# 1Security Full Documentation 1Security answers one question for Microsoft 365 tenants: who has access to what, and what did they do with it. It maps every identity - employee, guest, service principal, OAuth app, AI agent and device - to the files, sites, mailboxes and Teams it can actually reach, keeps up to three years of activity history behind that map, and remediates what should not be there. It connects with read-only consent, runs on standard Microsoft 365 licenses (no E5 or SIEM contract required), and returns first findings the same day. > This file contains the full text of the product pages followed by the full technical documentation. ================================================================= ## Make access make sense | 1Security URL: https://1security.ai/en/ ================================================================= Built for the #1 attack vector Make access make sense. Identity attacks are how companies get breached now - and almost nobody can answer who has access to what. 1Security maps every identity in Microsoft 365 - human, app, AI agent, device - what it can reach, what it actually did, and fixes what shouldn’t be there. Live, on the licenses you already own. Read-only consent · connected before lunch Why this exists Ten reasons teams come to us. Pick yours. Attackers log in now The valid login doing things it shouldn’t - the attack every tool files under normal. border-t-accent-orange-700 Who has access to what? The first question of every incident and audit. Nobody can answer it. You will. border-t-primary-600 Busywork, automated - with receipts Ready-made remediations counted against your live tenant, staged behind a review queue you control. border-t-accent-blue-700 You can’t improve what you can’t measure Every deviation recorded, every trend measured, every threshold yours to move. border-t-primary-500 A thousand new identities Every AI agent is an employee nobody interviewed. One inventory for all of them. border-t-accent-pink-500 03:14 - a breach replay Minute by minute, the breach your tools would sleep through. Scroll it. border-t-accent-orange-700 Security, measured Exposure, waste, speed - numbers the board can act on, not adjectives. border-t-accent-blue-600 Retire the ritual The access-review spreadsheet, the PowerShell folder, the SIEM log tax - replaced. border-t-accent-green-700 Answers before lunch Read-only in the morning, first findings the same day. It risks nothing. border-t-accent-orange-700 Why this category exists The founding document: how the attack became a permission. Read the manifesto. border-t-gray-700 Identity is the new private network Attackers don’t break in anymore. They log in. 600 million identity attacks a day, and every one looks like a valid login. Your firewall, your EDR and your SIEM all watch it happen - and file it under normal. The first question of every incident Who has access to what? In most organizations the honest answer is: nobody knows. You’ll answer it live - down to the file, the person, the app and the AI agent. Automations Automate the busywork. Keep the receipts. Ready-made remediations counted against your live tenant before you enable anything, staged behind a review queue you control, recorded in a ledger you can replay. Measurement You can’t improve what you can’t measure. Every number in your tenant, tracked day by day - files reachable by Copilot, links left open, guests still active. You see the direction of travel long before it becomes an incident. The agentic tenant is already here Your org chart just grew by a thousand. None of them are human. Every AI agent is an identity with its own permissions, reach and activity - built in an afternoon, vetted by no one. One inventory for all of them. A true story, statistically speaking At 03:14, someone became your finance director. A stolen token, a machine you’ve never seen, four hundred documents by sunrise - and not one alarm. Replay the breach your tools would sleep through. You can’t defend with adjectives The board asks for numbers. Security answers with adjectives. Exposure, waste, detection speed, direction of travel - measured, ranked and trended from your live tenant. Numbers the board can act on. This is the future of access security One graph to replace them all. The access-review spreadsheet, the PowerShell folder, the SIEM log tax - every one a partial, stale answer to the same question. Retire the ritual. No SIEM contract. No E5 upsell. Every access question, answered before lunch. Connect read-only in the morning on the licenses you already have. First scan results the same day. It risks nothing. A founding document Cybercrime changed sides of the login screen. For thirty years we defended the private network, then the endpoint. Meanwhile the attack became a permission, and the battlefield became who-can-reach-what. What you get Everything your tenant does, one living graph. Five branches, every identity and every path to your data. Pick a branch - each capability below is a screen, not a slide. identity Identity & Access Users Groups Devices - registered, unregistered, shadow Locations as identities Sign-in posture data Data & Content Files Sites Emails & conversations Sensitivity labels Sensitive-data detections ai Apps & AI Applications AI Agents Blueprints Permissions, atom by atom Reach: files · sites · users · emails detections Detections Security alerts Anomalies - with an alert line you own Automations with grace periods Policies & findings activity Activity & Trends 3-year activity log Activities: top & unused Trends over time Insight boards The data moat The deepest map of a Microsoft 365 tenant. Not an export. A living graph of identities, permissions and actions - kept current in real time, remembered for years. 1B+ - files scanned 100k+ - users scanned Every type - files, sites, users, groups, apps, agents, devices, email 3 years - of activity memory, no SIEM contract Signal nobody else has The access data Microsoft can’t show you. Native admin centers stop where the directory stops. 1Security reconstructs what actually happens from live activity: Shadow devices Machines touching your data with no observed sign-in at all - the signature of a stolen token, invisible to Intune by definition. Locations as identities Country, city and network for every action, with Microsoft’s own datacenter noise labelled out - so a foreign origin finally means something. Agent reach, resolved What each AI agent can actually get to - files, sites, users, mailboxes - resolved from knowledge sources, not assumed from a manifest. The paths nobody drew The unexpected route to a file - a guest, in a group, that inherits a folder - reconstructed hop by hop and drawn as a graph you follow with a finger, not a report you reverse-engineer. Evidence of deletion Email threads with missing parents - the quiet signal that someone cleaned up after themselves. Built for action From found to fixed - in the same screen. Every security product leaves a gap between the finding and the fix. 1Security closes it in three moves: 01 Map Every identity, permission and path to data - the full graph, from tenant-wide down to one file’s “why”. 02 Watch Real-time evaluation, anomaly baselines per identity, and an alert line you position - recorded even when it isn’t shouting. 03 Fix Automations that count what they’d fix before you enable them, stage proposals behind a grace period, and keep a review ledger. Everything that writes is opt-in. The platform runs read-only until you deliberately consent to remediation - and even then, a review window can hold every action for human approval. Major use cases The questions you’ll answer this week. Each one used to be a project. Each card carries its own number. 12h → 10min “Was this a breach?” Chart the exact blast radius of a compromised account - which files, which sessions, from where. Counted before rollout “What can Copilot see?” Know what every agent and assistant can reach before you switch it on - not at the incident review. Evidence drawn live “Are we audit-ready?” NIS2, ISO 27001, SOC 2 - reporting straight from the live permission and activity map, never stale. Ranked from day one “Where’s the waste?” Dormant licenses, abandoned apps, orphaned sites - every cost line ranked and reclaimable. Proof Trusted by security teams that measured the difference. 20× faster access reviews From a quarterly spreadsheet ritual to a filtered live view. 95% less time on manual audits Evidence assembled from the live map instead of screenshots. 8× quicker investigations Every event arrives connected - the anomaly, the device, the location, the sessions around it, every resource touched. The whole interconnected map in one intuitive view, not twelve log queries. How it feels Security tools ask for trust. This one shows its work. No black boxes Every detection is explainable: the baseline, the deviation, the line it crossed - and the line is yours to move, with history re-classified the moment you do. Busywork automated - with receipts The chasing, clicking and cleanup runs itself behind a review queue, and every action lands in a ledger you can replay. Your time goes to protecting, not administering. Peace of mind, not noise Everything is recorded even when nothing is shouting - so quiet means safe, not blind. And when something does matter, it arrives as one clear story. What it takes to try: almost nothing. Standard Microsoft licenses - no E5, no Purview required Read-only until you opt in to write First scan results the same day ISO 27001 · GDPR · European data centers Get your answer today. Connect read-only in the morning. By the afternoon, “who has access to what?” has an answer - for the first time. No thanks - nobody’s asked yet. ================================================================= ## Why identity and permission security | 1Security URL: https://1security.ai/en/why/ ================================================================= A founding document Cybercrime changed sides of the login screen. Security never followed. For thirty years we defended the private network, then the endpoint. Meanwhile the attack became a permission, the attacker became a login, and the battlefield became who-can-reach-what inside the world’s collaboration platforms. There is no shelf for the tool that watches this. So we built it. Three eras Private network. Endpoint. Identity. The first era built walls: firewalls, gateways, DMZs. The attack was a packet, and the industry built a shelf of tools to inspect packets. The second era followed the attack onto the machine: antivirus, then EDR. The attack was a process, and the industry built a shelf of tools to watch processes. The third era is already here. The attack is a permission exercised by a valid login - no exploit to patch, no signature to match, no malicious process to kill. The industry built no shelf for it. SIEMs store the evidence without understanding it; IAM provisions identities without watching them; compliance scanners photograph the crime scene once a quarter. The blind spot Nobody knows who has access to what. Not as a slogan - as the observed condition of essentially every Microsoft 365 tenant on Earth, including well-run ones. Access accumulates in seven places at once: direct grants, sharing links, group memberships, site roles, application permissions, agent knowledge sources, inheritance. No native surface joins them into one answer. Attackers know this. It’s why they stopped breaking in. 600M/day - identity attacks (Microsoft, 2024) 70% - of breaches exploit excessive permissions 98% - of granted permissions are never needed Doctrine What the category must do. A tool that fails any of these is a dashboard, not a defense. The map is always on A quarterly scan is a photograph of a river. The permission map must be live, or it is already wrong. The answer must not need an expert The truth about access currently lives in the heads of a few people who understand SharePoint inheritance, nested Entra groups and Graph semantics - and it dies when they change jobs. A category that only pays out for specialists has not solved the problem; it has moved it. Anyone in the room should be able to read who can reach what, and be right. Minutes to know, not months The measure of this category is the clock. “Were we breached, and what did they reach?” is answered today in weeks of log forensics, by which time the answer is archaeology. It has to be minutes - not because speed is impressive, but because every hour between the question and the answer is an hour the intruder keeps the access. Record everything, alert on your line Every deviation is kept; the alert threshold belongs to you, not to a vendor’s idea of your risk appetite - and moving it re-classifies history instantly. Findings must carry fixes A finding without a remediation path is homework. Detection and repair belong on the same screen, with human review where it matters. Every identity counts Humans, service accounts, OAuth apps, AI agents, devices. If it can touch data, it is an identity - and it gets the same map, baseline and history as an employee. It has to pay for itself on the simple things Visibility of this kind is infrastructure: it must run on standard licenses, not behind an E5 upsell or a SIEM contract. And it has to be worth its price on the first, dullest use case - the guests who never left, the licenses nobody reclaimed - before any programme, transformation or roadmap. A product that only earns its keep after a services engagement is charging you to finish it. Expertise on top should be a partner adding judgement, never a tax for making the tool work. The first instrument 1Security is the category’s first instantiation. One living graph of every identity and every path to data in Microsoft 365 - watched in real time, remembered for three years, and wired to act. This is not a feature list; it is the doctrine above, running. Not only our thesis Microsoft’s own innovation programme backs it. A manifesto is easy to write and cheap to believe. Microsoft’s Innovation Alley partners with 1Security and recommends it to the ecosystem - the platform whose tenants this category is about, arriving at the same conclusion independently. Being first in a category is only an advantage if somebody else can see the category too. [ video - Microsoft Innovation Alley on 1Security ] First to build it, and already trusted around the tenants it maps. If you run Microsoft 365, you already have the problem. Now there’s a tool for it. See it on your own tenant - read-only, today. ================================================================= ## Identity attacks: they log in, not break in | 1Security URL: https://1security.ai/en/why/identity-attacks/ ================================================================= Identity is the new private network Attackers don’t break in anymore. They log in. 600 million identity attacks a day, and the winning move is always the same: a valid login, doing things it shouldn’t. Your firewall, your EDR and your SIEM all watch it happen - and file it under normal. 1Security is built for the attack that looks like an employee. 600M/day - identity attacks (Microsoft, 2024) 70% - of breaches exploit excessive permissions 98% - of granted permissions are never needed The shift The attack stopped being a break-in. For twenty years a breach had a shape: an exploit, a payload, a malicious process. The industry built magnificent machinery to catch exactly that - and the machinery works. Which is precisely why attackers stopped doing it. Today the winning move is a credential. A phished password, a stolen session token, an OAuth consent granted on a Tuesday and forgotten by Friday. There is no exploit to patch, no signature to match, no process to kill - just a valid login, exercising permissions it was legitimately given, at a scale nobody is watching. The battlefield moved to the other side of the login screen. The tooling never followed. The blind spot Why your stack can’t see it. Three tool categories, three excellent answers to the previous era’s questions. Your SIEM stores the evidence Every event of an identity breach lands in a log. But a SIEM stores records without understanding permissions - it can tell you what happened once you already know what to ask. It’s an archive, not a witness. Your IAM provisions, then looks away Identity platforms are superb at granting access and terrible at watching it. Once the permission exists, nobody tracks whether it’s ever used, by whom, or from where - and 98% of it is never needed at all. Your EDR clears the machine Endpoint tools inspect processes, and every process in an identity attack is clean. Outlook is Outlook, the browser is a browser. The credential is the malware - and no endpoint agent scans for that. The answer What it takes to catch a login. A login-shaped attack has no signature - but it has tells. Catching it means correlating four things your tools keep in four different places, on one timeline: actor, device, location and behavior. A device that shouldn’t exist The token arrives from a machine that was never enrolled and never authenticated. 1Security reconstructs these shadow devices from real activity, keyed by a stable fingerprint - visible even when Intune has never heard of them. An origin that doesn’t fit A hosting-provider ASN in a country you don’t operate in. Every action resolves to country, city and network - with Microsoft’s own datacenter noise already labelled out, so an unfamiliar origin actually means something. A baseline that breaks The account suddenly reads four times its usual volume. Per-identity baselines turn “a number” into “an anomaly” - episodes, not events, with an alert line you position yourself. The context The map behind the timeline. Detection tells you something is wrong. The permission graph tells you how bad: every file, site and mailbox the compromised account could reach - direct grants, sharing links, groups, inheritance - resolved in minutes. Blast radius used to be a week of log stitching. Now it’s a question with an answer. The repair From found to fixed. Seeing the breach is half the job. 1Security carries every finding to its fix: revoke the access, expire the links, sever the sessions - through automations with grace periods and review queues, so nothing irreversible happens without a human deciding it should. And until you deliberately consent to write access, everything runs read-only. You choose the day the map is allowed to act. Proof and deployment Counted, not promised. No agents to deploy, no E5 upsell, no services engagement. Connect read-only in the morning and read your first findings the same day. 12h → 10 min - a blast-radius investigation, before and after Same day - from read-only consent to first findings 3 years - of activity memory - without a SIEM contract Standard - Microsoft licenses - no E5 prerequisite Attackers don’t break in anymore. They log in. See your tenant the way an attacker does - every identity, every permission, every login that doesn’t fit. Or keep assuming every login is legitimate. ================================================================= ## Microsoft 365 access review, answered live | 1Security URL: https://1security.ai/en/answers/ ================================================================= The first question of every incident, audit and AI rollout Who has access to what? In most organizations the honest answer is: nobody knows. Not IT, not security, not Microsoft’s own admin centers. 1Security exists so the answer is always: here - down to the file, the person, the app, the device, and the AI agent. Live, not last quarter’s export. …and what did they do with it? …and should that AI see it? …and since when? …and who else? The ordeal Try answering it today. Say the question lands on your desk this afternoon - from an auditor, an incident bridge, or a board member who just read about a breach. Here is the honest procedure: open three admin centers, dust off the PowerShell folder, export permissions to CSV, cross-reference group memberships by hand, screenshot the sharing panes one by one. A week later you present the answer. It was stale before the meeting started - access changed a thousand times while you were compiling it. None of this is your fault, and none of it is a skills problem. You didn’t choose this career to screenshot permission panes. The reason Why the question is structurally unanswerable. Access in Microsoft 365 hides in seven places at once - and no native surface joins them into one answer. This isn’t a missing feature. It’s a missing category. Direct grants The explicit permission on the file or folder - the only layer most access reviews ever look at, and by volume the smallest. Sharing links “Anyone with the link” created in one click, alive for years. A 500-seat tenant typically carries over a thousand of them. Group memberships Access through a team someone was added to in 2021, for a project that shipped in 2022. The grant outlived its reason. Site roles SharePoint sites run their own role system - owners, members, visitors - administered separately from everything else. Application permissions OAuth apps consented once, holding tenant-wide read scopes forever. Nobody remembers the consent screen. Agent knowledge sources Copilot and custom AI agents reach whatever their knowledge sources reach - an access path that didn’t exist two years ago. Inheritance Permission flows down site → library → folder → file, silently overridden and silently restored. The layer that makes the other six multiply. The living map One graph, from the whole tenant to a single file’s why. Identity & Access × Data & Content × Apps & AI × Activity - one graph, refreshed live. Zoom out to the whole tenant; zoom in to one file and read exactly why each person, app and agent can touch it: which grant, which link, which group, which inheritance. Under pressure The answer, when it matters most. Three moments when “we’re not sure” stops being an acceptable answer. 10 minutes A breach The blast radius of a compromised account - every file, site and mailbox it could reach, and what it actually touched. What used to take 12 hours of log stitching now takes ten minutes. Drawn live An audit NIS2, ISO 27001, SOC 2 - evidence pulled from the living map at the moment the auditor asks, not from a screenshot folder assembled the week before. Before rollout A Copilot rollout Know exactly what the assistant will be able to see before you switch it on - counted, listed, and trimmed down to what it should see. Kept current Answered forever, not once. Live A real-time engine Every permission change, share and sign-in lands on the map as it happens - the answer you get is the answer right now, not last quarter’s export. 3 years A memory Who had access last March, and what they did with it - the question forensics actually asks. Three years of attributed activity, without a SIEM contract. Per identity A watchful baseline Anomaly baselines watch every identity - human, app, agent, device - and open an episode when the answer changes in a way it shouldn’t. The alert line is yours to position. From answer to action What the answer reveals, you fix on the same screen. A finding without a fix is homework. Every excessive permission, stale link and over-scoped app on the map carries its remediation with it - automations with grace periods, review queues, and owner sign-off where it matters. From “nobody knows” to an answer in under 10 minutes - and first answers the day you connect. Read-only, on the licenses you already own. Get the answer for your tenant - today. Connect read-only in the morning. Ask anything by the afternoon. No thanks - nobody’s asked yet. ================================================================= ## AI agent & Copilot permissions in Microsoft 365 | 1Security URL: https://1security.ai/en/agents/ ================================================================= The agentic tenant is already here Your org chart just grew by a thousand. None of them are human. Microsoft is rebuilding 365 around AI agents - and every agent is a new identity with its own permissions, its own reach into your data, and its own activity log. Built by employees in an afternoon. Shipped inside products you already licensed. Vetted by no one. 1Security is the one list they’re all on. Copilot Studio Azure AI Foundry Entra Agent ID Declarative Copilot agents → one inventory The quiet hiring spree Three hires nobody interviewed. Each one quietly acquires a slice of your tenant. Nothing in Microsoft’s admin surface puts the three of them on the same list. The afternoon build An operations manager opens Copilot Studio after lunch and wires an agent to the finance site “to answer invoice questions”. By five o’clock it can read every document on the site. Nobody thinks of this as granting access - it felt like making a chatbot. The overnight vendor A product you already license ships an update, and suddenly there’s a declarative Copilot agent in your tenant with a knowledge source nobody reviewed. It arrived inside the license, so procurement never saw it either. The platform experiment A platform team spins up an agent in Azure AI Foundry to test a workflow. The test works, the agent stays, and its service principal keeps its permissions long after everyone forgot the experiment happened. The inheritance Agents inherit your mess. 98% of granted permissions are never needed. For years that was survivable, because the permission-holders were human - slow, distracted, unlikely to open ten thousand files on a Tuesday. The mess was real, but it moved at human speed. An agent with those same permissions is your oversharing problem operating at machine speed. It will read everything it can reach, remember all of it, and repeat it to anyone who asks the right question. Copilot doesn’t leak - it surfaces what was always reachable. The rollout didn’t create the exposure; it made the exposure searchable. 98% - of granted permissions are never needed One inventory One inventory, atom by atom. Discovery is the easy half. An inventory only earns its keep when it goes all the way down to the atoms. Every ecosystem, one list Copilot Studio, Azure AI Foundry, Entra Agent ID, declarative Copilot agents - every agent from every ecosystem in a single inventory, with its owner, its origin and its creation date. Blueprints reviewed once Fifty employees can clone the same agent blueprint. You review the blueprint once - its permissions, its knowledge sources - instead of chasing fifty copies through the tenant. Every permission, atomized Each permission with its source, its kind and Microsoft’s own blocked-for-agents flag - so you see at a glance which grants an agent holds that Microsoft itself says agents shouldn’t. Reach, quantified Not “it has Sites.Read.All” but the exact files, sites, users and mailboxes this agent can touch - resolved through the same permission graph that maps your humans. Under watch Watched like any employee. Every agent gets an activity trail: what it read, when, how much. Every agent gets an anomaly baseline of its own - so “this one read 4× its usual files today” is an episode above your alert line, not a needle in a log. And agents are policy targets like anyone else: alert when a new agent appears, when one gains a permission, when one touches a sensitive site. Agent risk lives in the same machinery as human risk - not in a separate console you’ll check less often. The reveal And everyone else too. Here’s the widening shot: the graph that inventories your agents is the same graph that maps your humans, your devices, your OAuth apps and your data. AI is the newest identity type on it - not a separate product. Because the access problem was always bigger than the robots. Agents didn’t create it; they gave it urgency. The tool that counts your agents also answers who-can-reach-what for everything else in the tenant. Before the rollout Guardrails before rollout. The right order is boring: clean up what’s reachable before Copilot ships, then prove the boundaries after. 1Security does both - it finds the oversharing agents will amplify, retires it, and once the agents arrive, watches each one against its own baseline. Connect read-only today, and the first scan returns the number your rollout plan is missing: how many agents you already have. Count your agents. Most organizations are off by an order of magnitude. Connect read-only and get the real number today. ================================================================= ## Microsoft 365 breach detection & forensics | 1Security URL: https://1security.ai/en/breach/ ================================================================= A true story, statistically speaking At 03:14, someone became your finance director. A stolen token. A machine you’ve never seen. Four hundred documents gone by sunrise - and not one alarm, because every event, taken alone, looked legitimate. This page replays the breach your tools would sleep through. Scroll. 