Microsoft 365 visibility
You cannot count what is in your tenant. We can.
Sites, guests, apps and devices are counted in different places, by different people, at different times - so nobody has one number. Most tenants hold several times more sites than IT believes, hundreds of guests who were invited straight into sites, and dozens of consented apps nobody remembers approving. 1Security connects read-only and counts all of it - live, in one place, with what each thing can reach.
The problem
The official inventory is the optimistic one.
The site count most teams carry in their heads covers the sites somebody deliberately created. It rarely includes the private-channel and shared-channel sites every Team spins up on its own, or the personal OneDrive behind every user - each a real store of company data with its own permissions and its own sharing links. In a typical tenant the real site count is three to five times the number IT would quote.
The same goes for people and things. A directory-based guest list covers directory guests; SharePoint-only guests - external people invited straight to a site - need to be counted from the sites themselves. Devices that read your files without ever enrolling only show up in activity. And the 30-50 consented apps and AI agents that hold a standing credential into your data are rarely on any inventory at all.
Every audit, every Copilot rollout and every incident starts with the same question: what do we actually have? Counting it by hand, source by source, is a quarter of work - and it is stale the week it is finished.
In practice
From one read-only consent to a counted tenant.
What discovery looks like on a real tenant - no agent, no scripts, no spreadsheet.
- 01
Connect read-only and let the scan run
One consent, standard Microsoft licenses, no agent to install. A tenant under 100,000 files is mapped in an hour or two; the largest tenants run past 40 million files and resume on their own if interrupted. New resources show up within about ten minutes at any size, so the lists are useful long before the deep scan finishes.
- 02
Watch eight inventories fill in
Sites (including channel sites and every personal OneDrive), Files, Users (including SharePoint-only guests), Groups (all six types kept distinct), Apps, Agents, Devices and Emails - each a live list you can filter, sort and export. The first surprise is usually the site count; the second is the guest count.
- 03
See what you did not know was there
Apps arrive with their consent channel and the first admin who let them in. Devices arrive classified as registered, unregistered or shadow - a shadow device is one seen reading data with no authentication observed at all. Sites arrive with their external users, storage in GB and last activity attached, so "we have 2,400 sites" comes with "and 310 of them are external-facing".
- 04
Keep it counted
The inventory stays live: a new Team, a new guest, a new app consent appears in about ten minutes. The number you quote in the steering meeting is the number as of this morning, not the export someone ran last quarter.
What makes it work
Not a list of names. A graph of what reaches what.
Every row in the inventory is connected to what it can access and what has touched it, so a count is one click away from a list.
The living inventory
Eight live inventories on one permission graph, with orphaned indicators on every one of them: no owners, no activity in a year, dormant with access still intact.
Explore the inventory tool →Sites ranked by exposure
Every site with its members, sharing links, external users, sensitive findings, storage and Copilot flag - ranked by what actually matters, not alphabetically.
Explore SharePoint governance →Devices the directory missed
Registered, unregistered and shadow devices reconstructed from real activity - including machines that read your files without ever authenticating the normal way.
Explore device detection →
FAQ
Common questions.
How long until we see the first numbers?
Minutes for the first lists, hours for a full map of a mid-size tenant. A tenant under 100,000 files is fully mapped in one to two hours, a million files in six to twelve, and the largest tenants run for weeks - resuming automatically if interrupted. New resources appear within about ten minutes regardless of size.
What will it find that our own inventory does not have?
Typically: private and shared channel sites, SharePoint-only guests, devices that read data without ever enrolling, and consented apps and AI agents nobody inventories. In most tenants the real site count is several times the one IT quotes and the guest count is higher than the directory-based list.
Does discovery change anything in the tenant?
No. Discovery runs on a read-only consent. Write actions exist in 1Security, but they live in separately consented modules and never run without that explicit opt-in.
What licenses do we need?
One user with a SharePoint Online license - Business Basic upward - is the only hard requirement. No E5, no Purview, no Entra P2. A few optional enrichments, like Purview label sync, use premium SKUs if you already own them.
Find out how many sites you really have.
Connect read-only and get your first counts the same day - sites including the hidden ones, guests including the SharePoint-only ones, apps, agents and devices with what each can reach.
Or keep quoting the number from last quarter.