risk-management measures, with management personally accountable.

Entra Suite supplies the enforcement: MFA and risk-based Conditional Access on every sign-in, per-application access instead of broad network reach, entitlements provisioned through access packages and recertified on schedule, identity proofed at onboarding.

1Security supplies the evidence: which assets each identity can actually reach inside Microsoft 365, which of those permissions were exercised across three years of activity, and reviewed, reversible automations to remove the ones that were not. Enforcement plus evidence is the whole answer.

See what every permitted identity can actually open.

Read-only consent in the morning. By the end of the day: what every identity Entra lets in can reach inside Microsoft 365, and what it did with it.

Or keep securing the sign-in without knowing what it opens.