03:14 sign-in 03:16 unknown device 03:17 hosting-provider ASN 03:20 baseline broken 06:05 blast radius 06:12 access severed The replay A valid token signs in No password prompt, no MFA challenge, no alert. The credential is legitimate - that’s the whole trick. Your EDR has never met this machine, so it has nothing to say. The machine that shouldn’t exist Never enrolled, never authenticated - accessing data with no observed sign-in at all. 1Security classifies it as a shadow device: reconstructed from real activity, keyed by a stable fingerprint, invisible to Intune by definition. The origin that doesn’t fit A hosting-provider ASN in a country you don’t operate in. Locations resolve every action to country, city and network - with Microsoft’s own datacenter noise already labelled out, so this origin actually means something. Four times the usual appetite File activity spikes past this account’s own 30-day baseline. Anomalies opens an episode - per-user baselines, episodes not events, and an alert line you position yourself. The blast radius, exactly Which 340 files, which two accounts, which sessions, from where. Per-action attribution over a three-year memory - the investigation that used to take 12 hours of log stitching, done in 10 minutes. Severed, staged, documented Access revoked, links expired, every action recorded in a review ledger. Composite revocation understands the permission graph - direct grants, links, groups, sites - and asks before touching anything that would affect other people. Epilogue Your tools saw all of this. They just had no reason to care. Every event in this story appeared in a log somewhere. The sign-in was valid, the device was silent, the origin was an IP address nobody resolved, and the download volume was just a number without a baseline. The breach wasn’t invisible - it was unassembled. We’re not selling fear. We’re selling sight: the same events, assembled into one story, while it’s still 03:20 and not the morning after. Replay this on your own tenant. Connect read-only and see what the last 90 days actually looked like - shadow devices, strange origins, broken baselines and all. ================================================================= ## Microsoft 365 remediation automations | 1Security URL: https://1security.ai/en/automations/ ================================================================= Automations Automate the busywork. Keep the receipts. The link cleanup, the offboarding leftovers, the license chase - the work that eats your week without making anyone safer. 1Security automations run it for you: counted against your live tenant before you enable anything, staged behind a review queue you control, and recorded in a ledger you can replay. Your time goes back to actually protecting. Nothing acts without a separate write consent The problem Security teams don’t drown in attacks. They drown in chores. An ex-contractor still holds access to three sites. Four hundred “Anyone” links have quietly outlived their purpose. A dozen licenses idle on accounts that left in March. None of it is an incident, so none of it ever wins against the incident queue - and every quarter the pile grows. The industry’s answer is a dashboard that shows you the pile. Ours is a machine that works through it - carefully, visibly, and only as far as you allow. The number, not the promise Every automation tells you what it would fix - before you enable it. A curated catalog of remediations across AI safety, oversharing, hygiene and cost - each one counted live against your tenant while you browse. The first question stops being “what could this do?” and becomes “it found 1,204 - do I want them fixed?” Ready to run suggested remediations Curated policies across sites, files, users, groups, apps, devices, email and licenses - with live counts on every card. Preview first the real affected resources Every suggestion opens onto the actual list of what it would touch, the conditions used, and the arguments the action would run with. Yours to tune review & customize Open any suggestion in the policy editor - conditions, arguments, severity - and your customization survives future catalog updates. Control A grace period and a human review queue, by default. Enabling an automation doesn’t fire it. It stages proposals - and the clock, the queue and the final word are yours. Enable The automation starts staging a proposal per resource instead of acting - by default with a 72-hour window before anything happens. Review Approve, reject (which snoozes the resource for 30 days), withdraw - or let the clock run out. Bulk review applies decisions by match, so proposals arriving mid-review are included. Act Only then does anything change - and composite actions understand the permission graph, showing the blast radius per source and asking before touching anything that would affect other people. Breadth One catalog for policies and one-off actions alike. Manual actions share the same catalog and the same ledger - run an action once from a list or a resource drawer, and it is recorded exactly like a policy-driven one. Sites - sharing, link defaults, privacy, Copilot indexing Files - link removal, revoke, downgrade, delete Users & groups Apps & agents Devices - enable / disable Email actions Licenses The receipts Every action, accounted for. Four live counters, an “engine live - last evaluation X ago” strip, per-automation firing stats, and an actions chart from one hour to one year - with click-through to the exact resources changed. When someone asks “what did the robot do?”, the answer is a list, not a shrug. Active - automations, visible at a glance 30 days - of runs and resources remediated, counted 1h → 1y - actions chart with click-through 100% - of actions in the review ledger Read-only until you say otherwise. Detection, counting and previews run on the read-only application. Remediation requires a second, separately consented write application - and even then automations stage instead of firing. Blocked attempts are logged. Nothing in this product changes your tenant without an explicit, revocable decision. Give the chores to the machine. Connect read-only, browse the catalog, and see the counts for your own tenant - before anything is allowed to act. No thanks - I’ll clean the links by hand. ================================================================= ## Measure Microsoft 365 exposure and risk | 1Security URL: https://1security.ai/en/measure/ ================================================================= Measurement You can’t improve what you can’t measure. Every other discipline earned its numbers decades ago. Security still runs on adjectives, gut feel and vendor black boxes. 1Security turns your live Microsoft 365 tenant into measured, trended, benchmarkable intelligence - where every deviation is recorded, every trend has a baseline, and every threshold belongs to you. First numbers the day you connect From black box to clarity The dial is yours - and history answers instantly. Anomaly detection is normally a black box: a threshold somebody else picked, invisible, immovable - and everything below it silently discarded. You can never tell whether quiet means safe or means the dial cut off exactly the thing that mattered. 1Security splits that decision. What is unusual is measured and always recorded, down to the smallest meaningful deviation. What deserves an alert is a line you set - and when you move it, your existing history re-classifies in place. You see what a stricter or looser setting would have caught, on your own real activity, with no tuning period and no quarter of waiting. What gets measured Everything that moves in the tenant, on a scale. Not samples, not surveys - measured activity across every resource type, cut both ways: the extremes and the dormant. Pre-defined suggested trends, counted live Permission creep, oversharing velocity, exposure direction - each template shows how many resources match in your tenant before you enable it. Every type ranked activity cuts Top downloaders, unused agents, dormant licensed users, quiet sites - across users, files, sites, groups, emails, apps, agents and devices. 1h → all-time windows that fit the question Sub-day windows evaluated from raw activity catch a mass download while it unfolds; long windows answer instantly from rollups. The numbers that run the program Direction of travel, not a snapshot. A point-in-time report is obsolete when it renders. These are living series - trending, comparable, exportable. Exposure - is it shrinking or growing, per quarter TTD / TTR - time-to-detect and time-to-remediate, tracked Waste - licenses, apps and storage, ranked by cost Adoption - Copilot, agents and sites - used or abandoned Shared, not siloed Boards you arrange, links you can send. Ranked, sparklined, exportable - arranged into boards per team, with shared views for the whole tenant and every filtered cut carried in a URL a colleague can open. Measurement that acts Act on what you measure. Any measurement becomes an alert in one click Threshold or deviation-from-own-baseline - the default needs no number from you, and instant or digest delivery is your choice. Any finding carries its fix The measured pile of oversharing or waste connects straight to automations - counted, staged and reviewed before anything changes. Every improvement stays proven The same series that found the problem shows it shrinking - evidence for the next audit, the next budget, the next board meeting. Put a number on it. Connect read-only and watch the first baselines build from your own activity - measured, not estimated. No thanks - gut feel has been fine so far. ================================================================= ## Security metrics your board can act on | 1Security URL: https://1security.ai/en/board/ ================================================================= You can’t improve what you can’t measure The board asks for numbers. Security answers with adjectives. Exposure, waste, detection speed, direction of travel - every other function reports in numbers. 1Security turns your live Microsoft 365 tenant into measured, ranked, trended intelligence, so “are we getting better?” finally has an answer that isn’t a feeling. ↓ 18% - exposure trend this quarter 143 - dormant licenses found 6 min - median time-to-answer 3 - anomalies above your line The meeting Everyone else brought numbers. The CFO opens with revenue against forecast, to the decimal. Marketing has pipeline, conversion, cost per acquisition. Sales has a number for everything, including the excuses. Then it’s security’s turn: a narrative, a red-amber-green slide, a statistic borrowed from someone else’s breach report - and a budget request. Nobody in that room thinks the security team is doing a bad job. They just can’t tell. “Improved posture” and “elevated risk” aren’t measurements; they’re adjectives with a slide template. And it’s nobody’s fault. The tooling never produced numbers worth standing behind - quarterly snapshots that expired before the deck was finished, scanners that counted findings without ranking them, logs that answered questions only after a week of stitching. You can’t report what you can’t measure. What measurement looks like A measured tenant reports itself. Connect 1Security read-only and the tenant starts producing its own reporting: measured, ranked and trended - always current, never assembled by hand the night before. Trended, not snapshotted Exposure as a direction, not a point: sharing links, external access, dormant accounts and unusual activity, sparklined over weeks and quarters - so “are we getting better?” is read off a chart, not argued. Ranked, not listed Top downloaders this week. Unused apps this quarter. Most-shared files this month. Every cut ordered by what matters, refreshed continuously, and exportable straight into the board pack. Benchmarked against yourselves Every user, app and site measured against its own history - not against an industry average that describes somebody else’s company. Return on visibility Numbers that pay for themselves. Every tenant we have ever scanned carries spend nobody meant to keep: licenses assigned to accounts that stopped signing in months ago, apps granted access in 2023 and never opened since, orphaned sites quietly holding terabytes of storage. The first scan finds it and ranks it - reclaimable spend, ordered by value, with the evidence attached. For most organizations that one list covers the subscription before the security findings are even on the table. Dormant licenses Paid seats mapped against actual sign-ins and activity - not against the HR roster. Ranked by monthly cost, ready to reclaim. Unused apps Applications holding standing permissions to your data with no activity for months - cost and risk in the same row, ranked by both. Orphaned storage Sites and teams with no owner and no readers - storage you pay for, holding data nobody governs. If the first scan doesn’t find reclaimable spend, you shouldn’t buy us. Numbers under pressure Audit evidence drawn live, not assembled quarterly. When the auditor asks who has access to the finance site and how you know, the answer is a live query, not a two-week evidence sprint. NIS2, ISO 27001, SOC 2 - the access-control, monitoring and review evidence they ask for is drawn from the running tenant at the moment it’s requested. And the two numbers every framework circles back to - how fast you detect and how fast you fix - stop being aspirations. Every incident stamps its own timeline, so time-to-detect and time-to-remediate become tracked KPIs with a trend line the board can hold you to. That’s a feature, not a threat: a KPI you can move is a budget you can defend. NIS2 · ISO 27001 · SOC 2 Evidence on demand Access reviews, permission reports and activity trails generated from current state - every export stamped with when it was drawn and from what. TTD / TTR Response as a KPI Every anomaly episode and finding records when it opened, when it was seen and when it was closed - the pair of numbers auditors and boards actually ask for. The dial you own Risk appetite as a setting, not a vendor’s opinion. Most tools ship with someone else’s idea of what deserves an alarm. 1Security records every deviation from baseline - always, all of it - and lets you decide where the alert line sits. Move the line and history re-classifies the moment you let go: a quiet quarter can run tighter, an acquisition month can run looser, and either way the record stays complete. Risk appetite becomes a setting the board can see - a dial in your hands, governed like any other number. Walk into the next meeting with numbers. Connect read-only and take the first measurements the same day - exposure trends, reclaimable spend, detection KPIs, ready for the board pack. No thanks - the board likes adjectives. ================================================================= ## Replace access reviews and PowerShell scripts | 1Security URL: https://1security.ai/en/switch/ ================================================================= This is the future of access security One graph to replace them all. The access-review spreadsheet. The PowerShell folder. The SIEM contract that stores logs nobody reads. The consultant’s PDF that was stale at the kickoff meeting. Each one is a partial, dated answer to the same question - so we built the one place where the answer is whole, live, and fixable. Access-review spreadsheets PowerShell script folders Log-storage SIEM contracts Point-in-time compliance scans Audit consultants’ PDFs Guesswork How it’s done today The quarterly ritual. Every quarter, the same choreography. Someone exports group memberships to a spreadsheet. Someone cross-references them against a leavers list that was current two weeks ago. Someone screenshots the sharing settings of the twelve sites everyone worries about, pastes them into a deck, and presents the result as the state of access. By the time the meeting ends, the spreadsheet is wrong. Permissions changed during the presentation; a new sharing link went out somewhere around slide nine. Everyone in the room knows this, and nobody says it, because the ritual was never designed to be true. It was designed to be finished. Around the ritual, the supporting cast: a folder of PowerShell scripts only one person can run, a SIEM paid handsomely to store logs nobody reads, and a consultant’s PDF that was stale at the kickoff meeting. Four tools, four partial answers, and one question none of them can hold: who can reach what, right now? Five pillars, one graph Everything the ritual was trying to answer, answered. The organization graph has five branches. Each one replaces a tool you’re maintaining today. Know every identity. Users, guests, service accounts, OAuth apps, AI agents and devices - every actor in the tenant on one list, with the dormant and the orphaned already flagged. See every path to your data. Direct grants, sharing links, group memberships, site roles, inheritance - the permission graph resolves all of them into one answer per file. Watch every app and agent. Every OAuth consent and every AI agent with its permissions, its reach and its activity trail - vetted like a new hire, not discovered like an incident. Catch what breaks the pattern. Per-identity baselines and anomaly episodes, with an alert threshold you set yourself - and history re-classified the moment you move it. Measure the direction of travel. Exposure trends, ranked cuts, three years of memory - so “are we getting better?” has an answer that isn’t a feeling. What comes with it You don’t start from a blank page. The tools this replaces all shipped empty. The spreadsheet was a template someone in your team designed. The SIEM came with a query language and the expectation that you’d write the detections. The scripts are yours to maintain forever. Here the content arrives with the graph - already written for Microsoft 365, already counted against your tenant. Trends worth watching, pre-defined Permission creep, oversharing velocity, exposure direction - each one already matched against your tenant, so you pick from real numbers instead of imagining a metric. History starts collecting the day you turn it on. Remediations ready to run Curated fixes across AI exposure, oversharing, hygiene and cost - each showing exactly what it would touch, staged behind a preview and a grace period before anything moves. Baselines learned, not written What normal looks like for every identity, derived from your own activity rather than a rule you had to author - with an alert line you move yourself, and history re-classified the moment you do. Policies to start from The access questions every audit asks, already expressed as policies you can run, edit or schedule - and your edits survive the next catalog update. The catalog grows with every release. Nothing you’ve tuned gets rebuilt when it does. Answer any access question in minutes - or keep the spreadsheet. Who can reach this file? What changed on this site last quarter? Who still has access three weeks after offboarding? Ask on your own tenant. If the answer doesn’t arrive in minutes, the ritual keeps its job. Switching Switching is an afternoon. There is nothing to migrate, because everything 1Security needs already lives in Microsoft 365. You grant read-only consent, and the graph builds itself from what Microsoft already has - permissions, memberships, links, activity. No agents to deploy. No premium licenses to buy first - it runs on the standard ones you already own. No services engagement, no six-week onboarding plan. First results land the same day, on the same screen you’ll use every day after. The spreadsheet doesn’t need a farewell ceremony. It just stops getting opened. Proof What the switch actually buys. 20× - faster access reviews 1B+ - files scanned 95% - less time on audit prep One graph to replace them all. Connect read-only this afternoon. By tomorrow’s stand-up, the question that took a quarter takes a minute - priced like a utility, not like a data lake. ================================================================= ## Microsoft 365 access audit in a morning | 1Security URL: https://1security.ai/en/start/ ================================================================= No SIEM contract. No E5 upsell. No deployment project. Every access question, answered before lunch. Connect read-only in the morning, on the Microsoft licenses you already have. First scan results arrive the same day - and the questions that used to take a week (who can reach this? was this a breach?) start taking about ten minutes. 09:00 - consent granted 09:20 - first resources mapped 13:00 - first answers this week - baselines learning The old math Security tooling is quoted in money and paid in time. The SIEM route: a procurement quarter, a professional-services engagement, a data-onboarding project, then a tuning period measured in months. Somewhere around month four, someone finally asks what question all of it actually answers. The premium-license route isn’t faster: an E5 uplift for every seat, a Purview rollout, a consultant to decode the licensing matrix - a project plan before a single answer. Meanwhile the question doesn’t wait, and neither does whoever caused it. “Who can reach this folder?” is urgent on the day it’s asked - not in the quarter the deployment lands. The new math The same questions, on a different clock. Not adjectives - measurements from live tenants, with the mechanism one section down. 20× faster Access reviews Who can reach a site, a folder, a file - resolved across direct grants, links, groups and inheritance in minutes, not in a scheduled afternoon of PowerShell. 12 h → 10 min Investigations One account’s every action across three years of activity, on one timeline - the log-stitching week collapsed into a coffee break. < 1 h Mass-download detection Per-user baselines flag the account pulling four times its normal volume while the download is still running - not in next month’s review. Live Audit evidence Access reviews and activity trails drawn from current state the moment the auditor asks - never assembled retroactively. Why it’s this fast Speed is an architectural consequence, not a marketing claim. There is nothing to deploy because there is nothing we need from your machines. 1Security reads what Microsoft already has - the permissions, the sharing links, the audit trail your tenant has been writing all along - through APIs, under a read-only consent. No agents on endpoints. No data to migrate, no log pipeline to build, no E5 or Purview prerequisites. Grant consent in the morning and the first map is drawing itself before your next meeting. Fast doesn’t mean shallow Quick to start, because the heavy machinery is ours - not yours. A three-year memory Activity is kept for three years, so “has this ever happened before?” has an answer from month one - the history is your tenant’s own audit trail, replayed and retained. The full permission graph Every identity - human, app, agent, device - and every path it has to data: direct grants, links, groups, sites, inheritance. One graph, always current. A real-time engine Baselines learn each identity’s normal within the first week; every deviation is recorded, and the alert line is yours to place. First useful finding the same day, or walk away. It was read-only anyway. Nothing installed, nothing migrated, nothing to unwind - revoke the consent and it’s as if we were never there. The close This page wants a form, not a meeting. Pricing is one screen away and flat - no SIEM contract to negotiate, no per-gigabyte surprise, no services quote stapled to the back. If you’d rather see it before you connect, the live demo is one click and no calendar. But you don’t need our permission, a project code or a change window to find out what’s in your tenant. You need a morning. Connected by coffee. Answers by lunch. Read-only consent on the licenses you already own. First results today; baselines learning by Friday. ================================================================= ## Microsoft 365 security for MSPs and partners | 1Security URL: https://1security.ai/en/for-partners/ ================================================================= Partner program Sell the answer nobody else has. “Who has access to what?” is the question every one of your clients fails, every audit asks, and no product in their stack answers. It is the largest known problem in Microsoft 365 with the emptiest solution space - which makes it the rarest thing in this market: something new to walk in with, on top of the portfolio you already sell. Modern work Security & cyber Managed services & IT Compliance & GRC Adoption & productivity AI & Copilot readiness The opening Every client has this problem. None of them have a product for it. Ask any client who can reach the finance folder right now. You will get a pause, then a spreadsheet, then a promise to check. Their tenant has grown for a decade - guests who never left, sharing links nobody revoked, groups nested three deep, OAuth apps consented once, and now AI agents inheriting all of it. Nobody in the room can answer, and everybody knows the answer matters. That gap is unusual. Most of what you sell competes against four alternatives and a budget line that already exists - you are arguing about price and roadmap on someone else’s ground. Here there is no incumbent to displace. The admin centers stop where the directory stops, the SIEM stores the evidence without assembling it, and the access review is a quarterly ritual everyone knows is fiction by the time the meeting ends. A well-known problem with an empty solution space is the best thing that can happen to a practice: you are not fighting for a share of a category, you are the first credible answer in one. Growth, not just attach It doesn’t only upsell your book. It opens doors you couldn’t knock on. New logos are the hardest thing a partner does. Everything else - renewals, attach, expansion - is easier than the first meeting with a company that already has a provider. Access is the one topic that reliably gets that meeting, because it is a question a prospect cannot answer and cannot ignore. You ask the question that has no answer Not a pitch: “can you show me every external person who can open your finance site right now?” Nobody can. The conversation stops being about vendors and starts being about their tenant. Read-only consent, same meeting No agents, no infrastructure, no premium licence to buy first. Consent is read-only and revocable, and the scan starts on the tenant they already pay for. Findings while they’re still watching The first real numbers land the same day: the guests still holding access, the “Anyone” links quietly outliving their purpose, the agent that can reach HR. Their tenant, their names, their problem - not a slide. The statement of work writes itself You are no longer proposing a project on faith. You are quoting the remediation of a list you both just read - which is the shortest path from first contact to signature that this market offers. Fits the practice you already run One product, whichever practice you sell from. Access sits underneath most of what partners already deliver, so this rarely becomes a new specialisation - it becomes a better answer inside the one you have. Modern work The Teams, SharePoint and OneDrive estate you deployed, with every sharing link, guest and inherited permission finally visible - and fixable - after the rollout. Security & cyber Identity attacks are the breach story now. Blast radius per identity, anomaly baselines per user, and the containment answer at 3 a.m.: what could this account actually reach? Managed services & IT Joiner-mover-leaver proven rather than promised: who still has access three weeks after offboarding, which licences idle on departed accounts, what changed on the site last quarter. Compliance & GRC NIS2, ISO 27001, DORA and SOC 2 all ask who can reach regulated data and who approved it. Evidence with dates and owners, exported - instead of a screenshot pack assembled the week before the audit. Adoption & productivity Adoption programmes create sharing. Show the client the exposure their rollout produced and the cleanup that keeps it healthy - the conversation that turns a project into a retainer. AI & Copilot readiness Copilot surfaces whatever the user could already reach. Oversharing stops being a hygiene topic and becomes the blocker to an AI rollout - and you own both the assessment and the fix. The economics Margin that survives the deal. Resale margin on the products everyone else also resells is thin and getting thinner, and the services around them are priced by the hour against competitors doing the same work. This is different on both sides of the invoice: the delivery cost is low because there is nothing to deploy, and the value is high because nobody else is selling it. Read-only - consent to deliver - no agents, no infrastructure project Same day - from connection to findings you can quote against Their licences - runs on the Microsoft 365 the client already pays for Recurring - monitoring and remediation, not a one-off audit PDF And because the scan keeps running, the engagement doesn’t end at the report - the same tenant produces next quarter’s findings without another discovery phase. The ladder One question becomes a platform engagement. Every stage here is a real deliverable a client will pay for on its own, and each one makes the next obvious rather than pushy. Access assessment The door-opener. Who can reach what, what is exposed externally, what is dormant - the picture nobody in the tenant has ever seen. Remediation Curated fixes for oversharing, stale guests, idle licences and over-scoped apps - staged behind a preview and a grace period, so the client approves before anything moves. Managed monitoring Baselines per identity, anomaly episodes, an alert line the client sets, and trends that answer “are we getting better?” with a number. This is the retainer. AI & agent governance Every OAuth app and AI agent inventoried with its permissions and real reach. The newest budget line in the client’s organisation, and you are already inside it. Board reporting Exposure, waste and time-to-remediate as a quarterly number the board can act on - the report that makes the renewal conversation a formality. Fits what they already bought Nothing to rip out. Nothing to migrate. 1Security reads the tenant your client already runs, using their own licences and their own permission model. It does not replace Entra, Purview, Defender or their SIEM - it answers the question those tools were never built to answer, and it uses what they already produce. That matters commercially as much as technically: you are not asking a client to abandon an investment or a competitor to lose a renewal. There is no political fight inside the account, which is why these deals close on their own merits instead of on a displacement argument. Standard Microsoft licences - no E5 requirement Entra ID Microsoft Purview Defender Their existing SIEM Their own permission model Enablement Your team is ready to sell in a day, not a quarter. The deal will take as long as your client’s procurement takes - the ramp won’t. The surface is broad (identities, permissions, activity, agents, anomalies) but nobody has to learn all of it to start. Pick two use cases, run them well, and let the product carry the rest of the story when the client asks the next question. It demos itself The findings are the demo. You are not walking through features, you are reading their own tenant back to them - which is why first calls convert without a specialist in the room. Start with two use cases External sharing and offboarded access are enough to prove value in the first engagement. The rest of the platform is there when the client is, not homework before your first sale. Sales materials that match the page Decks, one-pagers, discovery questions and objection handling - written from the same use cases the product screens are organised around, so the story survives the handoff to delivery. A live demo environment A populated tenant you can open in a browser mid-call, with no fixture data to explain away and nothing to install before a prospect meeting. Documentation people actually read Every screen documented with the decision it supports, in English and Polish - so a new consultant can be useful on a client call in their first week. We join the hard calls Co-selling support for the deals that need it: architecture reviews, security questionnaires, procurement. Your logo stays on the engagement. Deployment Wherever the client’s data is allowed to live. Security, defence, public sector and regulated clients ask the hosting question first. Three answers, all first-party - no third-party providers in the path, whichever one they choose. Our cloud European data centres, ISO 27001 and GDPR, connected read-only in an afternoon. The default, and the fastest way to a first engagement. Their cloud (BYOC) Runs inside the client’s own subscription, so the data never leaves their tenancy or their compliance boundary - the answer that unblocks regulated accounts. On premise Fully self-hosted for clients whose data cannot leave the building, with no third-party services in the deployment. Rare in the market, and often the reason a deal is winnable at all. Microsoft Innovation Alley Recommended by Microsoft’s own innovation programme. Microsoft’s Innovation Alley partners with 1Security and recommends it to the ecosystem - which shortens the part of your sales cycle that is hardest to shorten: the question of whether a young vendor can be trusted around a client’s tenant. [ video - Microsoft Innovation Alley on 1Security ] Bring it to the first meeting. It answers the trust question before it is asked. Add the practice line your clients are already asking for. Bring one account, or bring your book. We will run the first assessment with you, hand over the materials, and stay on the calls until your team doesn’t need us on them. ================================================================= ## Case study: Medical University of Warsaw | 1Security URL: https://1security.ai/en/case-studies/medical-university-of-warsaw/ ================================================================= Case study - Medical University of Warsaw Full visibility and control over the Microsoft 365 data of 24,000 students and academics. A leading Polish medical university deployed a comprehensive solution for access governance, cost optimisation and protection of sensitive data across a rich Microsoft 365 ecosystem. 24,000+ users 11 million files 67 TB in the cloud 18,000 OneDrive accounts 6,700 SharePoint sites The organisation A university hospital’s data estate, run by a handful of people. The Medical University of Warsaw educates thousands of medical students and handles sensitive patient data for teaching and research. The university set out to deploy a new solution that would improve control over access across its extensive Microsoft 365 ecosystem. Rapid student turnover, access to medical data and a small IT team called for something that combined security with operational efficiency. The scale of the Microsoft 365 estate 24,000+ - students, academics and administrative staff 11M - files 67 TB - of data in the cloud 6,700 - SharePoint sites Plus 18,000 OneDrive accounts, thousands of Teams teams, and sensitive personal data that requires particular care under GDPR and health-sector regulation. Outcomes What the 1Security rollout delivered. Full visibility of the data of more than 24,000 people across SharePoint, OneDrive, Teams and Entra ID. Sensitive medical and personal data located across 67 TB - and its exposure measured rather than guessed at. Oversharing reduced: the widest-open sites, links and group memberships found, prioritised and cleaned up. Unused Microsoft 365 licences and resources identified and reduced, freeing up IT budget. Continuous monitoring of access changes for thousands of active users. Stronger compliance with the requirements governing medical data. The challenges A vast estate, a population in constant motion, a small team. Each of the following was true of the environment before the rollout - and any one of them would justify the project on its own. No complete picture of access in a constantly changing ecosystem A medical university has exceptionally high user turnover. Every year hundreds of students graduate and new ones enrol. Academics collaborate with outside research institutions, and access is granted inside teaching and research projects. Despite the advanced administrative capabilities built into Microsoft 365, the data sat spread across separate services - SharePoint, OneDrive, Teams - and the IT team had no tooling that brought ongoing monitoring into one place. The risk of exposing sensitive medical data Medical universities process particularly sensitive data: patient information used for teaching, research data and medical records. Any breach can mean a violation of medical confidentiality, heavy financial penalties (tens of thousands of złoty for a single breach in the medical sector) and lasting damage to the institution’s reputation. At the same time, the IT team had no way to automatically identify where in 67 TB of data the sensitive medical information actually sits - the places security effort should be concentrated on. Manual review does not scale to that volume. An unusually large risk surface against limited IT capacity The Medical University of Warsaw manages 18,000 OneDrive accounts and 6,700 SharePoint sites used by tens of thousands of people. That entire environment is administered by an IT team of a few. Licences and cloud resources used below their potential Research shows that educational institutions can cut Microsoft 365 costs by 14-30% through better licence management alone. What was missing was the tooling to identify: inactive licences left behind by graduates and former employees premium licences whose advanced M365 capabilities are never used duplicate and overlapping licences excessive consumption of storage space The overhead of compliance and audit On top of that, medical universities answer to several regulatory regimes at once: GDPR and personal-data protection Poland’s National Cybersecurity System Act (KSC) - the university’s clinical centre, UCK WUM, is designated a provider of an essential service medical confidentiality obligations ISO 27001 standards Producing compliance reports and access audits by hand in Microsoft 365 is slow and error-prone. The reporting built into that environment requires lengthy processing, so answering auditors and regulators quickly is not realistic in practice. We needed a solution that would let our small IT team manage a huge, constantly changing Microsoft 365 environment. 1Security gives us the full visibility and control we simply did not have before. We can now manage security proactively instead of only reacting to incidents. Marcin Wszendyrowny Medical University of Warsaw The solution 1Security as one platform for access governance across Microsoft 365. The Medical University of Warsaw chose 1Security as its partner for a comprehensive system to govern, monitor and optimise its Microsoft 365 environment - one that extends the administrative capabilities already available in M365. How the rollout ran Proof of concept - complete visibility of access 1Security connected to the university’s Microsoft 365 cloud environment every resource, user and permission scanned and mapped an interactive dashboard built to show the complete access picture Analysis of sensitive data and its exposure data exposure mapped in the context of users and teams 1Security’s sensitive-data detection deployed across the estate potential security gaps identified Reduction and optimisation oversharing worked down from the top: the widest-open sites, links and groups first unused resources, dormant accounts and premium licences surfaced for review and cleanup third-party and AI application access brought under review automated remediation available in the platform for whenever the university chooses to switch it on In daily use The capabilities the university runs on. Three of the platform’s capabilities carry the day-to-day work of the WUM IT team. One control panel for the whole estate Administrators moved to a single central control panel that presents all data in SharePoint, Teams, OneDrive and Entra ID (part of Microsoft 365) visually and intuitively. In real time, the IT team can see: who has access to which Microsoft 365 resources, and on what basis where data sits in the M365 ecosystem and how it is being used which Teams teams and SharePoint sites are active, and which are unused Automatic analysis of licence and resource usage Administrators also started using automatic analysis of Microsoft 365 licence and resource usage, which includes identifying inactive users and unused premium M365 subscriptions. This capability could deliver savings of 14-30% of licence spend. Sensitive-data detection, deployed The algorithm that detects medical, personal and other sensitive data is deployed and running on the university’s content. It answers the question manual review could not: where, inside 67 TB, the sensitive material actually sits - and it scores the exposure and risk of each area of the environment, so the small IT team can put its effort where the consequences are highest. Results Security, efficiency and savings. Security and compliance 24,000+ people Full visibility of the data estate For the first time, the WUM IT team has a complete picture of all data in Microsoft 365, where it sits and who can reach it. 43-52% Proactive identification of threats The system monitors permission changes, so potential security gaps surface before an incident. In healthcare, where 43-52% of data breaches involve Microsoft 365 misconfiguration, being proactive is decisive. GDPR Compliance with medical regulation Sensitive medical and personal data is located, and continuous monitoring of who can reach it significantly reduces the risk of financial penalties for data-protection breaches. Operational efficiency Days → minutes IT team time returned Because the estate is mapped continuously, work that used to take days - preparing audit reports, analysing permissions - now takes minutes. 14-30% Unused licences identified WUM has begun a licence review that could yield savings of 14-30% of Microsoft 365 cost by removing inactive and unused licences and third-party applications. Hundreds of thousands of złoty Storage space under management Identifying and archiving unused data optimises Microsoft 365 cloud storage cost. Combined with the licence savings, this could add up to hundreds of thousands of złoty over the next three years. What the rollout shows The 1Security rollout at the Medical University of Warsaw shows how a comprehensive approach to Microsoft 365 access governance can transform the way medical universities manage security, compliance and the cost of IT services. See the same picture of your own tenant. Connect 1Security and get the complete access map of your Microsoft 365 - users, files, sites, teams and applications - in days, not quarters. ================================================================= ## 1Security + your security stack: 12 pairings | 1Security URL: https://1security.ai/en/plus/ ================================================================= Complements, not replacements Keep your stack. Add the map. Purview, Copilot, Entra, Defender, Sentinel, Splunk, SailPoint, CyberArk, Veeam - excellent tools, each built for its own question. 1Security adds the one none of them was designed to answer: who can reach what in Microsoft 365, and what did they actually do. These pages show how each pairing works. The Microsoft stack Built on Microsoft. Built for Microsoft. Seven pairings with the platform you already run. Microsoft Purview Purview knows what your data is. The permission graph shows who can reach it - labels and access, resolved together. Microsoft 365 Copilot Copilot inherits every permission you ever granted. 1Security shows what it inherited - before the licences go out. Microsoft Entra Suite The Suite secures the way in. 1Security maps what is inside - every file, mailbox and agent a permitted identity can reach. Microsoft Entra ID Governance Governance decides who should have access. 1Security watches what granted access actually does inside the tenant. Microsoft Defender XDR Defender stops the attack in motion. 1Security shrinks what the next one can reach. Microsoft Defender for Cloud Apps Defender for Cloud Apps governs the session and the app. 1Security resolves the permissions behind them. Microsoft Sentinel Sentinel holds the record. The permission graph turns a suspicious login into a blast radius in minutes. The wider stack The tools around the tenant. Five more pairings - SIEM, identity, privileged access and backup. Splunk The index and the map - Splunk stores every event; 1Security explains what the actor behind them could reach. SailPoint SailPoint decides who should have access across the enterprise. 1Security shows what that access does in Microsoft 365. One Identity Active Roles Active Roles gets the grant right in AD and Entra. 1Security watches the granted estate live. CyberArk The keys above, the doors below - CyberArk vaults privileged access; 1Security maps the collaboration layer beneath it. Veeam Veeam restores the data. 1Security answers for the access - before, during and after the incident. Keep your stack. Add the map. Read-only consent in the morning - first findings the same day, on the licenses you already own. Or keep answering access questions one console at a time. ================================================================= ## 1Security + Microsoft Purview: labels meet access URL: https://1security.ai/en/plus/microsoft-purview/ ================================================================= 1Security + Microsoft Purview Purview knows what your data is. 1Security knows who can reach it. Microsoft Purview classifies, labels and protects your sensitive data - brilliantly, across every app and service it touches. What it was never designed to map is the other half of the risk: the permissions, sharing links and group memberships that decide who can reach that data. That is where 1Security begins. 70% - of breaches exploit excessive permissions 98% - of granted permissions are never needed 12h → 10 min - a blast-radius investigation, before and after Credit where due What Purview does brilliantly. One platform for data security, governance and compliance - built into the Microsoft 365 you already run. Labels that never let go Sensitivity labels classify and protect content with encryption and markings, and because the label lives in the file’s metadata, it stays with the data wherever it’s saved or sent. Labels protect whole containers too - Teams, Microsoft 365 Groups and SharePoint sites. DLP that acts in the moment Purview DLP runs deep content analysis - not a simple text scan - across Exchange, SharePoint, OneDrive, Teams, endpoints and on-premises shares. When a sensitive item is about to leave, it warns, blocks or quarantines, right inside the apps people already use. Compliance machinery at platform scale Audit, eDiscovery, Compliance Manager, Records Management - a full compliance suite in one portal. And in the Copilot era the labels carry over: Copilot honors label permissions and returns data only to users granted the right to extract it. The other half A content engine, by design. Purview’s whole model is the item: classify the file, label the email, block the sensitive upload. That focus is exactly why it works so well - the policy travels with the content, and every decision is anchored to what the data is. The standing access around that content is a different question. Which identities can reach a Highly Confidential library - through direct grants, sharing links, nested groups, inheritance? Which of those permissions has ever been used? What else could the account behind a DLP alert have reached? Those are questions about the graph of access, not about any single item. That graph was never Purview’s design brief. It is 1Security’s entire product. The complement What 1Security adds around the label. 1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did. The reach behind every account Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. When Purview marks a document Highly Confidential, the permission graph tells you exactly how far the accounts around it extend. A memory that predates the incident Three years of activity history without a SIEM contract, and a behavior baseline for every identity. When something breaks the norm, you get an anomaly episode with an alert line you position yourself - not a pile of raw events. Findings that carry to their fix Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. Joint architecture Two layers, one tenant. Purview enforces at the content layer - labels, encryption, DLP - inside the Microsoft 365 services where your data lives. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licenses, and resolves the access layer: every identity, every permission, three years of activity. The label says what the data is; the graph says who can reach it and what they did with it. First findings land the same day. NIS2, jointly One directive, two obligations, one pair. NIS2 - Directive (EU) 2022/2555 - makes access control policies and asset management an explicit risk-management measure under Article 21(2)(i), and expects you to prove both. Purview covers the asset side: sensitive data is discovered, classified and labeled, and DLP enforces how it may move. 1Security covers the access side: the permission graph shows which identities can reach that data and which of those permissions were ever used - then trims the excess through reviewed, reversible automations. When the auditor asks who can access your critical data and why, the answer is a report, not a project. Integration status Where the integration stands. Purview labels it. 1Security maps who can reach it. Keep Purview doing what it does best - and put the permission graph around it. Or keep guessing who can open the files you just labeled. ================================================================= ## 1Security + Microsoft 365 Copilot: fix oversharing first URL: https://1security.ai/en/plus/microsoft-365-copilot/ ================================================================= 1Security + Microsoft 365 Copilot Copilot honours your permissions perfectly. That is exactly the problem. Every answer is grounded in the Microsoft Graph and trimmed to the asking user’s own access - Copilot will never surface a file that person could not already open. It is the right design. It also means Copilot inherits, in one afternoon, every permission your tenant accumulated over a decade. 1Security is the map of what it inherited. 98% - of granted permissions are never needed 3 years - of activity history, Copilot usage included Same day - from read-only consent to the first exposure list Credit where due What Copilot does brilliantly. Three things Microsoft got right, and none of them are the reason rollouts stall. Grounded in your tenant, not the open web Copilot reasons over your own files, mail, chats and meetings through the Microsoft Graph, with citations back to the source item. Answers come from work that actually happened in your organisation instead of a plausible-sounding generalisation. Security trimming by design Microsoft’s own wording: Copilot only surfaces organizational data the user has at least view permissions to, and the semantic index honours the same identity-based access boundary when it grounds an answer. Where a Purview label applies encryption, content comes back only if the user holds the EXTRACT usage right. Prompts, responses and Graph data are not used to train the foundation models. A platform, not a chat box Copilot Studio and declarative agents let a business team stand up a purpose-built assistant over a chosen set of sites, files and connectors - which is why the agent count in a tenant grows far faster than anyone planned for. The mirror problem Copilot does not create the exposure. It finds it. The permission model Copilot inherits was never built to be queried in natural language. It accumulated one exception at a time: a folder shared with “Everyone except external users” for a single deadline, a site nobody has opened since 2019, an anonymous link on a spreadsheet, a guest who stayed after the project ended. None of it was ever wrong enough to fix, because nobody could find those files anyway. Semantic search removes obscurity as a control. What used to require knowing a site name, a folder path and a file title now requires knowing what to ask. Week one of a rollout is when someone types “what is our redundancy plan?” and gets a genuinely correct, correctly-permissioned answer that nobody intended them to have. Microsoft says as much: the deployment guidance leads with reducing oversharing before you turn Copilot on, and monitoring it afterwards. What it does not hand you is the tenant-wide map of who - and which app, and which agent - can currently reach what. That part you have to bring. The complement What 1Security adds around the rollout. 1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did. The pre-flight exposure list Before a single licence is assigned: every file each pilot user can reach, ranked by sensitivity rather than alphabetically. Payroll, board packs, legal, credentials - surfaced as a list to fix, not a risk to accept. The oversharing that survives go-live Dormant anonymous links, tenant-wide grants, guests still sitting in sites, folders inheriting from a permission set nobody remembers approving. The exact patterns that turn into instant retrieval the moment semantic search is switched on. Agents counted alongside the humans Copilot Studio agents and third-party AI apps are identities with consented scopes and knowledge sources of their own. One inventory for all of them - what each can reach, which are active, which were built once and abandoned. Adoption and drift, measured Who is actually using Copilot versus who is holding a licence, and whether reachable-sensitive-data is shrinking or growing week over week. Three years of activity history, no SIEM contract required. Joint architecture Copilot answers. 1Security decides what it is allowed to answer from. Copilot stays the assistant, grounded in the Graph and trimmed by the tenant’s own access controls. 1Security connects to that same tenant with read-only consent, no agents and standard Microsoft licences, and resolves the layer underneath - every identity, every effective permission, three years of activity. Fix the permission model with 1Security, and Copilot’s security trimming stops being a promise you hope holds and becomes a boundary you have measured. First findings land the same day, which is usually well before the licences do. The three weeks before go-live A rollout that survives contact with the executive floor. The pattern repeats in almost every deployment. A pilot group is chosen, the licences are assigned, and within days someone in that group retrieves something they should never have been able to find. The permission was always there; Copilot just made it reachable. The rollout pauses, and the security team is asked for a number nobody has: how much more of this is there? Run in the other order, the same three weeks look different. 1Security resolves what each pilot identity can reach and ranks it by sensitivity. The genuinely dangerous grants - the tenant-wide shares, the live anonymous links, the finance site with an inherited “Everyone” entry - get trimmed through reviewed, reversible automations with a grace period, so nothing irreversible happens without a human decision. Then the licences go out. Same deployment, same licences. The difference is whether the exposure list is produced by your security team in week one or by an executive in week four. Integration status Where the integration stands. Deploy Copilot on a tenant you can vouch for. Read-only consent in the morning - by the end of the day, the ranked list of sensitive data Copilot would be able to reach. Or find out what Copilot can reach the way everyone else does. ================================================================= ## 1Security + Microsoft Entra Suite: beyond the front door URL: https://1security.ai/en/plus/microsoft-entra-suite/ ================================================================= 1Security + Microsoft Entra Suite The Suite secures the way in. 1Security maps what is inside. Identity Protection, ID Governance, Private Access, Internet Access and Verified ID make up the strongest front door Microsoft has shipped - risk scored in real time, sessions conditioned, apps reached without a network. What that identity can then touch inside Microsoft 365 - which files, which mailboxes, which agents - is a different question, at a finer resolution. That resolution is 1Security. 70% - of breaches exploit excessive permissions 98% - of granted permissions are never needed 12h → 10 min - a blast-radius investigation, before and after Credit where due What the Suite does brilliantly. Five products sold as one control plane for how an identity gets in - and each of them is best-in-class at that job. Risk that enforces itself Entra ID Protection scores sign-in and user risk against Microsoft’s signal volume, and Conditional Access turns the score into a decision while the session is still being established - block it, step up authentication, force a credential reset. No analyst in the loop, no ticket queue. Access to an app, not to a network Entra Private Access and Internet Access replace legacy VPN with identity-centric, per-application access behind the same Conditional Access policies - on-premises apps and internet destinations alike. An identity gets one application, not a subnet. Lifecycle and proof of who you are Entra ID Governance automates joiners, movers and leavers with access packages and recurring reviews, while Verified ID adds cryptographically verifiable credentials for onboarding and helpdesk identity proofing - so the person on the phone is the person on the record. The far side of the door The Suite governs the session. Risk lives in what the session opens. The Suite’s unit of work is the identity and its access: should this sign-in be allowed, under what conditions, to which application, for how long. That is exactly the right altitude for the front door, and it is engineered better than any alternative on the market. Below the application, the question changes shape. Conditional Access can allow a session to SharePoint; it cannot say that the token behind it reaches 12,000 files it will never open, a finance site inherited through three nested groups, or a mailbox delegated years ago and never revoked. And some access paths never present a session to the door at all - an anonymous sharing link, a guest already sitting inside a site, an OAuth app or AI agent running on application permissions with no user attached. Resolving access at the per-file, per-identity, per-action level was never the Suite’s design brief. It is 1Security’s entire product. The complement What 1Security adds behind the door. 1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did. Every identity resolved to its reach Direct grants, sharing links, group nesting, site inheritance - collapsed into one answer per identity: exactly which files, sites and mailboxes it can open. The thing a Conditional Access policy is ultimately protecting, finally visible. Blast radius while the risk signal is still warm A risky sign-in raised by ID Protection becomes a scoped answer in minutes: what that account could reach, what it actually touched, from which device and which location - with Microsoft’s own backend IPs filtered out so the anomalies are real ones. The identities that never sign in Service principals, OAuth apps and AI agents hold consented scopes and run without a user session, so they pass no front door at all. 1Security inventories them next to the humans, with the same reach map and the same activity history. The trim, reversibly executed Revoke access, expire links, remove stale guests - automations staged behind a review queue with a grace period, recorded in a ledger you can replay. Nothing irreversible happens without a human decision. Joint architecture The Suite conditions the session. 1Security accounts for what it opens. Entra Suite remains the front door: risk scored, sessions conditioned, apps published per-identity, entitlements provisioned and recertified - including ID Governance, which has its own pairing page. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licences, and resolves the interior - every effective permission, every non-human identity, three years of activity history without a SIEM contract. Front-door decisions get made against evidence of what is behind it, and first findings land the same day. NIS2, jointly Access control you can enforce and evidence. NIS2 - Directive (EU) 2022/2555 - obliges essential and important entities to implement access control policies, asset management and multi-factor authentication as part of their risk-management measures, with management personally accountable for them. The Suite supplies the enforcement: MFA and risk-based Conditional Access on every sign-in, per-application access replacing broad network reach, entitlements provisioned through access packages and recertified on schedule, identity proofed at onboarding. 1Security supplies the evidence the same article implies but no front door can produce: which assets each identity effectively reaches inside Microsoft 365, which of those permissions were ever exercised across three years of activity, and reviewed, reversible automations to remove the ones that were not. Enforcement plus evidence is the answer; either alone is half of one. Integration status Where the integration stands. Keep the door. Add the floor plan. Read-only consent in the morning - by the end of the day, what every identity the Suite lets in can actually reach. Or keep securing the entrance to rooms nobody has mapped. ================================================================= ## 1Security + Entra ID Governance: intent meets evidence URL: https://1security.ai/en/plus/entra-id-governance/ ================================================================= 1Security + Entra ID Governance Governance models the access you intend. 1Security maps the access you actually have. Microsoft Entra ID Governance is how a modern tenant decides who should have access: packages, approvals, reviews, lifecycle automation. What sits beneath every one of those entitlements - the files, sites and mailboxes a single membership really unlocks, and whether anyone ever touched them - is a finer resolution of the same question. That resolution is 1Security. 98% - of granted permissions are never needed 70% - of breaches exploit excessive permissions 12h → 10 min - a blast-radius investigation, before and after Credit where due What ID Governance does brilliantly. Four questions, answered as process: which identities should have access, what are they doing with it, are controls in place, and can auditors verify them. Entitlements as products Access packages bundle the groups, Teams, apps and SharePoint sites a role needs - requested through multi-stage approval, time-limited by policy. External partners get invited as B2B guests on approval and removed automatically when access expires. A lifecycle that runs itself Lifecycle workflows automate joiner, mover and leaver events straight from HR sources like Workday and SuccessFactors, and provisioning connectors reach hundreds of cloud and on-premises applications. Day one access on day one, and clean exits when people leave. Recertification and privileged control Recurring access reviews put group memberships, application access and role assignments in front of the people who can judge them - with AI-powered suggestions. Privileged Identity Management adds just-in-time elevation and role-change alerting on top. The resolution limit Governance works at the entitlement. Risk lives at the item. ID Governance’s unit of work is the entitlement: a group, a role, an access package. That’s the right altitude for deciding intent - model the access, route the approval, expire what isn’t renewed. It’s governance done as engineering, and it works. Inside Microsoft 365, each entitlement then fans out. One group membership cascades through nested groups and site inheritance into thousands of individual files. And access also gets created outside the model entirely - an ad-hoc sharing link never passes through an access package or an approval stage. So when a reviewer certifies a membership, the honest questions underneath are: what does this membership actually reach, and has any of it ever been used? Answering at that per-file, per-action resolution was never ID Governance’s design brief. It is 1Security’s entire product. The complement What 1Security adds beneath the entitlement. 1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did. Entitlements resolved to reach Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The membership you’re asked to certify stops being a name and becomes a map. Evidence instead of instinct Three years of activity history without a SIEM contract, with a behavior baseline per identity. 98% of granted permissions are never needed - now a reviewer can see which 98%, before clicking approve. The trim, safely executed Revoke access, expire links, sever sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. Joint architecture Intent upstream, evidence downstream. Entra ID Governance stays the system of intent: it decides, provisions and recertifies access at the entitlement level. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licenses, and resolves the effective layer beneath it - every identity, every permission, three years of activity. Governance decisions get made on evidence of reach and use instead of on names; first findings land the same day. DORA, jointly Least privilege you can demonstrate. DORA - Regulation (EU) 2022/2554 - requires financial entities to restrict access to ICT assets and data to what legitimate functions actually need, and to keep that restriction demonstrable as part of ICT risk management under Article 9. ID Governance supplies the control machinery: entitlements modelled as access packages, approvals recorded, access recertified on schedule, privileged roles elevated just-in-time. 1Security supplies the evidence: what each entitlement effectively reaches inside Microsoft 365, which of those permissions were used across three years of activity - and reviewed, reversible automations to trim what wasn’t. Control plus evidence is what the regulator is actually asking for. Either alone is half an answer. Integration status Where the integration stands. Intended access, meet actual access. Keep ID Governance deciding who should have access - and put the map of what that access really reaches underneath it. Or keep certifying memberships nobody has seen the bottom of. ================================================================= ## 1Security + Defender XDR: shrink the blast radius URL: https://1security.ai/en/plus/defender-xdr/ ================================================================= 1Security + Defender XDR Defender stops the attack. 1Security shrinks what the next one can reach. Microsoft Defender XDR is the incident machine: it correlates signals across endpoints, identities, email and apps into one attack story, disrupts the attack at machine speed, and heals what was hit. The standing permissions that decide how far any attack could travel exist before the first alert - and that layer is 1Security’s. 600M/day - identity attacks (Microsoft, 2024) 70% - of breaches exploit excessive permissions 12h → 10 min - a blast-radius investigation, before and after Credit where due What Defender XDR does brilliantly. A unified pre- and post-breach defense suite that natively coordinates detection, prevention, investigation and response across endpoints, identities, email and applications. One incident, the whole story Correlation engines stitch alerts from Defender for Endpoint, Office 365, Identity and Cloud Apps into a single incident: the timeline, the tactics, every impacted user, device and mailbox, and a visual map of how they interact. The full attack story, not a queue of fragments. Disruption at machine speed Automatic attack disruption correlates millions of signals to spot active ransomware and BEC campaigns, then contains compromised assets in real time - device contained, user disabled, sessions revoked - at a maintained confidence of 99% or higher. Every action can be undone by your team. Self-healing after the fight AI-powered automatic actions and playbooks remediate impacted mailboxes, endpoints and identities back to a secure state. For everything else there’s advanced hunting: KQL over the raw signal and alert data, in one portal. Before and after Built for the attack in progress. Defender XDR’s unit of work is the incident. It begins when threat signals correlate and ends when the impacted assets are remediated - and that focus is exactly why disruption at 99% confidence is possible at all. An incident machine should be judged on incidents, and this one is superb. Two questions live outside that model, by design. Before the alert: the standing permission sprawl that decides how far any compromised account could travel - nothing malicious has happened yet, so there is no signal to correlate. And after the disruption: the account is disabled, the device contained - but which of its permissions should ever come back, and what did it quietly touch over the past year? Hunting is scoped to 30 days of raw signals, the right window for incident work - not for a question that spans quarters. Both are questions about the permission layer, not the threat layer. That layer is 1Security’s entire product. The complement What 1Security adds around the incident. 1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did. Blast radius, mid-incident Every file, site and mailbox a compromised account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The impact question your incident report needs answered while Defender is still disrupting, not a week later. Memory beyond the hunting window Three years of activity history without a SIEM contract, and a behavior baseline per identity with anomaly episodes and an alert line you position yourself. What the account touched last spring is a query, not an archaeology project. A smaller surface for the next one Revoke access, expire links, sever sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. 98% of granted permissions are never needed; trimming them is how the next incident starts smaller. Joint architecture The threat lane and the permission lane. Defender XDR owns the threat lane: detect, correlate, disrupt, heal. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licenses, and owns the permission lane: before the incident it maps and trims what every identity can reach, during it it answers blast radius in minutes, and after it it decides - with a human in the loop - which access should never come back. First findings land the same day. NIS2, jointly Seventy-two hours is not long. NIS2 - Directive (EU) 2022/2555 - puts incident handling on the clock under Article 23: an early warning within 24 hours of a significant incident, a notification within 72 hours including an initial assessment of its severity and impact, and a final report within a month. Defender XDR carries the detection half: the incident, the attack story, the disruption timeline - what happened and what was contained, ready when the clock starts. 1Security carries the impact half: what the compromised account could reach, resolved in minutes instead of a 12-hour log hunt, and what it actually did across three years of activity memory - the severity and impact assessment the 72-hour notification demands. One pair, one report, inside the deadline. Integration status Where the integration stands. Stop the attack. Then shrink the next one. Keep Defender XDR on the incident - and put the permission graph around everything the incident could have reached. Or keep meeting every incident with 98% of your permissions still granted. ================================================================= ## 1Security + Defender for Cloud Apps: session and map URL: https://1security.ai/en/plus/defender-for-cloud-apps/ ================================================================= Better together 1Security + Microsoft Defender for Cloud Apps. Defender for Cloud Apps watches behavior in motion: which cloud apps your people use, what happens inside the live session, which OAuth grants deserve a second look. 1Security resolves the access at rest - every file, site and mailbox each identity in your Microsoft 365 tenant can reach, and whether it ever needed to. One instrument for the session, one for the standing grant. Credit where due What Defender for Cloud Apps does well. A CASB, an SSPM layer and OAuth app governance in one product, wired straight into Microsoft Defender. Shadow IT, discovered and scored Cloud discovery analyzes your traffic logs against a catalog of over 31,000 cloud apps, each ranked on more than 90 risk factors. You see what your organization really uses - on the corporate network and off it - and you sanction, unsanction and block from one screen. Sessions controlled in real time Conditional Access app control puts policy inside the live session: monitor low-trust sessions, block downloads of sensitive data to unmanaged or risky devices, watch collaboration with external users as it happens. OAuth apps under governance App governance closes the app-to-app gap: the OAuth apps your users consent to, their permissions, unused apps and expired credentials - all monitored, with every signal correlated at incident level inside Microsoft Defender. The design boundary Built for the session, not the standing grant. Defender for Cloud Apps is deliberately session-shaped. Its raw material is behavior in motion - the traffic log, the live session, the OAuth consent - and inside that scope it is the strongest answer in the Microsoft stack. That focus is a design decision, and for a CASB it’s the right one. Standing access is a different material. Inside Microsoft 365, an identity’s real reach is assembled from direct grants, sharing links, group memberships and inheritance - permissions that exist and keep working whether or not any session touches them. 70% of breaches exploit excessive permissions, and 98% of granted permissions are never needed at all. That reach isn’t a session artifact, so no session control is meant to render it. It’s a different question - and it takes a different instrument to answer. The other instrument What 1Security adds. 1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did. The permission graph Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. A blast-radius investigation that used to take 12 hours now takes 10 minutes. Memory that outlasts the session Three years of activity history, per-identity behavior baselines, and anomaly episodes with an alert line you position yourself. When a session raises a question, the answer is already on file. Devices and origins, reconstructed Shadow devices rebuilt from real activity by a stable fingerprint - no Intune enrollment required. Every action enriched with location and ASN, Microsoft’s own datacenter noise labelled out. Findings that end in a fix Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. Joint architecture Two lenses on one tenant. Defender for Cloud Apps sits with your sessions and app traffic - discovery, session policy, OAuth governance - and correlates its signal inside Microsoft Defender. 1Security connects to the same Microsoft 365 tenant with read-only consent - no agents, standard Microsoft licenses, first findings the same day - and resolves the layer beneath: who can reach what, who actually did, and which permissions should never have existed. When a Defender for Cloud Apps alert names an identity, 1Security tells you what that identity could touch. Same day - from read-only consent to first findings 12h → 10 min - a blast-radius investigation, before and after Standard - Microsoft licenses - no E5 prerequisite Joint use case NIS2 wants proof, not policy documents. NIS2 Article 21 obliges essential and important entities to run risk-management measures that include access-control policies - and to demonstrate they work. A policy PDF doesn’t demonstrate anything; the regulator’s question is concrete: who can access what, why, and what happens when that access is abused. Together the two products answer it end to end. Defender for Cloud Apps enforces the in-session half: sensitive downloads blocked on unmanaged devices, external collaboration monitored in real time, risky OAuth grants governed. 1Security supplies the evidence half: the resolved permission graph as the current access-control state of the tenant, three years of activity memory behind every identity, and remediation - revoke, expire, sever - with review queues that record the human decision. When the auditor asks who could reach the finance site on the day of the incident, that’s a lookup, not a project. Integration status Integration status. Keep the session covered. Add the map beneath it. Defender for Cloud Apps already watches your apps in motion. See what it looks like with the standing access resolved underneath - every identity, every permission, every action. Or keep answering “who has access to what” by hand. ================================================================= ## 1Security + Microsoft Sentinel: the record and the witness URL: https://1security.ai/en/plus/microsoft-sentinel/ ================================================================= Better together 1Security + Microsoft Sentinel. Sentinel remembers everything you send it: every source, normalized, correlated, hunted and answered with a playbook - a cloud-native SIEM doing exactly what a SIEM should. 1Security adds the one thing no log stream carries: the standing permissions of your Microsoft 365 tenant - who can reach what, through which grant, and whether they ever needed to. Credit where due What Sentinel does well. A cloud-native SIEM built for multicloud, multiplatform scale - detection, investigation, response and proactive hunting on one query surface. Every source, one surface Data connectors ship packaged in solutions: Microsoft sources integrate in real time, and Syslog, CEF and REST APIs bring in the rest of the ecosystem. ASIM normalization translates it all into one uniform view you can actually query. Alerts become incidents Analytics combine low-fidelity alerts about different entities into high-fidelity incidents, mapped against MITRE ATT&CK and enriched with threat intelligence. The analyst starts from a case, not a haystack. Response as workflow Automation rules coordinate incident handling centrally; playbooks built on Azure Logic Apps carry the response into ServiceNow, Jira and the rest of your stack. Hunting queries and notebooks extend the reach beyond what any rule anticipated. The design boundary An archive, not a witness. A SIEM’s contract is the record: ingest it, normalize it, correlate it, keep it immutable. Sentinel honors that contract at cloud scale, and everything a SOC does - detection, forensics, compliance - stands on it. The contract is the point. But permissions are state, not events. A sharing link created in 2023 emits nothing tonight. A nested group quietly extends reach to a site nobody mentions in any log. An identity’s real blast radius inside Microsoft 365 is assembled from direct grants, links, group memberships and inheritance - and none of that assembly travels in a log stream, so no query against the stream can return it. 70% of breaches exploit excessive permissions; 98% of granted permissions are never needed at all. Sentinel answers “what happened” better than anything else you run. “What could happen - who can reach what, right now” is a different question, held in a different structure. A SIEM stores records; understanding permissions was never its assignment. The witness What 1Security adds. 1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did. The permission graph Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. A blast-radius investigation that used to take 12 hours now takes 10 minutes. Identity-shaped memory Per-identity behavior baselines over three years of activity history, with anomaly episodes and an alert line you position yourself. When an incident names an account, its normal is already established. Devices and origins, reconstructed Shadow devices rebuilt from real activity by a stable fingerprint - no Intune enrollment required. Every action enriched with location and ASN, Microsoft’s own datacenter noise labelled out. Findings that end in a fix Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. Joint architecture The record and the map. Sentinel stays exactly where it is: the organization-wide record, the incidents, the hunting surface, the playbooks. 1Security connects to your Microsoft 365 tenant with read-only consent - no agents, standard Microsoft licenses, first findings the same day - and holds the map the record can’t carry: the resolved permission graph and per-identity baselines. When a Sentinel incident names an account, the analyst pivots to 1Security for its blast radius and its history, then closes the loop with remediation that queues for human review. The archive states the facts; the witness explains what they touch. Same day - from read-only consent to first findings 12h → 10 min - a blast-radius investigation, before and after Standard - Microsoft licenses - no E5 prerequisite Joint use case DORA asks how far it could spread. DORA requires financial entities to classify ICT-related incidents and report the major ones on fixed deadlines - initial notification, intermediate report, final report - with a defensible assessment of impact. The clock starts before the investigation ends. Together the two products keep that clock honest. Sentinel establishes what happened and when: the incident, its timeline, the correlated evidence across every source you ingest. 1Security establishes how far it could spread: every file, site and mailbox the affected identity could reach, resolved in minutes instead of a day of log stitching - and what it actually touched, against three years of its own baseline. The impact section of the report stops being an estimate. It becomes a lookup - and the remediation that follows is queued, reviewed and recorded. Integration status Integration status. Keep the record. Add the witness. Sentinel already remembers everything that happened. See what changes when the permissions underneath it are resolved - every identity, every grant, every blast radius on demand. Or keep reconstructing blast radius from queries, one incident at a time. ================================================================= ## 1Security + Splunk: the index and the map URL: https://1security.ai/en/plus/splunk/ ================================================================= Better together 1Security + Splunk. Splunk turned machine data into a discipline: thousands of sources at terabyte scale, one search language over all of it, alerts ranked by risk instead of arrival time. 1Security adds the layer that never emits anything for Splunk to index: the standing permissions of your Microsoft 365 tenant - who can reach what, through which grant, and whether they ever needed to. Credit where due What Splunk does well. The index that built the modern SOC, and a detection practice run on top of it like engineering. Any data, at terabyte scale Splunk Enterprise collects machine data from thousands of sources at terabyte scale, with more than 2,300 out-of-the-box integrations and one search language to interrogate all of it. If it happened and it was logged, a search will find it. Alerts ranked by risk Splunk Enterprise Security unifies SIEM, SOAR and UEBA into one threat detection, investigation and response platform. Risk-based alerting cuts alert volumes by up to 90%, so analysts work genuine threats instead of a queue of noise. Detection as a discipline Detection Studio manages the detection lifecycle end to end, with coverage mapped to the MITRE ATT&CK framework and Cisco Talos threat intelligence enriching it at no additional cost. Detection engineering, run like engineering. The design boundary The index answers what arrived. Splunk’s contract is beautifully simple: if a system emitted it, Splunk indexes it, and a search will answer questions about it for as long as you keep it. That contract built the modern SOC, and nothing about it needs fixing. But the permissions inside Microsoft 365 never emit anything. A sharing link created in 2023 is silent tonight. A nested group extends reach to a site no event ever mentions. An identity’s real blast radius is assembled from direct grants, sharing links, group memberships and inheritance - state, not events. It never arrives at the indexer, so no search can return it. 70% of breaches exploit excessive permissions; 98% of granted permissions are never needed at all. That’s the boundary: an archive, not a witness. Splunk stores and searches the record of what happened; who can reach what, right now, lives outside the record - by design, not by omission. The map What 1Security adds. 1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did. The permission graph Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. A blast-radius investigation that used to take 12 hours now takes 10 minutes. Memory with an identity attached Per-identity behavior baselines over three years of activity history, with anomaly episodes and an alert line you position yourself. When a detection names an account, its normal is already established. Devices and origins, reconstructed Shadow devices rebuilt from real activity by a stable fingerprint - no Intune enrollment required. Every action enriched with location and ASN, Microsoft’s own datacenter noise labelled out. Findings that end in a fix Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. Joint architecture The index and the map. Splunk keeps the organization-wide record and the SOC workflow - the index, the detections, the automated response. 1Security connects to your Microsoft 365 tenant with read-only consent - no agents, standard Microsoft licenses, first findings the same day - and maintains the map the index was never sent: the resolved permission graph and per-identity baselines. When a Splunk detection names an account, the analyst pivots to 1Security for its blast radius and its history, then closes the loop with remediation that queues for human review. The index states what happened; the map states what it can touch. Same day - from read-only consent to first findings 12h → 10 min - a blast-radius investigation, before and after Standard - Microsoft licenses - no E5 prerequisite Joint use case NIS2 gives you 24 hours. NIS2 Article 23 puts significant incidents on a clock: an early warning within 24 hours of awareness, a full incident notification within 72, a final report after. What the regulator wants inside those windows isn’t prose - it’s scope: what was hit, how severe, what impact. Together the two products fill the windows with facts. Splunk establishes the event chain: when the incident started, which systems were involved, what the detections and the automated response did about it. 1Security establishes the reach: every file, site and mailbox the affected identity could touch - resolved in minutes, not reconstructed against the deadline - and what it actually touched, measured against three years of its own baseline. The early warning ships with real scope in it. The 72-hour notification cites a permission graph, not an estimate - and the remediation that follows is queued, reviewed and recorded. Integration status Integration status. Keep the index. Add the map. Splunk already answers what happened. See what changes when the permissions underneath are resolved - every identity, every grant, every blast radius on demand. Or keep estimating impact while the 24-hour clock runs. ================================================================= ## 1Security + SailPoint: intended vs effective access URL: https://1security.ai/en/plus/sailpoint/ ================================================================= 1Security + SailPoint SailPoint decides who should have access. 1Security shows what access actually does. SailPoint Identity Security Cloud governs identities and their access across every system you connect - entitlements shaped into roles, lifecycle states that provision and deprovision on their own, campaigns that keep certifying. What it hands the reviewer is the entitlement. Inside Microsoft 365, every one of those entitlements has an interior - sharing links, inheritance, three years of actual usage. That interior is where 1Security begins. 70% - of breaches exploit excessive permissions 98% - of granted permissions are never needed 12h → 10 min - a blast-radius investigation, before and after Credit where due What SailPoint does brilliantly. One platform to manage and govern identities and their access - across every source you connect. Governance across every source Connectors aggregate account data from the systems you run into one governed model - entitlements, access profiles and roles - so least privilege is decided in one place, for everything at once. A lifecycle that runs itself Lifecycle states drive provisioning as people join, move and leave; access requests route through approvals; separation-of-duties policies catch conflicting access before it lands - with violations handled, not just flagged. Certification with intelligence Manager and source-owner campaigns put every access decision back in front of a human on schedule - and Identity Outliers and Access Intelligence point the reviewer at the identities that deserve the closest look. The other half An entitlement engine, by design. SailPoint’s model is the entitlement: aggregated from a source, shaped into roles and access profiles, requested, approved, certified. That abstraction is the whole point - it is what lets one platform govern hundreds of systems with one set of decisions. Inside Microsoft 365, standing access has a second life below the entitlement. Sharing links, item-level grants, nested groups and inheritance decide what a mailbox or a site membership really opens - and how that access is exercised day to day is a story the entitlement itself doesn’t tell. What did this account actually reach? Was the permission ever used, from which device, from where? Those are questions about one workload’s interior, resolved item by item. That interior was never SailPoint’s design brief. It is 1Security’s entire product. The complement What 1Security adds under the entitlement. 1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did. The reach behind every entitlement Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The line item a reviewer certifies becomes a map of what it actually opens. Usage evidence for every decision Three years of activity history without a SIEM contract, and a behavior baseline for every identity. Revoke-or-keep stops being a memory test - anomaly episodes, with an alert line you position yourself, show how the access behaves. Findings that carry to their fix Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. Joint architecture Breadth above, depth below. SailPoint governs the entitlement layer across every source you connect - lifecycle, requests, certifications, separation of duties. 1Security connects to your Microsoft 365 tenant with read-only consent, no agents and standard Microsoft licenses, and resolves the item layer: every identity, every permission, three years of activity. The role says what an identity should hold; the graph says what it can reach and what it did. First findings land the same day. DORA, jointly One regulation, two halves of least privilege. DORA - Regulation (EU) 2022/2554 - requires financial entities to limit access to ICT assets to what legitimate, approved functions actually need, under Article 9(4)(c) - and to keep proving that the limits hold. SailPoint covers the decision side: access granted through roles and approvals, re-checked in certification campaigns, conflicting combinations blocked by separation-of-duties policy. 1Security covers the evidence side: the permission graph shows what each entitlement really opens inside Microsoft 365 and which of those permissions were ever used - then trims the excess through reviewed, reversible automations. When the supervisor asks whether access is limited to what’s required, the answer is a report, not a project. Integration status Where the integration stands. SailPoint decides. 1Security shows the evidence. Keep SailPoint governing every source - and put the permission graph under the one that matters most. Or keep asking reviewers to certify what they can’t see. ================================================================= ## 1Security + One Identity Active Roles: grant vs reach URL: https://1security.ai/en/plus/one-identity-active-roles/ ================================================================= 1Security + One Identity Active Roles Active Roles gets the grant right. 1Security shows what the grant can reach. One Identity Active Roles runs your hybrid Microsoft directory the way it should be run - delegated without standing privilege, provisioned by policy, deprovisioned on time, every operation on the record. What it was never designed to map is the life of a grant after it lands: the files, sites and mailboxes it opens inside Microsoft 365, and what the account actually did there. That is where 1Security begins. 70% - of breaches exploit excessive permissions 98% - of granted permissions are never needed 12h → 10 min - a blast-radius investigation, before and after Credit where due What Active Roles does brilliantly. One console for Active Directory, Entra ID and Microsoft 365, with policy behind every change. One console for the hybrid directory Active Directory, Entra ID and Microsoft 365 administered from a single console - across domains, tenants and multi-forest environments. Workflow automation keeps every change inside consistent, enforced policy. Delegation without standing privilege Access Templates delegate fine-grained, role-based permissions precisely where they’re needed - and zero standing privilege takes the always-on admin rights off the table. A lifecycle that ends cleanly Immediate least privilege for every account, dynamic groups that follow attributes, and deprovisioning that actually finishes - membership removal, relocation, permanent deletion - with an audit trail of every operation performed or attempted. The other half A directory engine, by design. Active Roles’ model is the change: the account created right, the group membership set by rule, the delegated permission scoped tight, the leaver deprovisioned on time. Enforcement lives at the moment of change, and the audit trail records every operation performed or attempted in the directory. What happens between the changes is a different question. Once the account exists and the group is correct, that identity spends its working life inside SharePoint, Exchange and Teams - opening files, creating sharing links, accumulating reach through inheritance the directory never sees. Which of those permissions were ever used, from which device, what a compromised account could actually reach - those are questions about the workload, not the directory. That layer was never Active Roles’ design brief. It is 1Security’s entire product. The complement What 1Security adds after the grant. 1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did. The reach behind every grant Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The directory object Active Roles provisioned becomes a map of everything it opens. A memory the directory doesn’t keep Three years of activity history without a SIEM contract, and a behavior baseline for every identity. When an account breaks its own norm, you get an anomaly episode with an alert line you position yourself - not a pile of raw events. Findings that carry to their fix Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. Joint architecture Two layers, one identity. Active Roles enforces at the directory layer - accounts, groups, delegation, deprovisioning - across Active Directory, Entra ID and Microsoft 365. 1Security connects to the same tenant with read-only consent, no agents and standard Microsoft licenses, and resolves the workload layer: every identity, every permission, three years of activity. The directory says what an account holds; the graph says what it can reach and what it did. First findings land the same day. NIS2, jointly One directive, two halves of access control. NIS2 - Directive (EU) 2022/2555 - makes access control policies an explicit risk-management measure under Article 21(2)(i), and expects you to prove they work in practice, not just on paper. Active Roles covers the policy side: access granted by rule, delegated without standing privilege, removed on schedule, every directory operation in the audit trail. 1Security covers the practice side: the permission graph shows what those grants can actually reach inside Microsoft 365 and which of them were ever used - then trims the excess through reviewed, reversible automations. When the auditor asks whether your access control policy matches reality, the answer is a report, not a project. Integration status Where the integration stands. Active Roles gets the grant right. 1Security shows its reach. Keep Active Roles running the directory - and put the permission graph after it. Or keep assuming a well-made grant is a well-used one. ================================================================= ## 1Security + CyberArk: the keys above, the doors below URL: https://1security.ai/en/plus/cyberark/ ================================================================= Complementary by design 1Security + CyberArk. The keys above, the doors below. CyberArk owns the privileged tier: credentials vaulted and rotated, sessions isolated and recorded, standing privileges reduced to zero. 1Security maps the tier underneath - the everyday permissions inside Microsoft 365 that no vault was ever meant to hold. Together they answer both questions: who holds the keys, and what every identity can actually open. 98% - of granted permissions are never needed 70% - of breaches exploit excessive permissions 12h → 10 min - a blast-radius investigation, before and after Credit where due What CyberArk does well. Privileged access is where one mistake ends companies - and CyberArk treats it that way. The vault, done right Critical system-level accounts get automated credential vaulting and rotation. The password an attacker would most love to steal stops being worth stealing - it has already changed. Sessions brokered and recorded Sensitive sessions across infrastructure and SaaS run isolated and recorded, with AI-generated summaries surfacing anomalous commands in real time. When an auditor asks what the admin did, there is a tape. Zero standing privileges Ephemeral privileges are created when a task starts and destroyed when it ends - just-in-time entitlements scoped to the task, with agentless, brokered access to AWS, Azure, GCP and Kubernetes. A different layer The gap CyberArk isn’t designed to close. CyberArk’s scope is deliberate: the privileged tier. Admin credentials, root sessions, the accounts that can take infrastructure down. Everything about the product - the vault, the broker, the recording - is shaped for access that is rare, powerful and worth ceremony. Everyday access inside Microsoft 365 is the opposite shape. Sharing links minted in a click, group memberships that quietly inherit whole sites, OAuth consents granted on a Tuesday - millions of small permissions held by ordinary accounts. Nobody vaults a sharing link. Nobody brokers a session into a SharePoint folder. This layer is too broad and too fluid for ceremony - and 98% of it is never needed at all. That’s not a flaw in the vault. It’s a different question, and it needs a different instrument: not a stronger lock, a map. The map What 1Security adds. A permission-centric decision engine for Microsoft 365 - every identity, what it can reach, and what it actually did. Every identity, mapped Human, app, AI agent, device - 1Security maps what each one can reach and what it actually did. The everyday layer stops being a rumor and becomes a graph. Blast radius in minutes Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. The question the privileged tier can’t see from above. Memory and baselines Three years of activity history without a SIEM contract, and per-identity behavior baselines that turn a number into an anomaly - episodes, with an alert line you position yourself. From found to fixed Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. Joint architecture The vault above, the graph below. CyberArk keeps holding the privileged tier - vaulted credentials, brokered and recorded sessions, zero standing privileges. 1Security connects to the Microsoft 365 tenant with read-only consent - no agents, standard Microsoft licenses, first findings the same day - and builds the permission graph underneath: every identity, every grant, every action, three years back. Neither touches the other’s layer; together they leave no layer unwatched. NIS2 in practice Access control you can evidence. NIS2 Article 21(2)(i) obliges essential and important entities to run access control policies and asset management as part of their cyber-risk measures - and Article 23 gives them 24 hours to file an early warning once a significant incident is detected. CyberArk evidences the privileged half: who could use the powerful accounts, when, and under which policy - with rotation and session recordings as proof. 1Security evidences the everyday half: which identities could reach which data across Microsoft 365, and what they actually did with it. And when the 24-hour clock starts, the first question is scope. A blast-radius answer in ten minutes instead of twelve hours is the difference between an early warning written with facts and one written with adjectives. Integration status Where the integration stands. Two layers of access. One picture. Keep the vault on the keys. Put a map under the doors - every identity, every permission, every action in Microsoft 365. Or keep the map of everyday access in your head. ================================================================= ## 1Security + Veeam: restore data, answer for access URL: https://1security.ai/en/plus/veeam/ ================================================================= Before the restore 1Security + Veeam. Recovery for the data, memory for the access. Veeam Backup for Microsoft 365 is the last line: Exchange Online, SharePoint Online, OneDrive and Teams, backed up to storage you control, immutable, restorable down to the item. 1Security is the line before it: who could reach that data, who actually touched it, and what changed in the days before the incident. Together, you can bring the data back - and answer for it. 12h → 10 min - a blast-radius investigation, before and after 3 years - of activity memory - without a SIEM contract Same day - from read-only consent to first findings The last line What Veeam does well. When the worst has already happened, one layer decides how bad it stays - and Veeam takes that layer seriously. The whole tenant, backed up Exchange Online, SharePoint Online, OneDrive for work or school and Microsoft Teams, backed up to storage you choose - from local disk and SMB shares to Amazon S3, Azure Blob, IBM Cloud or Wasabi. Immutable means immutable On object storage with immutability, backed-up data cannot be modified or deleted within the immutability period - compliance mode by default, and once enabled, immutability can’t be switched off. The copy an incident can’t rewrite. Restore down to the item Veeam Explorers bring back a single mail, file or Teams item - and the Restore Portal lets end users recover their own data without opening a ticket. The question before The gap Veeam isn’t designed to close. Veeam’s scope is recovery, and it holds that scope deliberately: when data is encrypted, deleted or corrupted, an immutable copy exists somewhere the incident can’t rewrite, and it comes back - down to the single item. That is exactly what the last line of defense should be. But a backup is a photograph of content, not of access. It can put every file back; it was never meant to say who could reach those files before the incident, which sharing links were live, or which account was reading four times its usual volume the week before. Recovery answers “can we get it back?”. The incident’s other questions - what was reachable, by whom, since when - belong to a different instrument. The memory What 1Security adds. A permission-centric decision engine for Microsoft 365 - every identity, what it could reach, and what it actually did, three years back. Every identity, mapped Human, app, AI agent, device - 1Security maps what each one can reach and what it actually did. The access side of the incident stops being a reconstruction and becomes a record. Blast radius in minutes Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. When you know what was reachable, you know what to check - and what to restore first. The week before, on record Three years of activity history without a SIEM contract, per-identity baselines and anomaly episodes with an alert line you position yourself - so “what changed before the incident” is a lookup, not an archaeology project. From found to fixed Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision. Joint architecture The copy and the memory. Veeam keeps the immutable copy: the tenant’s content - Exchange, SharePoint, OneDrive, Teams - backed up to storage you control and restorable down to the item. 1Security connects to the same tenant with read-only consent - no agents, standard Microsoft licenses, first findings the same day - and keeps the memory: the permission graph of who can reach what, and three years of who actually did. When an incident hits, Veeam brings the data back while 1Security scopes what was reachable and closes what let it happen - revoked access, expired links, severed sessions, each behind a human decision. DORA in practice Response and recovery, both halves. DORA’s ICT risk-management framework splits an incident in two. Articles 11 and 12 demand response and recovery: backup policies and procedures, restoration and recovery methods that bring the entity back. Article 17 demands the other half: an incident management process that detects, records and classifies every ICT-related incident. Veeam is the recovery half made real: immutable backups of Exchange, SharePoint, OneDrive and Teams, restoration down to the item, on storage the incident can’t rewrite. 1Security is the detection-and-record half for Microsoft 365: baselines that flag the anomaly, a permission graph that scopes it in minutes, and three years of activity to classify it against. One regulation, two obligations, two instruments - and a financial entity that can show its supervisor both the restore and the record. Integration status Where the integration stands. Restore the data. Answer for the access. Keep the immutable copy with Veeam. Keep the memory of who could reach it - and who did - with 1Security. Or explain the incident from the backup alone. ================================================================= ## Agents URL: https://1security.ai/en/docs/agents ================================================================= Microsoft spreads AI agents across separate admin portals - Copilot, Azure AI Foundry, and Entra - each with its own model, tags, and APIs. The **Agents** screen unifies all of them into one governed list, with the same access-insight lens 1Security applies to users, apps, and files. ## One screen for every agent The Agents screen covers the three overlapping agent ecosystems Microsoft exposes: - **Microsoft Copilot agents** - declarative agents built in Copilot Studio / Agent Builder (e.g. a SharePoint policy finder, a Teams message extension). - **Entra Agent ID agents** - autonomous backend agents with their own Entra identity (Copilot Studio, Azure AI Foundry). - **Third-party agents** - SaaS apps that use Copilot behind the scenes (e.g. Decisions, Adobe). Instead of three consoles, you get one list - and, where the same agent shows up in more than one place, a **single unified record** that joins its Copilot chat presence to its Entra API permission grants. ## Unified access insights Every agent is broken down by what it can actually reach - the same model 1Security applies to identities and apps: - **Files, sites, users, and emails** the agent can access - **Sensitive data** exposed through that access - down to the specific sensitive information types within reach - **Activity** - what the agent actually did, drawn from the same audit-log pipeline as users and apps, with per-action breakdowns: created, modified, deleted, moved, shared, downloaded - **Knowledge / data sources** it reads from - SharePoint, OneDrive, Teams, email, Graph connectors, Dataverse, the web - resolved to what's actually inside them, so you can review the content an agent learns from - **Permissions** - every atomic permission with its source (direct, inherited from a blueprint, or declared) and Microsoft's "blocked for agents" flag The value is the stitching: signals from **Copilot, Azure, and Entra** become one agent record, so you can govern an agent's behaviour and its real data access in one place - without hopping between portals. ## Working with Microsoft's agent stack, not against it Everything above is read natively from Microsoft's own surfaces - Copilot, Entra, and Azure - so this inventory always agrees with the portals your admins already use. 1Security doesn't replace the agent platforms; it adds the governance layer they don't have: - **Access, quantified.** Copilot Studio shows an agent's configuration; 1Security shows the blast radius - how many files, sites, users, and emails it can actually reach. - **Sensitive data, before it leaks.** Access is one thing; what enterprises actually fear is an agent surfacing regulated data to whoever asks it a question. 1Security lists the exact sensitive information types within each agent's reach - payment cards, health records, credentials - so you know which agent could leak what, and can block that access before an employee's innocent prompt (or an injected one) turns reach into disclosure. - **Activity, attributed.** Agent actions land in the same activity stream as users and apps, with per-action breakdowns - so "what has this agent deleted, moved, or downloaded?" is a filter, not a log-parsing project. - **Knowledge sources, opened up.** In the agent platforms a knowledge source is a pointer; 1Security resolves it to the content behind it, so you can review what an agent would learn _before_ employees start chatting with it. Licensing is the one place agents differ from the rest of 1Security: everywhere else Business Basic is enough, but Microsoft gates the Copilot agent catalog behind **Agent 365** - a single license on the admin account that connects 1Security unlocks it (details below). Entra-backend agents need nothing extra. ## Licensing: what you can see Agent visibility depends on the tenant's Microsoft licensing. This is a Microsoft API limitation, not a 1Security one. 1Security **always** scans the Entra backend. A license only gates the Microsoft **Copilot Package catalog** - the API where lightweight Copilot agents live. | Agent type | Visible without Agent 365 | Needs Agent 365 | | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :-----------------------: | :-------------: | | **Entra Agent ID agents** - everything Microsoft registers as an agent identity, including agents built in Azure AI Foundry and Copilot Studio, plus the earlier generation of both, which exist as ordinary service principals carrying Microsoft's agent tags (`AgenticInstance`, `AgentCreatedBy:CopilotStudio`, `power-virtual-agents-*`) | ✅ | | | **Declarative Copilot agents** - SharePoint policy finders, Teams extensions, and third-party wrappers like Decisions / Adobe (no Entra footprint; they live only in the Copilot Package catalog) | | ✅ | Without the license, declarative Copilot agents either don't surface or look like ordinary enterprise apps - 1Security can't tell they're agents. This affects **both third-party wrappers and first-party declarative Copilot agents**, not just third-party apps. ## Licensing: what you need to buy You do **not** need the $99 Microsoft 365 E7 bundle. The product that unlocks the catalog is **Agent 365**. - **E7 ("Frontier" suite)** just bundles E5 + Microsoft 365 Copilot + the Entra Suite + Agent 365. It's the expensive way in. - **Agent 365** is available **standalone at ~$15/user per month** and can be added on top of an existing E3 or E5 - this is all the API actually checks for. **You only need ONE license.** 1Security reads the catalog with a **delegated** admin token, so Microsoft validates the license of the single admin who connected it - not every user. License that one admin account and the entire tenant's Copilot agent catalog unlocks. **For testing:** assign one standalone **$15 Agent 365** license to the admin account you use to connect 1Security. ## Connecting & graceful degradation To scan Copilot agents, an admin connects a delegated token once (see the **Connecting Tenants** guide). Until that's done - or if the tenant has no Agent 365 - 1Security: - still scans and governs every **Entra** agent, - shows a banner on the Agents screen explaining that Copilot agents need Agent 365, - never fails the tenant scan over a missing license. ### Talking to customers A customer worried about Copilot security already owns Microsoft 365 Copilot - and Microsoft requires **Agent 365** to govern the agents they build with it using native tools, so most target customers already have it. If they don't, 1Security states the limit plainly: > We can only scan your Entra backend. License your admin with Agent 365 to also scan your Copilot chat agents. ================================================================= ## Conditional Access URL: https://1security.ai/en/docs/conditional-access ================================================================= # Conditional Access Conditional Access is the front door of a Microsoft 365 tenant. It is also one of the hardest controls to be sure about, because the Entra portal can only show you **what you declared** - the policies, the named locations, the trusted ranges. It cannot show you **what actually happened at the door**: which places your people really sign in from, which of those places no policy covers, and which sign-ins completed with no policy in force at all. 1Security answers that second half. It reads your Conditional Access configuration, lays it over the locations it already observes from your audit logs, and reports the difference: **"you said this; your tenant does that."** The gap between declared and observed is the whole product here. A policy that names a location and never fires there looks identical - in the portal - to one that protects you every day. ## What You Can Achieve ## What 1Security Reads Three inputs, all read-only: - **Named locations** - the IP ranges and countries you declared in Entra, including which are marked **trusted**. - **Conditional Access policies** - their state (enabled, report-only, disabled), their grant controls, and which named locations they include or exclude. - **The per-sign-in verdict** - which policies Microsoft applied to each sign-in, and with what result. This one is free: it already travels inside the sign-in records 1Security ingests, so no extra permission or API call is involved. The first two need the **`Policy.Read.All`** permission, which rides a re-consent of the read-only application you already granted - not a new app registration. 1Security never writes Conditional Access configuration; every remediation this screen points at is performed by you, in Entra. Conditional Access itself requires a **Microsoft Entra ID P1** licence. If your tenant doesn't have one, 1Security says so plainly and drops the consent prompt - no amount of consenting can produce policies that don't exist. Everything else on the Locations screen keeps working without it. ## Connecting It Open **Locations → Conditional Access** and grant the permission from the card shown there (the same card lives on the Integrations screen). Within the next sync 1Security pulls your configuration, matches it against every location it has already resolved, and fills the tab in. Two clocks run afterwards, deliberately at different speeds: - **Configuration** is refreshed every few hours. Policies change a handful of times a quarter, and when they do change, the event already reaches you in real time through the audit log - `policy.ca.create`, `policy.ca.update` and `policy.ca.delete` are ingested as high-severity activity. - **Coverage is recomputed hourly**, because the other side of the comparison never stops moving: new locations appear, new sign-ins are attributed, and yesterday's verdict goes stale on its own. ## How Coverage Is Decided Every observed location gets one verdict, computed from the source addresses actually seen there - not from the policy's stated scope: | Verdict | What it means | | ----------------- | ------------------------------------------------------------------------------------------------------------------------ | | **Not covered** | Real activity, and no named location covers it. The blind spot. | | **Partly covered** | Some observed addresses fall inside a declared range and some don't - usually an office whose egress outgrew its CIDR. | | **Named** | Covered by a named location that is not marked trusted. | | **Trusted** | Covered by a named location marked trusted in Entra - a standing exception in every rule that excludes trusted locations. | | **Undetermined** | Not decidable: no usable address sample and no resolvable country. Reported as unknown, never as a gap. | "Partly covered" is the verdict most worth understanding. A declared range that covers four of a site's nine egress addresses looks correct in the portal, and the other five reach Microsoft 365 from outside every rule that mentions it. ## The Findings The verdict says covered or not. These findings say **why you should act**, and a location can carry several at once: - **No enforcement** - sign-ins here completed with no Conditional Access policy in force at all. Measured from real sign-ins, not inferred from configuration. - **Undeclared, active** - meaningful, sustained activity from a place no named location covers. Thresholded on events and distinct users so one-off traffic doesn't bury the genuine gaps. - **Office not trusted** - you marked this as a company office, but it sits outside every trusted named location. Read either way: your rules treat the office as hostile, or the office is missing from the exception list it was meant to be in. - **Trusted, risky network** - a range Entra marks as trusted resolves to VPN, Tor, or hosting infrastructure. Trusted status is a standing exception in every policy that excludes trusted locations, so this hands that exception to whoever rents the address next. - **Range outgrown** - only part of this location's source addresses fall inside the declared range. - **Ungoverned anonymised egress** - anonymised or hosted egress with real activity and no policy observed applying to it. Either half is common; together they are worth a look. Tenant-wide tiles count the locations carrying each finding, alongside the **share of sign-ins with no policy applied** - the single number that says how much of your traffic walks in ungoverned. ## Named Locations: The Other Direction The **Named locations** view turns the comparison around and starts from what you declared, so config that never meets reality can't hide: - **Never seen** - nothing has ever signed in from a declared range. A trusted range nobody is behind is a standing exception with no owner. - **Referenced by** - how many enabled policies reference this named location. None means the declaration is dead config. - **Unreadable ranges** - ranges Microsoft returned in a form that could not be parsed as CIDR. They are shown rather than swallowed, because an unmatchable range would otherwise make its named location look like it covers less than it does. ## In a Location's Drawer Open any location and its **Conditional Access** tab tells the story for that one place: the coverage verdict and the named location behind it, how many of its observed addresses matched the declared range, how many sign-ins were attributed here and how many carried no policy, every finding with an explanation - and the policies actually observed acting on sign-ins from this location, each with its grant controls and its counts of applied, allowed, blocked, and report-only. Policies are listed as observed, so the tab is honest in two directions that a config view cannot be: **report-only** and **disabled** policies are labelled rather than counted as protection, and a policy that has since been **deleted in Entra** still appears, tagged - "the rule that used to cover this office was deleted" is a finding, not a missing row. ## Where Else It Shows Up - **Locations list** - a **CA coverage** column rides the main list, not just the Coverage tab: whether a place is governed belongs next to the place, wherever you are looking at it. - **Filters** - narrow any location list by coverage verdict or by a specific finding. - **Location drawer** - the Conditional Access tab described above. ## Honest Limits - Coverage is computed from **observed** sign-ins. A policy that is configured correctly but has never had a sign-in to act on will show no observations - that is a statement about your traffic, not a claim that the policy is broken. - 1Security reads Conditional Access; it never edits it. Every fix - adding a range, trusting an office, retiring a dead named location - happens in Entra. - Locations discovered since the last recompute show as **Undetermined** until the next hourly pass, rather than being reported as gaps they may not be. See [Location Intelligence](/en/docs/location) for how the places themselves are resolved, and [Devices](/en/docs/screens/devices) for the device side of the same sign-in story. ================================================================= ## Connecting Tenants URL: https://1security.ai/en/docs/connecting-tenants ================================================================= You can connect multiple Microsoft 365 tenants to a single 1Security account - useful for MSPs, holding companies, and organisations with several tenants. ## Adding a tenant ### Open the tenant menu Click the tenant switcher in the top-left of the dashboard, then **Add tenant**. ### Authenticate A new tab opens to Microsoft's OAuth consent flow. Sign in with a global admin of the tenant you want to add. ### Grant permissions Approve the same permissions you granted during the initial install. ### Wait for the initial scan The new tenant appears in your switcher immediately, but full data takes the duration of the [initial scan](/en/docs/scans) to populate. ## Troubleshooting This error means the account you tried to sign in with isn't a member of the target tenant. Make sure you're using a global admin account **from the tenant you're adding**, not from your main 1Security account. Microsoft Graph rate limits sometimes throttle initial discovery. Check **Settings → Scan status** for error messages. If you see `TooManyRequests`, the scan will retry automatically - no action needed. Newly created users in Microsoft 365 take up to 24 hours to appear in 1Security. Manually trigger a delta scan from **Settings → Scan status → Run delta** to pull them in immediately. Go to **Settings → Tenants**, click the three-dot menu next to the tenant, then **Disconnect**. This removes all data associated with the tenant from 1Security within 7 days. ## Tenant permissions 1Security requests **read-only** permissions by default. Write permissions (used by automations) are opt-in per module. Each tenant you add grants the same permissions as the first one, and each is consented separately - connecting a second tenant never extends the first tenant's grant. The full list of permissions per module, the licenses each tenant needs, and the admin roles involved are in [Requirements](/en/docs/requirements). ================================================================= ## Data Handling URL: https://1security.ai/en/docs/data-handling ================================================================= # Data Handling 1Security reads a lot about your tenant, which makes "what happens to it?" a fair question - and usually the first one a security review asks. This page answers it in the order those reviews tend to go. ## What is read, and what is stored The distinction matters more than the volume. Most of what 1Security touches is read, evaluated and discarded; what persists is the map, not the material. | Data | Read | Stored | | :--- | :--- | :--- | | Identities, groups, roles, devices, apps, agents | Yes | Yes - metadata only (names, IDs, membership, timestamps, licence assignment) | | Sites, files, folders, links | Yes | Yes - **metadata and permissions**: path, owner, sharing state, who can reach it | | **File content** | Yes, during a sensitivity scan | **No.** Content is streamed into the analysis process and discarded when it finishes | | **Email content** | Yes, when the Email module is enabled | **No.** Bodies and attachments are analysed in the same transient way | | Sensitivity findings | - | The detection **type**, the match count and a confidence bucket, linked to the file. The matched values themselves are not written to the database | | Activity (unified audit log) | Yes | Yes - actor, action, resource, app, device, location, timestamp | The practical summary customers care about: 1Security never becomes a second copy of your documents or your mailboxes. It becomes a copy of who can reach them and what was done with them. ## How sensitivity scanning analyses content The [sensitivity engine](/en/docs/sensitivity) runs **in your deployment's own process**: - **Detectors are deterministic** - over 300 regular-expression and keyword detectors, plus validation rules such as checksum tests on card and identifier formats. - **OCR runs locally** - images and scanned documents are processed offline inside the same process, not sent anywhere. - **No third-party AI service sees file content** in the default configuration. Optional LLM-assisted analysis exists for harder cases, is gated per tenant, and falls back to the deterministic detectors whenever AI is disabled for the tenant. ## Where the data lives | Model | Where processing and storage happen | Fits when | | :--- | :--- | :--- | | **Cloud (SaaS)** | 1Security's managed environment | You want zero infrastructure. Setup is minutes. | | **BYOC (Azure)** | Your own Azure subscription, using our container images | Data residency rules require the data to stay in your cloud | | **On-Premise** | Your own hardware, air-gapped if needed | Full control of location and network boundaries | Deployment specifics, sizing and cost estimates are in [Installation](/en/docs/installation). ### Tenant isolation Every connected tenant gets its **own dedicated database**, not a shared table with a tenant column. A query issued for one tenant physically cannot reach another tenant's rows. On top of that, every tenant-scoped table carries the tenant identifier and every query filters on it - the isolation is enforced twice, at the infrastructure layer and in the query layer. This is also what makes multi-tenant scenarios safe for MSPs and holding companies: connecting a second tenant adds a database, it does not widen the blast radius of the first. ## Access inside 1Security Reading your tenant is one permission question; who inside your organisation can read it in 1Security is another. Three access levels are available when inviting a user: - **Sync with Microsoft 365** - admin status follows the person's existing Entra roles. - **Admin** - full access to all resources, settings and connected tenants. - **User (limited access)** - sees only their own resources: files, emails, groups and sites they own or interact with, plus trends explicitly shared with them. Before inviting a limited user you can preview exactly what they will see. Details in [Getting Started](/en/docs/getting-started#managing-accounts-and-access). ## Write access The base installation cannot change anything in your tenant. Write permission exists in exactly two opt-in modules - [Automations](/en/docs/screens/automations) and Mailbox Management - and even once enabled: - Actions are **staged behind a review queue** with a grace period before anything executes. - Every action is recorded in a ledger you can replay - what was proposed, who approved it, what actually changed. - Mailbox actions quarantine or flag; they do not permanently delete. The exact permission each module requests is listed in [Requirements](/en/docs/requirements#permissions-module-by-module). ## Retention - **Activity history** is retained for as long as your subscription is active, up to **three years**. Three years of continuous subscription means three years of history available for investigation - far past Microsoft's default audit retention. - **Sensitivity findings and the permission graph** reflect the current state of the tenant and are refreshed by [scans](/en/docs/scans); historical trend points are kept so you can see direction of travel. ## Disconnecting and deletion Disconnect a tenant from **Settings → Tenants → Disconnect**. All data associated with that tenant is removed from 1Security **within 7 days**. Because each tenant has its own database, disconnection removes that database rather than filtering rows out of a shared one - there is no residue in another customer's dataset. Revoking consent in Microsoft Entra also cuts access immediately, independently of anything done in 1Security: the application's tokens stop working the moment consent is withdrawn. Disconnecting is not the same as pausing. Once the deletion completes, the activity history built up under that tenant is gone - reconnecting starts the three-year window again from the data Microsoft still holds, which is usually 90 days. ## Frequently asked in security reviews No. File and email content is read during analysis and discarded when the analysis finishes. What persists is metadata, permissions, and the type and count of any sensitive information detected. Not in the default configuration. Detection is deterministic - regular expressions, keyword rules and validation checks - and OCR runs locally. Optional LLM-assisted analysis is gated per tenant and falls back to the deterministic detectors when AI is disabled. Not unless you enable Automations or Mailbox Management. The base installation holds read permissions, with the one documented exception of SharePoint's `Sites.FullControl.All` scope, which SharePoint's own API requires to expose sharing configuration - see [Requirements](/en/docs/requirements#core-visibility---read-only-granted-at-install). Yes - the BYOC model runs the whole platform in your Azure subscription, and the On-Premise model runs it on your own hardware, air-gapped if required. Disconnect the tenant and everything associated with it is deleted within 7 days. Revoking application consent in Entra cuts access immediately in the meantime. ================================================================= ## Getting Started with 1Security URL: https://1security.ai/en/docs/getting-started ================================================================= Welcome to 1Security! This guide will help you understand the core concepts of the platform, how to navigate the interface, and how to start investigating your Microsoft 365 environment immediately. Connecting the tenant comes first - see [Requirements](/en/docs/requirements) for what your tenant needs and [Installation](/en/docs/installation) for the deployment models. ## 1. Platform Basics & Navigation 1Security is designed to make complex security data easy to explore. - **Interactive Visualizations:** Every element on our graphs and lists is interactive. Clicking on an item (like a user, file, or site) will drill down and reveal more detailed results and relationships. - **Data Export:** Every list in the platform can be downloaded. This is highly useful for offline reporting, compliance processing, or forensic investigations. - **Helpful Tooltips:** Hover over table cells to view additional context and definitions without leaving your current view. - **Language Preferences:** You can easily toggle the platform language in your account settings to suit your team's needs. ## 2. Filters & Saved Views Finding the exact data you need is fast thanks to our precomputed values. - **Combine Filters:** You can stack multiple filters to narrow down results. For example, you can filter for *Files containing sensitive information* AND *Files shared with external users*. - **Precomputed Values:** Because our filters use precomputed data, you'll immediately see counts (e.g., exactly how many users have access to sensitive information) before you even apply the filter. - **Saved Views:** Once you build a useful combination of filters, use **Save view** to keep it for later. - **Share with Your Team:** When saving a view, you have the option to make it public/shared, allowing other team members to access your specific filter configurations. ## 3. Trends Trends are automated rules that alert you to risks, potential cost savings, and data exposure. See [Trends](/en/docs/screens/trends) for the full screen. - **Ready to Use:** When you join, 1Security pre-populates several useful trends to give you immediate insights. - **Relationship-Based Alerts:** Trends excel at finding complex relationship scenarios. Common examples include: - *Users with access to sensitive files* - *SharePoint sites with zero active users* - **Customizable & Shareable:** You can edit existing trends or create your own. You can also share specific trends with selected non-admin users so they can track risks relevant to their departments. ## 4. Logs & Forensics 1Security provides a complete forensic trail of activity in your environment. - **Comprehensive Tracking:** Logs show exactly *what* resource was modified, by *whom*, through *which app*, and on *which device*. - **Interactive Log Viewer:** For deeper forensic and admin needs, you can access the raw version of the logs using our interactive log viewer. - **Data Retention:** Your logs are retained securely for as long as your tenant maintains an active 1Security license, up to three years. For example, a continuous subscription over three years gives you three full years of logs to investigate. See [Data Handling](/en/docs/data-handling#retention). ## 5. Multitenancy & Administration 1Security makes it simple to manage multiple environments from a single interface. - **Switching Tenants:** Add or switch between tenants quickly using the **Select tenant** dropdown in the navigation bar, or manage them directly via `/dashboard/tenants/`. ### Managing Accounts and Access Tenant admins can invite new team members by navigating to `/dashboard/1Security-users/` and clicking **Invite user**. When inviting a user, you can assign one of three access levels: 1. **Sync with Microsoft 365:** The user's admin status in 1Security is automatically determined by their existing Azure AD / Microsoft Entra roles (e.g., Global Administrator, Security Administrator). 2. **Admin:** Grants full access to all resources, settings, and tenants in 1Security, bypassing their Microsoft role. 3. **User (Limited Access):** The user only sees their own resources. This includes files, emails, groups, and sites they own or interact with, as well as specific trends assigned to them. *Tip for Admins:* Before sending an invite to a limited User, you can use the built-in preview feature to see exactly what they will see, ensuring they only have access to appropriate data. ================================================================= ## Installation URL: https://1security.ai/en/docs/installation ================================================================= 1Security offers flexible deployment options to meet your organization's compliance, data residency, and operational requirements. You can choose to run 1Security as a fully managed SaaS (Cloud), deploy it within your own Azure environment (BYOC), or host it fully On-Premise. ## Prerequisites Regardless of your chosen deployment method, you will need: - A **Microsoft 365 tenant** with at least one license that includes SharePoint Online (Business Basic upwards - no E5 required) - **Global Administrator** access (for the initial OAuth consent) - Modern browser (Chrome, Edge, Firefox, Safari - last two major versions) Full detail - which license SKUs qualify, which admin roles are used and when, every permission each module requests, and the four features that need a premium Microsoft SKU - is in [Requirements](/en/docs/requirements). ## Deployment Models **Recommended for most teams.** 1Security manages the infrastructure, updates, and maintenance. You simply log in and connect your tenant. - **Zero infrastructure** to manage. - **Continuous updates** with no downtime. - Setup takes less than 5 minutes. - Hosted in secure, SOC 2 Type II compliant environments. ### Getting Started ### Create your account Go to [1security.ai](https://1security.ai) and sign up using your Microsoft work account. We use OAuth - your password never leaves Microsoft. ### Grant tenant permissions During the consent dialog, an admin in your tenant approves the permissions 1Security needs to read your Microsoft 365 metadata. We never request write access to user data without an explicit per-action prompt. ### Run your first scan Once connected, the platform automatically queues an initial scan. You'll see results stream in over the next few minutes. **Bring Your Own Cloud** is ideal for organizations with strict data residency requirements that want to keep all processed data inside their own Azure tenant, while still using our managed Docker images. ### Architecture Overview Docker images are provided pre-built from 1Security's Azure Container Registry. You will receive access credentials to pull images directly to your environment. **Required Azure Services:** - **Azure App Service (Linux)**: 2 instances (API + Client) - **Azure App Service Plan**: Separate compute plans for API and Client recommended. - **Azure Database for PostgreSQL**: Flexible Server recommended over Single Server. - **Azure Key Vault** (Optional): Secure storage for secrets and certificates. - **Azure Storage Account** (Optional): File share for certificate mounting. ### Resource Specifications & Estimated Costs Tenant scans are CPU and memory-intensive. Below are recommended specs based on active users (costs exclude discounts like Reserved Instances, which can reduce prices by ~60%): | Tenant Size | API Server | Client App | PostgreSQL | Estimated Monthly Cost | | :--- | :--- | :--- | :--- | :--- | | **Small** (< 350 users) | **P2V3** (2 vCPU, 8GB RAM) | **P1V2** (1 vCPU, 3.5GB RAM) | **Standard_D2s_v3** (2 vCores, 8GB RAM) | ~$355 / month | | **Medium** (350-1,000 users) | **P3V3** (4 vCPU, 16GB RAM) | **P2V3** (2 vCPU, 8GB RAM) | **Standard_D2s_v3** (2 vCores, 8GB RAM) | ~$580 / month | | **Large** (1,000+ users) | **P3V3** (4 vCPU, 16GB RAM) | **P2V3** (2 vCPU, 8GB RAM) | **Standard_D4s_v3** (4 vCores, 16GB RAM) | ~$840+ / month | ### Required Permissions To set up the BYOC deployment, the administrator needs: - **Azure Subscription**: Contributor role (or Resource Group Owner). - **Entra ID**: Application Admin or Cloud Application Admin (to create App Registrations and grant consent). - **Specific Resources**: App Service Contributor, Key Vault Admin, PostgreSQL Contributor. *Contact our support team to receive your ACR credentials and the complete BYOC deployment manifests.* **Fully self-hosted deployment** for organizations with air-gapped environments or ultimate infrastructure control needs. - **Total control** of data location and network boundaries. - **Air-gapped** installation supported. ### Minimum Hardware Requirements - **Compute**: 16 vCPU - **Memory**: 64 GB RAM - **Storage**: 500 GB SSD (NVMe recommended) *Contact our enterprise sales team to plan an on-premise deployment.* Granting consent requires **Global Administrator** privileges. If you're not a global admin, ask one to complete the consent flow - you can still own day-to-day operations afterwards. ## Verifying the install After the consent flow and environment setup finish, you should land on the dashboard with at least the following populated: - **Tenant** card showing your tenant ID and domain - **Scan status** showing "Running" or "Queued" - **Users** count matching what you see in the Microsoft 365 admin centre (give it a minute to sync) If any of these are missing, see [connecting tenants](/en/docs/connecting-tenants) for troubleshooting. ================================================================= ## Integrations & Modules URL: https://1security.ai/en/docs/integrations-modules ================================================================= 1Security is built from the ground up around the **Principle of Least Privilege**. By default, the platform operates entirely as a **read-only visibility module**, requiring only the minimum Microsoft 365 permissions necessary to map your environment. You can optionally extend 1Security with additional capabilities through specific modules. This architecture ensures you only grant expanded permissions-especially write access or access to communication data-when you explicitly need those features. ## Core Visibility (Default) The base installation of 1Security provides complete operational visibility into your Microsoft 365 tenant without requiring any write permissions. - **Permission Graph**: A fully interactive tenant map of users, groups, applications, and resources. - **Activity & Risk Monitoring**: Out-of-the-box tracking of unified audit logs and basic risk scorings. - **Built-in Sensitivity**: 1Security's proprietary text-extraction and OCR engine securely scans file contents for sensitive patterns without requiring Purview or Exchange access. --- ## Extension Modules When you are ready to expand your workflow, you can enable the following extension modules from the **Settings → Integrations** dashboard. Each module requests a localized set of new permissions. ### 1. Sensitivity (1Security Engine + Microsoft Purview) 1Security includes a powerful, built-in sensitivity scanning engine that automatically identifies and classifies sensitive data across your Microsoft 365 environment. Using a combination of text extraction, OCR for images, and pattern matching, it detects over 300 types of sensitive information-all without requiring advanced Microsoft licenses. Enabling this extension module expands these built-in capabilities by integrating directly with Microsoft Purview Information Protection. - **Why it requires an extension**: Requires explicit permissions to read your tenant's Purview configuration and sensitivity labels. - **Benefits**: Merges Microsoft Purview's native labeling system with 1Security's independent algorithmic scanning. This provides a powerful hybrid classification layer, allowing you to utilize your custom Purview labels alongside 1Security's findings, even if you don't have Purview autodiscovery licensed. ### 2. Email (Microsoft Exchange) Expands the platform to analyze email traffic and individual mailbox contents. - **Why it requires an extension**: Requires explicit read access to Exchange mailbox contents, email bodies, and attachments. - **Benefits**: Detects sensitive data shared via email, analyzes attachments in transit, and seamlessly maps complex email activities (like forwarding sensitive data externally) into the interactive permission graph. ### 3. Automations Unlocks active remediation capabilities, transforming 1Security from an auditing platform into a security orchestrator. - **Why it requires an extension**: This is the **only** module that requires **Write permissions** in your Microsoft 365 tenant. - **Benefits**: Enables you to manage permissions at scale. You can create rules to instantly revoke stale external access, expire widely-shared sensitive links, remove overprivileged Copilot agents, and automatically remediate permission sprawl across thousands of files simultaneously. ================================================================= ## Location Intelligence URL: https://1security.ai/en/docs/location ================================================================= Every action in your Microsoft 365 environment happens _somewhere_. Location Intelligence turns the raw, throwaway IP addresses buried in your audit logs into a clear, human answer to a deceptively hard question: **"Where is this activity actually coming from - and should I be worried about it?"** Knowing where your people work is one of the strongest security signals you have, and the cheapest to check. If your company operates in Europe, a document library downloaded from Asia at three in the morning is a red flag before anyone looks at behaviour, permissions or file contents - no modelling, no baseline, no tuning. Stolen credentials are used from wherever the attacker happens to be, and that is rarely where the employee sits. ## What You Can Achieve ## Where a Location Comes From A **Location** in 1Security is not an IP address. Raw IPs are noisy and disposable - a single user on a phone might use dozens in a day. Instead, we resolve each event's network address into a stable, meaningful identity made of three parts: - **Country and City** - _where_ the activity appears to originate. - **Network (ASN)** - _who_ owns the connection: a home ISP, a corporate network, a mobile carrier, a cloud provider, or an anonymity service. Dynamic IPs that all belong to the same place collapse into one Location, so you see "Warsaw, Poland - home ISP" once, not two hundred fleeting addresses. ## The Signals That Matter Beyond the map, 1Security classifies the **type of network** behind each action. This is often the real story: - **Standard** - an ordinary residential or corporate connection. Expected. - **VPN** - traffic routed through a commercial VPN. Sometimes legitimate, sometimes an attacker hiding their true location. - **Tor** - the anonymity network. Almost never a normal way for an employee to open a spreadsheet. - **Datacenter** - a hosting/cloud provider. A person browsing files from a datacenter is unusual and worth a look. - **Microsoft** - Microsoft's own infrastructure (see below). VPN, Tor, and datacenter egress on a user's activity is one of the strongest early signals of a stolen session or compromised account. Location Intelligence surfaces it automatically - no rules to write. ## The Microsoft Relay Problem (and How We Solve It) Here is a subtlety that trips up almost every security tool: **many Microsoft 365 actions do not carry the user's real IP address.** When a server-side operation happens - adding a mailbox permission, a background SharePoint action, a Copilot interaction - Microsoft often records the IP of _its own datacenter_, not the person who triggered it. Left unhandled, this floods your logs with hundreds of "logins from a US datacenter" for users who never left the office. It buries real threats in false alarms. 1Security handles this in two ways: 1. **We recognise Microsoft's own networks** - across both IPv4 and IPv6 ranges - and label that traffic clearly as **Microsoft** origin, styled neutrally rather than as a suspicious datacenter. 2. **We use Microsoft's own location signal when it's available.** Microsoft frequently includes the user's _real_ country alongside the relayed IP. We trust that over the meaningless address of the relay, so a file previewed by someone in Poland reads as Poland - even though the underlying connection was a Microsoft server in the US. Crucially, we do this by recognising Microsoft's *infrastructure*, never by assuming "any foreign-looking activity is just Microsoft." A genuine sign-in from an unexpected country stays fully visible - because that might be exactly the compromise you need to catch. ## Conditional Access, Laid Over What You Observe Locations answer _where your people work_. Conditional Access declares _where you allow them to work from_. Neither half is worth much alone - and the interesting part is always the difference between them. Grant the read-only `Policy.Read.All` permission and 1Security pulls your named locations and Conditional Access policies, then matches them against every location it has already resolved. Each place gets a coverage verdict - **not covered**, **partly covered**, **named**, **trusted** - computed from the source addresses actually seen there rather than from the policy's stated scope, plus findings such as an office that sits outside every trusted range, a trusted range that resolves to a VPN, or sign-ins that completed with no policy in force at all. This is exactly the pairing neither side can produce on its own: the Entra portal knows what you declared but has never seen your traffic; a location list knows your traffic but not what you promised about it. Coverage lives on the **Conditional Access** tab of the Locations screen, as a **CA coverage** column on the location lists, and as a per-location tab in the drawer. See [Conditional Access](/en/docs/conditional-access) for the full picture, including the named-locations view and what each finding means. ## Where You'll See It Location Intelligence is woven through the product rather than hidden on one screen: - **Activity Logs** gain **Location** and **Infrastructure** columns, plus filters for country, network type, and whether a location is new for that user. - **User and Device drawers** include a **Locations** tab - a travel timeline of everywhere that identity has been seen active, newest first. Click any location to jump straight to the exact events that came from it. - **First-seen detection** flags the first time a user is observed at a given location - a lightweight, high-signal indicator of a new or anomalous session. ## Licensing Like the rest of 1Security, Location Intelligence works with a **standard Microsoft 365 license**. Enrichment runs locally and privately - we never send your IP data to a third-party lookup service. No Microsoft E5, Entra ID P2, or premium sign-in log add-on is required. ================================================================= ## Network Requirements URL: https://1security.ai/en/docs/network-requirements ================================================================= # Network requirements Everything your network team needs to let 1Security through: the exact hostnames, ports and directions, what happens if each one is blocked, and vendor-by-vendor instructions for the one thing that actually trips deployments - a category-based web filter that reads `1security.ai` as an AI site and blocks it. The headline: **1Security is a browser-only SaaS product.** No inbound rules, no VPN, no tunnel, no collector, no agent on endpoints. Your users' browsers make ordinary outbound HTTPS connections, and that is the whole footprint. ## What has to be reachable All entries are **TCP 443, outbound only**, from your users' browsers. | Hostname | Purpose | If it's blocked | | :--- | :--- | :--- | | `app.1security.ai` | The dashboard itself | Nothing loads. | | `api.1security.ai` | GraphQL API and [public REST API](/en/docs/reference/api) - every screen's data, plus SIEM polling | The dashboard shell loads and then stays empty or spins forever. **This is the most common half-configured state:** the apex domain gets allowlisted, the API subdomain doesn't. | | `1security.ai` | Public site, documentation, sign-in entry point | Users can't reach sign-in or these docs. | | `login.microsoftonline.com` | Microsoft sign-in and admin consent | Nobody can authenticate. Almost always already allowed in a Microsoft 365 tenant. | | `*.sharepoint.com`, `*-my.sharepoint.com` | "Open in SharePoint" deep links from findings | The product works; the jump-to-file links fail. Also normally already allowed. | Optional, and safe to leave blocked - none of these affect functionality: | Hostname | Purpose | | :--- | :--- | | `posthog.1security.ai`, `eu.i.posthog.com` | Product analytics | | `o4509649988026368.ingest.de.sentry.io` | Browser error reporting | **Nothing else.** No inbound firewall rules. No source-IP allowlist on your side. No ports other than 443. No software to install - no browser extension, no desktop agent, no endpoint software, no log forwarder. ### Which way the traffic goes - **1Security never connects into your network.** It calls Microsoft Graph on your tenant's behalf, from our cloud to Microsoft's - your perimeter isn't in that path at all. - **SIEM integration is pull-based.** Your SIEM calls `api.1security.ai` on a schedule; we never call it. See [SIEM Integration](/en/docs/guides/siem-integration). - **Plain HTTPS request/response.** No WebSockets, no long-polling, no streaming connections to keep open through a proxy. ## When a web filter blocks 1Security The symptom is unmistakable: instead of the dashboard, users get **your own vendor's block page** - FortiGuard, Zscaler, Umbrella and the rest all serve a branded page naming the category they blocked. The cause is almost always the same. Every major web filter added a dedicated AI category in 2024-2025 (FortiGuard's **Artificial Intelligence Technology**, Palo Alto's **artificial-intelligence**, Umbrella's **Generative AI**), and many organizations block that whole category by default. A domain that ends in `.ai` and has a product name containing "Security" for an AI-adjacent product gets swept up by automated classification - even though 1Security is a Microsoft 365 security dashboard, not a generative-AI service, and users neither upload nor paste data into a model through it. There are two fixes and you want both: 1. **Unblock locally** using your vendor's instructions below. Takes minutes, works immediately, done by whoever administers your web filter. 2. **Tell us**, so we file a recategorization request with the vendor. That fixes it globally for every customer on that vendor - see [Getting the rating fixed at source](#getting-the-rating-fixed-at-source). Prefer a **domain-specific override** over disabling the AI category. Every option below unblocks 1Security alone and leaves the rest of your AI policy exactly as it is. Nobody should have to weaken a working control to run a security tool. ## FortiGate Locally re-rates the domain into a category you already permit. The AI category block stays fully intact for every other site, no policy is edited, and all remaining UTM inspection (antivirus, DLP, content filter) still applies to 1Security traffic. This is the cleanest option. **GUI:** Security Profiles → Web Rating Overrides → Create New. For each hostname, set **Category** to `General Interest - Business` and **Sub-Category** to `Information Technology`. **CLI:** ``` config webfilter ftgd-local-rating edit "1security.ai" set status enable set rating 52 next edit "app.1security.ai" set status enable set rating 52 next edit "api.1security.ai" set status enable set rating 52 next end ``` Rating `52` is **Information Technology** in the current FortiGuard category set - confirm against the dropdown in your own build if you prefer. Add an entry per hostname as shown: an override matches the hostname you enter, so a single `1security.ai` entry is not guaranteed to cover `app.` and `api.`, and those two are exactly the ones that must work. Works, but it is the blunt instrument - reach for it only if your change process rules out rating overrides. Security Profiles → Web Filter → your profile → **Static URL Filter** → Create New. Add each hostname with Type `Simple` and action **Exempt**. **The action must be `Exempt`, not `Allow`.** This is the single most common mistake here. In FortiOS, `Allow` means "passed by the URL filter, now continue to the remaining inspections" - including the FortiGuard category filter, which is the thing doing the blocking. The site stays blocked and the change looks like it silently did nothing. Only `Exempt` bypasses the category lookup. See Fortinet's own [Allow vs Exempt](https://community.fortinet.com/t5/FortiGate/Technical-Tip-The-difference-between-Allow-and-Exempt-in-the-web/ta-p/261349) note. The trade-off: `Exempt` bypasses **all** remaining scanning for that destination - antivirus, DLP, web content filter, everything - not just the category check. A rating override doesn't. A **separate axis** from the category block, and usually not what you need. Only relevant if 1Security loads but behaves erratically - certificate warnings, truncated responses, requests failing under deep inspection. Security Profiles → SSL/SSH Inspection → your deep-inspection profile → **Exempt from SSL Inspection** → Addresses / Web categories. If users are seeing a FortiGuard block page naming a category, this is not the fix - use a rating override instead. Exempting from SSL inspection does not lift a category block. ## Zscaler Two places may need attention, because Zscaler filters URLs and cloud apps separately. ### Create a custom URL category Administration → URL Categories → Add. Include `1security.ai`, `app.1security.ai` and `api.1security.ai`. Custom categories take precedence over Zscaler's own categorization. ### Allow it in URL Filtering Policy → URL & Cloud App Control → URL Filtering. Add a rule with action **Allow** for that custom category, ordered **above** any rule blocking the AI-related categories. ### Check Cloud App Control If your tenant blocks the **AI & ML Applications** cloud-app category, add an allow rule for 1Security there too. A URL Filtering allow does not override a Cloud App Control block - deployments that fix only the first one still fail. ## Netskope ### Add a URL list Policies → Profiles → URL Lists → New URL List. Add the three hostnames. ### Wrap it in a custom category Policies → Profiles → Custom Categories. Netskope applies URL lists to policies through a custom category, not directly. ### Allow it ahead of the Gen-AI rule Policies → Real-time Protection. Add an **Allow** policy for that category and order it **above** any Generative AI blocking policy. Netskope evaluates top-down and stops at the first match. ## Palo Alto Networks Objects → Custom Objects → **URL Category**. Create a category containing `1security.ai`, `app.1security.ai` and `api.1security.ai`, then set that custom category to **allow** in the URL Filtering profile attached to your outbound policy. Custom categories are evaluated before PAN-DB, so this holds regardless of how PAN-DB rates the domain - including the granular AI categories introduced in Advanced URL Filtering. ## Cisco Umbrella Policies → Policy Components → **Destination Lists**. Create an *Allow* list with the three hostnames and apply it to the policy covering your users. Umbrella evaluates allow lists before content categories, so this takes effect without touching your Generative AI category setting. Note that Umbrella's DNS-layer enforcement resolves on the domain only - one allow list entry per hostname is still the safe shape. ## Getting the rating fixed at source Local overrides fix one organization. A recategorization request fixes everyone on that vendor, usually within 24-48 hours, and it is free. If you have hit this block, **tell your 1Security contact which vendor and which category the block page named** - we file the request. You are welcome to file one in parallel; a report from an affected customer often carries more weight than one from the site owner. | Vendor | Where to submit | | :--- | :--- | | Fortinet / FortiGuard | [fortiguard.com/faq/wfratingsubmit](https://www.fortiguard.com/faq/wfratingsubmit) - reviews generally processed within 24 hours | | Zscaler | [sitereview.zscaler.com](https://sitereview.zscaler.com/) | | Netskope | Skope IT → Tools → **URL Lookup** → *Report Miscategorization* | | Palo Alto Networks | [urlfiltering.paloaltonetworks.com](https://urlfiltering.paloaltonetworks.com/) → *Request a Change* | | Cisco Umbrella | [Dispute a categorization](https://docs.umbrella.com/umbrella-user-guide/docs/dispute-a-categorization), or submit directly through Cisco Talos | The category to request is **Information Technology** (or your vendor's nearest equivalent - Business, Computers and Internet, Software as a Service). ## Self-hosted deployments The table at the top covers Cloud (SaaS), where 1Security calls Microsoft and your network is not involved. **BYOC and On-Premise** deployments make those Microsoft calls from inside your environment, so the deployment itself needs outbound HTTPS (443) to `login.microsoftonline.com`, `graph.microsoft.com`, `manage.office.com`, `.sharepoint.com`, `-my.sharepoint.com`, plus `outlook.office365.com` and `*.compliance.protection.outlook.com` for the audit and Purview modules. Sizing and deployment models are in [Installation](/en/docs/installation). ## Troubleshooting A category-based web filter. Read the category off the block page itself - it will name one - and apply the matching vendor section above. Then send us the vendor and category so we can file the recategorization. `app.1security.ai` is allowed but `api.1security.ai` is not. The page is static assets, so it loads; every piece of data on it comes from the API host. Allowlist both. This accounts for most "it half works" reports. The action is almost certainly `Allow`. It has to be `Exempt` - `Allow` passes the request on to the FortiGuard category filter, which blocks it again. Or switch to a web rating override, which is the better fix anyway. TLS deep inspection, not category filtering. Add 1Security's hostnames to your inspection exemption list and retest. If the error is a block page rather than a certificate warning, this is not the cause. Server egress usually runs through a different policy than user browsing. The API host `api.1security.ai` needs to be reachable on 443 from whichever host runs the poller - see [SIEM Integration](/en/docs/guides/siem-integration). Next: the tenant-side prerequisites - licenses, admin roles and permissions - are in [Requirements](/en/docs/requirements). ================================================================= ## NIS2 URL: https://1security.ai/en/docs/nis2 ================================================================= # NIS2 Readiness NIS2 turns incident response into a race against statutory clocks: an **early warning within 24 hours** of becoming aware of a significant incident, an **incident notification with an initial assessment within 72 hours**, and a **final report within a month**. Most organizations cannot answer the underlying questions - _what happened, who was affected, is it still happening_ - in that window, because the evidence lives in 90-day logs and disconnected admin centers. 1Security's job is to make the deadline the easy part. ## What NIS2 Actually Requires The directive (EU 2022/2555, transposed into national law since October 2024) applies to _essential_ and _important_ entities across 18 sectors, and it is not a checkbox exercise: - **Article 21** mandates risk-management measures: incident handling, logging and detection, access control and asset management, supply-chain security, cyber hygiene, and - critically - _policies to assess the effectiveness_ of those measures. - **Article 23** sets the reporting clock: 24-hour early warning (including whether malicious action is suspected), 72-hour notification with severity, impact, and indicators of compromise, and a one-month final report covering root cause and mitigation. - **Management is personally accountable.** Boards must approve and oversee the measures, and can be held liable for violations - with fines up to €10M or 2% of worldwide turnover for essential entities (€7M / 1.4% for important ones). ## Beating the Reporting Clock | Deadline | What the regulator needs | Where you get it | | -------------------------- | ----------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **24 h** - early warning | Is it real? Is it malicious? Is it cross-border? | [Activity Logs](/en/docs/screens/activity-logs): the account's full timeline with every action attributed to actor, resource, app, device, and location. [Location Intelligence](/en/docs/location) separates a genuine foreign sign-in from Microsoft backend noise in one glance. | | **72 h** - notification | Severity, impact assessment, indicators of compromise | Blast radius on demand: everything the account touched, [every file it can still reach](/en/docs/screens/files), whether [sensitive or regulated data](/en/docs/screens/sensitive-info) was in scope, and which [device](/en/docs/screens/devices) - managed, personal, or shadow - carried the activity. | | **1 month** - final report | Root cause, full chronology, mitigation applied | Up to **three years of retained history** reconstructs the entire attack path - including entry points months old - and the remediation trail (revoked links, stripped permissions) documents your response. | ## Evidence for the Article 21 Measures NIS2 doesn't just ask you to have controls - it asks you to _demonstrate they work_. That's the hard part, and it's where continuous visibility replaces the annual PDF: - **Incident handling & detection** - [Trends](/en/docs/screens/trends) run 50+ prebuilt and unlimited custom detections over the permission graph: mass downloads, insider-risk patterns, sensitive data exposed to AI. Alerts arrive in minutes, not at the next audit. - **Logging & forensic readiness** - three years of unified, searchable audit history on standard licenses, instead of a log-storage bill that punishes you for being prepared. - **Access control policy** - the [permission graph](/en/docs/permission-graph) shows effective access (nested groups and inheritance resolved), so least-privilege is something you _measure_, and access reviews audit reality instead of intentions. - **Asset management** - live inventories of [devices](/en/docs/screens/devices) (including shadow devices that never registered), [sites](/en/docs/screens/sites), and [connected apps](/en/docs/screens/apps) - the assets you can't protect are the ones you don't know about. - **Supply-chain security** - every third-party app and [AI agent](/en/docs/screens/agents) with a foothold in your tenant, its publisher verification, its access channel, and who let it in. - **Effectiveness assessment** - [sensitivity-label coverage](/en/docs/screens/sensitivity-labels) measured against actual [sensitive-data locations](/en/docs/sensitivity): the difference between "we have a data classification policy" and "here is its coverage, as a number, trending quarterly." ## The 72-Hour Drill Run this as an exercise before you run it as an incident: pick a user account, and within one sitting produce (1) their complete 90-day activity timeline with devices and locations, (2) every file, site, and mailbox item they can currently reach, (3) how much of it carries regulated data, and (4) one revoked permission as remediation evidence. If you can do it in a drill, the 72-hour notification stops being frightening. ## Scope, Honestly 1Security provides the forensic record, the live risk visibility, and the remediation trail that NIS2 obligations rest on. Whether a given incident is "significant," which national authority receives your report, and how your sector's transposition applies - those are calls for your compliance counsel. Bring them the evidence; 1Security makes sure you have it. ================================================================= ## Permission Graph URL: https://1security.ai/en/docs/permission-graph ================================================================= # Permission Graph The permission graph answers the question that burns more analyst hours than any other in Microsoft 365: **"Why does this person have access to this file?"** Native tools can sometimes tell you _that_ someone has access. The _why_ - the chain of nested groups, site inheritance, and sharing links behind it - is scattered across admin centers and PowerShell output. 1Security draws it as a path you can walk, in either direction, from any starting point. ## What You Can Achieve ## One Map, Every Relationship The graph connects the two halves of your tenant that Microsoft keeps in separate tools: - **Identities** - users, groups, third-party apps, and AI agents. - **Resources** - sites, files, and emails. The edges between them are the permissions and activity that actually matter: membership, direct grants, link access, inheritance, and actions taken. Because indirect paths are resolved - including the hard ones, like multi-level group nesting and per-site SharePoint permission inheritance - the graph is a **single source of truth** for who has access to what at any moment. ## Where the Graph Works for You The graph isn't a page you visit; it's the backbone the platform runs on, and every screen is one of its views: - The [Files screen](/en/docs/screens/files) answers "who has access to our files - and why?" with the graph's resolved paths behind every count. - The [Groups screen](/en/docs/screens/groups) shows effective membership - nesting resolved - and the blast radius each group unlocks. - The [Sites screen](/en/docs/screens/sites) separates direct from indirect access, so you see through which doors people enter each site. - The [Apps](/en/docs/screens/apps) and [Agents](/en/docs/screens/agents) screens quantify how far third-party software and AI reach along the same edges. - The [Activity Logs](/en/docs/screens/activity-logs) attribute every action to the actor, resource, app, device, and location - the graph in motion. - [Trends](/en/docs/screens/trends) evaluate conditions over the graph continuously, turning any pattern you can describe into an alert. ## Investigative Patterns **The why-chain audit**: pick a high-risk detection on the [Sensitive Info screen](/en/docs/screens/sensitive-info), open the files that carry it, and walk each access path to its origin. Every path ends in one of three places - a deliberate grant, a forgotten link, or an inheritance nobody considered. The second and third are your findings, and you can revoke them where you stand. ================================================================= ## Requirements URL: https://1security.ai/en/docs/requirements ================================================================= # Requirements Everything 1Security needs from your tenant, in one place: the license check that runs at connect time, the admin roles involved, the exact permissions each module requests, and the handful of things that genuinely need a premium Microsoft SKU. The headline: **1Security runs on a standard Microsoft 365 license.** There is no agent to install, no appliance, no log forwarder, and no E5 requirement for the core product. ## Microsoft 365 licensing ### The one hard requirement Your tenant needs **at least one user with a license that includes SharePoint Online.** That is the whole check. 1Security verifies it at connect time and blocks with _"Your tenant does not have the required license"_ if no qualifying subscription is found. Any of these qualify (the list is matched on subscription SKU, so equivalents and regional variants count too): | Family | Plans that qualify | | :--- | :--- | | **Business** | Business Basic, Business Standard, Business Premium | | **Enterprise** | Office 365 E1 / E3 / E5, Microsoft 365 E3 / E5 | | **Frontline** | Microsoft 365 F1 / F3 (including the EEA "no Teams" variants) | | **Standalone SharePoint** | SharePoint Online Plan 1, Plan 2, Office for the web | | **Developer & Government** | E3 / E5 Developer, GCC High and DoD variants of E3 / E5 | The license is checked at the **tenant** level, not per seat. 1Security does not need a license for every user it maps - it needs the tenant to have SharePoint Online, because that is what makes the Microsoft Graph endpoints 1Security reads available at all. ### What needs nothing extra These all work on Business Basic - no E5, no add-ons, no premium sign-in logs: - The full [permission graph](/en/docs/permission-graph) - users, groups, sites, files, apps, agents, devices. - [Sensitivity scanning](/en/docs/sensitivity) with 1Security's own engine (300+ detectors, OCR included). - Up to three years of [activity history](/en/docs/screens/activity-logs), well past Microsoft's default retention. - [Location intelligence](/en/docs/location) - enrichment runs locally, no premium sign-in log add-on. - [Devices](/en/docs/screens/devices), including unregistered and shadow devices. - [Automations](/en/docs/screens/automations) and the whole remediation layer. ### What needs a premium Microsoft SKU Four features depend on something Microsoft itself puts behind a higher tier. Each one degrades on its own - the rest of the platform is unaffected. | Feature | What it needs | Without it | | :--- | :--- | :--- | | **Purview labels & SIT detections** | Microsoft Purview (Information Protection / Content Explorer) | 1Security's own sensitivity engine still classifies everything - you lose the Microsoft second opinion, not the finding. See [Sensitivity Labels](/en/docs/screens/sensitivity-labels). | | **Native security alerts** | Microsoft Defender | Defender's alerts don't flow in. 1Security's own anomaly detection is unaffected. | | **Copilot agent catalog** | **Microsoft Agent 365** on the one admin who connects the tenant (~$15/user standalone, or bundled in E7) | Entra-backend agents are still scanned in full; declarative Copilot agents look like ordinary enterprise apps. Details in [Agents](/en/docs/agents). | | **Historical audit backfill** | The `AuditLogsQuery.Read.All` permission granted on the read app | Forward audit-log polling keeps running - only the backfill of history from before you connected stays dormant. | ## Admin roles | When | Who has to do it | Why | | :--- | :--- | :--- | | Initial consent, and each extension module | **Global Administrator** | Microsoft requires a Global Admin to grant tenant-wide application permissions. | | Purview module | An admin who can edit Purview role groups | The 1Security service principal must be added to the **Content Explorer List Viewer** role group before Purview detections can be read. | | Day-to-day use | No Microsoft admin role at all | Analysts work inside 1Security. Access there is governed by [1Security's own roles](/en/docs/getting-started#managing-accounts-and-access). | Consent is a one-time action per module. If you are not a Global Admin, ask one to complete the consent flow - you can still own day-to-day operations afterwards. ### Directory roles 1Security assigns to itself Two modules need a Microsoft role on their own service principal, because the underlying API is Exchange-based rather than Graph-based. This is why those modules request `RoleManagement.ReadWrite.Directory` - it is used to make exactly one assignment, to 1Security's own application: - **Audit module** - assigns **Exchange Administrator** to the audit app's service principal, so it can read the unified audit log configuration through Exchange Online PowerShell. - **Purview module** - the same permission pattern, paired with the Content Explorer List Viewer role-group membership above. ## Tenant settings - **Unified audit log must be turned on.** It is on by default in most tenants. 1Security checks its status and, once the audit module is connected, can turn it on for you - or you can do it yourself first, see [Microsoft's guide](https://learn.microsoft.com/en-us/purview/audit-log-enable-disable). Without it, Microsoft records no activity for anyone to read, so the [Activity Logs](/en/docs/screens/activity-logs) screen stays empty. - **No other tenant configuration is required.** No mail flow rules, no conditional access exceptions, no service accounts, no mailbox impersonation. ## Permissions, module by module 1Security follows least privilege literally: the base install is **read-only**, and every capability that needs more permission is a separate consent you grant only if you want the feature. Write access exists in exactly two modules, both opt-in. ### Core visibility - read-only, granted at install Microsoft Graph: ```text User.Read.All Group.Read.All GroupMember.Read.All Directory.Read.All Files.Read.All Sites.Read.All Organization.Read.All Application.Read.All Team.ReadBasic.All Reports.Read.All Insights-UserMetric.Read.All UserAuthenticationMethod.Read.All AuditLog.Read.All SecurityAlert.Read.All SecurityIncident.Read.All Sites.FullControl.All AuditLogsQuery.Read.All (optional - historical audit backfill only) ``` SharePoint: ```text Sites.Read.All User.Read.All Sites.FullControl.All ``` **Why `Sites.FullControl.All` appears in a read-only module.** SharePoint's own API offers no read-only scope that exposes site-collection sharing settings and permission inheritance - the data the permission graph is built from. The visibility module only ever issues read calls with it. Nothing in 1Security writes to your tenant until you enable the Automations or Mailbox Management module below. ### Audit log ```text Office 365 Management API: ActivityFeed.Read, ActivityFeed.ReadDlp Microsoft Graph: RoleManagement.ReadWrite.Directory ``` The Graph permission is used only for the Exchange Administrator self-assignment described above. ### Purview ```text Microsoft Graph: RoleManagement.ReadWrite.Directory ``` Plus membership of the **Content Explorer List Viewer** role group in Purview. ### Email visibility ```text Mail.Read Domain.Read.All ``` Read-only access to mailbox contents. Message bodies and attachments are read during analysis, not stored. ### Mailbox management (optional, write) ```text Mail.ReadWrite ``` Granted **separately** from email visibility - you can read mailboxes without ever allowing changes. Lets an automation quarantine or flag a message rather than only alerting on it. No permanent deletion. ### Automations (optional, write) ```text Microsoft Graph: Files.ReadWrite.All, Group.ReadWrite.All, GroupMember.ReadWrite.All, User.ReadWrite.All SharePoint: Sites.FullControl.All ``` The only module that can change anything in your tenant. Actions are staged behind review queues and grace periods - see [Automations](/en/docs/screens/automations). ### Copilot agents (optional) ```text CopilotPackages.Read.All (delegated, on the read app) ``` Delegated rather than application permission, which is why Microsoft validates the **license of the single admin who connected the tenant** rather than every user. See [Agents](/en/docs/agents). ## Clients and network - **Browser** - Chrome, Edge, Firefox or Safari, last two major versions. Nothing to install: no extension, no desktop agent, no endpoint software. - **Cloud (SaaS)** - nothing to open on your side. 1Security calls Microsoft, not your network. Users' browsers need outbound HTTPS (443) to `app.1security.ai` and `api.1security.ai` - the full hostname list, and what to do when a web filter classifies 1Security as an AI site and blocks it, is in [Network Requirements](/en/docs/network-requirements). - **BYOC and On-Premise** - the deployment needs outbound HTTPS (443) to the Microsoft endpoints 1Security calls: `login.microsoftonline.com`, `graph.microsoft.com`, `manage.office.com`, `.sharepoint.com` and `-my.sharepoint.com`, plus the Exchange Online and Security & Compliance PowerShell endpoints (`outlook.office365.com`, `*.compliance.protection.outlook.com`) used by the audit and Purview modules. Hardware and Azure resource sizing is in [Installation](/en/docs/installation). ## When a prerequisite is missing No subscription in the tenant includes SharePoint Online, or no user has been assigned one. Assign a qualifying license (see the table above) to at least one user and reconnect - a trial license is enough to verify. Two normal causes. Either Azure is still propagating the application permission assignment - this can take a few minutes after consent - or a module was added after the original consent and needs its own grant. Click **Assign permissions** in the banner to re-run the consent flow for what's missing. Check that the unified audit log is enabled in your tenant. Microsoft records nothing while it is off, and no tool can recover activity from that period afterwards - which is why turning it on is the first thing worth doing, even before connecting 1Security. The 1Security service principal is almost certainly not a member of the **Content Explorer List Viewer** role group. Purview exposes Sensitive Information Type detections only to members of that group, so the connection succeeds while every query comes back empty. The admin account that connected the tenant has no Microsoft Agent 365 license, so Microsoft won't return the agent catalog. One standalone Agent 365 license on that one admin unlocks the whole tenant's catalog - see [Agents](/en/docs/agents). Next: pick a deployment model in [Installation](/en/docs/installation), then see what the [first scan](/en/docs/scans) does with the access you granted. ================================================================= ## Your First Scan URL: https://1security.ai/en/docs/scans ================================================================= 1Security automatically schedules a full scan after a tenant is connected. This page explains what that scan actually does, how long it takes, and what to look at first. ## What gets scanned ## Scan stages The scan runs through several stages in order. You can watch progress in the header or **Tenants page → Scan status** column. ### Discovery 1Security discovers all identities, resources, and activities in your tenant. You can track found identities across pages like **Users**, **Files**, **Activity**, and **Alerts**. Permissions for a resource are mapped shortly after discovery. Sites require to be **Fully scanned** for the permissions to be mapped. ### Permission graph For each resource, we map every identity that can access it - including indirect access through nested groups. This is the longest stage. We map access not just for **Users** but **Apps** including Copi Agents. This makes 1Security into a fully interactive tenant map. You can navigate from users to their actions to the modified files to their sensitive data - any point allows for an audit travel. ### Sensitivity classification Files are scanned for sensitive content using our 300+ pattern library, OCR for images, and (optionally) LLM-based classification. Sensitivity can work with Microsoft Purview, with 1Security handling classification, or both. As for both, the advantage is it allows you to use custom Purview labels while having 1Security as a sensitivity analysis layer - as many clients do not have Purview autodiscovery enabled. ### Risk scoring Each resource is scored on multiple dimensions: external sharing, sensitivity, stale access, abnormal patterns. ## Expected duration For the largest tenants in production (40M+ files), the **initial** full scan can take weeks. Incremental scans run continuously after that and process changes within minutes. | Tenant size | Files | Initial scan \* | New resources / Activity | | ------------- | ------ | --------------- | ------------------------ | | Small | < 100K | 1–2 hours | ~ 10 min | | Medium | 1M | 6–12 hours | ~ 10 min | | Large | 10M | 1 week | ~ 10 min | | Enterprise \* | 40M+ | 4+ weeks | ~ 10 min | - \*Enterprise tenants can significantly improve initial scan speeds by contacting Microsoft Support to increase their API throttling limits. To do this, go to the **Microsoft 365 Admin Center**, navigate to **Support > Help & support**, and open a new service request asking to "Increase Microsoft Graph and SharePoint API throttling limits for a security auditing application." ## Live updates New and updated entities such as files, emails, logs (excluding Sensitive Info and Sensitivity Labels) etc should appear in the system within several minutes alongside their changed permissions. Similar to how Copilot works, we use a combination of real-time updates and periodic scans to keep the system up to date. Updated Sensitive Info and Sensitivity Labels are processed in the background and may take longer to appear. ## Trends Track your tenant over time using the permission map as a base. We provide over 50 default, pre-configured trends (such as 'External Users Downloading Files') that you can easily edit or use as templates for nearly limitless custom rules in an intuitive UI. By default, trend results are evaluated and updated once a day. ================================================================= ## Sensitivity Scanning URL: https://1security.ai/en/docs/sensitivity ================================================================= # Sensitivity Scanning Sensitivity scanning answers a question Microsoft puts behind its most expensive licenses: **"Where is our sensitive data - and who can reach it?"** 1Security ships its own scanning engine that reads file and email content, detects over 300 types of sensitive information - credit card numbers, personal identifiers, financial records - and connects every detection to the permission graph. It runs on a **standard Microsoft 365 Business Basic license**. ## What You Can Achieve ## How the Scan Works 1. **Extraction** - text is securely extracted from documents, spreadsheets, presentations, and emails. 2. **OCR** - for images and scanned documents, built-in optical character recognition reads the text inside the pixels. 3. **Pattern matching** - extracted text is evaluated against the library of 300+ sensitive information patterns, each detection carrying a confidence level. 4. **Risk assessment** - files and emails with detections are flagged in the permission graph and across every screen, so exposure analysis starts immediately. ## Supported Formats and Limitations The scanner focuses on the formats where business data actually lives: - **Documents**: `.txt`, `.csv`, `.docx`, `.pdf`, `.xlsx`, `.pptx` - **Images (OCR)**: `.jpg`, `.jpeg`, `.png`, `.gif`, `.bmp`, `.tif`, `.tiff`, `.webp` - **Emails**: message bodies are enriched and scanned. **Performance limits:** - **File size** - files up to **50 MB** are scanned; larger files are skipped to keep the system responsive. - **PDF depth** - the **first 5 pages** of each PDF are processed, capturing the most relevant context. - **Embedded images** - up to **10 embedded images** per document (e.g. `.docx`) go through OCR. ## Where Detections Land - The [Sensitive Info screen](/en/docs/screens/sensitive-info) rolls every detection type into an estate-wide map: which files, emails, sites, groups, users, and apps each type touches, filterable by compliance framework (GDPR, HIPAA, PCI-DSS, and more). - The [Files](/en/docs/screens/files) and [Emails](/en/docs/screens/email) screens filter by sensitive info presence, specific types, minimum counts, and confidence - and combine those with sharing and exposure filters. - The [Sensitivity Labels screen](/en/docs/screens/sensitivity-labels) closes the loop: compare what the scan _found_ against what Purview labels _cover_, and measure your real protection gap. ## Licensing Requirements You do not need premium Microsoft licenses for deep security visibility. **Nearly every functionality in 1Security works with a standard Microsoft 365 Business Basic license.** The only exceptions that require advanced Microsoft licenses are: - **Security Alerts** - requires **Microsoft Defender** to pull native security alerts into 1Security. - **Sensitivity Labels** - requires **Microsoft Purview** if you want to sync and display Purview's native labels alongside 1Security's findings. Even without Microsoft Purview, 1Security's independent sensitivity engine fully classifies and analyzes your sensitive data - Purview adds a second opinion, not the first one. ================================================================= ## Welcome URL: https://1security.ai/en/docs/welcome ================================================================= Welcome to the **1Security** documentation. 1Security is the platform for the permission-centric era of security: attackers don't break in anymore, they **log in** - and 1Security is built to catch them, on standard Microsoft 365 licenses. These pages walk you through everything from your first scan to the deepest configuration knobs the platform exposes. ## Start here ## Explore the platform New here? Read [Why 1Security](/en/docs/why-1security) first - it frames everything the platform does around questions you already know you can't answer today. ================================================================= ## Why 1Security URL: https://1security.ai/en/docs/why-1security ================================================================= # Why 1Security ## Attackers don't break in anymore. They log in. The vast majority of today's breaches are not sophisticated malware slipping past a firewall - they are **identity and permission attacks**. Attackers exploit overshared data, dormant accounts, rogue AI agents, and unmanaged shadow devices, moving through your environment along the _exact same access pathways your employees use_. There's no exploit to patch and no signature to match - just a valid login doing things it shouldn't. Cybercrime evolved from vulnerabilities to permissions. Most security tooling didn't. ### The Invisible Attack Vector **Access permissions are the #1 attack vector** of successful cybercrime and AI data leaks - and the surface almost no tool actually watches. ## The tooling landscape completely failed to evolve Despite the shift, legacy tools are stuck in the past: - **SIEMs & Data Lakes** extort organizations into storing "dead logs" for compliance, but lack the contextual intelligence to catch a threat in real time. - **IAM & Directory tools** manage provisioning, but are completely blind to what identities are actually _doing_ with your data - or which unmanaged devices they're doing it from. - **Static compliance scanners** produce point-in-time dashboards that are obsolete the moment they're exported, leaving teams drowning in alerts they can't act on. The result: security teams flying blind, manually stitching cryptic audit trails across fragmented systems just to answer one deceptively simple question - **"Who has access to what, and what did they do with it?"** 1Security is built to answer it. ## Measure what matters. Act on what you measure. The old management adage holds in security too: **you can't improve what you can't measure**. Legacy tools give you either raw logs without intelligence or static dashboards without context. 1Security turns your live Microsoft 365 data into measured, ranked, trended intelligence - and then lets you act on it in the same interface. - **Savings you can quantify** - every dormant license, abandoned app, and orphaned site is a cost line you can measure and reclaim. Not "you might have waste" - a ranked list of exactly what's unused and for how long. - **Time to action** - from "who has access to what?" taking days of manual stitching across systems to minutes. From detecting a mass-download spike to alerting in as little as one hour. From finding a risk to remediating it without leaving the screen. - **Data-driven decisions** - every finding, every trend, every alert is backed by measured activity data, not assumptions. You're acting on evidence: real usage numbers, real permission states, real activity timelines. - **Available now** - same-day deployment on standard Microsoft 365 licenses. No SIEM contract, no professional services engagement, no multi-month implementation. First scan results arrive before the day is over. Six questions every security team gets asked and can't answer from native Microsoft 365 tooling - each turned into minutes of work, on a standard license. ## 1. The Identity-Attack Forensic Tool > _Did somebody steal our data - and exactly what was affected?_ A new category of tool for a threat the old ones can't see. - **Proactive anomaly & insider-threat alerting** - active defense, not post-breach autopsy. High-signal alerts for tenant-wide risks, sudden mass downloads, and anomalous access catch compromised accounts and insiders in real time. See [Activities](/en/docs/screens/activities). - **3-year forensic memory without the log-storage tax** - storing logs is expensive even with tools that add no intelligence on top. 1Security retains up to **three years** of [activity history](/en/docs/screens/activity-logs) out of the box, on standard licenses. - **12 hours to 10 minutes** - answer definitively _"is this a breach, or normal behavior?"_ and chart the exact blast radius of a compromised account. - **Shadow Devices & Shadow Locations** - automatically surface unmanaged [endpoints touching your data](/en/docs/screens/devices) and anomalous, previously-unseen access origins - with [Microsoft's own backend IPs filtered out](/en/docs/location) so real anomalies aren't buried in false positives. - **Contextual enrichment vs. cryptic logs** - turn raw, unreadable audit events into a unified timeline that attributes every action to the exact **Actor, Resource, App, Device, and Location**. - **Unmasking the insider threats traditional tooling misses** - most successful breaches never trip a single alarm: an email quietly forwarded to an unknown recipient, an unknown device signing in with a stolen employee token, data accessed from an unexpected location, activity patterns just slightly off the norm. To traditional tooling, every one of those events looks completely legitimate. 1Security correlates **Actor, Device, Location, and behavior** across the full activity timeline to expose the attack hiding inside "normal" events. ## 2. The Data & Permission Crystal Ball > _Who has access to what - and why?_ Another new category: permission visibility at every altitude. - **From bird's-eye to single detail** - zoom seamlessly from a tenant-wide view of permission creep down to a single risk. Not just _"which financial files are available to AI?"_ but _"exactly why does this specific user and this specific AI have access to this one file?"_ See the [Permission Graph](/en/docs/permission-graph). - **The ultimate access map** - map where data lives, who (humans, service accounts) can reach it, what AI and apps can read it, and where your real sensitivity risks are concentrated across [Files](/en/docs/screens/files), [Sites](/en/docs/screens/sites), and [Groups](/en/docs/screens/groups). - **Oversharing & exposure profiling** - spot widely-available sensitive data before it leaks, and reveal the hidden pathways normal directory logs miss: dormant public links, over-permissioned folders, unauthorized routes. - **Security-measure verification** - see the true, real-time coverage of controls you already pay for, like [Microsoft Purview labels](/en/docs/screens/sensitivity-labels). Know instantly what's tagged and what's exposed. - **Audit-ready compliance & reporting** - frameworks like [NIS2](/en/docs/nis2), ISO 27001, and SOC 2 demand continuous evidence of who can access what and what's done with the data. With black-box permission models, producing that evidence is slow and costly - and every report is outdated the moment it's generated, because data ecosystems never stop changing. 1Security draws reporting straight from the live permission and activity map, so it's always current. ## 3. Total Hygiene & Attack-Surface Cleanup > _Are we wasting budget and hoarding hidden risks?_ Every stale account and forgotten resource is both a cost line and an attack path. 1Security finds both in one pass. - **Zero-waste IT** - reclaim budget by finding [unused licenses](/en/docs/screens/licenses), [dormant apps](/en/docs/screens/apps), inactive users, abandoned mailboxes, and orphaned sites. - **Attack-surface cleanup** - eliminate stale, orphaned, and disabled [devices](/en/docs/screens/devices), and sever lingering access for offboarded employees before it becomes an insider threat or breach vector. - **AI context-window optimization** - declutter the data footprint so corporate AI like Copilot doesn't hallucinate on outdated junk or surface sensitive executive documents to regular employees. ## 4. Shadow AI, Shadow IT & Autonomous Agents > _What AI tools and third-party apps are secretly reading our data?_ Employees consent to OAuth apps and build agents in an afternoon; IT finds out at the incident review. - **Shadow AI discovery** - catch rogue AI tools and unvetted third-party [apps](/en/docs/screens/apps) that employees quietly connect to corporate data. - **Safe AI guardrails** - establish bulletproof data-access boundaries and clean up permissions _before_ rolling out enterprise AI, so every [agent](/en/docs/screens/agents) operates only within authorized limits. ## 5. Instant Ecosystem-Wide Remediation > _How do we immediately fix the vulnerabilities we just found?_ - **From dashboards to control** - move past read-only. Safely revoke, grant, or update permissions - from a tenant-wide oversharing fix down to [removing one user's access to a single file](/en/docs/screens/files) - across the entire Microsoft 365 ecosystem, right from the 1Security interface. - **Strict opt-in write model** - the platform runs read-only until you deliberately enable remediation, so granting write access is a controlled decision, never a leap of faith. ## 6. The Measurement & Benchmarking Engine > _Are we getting better or worse - and how do we know?_ Management asks for numbers. Security teams deliver narratives. 1Security closes that gap with measured, trended, benchmarkable intelligence - the kind C-level needs for board reporting, budget decisions, and risk-posture tracking. - **Usage & adoption tracking** - who is actually using Copilot, which agents are active vs abandoned, which sites are thriving vs going quiet. Real adoption numbers, not survey guesses. See [Activities](/en/docs/screens/activities). - **Cost intelligence** - license-utilization rates, dormant-app spend, orphaned-site storage costs. Every dollar of Microsoft 365 spend, accounted for and ranked by waste. - **Risk posture over time** - is your exposure shrinking or growing? Track permission-creep trends, oversharing velocity, and sensitive-data exposure as they evolve - not as a point-in-time snapshot, but as a direction. - **Time-to-detect and time-to-remediate** - measure how quickly your team catches and closes risks. Sub-hour detection windows for active threats, same-session remediation for found exposures. - **Board-ready benchmarks** - ranked, sparklined, and exportable. _Top downloaders this week. Unused apps this quarter. Most-shared files this month._ The numbers that matter, always current, always shareable. ## Built to be affordable All of this runs on **standard Microsoft 365 licenses**. [Sensitivity scanning](/en/docs/sensitivity) doesn't need E5 or Purview. [Location intelligence](/en/docs/location) doesn't need premium sign-in logs. Three-year retention doesn't need a SIEM contract. The pattern is deliberate: elite visibility priced like a utility, not like a data lake. Ready to see it on your own tenant? Start with the [installation guide](/en/docs/installation) - first scan results arrive the same day. If NIS2 is on your desk, jump to [NIS2 Readiness](/en/docs/nis2). ================================================================= ## SIEM Integration URL: https://1security.ai/en/docs/guides/siem-integration ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/guides/siem-integration.mdx'] ================================================================= ## API Reference URL: https://1security.ai/en/docs/reference/api ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/reference/api.mdx'] ================================================================= ## Configuration URL: https://1security.ai/en/docs/reference/configuration ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/reference/configuration.mdx'] ================================================================= ## Activities URL: https://1security.ai/en/docs/screens/activities ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/activities.mdx'] ================================================================= ## Activity Logs URL: https://1security.ai/en/docs/screens/activity-logs ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/activity-logs.mdx'] ================================================================= ## Agents URL: https://1security.ai/en/docs/screens/agents ================================================================= Microsoft spreads AI agents across separate admin portals - Copilot, Azure AI Foundry, and Entra - each with its own model, tags, and APIs. The **Agents** screen unifies all of them into one governed list, with the same access-insight lens 1Security applies to users, apps, and files. ## One screen for every agent The Agents screen covers the three overlapping agent ecosystems Microsoft exposes: - **Microsoft Copilot agents** - declarative agents built in Copilot Studio / Agent Builder (e.g. a SharePoint policy finder, a Teams message extension). - **Entra Agent ID agents** - autonomous backend agents with their own Entra identity (Copilot Studio, Azure AI Foundry). - **Third-party agents** - SaaS apps that use Copilot behind the scenes (e.g. Decisions, Adobe). Instead of three consoles, you get one list - and, where the same agent shows up in more than one place, a **single unified record** that joins its Copilot chat presence to its Entra API permission grants. ## Unified access insights Every agent is broken down by what it can actually reach - the same model 1Security applies to identities and apps: - **Files, sites, users, and emails** the agent can access - **Sensitive data** exposed through that access - down to the specific sensitive information types within reach - **Activity** - what the agent actually did, drawn from the same audit-log pipeline as users and apps, with per-action breakdowns: created, modified, deleted, moved, shared, downloaded - **Knowledge / data sources** it reads from - SharePoint, OneDrive, Teams, email, Graph connectors, Dataverse, the web - resolved to what's actually inside them, so you can review the content an agent learns from - **Permissions** - every atomic permission with its source (direct, inherited from a blueprint, or declared) and Microsoft's "blocked for agents" flag The value is the stitching: signals from **Copilot, Azure, and Entra** become one agent record, so you can govern an agent's behaviour and its real data access in one place - without hopping between portals. ## Working with Microsoft's agent stack, not against it Everything above is read natively from Microsoft's own surfaces - Copilot, Entra, and Azure - so this inventory always agrees with the portals your admins already use. 1Security doesn't replace the agent platforms; it adds the governance layer they don't have: - **Access, quantified.** Copilot Studio shows an agent's configuration; 1Security shows the blast radius - how many files, sites, users, and emails it can actually reach. - **Sensitive data, before it leaks.** Access is one thing; what enterprises actually fear is an agent surfacing regulated data to whoever asks it a question. 1Security lists the exact sensitive information types within each agent's reach - payment cards, health records, credentials - so you know which agent could leak what, and can block that access before an employee's innocent prompt (or an injected one) turns reach into disclosure. - **Activity, attributed.** Agent actions land in the same activity stream as users and apps, with per-action breakdowns - so "what has this agent deleted, moved, or downloaded?" is a filter, not a log-parsing project. - **Knowledge sources, opened up.** In the agent platforms a knowledge source is a pointer; 1Security resolves it to the content behind it, so you can review what an agent would learn _before_ employees start chatting with it. Licensing is the one place agents differ from the rest of 1Security: everywhere else Business Basic is enough, but Microsoft gates the Copilot agent catalog behind **Agent 365** - a single license on the admin account that connects 1Security unlocks it (details below). Entra-backend agents need nothing extra. ## Licensing: what you can see Agent visibility depends on the tenant's Microsoft licensing. This is a Microsoft API limitation, not a 1Security one. 1Security **always** scans the Entra backend. A license only gates the Microsoft **Copilot Package catalog** - the API where lightweight Copilot agents live. | Agent type | Visible without Agent 365 | Needs Agent 365 | | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :-----------------------: | :-------------: | | **Entra Agent ID agents** - everything Microsoft registers as an agent identity, including agents built in Azure AI Foundry and Copilot Studio, plus the earlier generation of both, which exist as ordinary service principals carrying Microsoft's agent tags (`AgenticInstance`, `AgentCreatedBy:CopilotStudio`, `power-virtual-agents-*`) | ✅ | | | **Declarative Copilot agents** - SharePoint policy finders, Teams extensions, and third-party wrappers like Decisions / Adobe (no Entra footprint; they live only in the Copilot Package catalog) | | ✅ | Without the license, declarative Copilot agents either don't surface or look like ordinary enterprise apps - 1Security can't tell they're agents. This affects **both third-party wrappers and first-party declarative Copilot agents**, not just third-party apps. ## Licensing: what you need to buy You do **not** need the $99 Microsoft 365 E7 bundle. The product that unlocks the catalog is **Agent 365**. - **E7 ("Frontier" suite)** just bundles E5 + Microsoft 365 Copilot + the Entra Suite + Agent 365. It's the expensive way in. - **Agent 365** is available **standalone at ~$15/user per month** and can be added on top of an existing E3 or E5 - this is all the API actually checks for. **You only need ONE license.** 1Security reads the catalog with a **delegated** admin token, so Microsoft validates the license of the single admin who connected it - not every user. License that one admin account and the entire tenant's Copilot agent catalog unlocks. **For testing:** assign one standalone **$15 Agent 365** license to the admin account you use to connect 1Security. ## Connecting & graceful degradation To scan Copilot agents, an admin connects a delegated token once (see the **Connecting Tenants** guide). Until that's done - or if the tenant has no Agent 365 - 1Security: - still scans and governs every **Entra** agent, - shows a banner on the Agents screen explaining that Copilot agents need Agent 365, - never fails the tenant scan over a missing license. ### Talking to customers A customer worried about Copilot security already owns Microsoft 365 Copilot - and Microsoft requires **Agent 365** to govern the agents they build with it using native tools, so most target customers already have it. If they don't, 1Security states the limit plainly: > We can only scan your Entra backend. License your admin with Agent 365 to also scan your Copilot chat agents. ================================================================= ## Anomalies URL: https://1security.ai/en/docs/screens/anomalies ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/anomalies.mdx'] ================================================================= ## Apps URL: https://1security.ai/en/docs/screens/apps ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/apps.mdx'] ================================================================= ## Automations URL: https://1security.ai/en/docs/screens/automations ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/automations.mdx'] ================================================================= ## Devices URL: https://1security.ai/en/docs/screens/devices ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/devices.mdx'] ================================================================= ## Emails URL: https://1security.ai/en/docs/screens/email ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/email.mdx'] ================================================================= ## Files URL: https://1security.ai/en/docs/screens/files ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/files.mdx'] ================================================================= ## Groups URL: https://1security.ai/en/docs/screens/groups ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/groups.mdx'] ================================================================= ## Licenses URL: https://1security.ai/en/docs/screens/licenses ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/licenses.mdx'] ================================================================= ## Sensitive Info URL: https://1security.ai/en/docs/screens/sensitive-info ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/sensitive-info.mdx'] ================================================================= ## Sensitivity Labels URL: https://1security.ai/en/docs/screens/sensitivity-labels ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/sensitivity-labels.mdx'] ================================================================= ## Sites URL: https://1security.ai/en/docs/screens/sites ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/sites.mdx'] ================================================================= ## Trends URL: https://1security.ai/en/docs/screens/trends ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/trends.mdx'] ================================================================= ## Users URL: https://1security.ai/en/docs/screens/users ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/screens/users.mdx'] ================================================================= ## July 2026 Platform Update URL: https://1security.ai/en/docs/updates/2026-07 ================================================================= [Error reading content for this section: ENOENT: no such file or directory, open 'content/docs/en/updates/2026-07.mdx']