Files
Answer the question every access review stalls on - who has access to our files, and why - for every user, link, app, and AI agent across Microsoft 365.
Files
The Files screen answers the question most organizations can't: "Who has access to our files - and why?" Not who should have access according to the org chart - who actually does, right now: which people, which sharing links, which apps, which AI agents, across every SharePoint site and OneDrive in the tenant. Microsoft scatters that answer across thousands of permission dialogs. 1Security assembles it into one filterable map - and the map works at every altitude: start from the tenant-wide picture of oversharing, then drill until you can say exactly why one specific user, or one specific AI, can open one specific file.
What You Can Achieve
Map any file's real access in seconds
Every user with access, how they got it, whether they're internal or external, which groups and links are involved, and which apps can read it - no PowerShell, no clicking through site permissions one by one.
Expose shadow access paths
'Anyone with the link' URLs created years ago, edit links with no password and no expiration, links nobody remembers granting. The routes to your data that a directory-based access review never sees.
Verify protection coverage
Cross sensitivity detections with Purview labels to list the files that contain credit card or health data but carry no label and no encryption - your real coverage gap, measured instead of assumed.
Fix what you find, in place
Select files, review everyone and everything with access, and revoke the grants you don't want - applied to Microsoft 365 directly, under a strict opt-in write model.
Exposure, Classified
1Security classifies every file by the paths that lead to it, so you filter by risk instead of reading permission dialogs one at a time:
- Shared with anyone - an anonymous link exists; the file is effectively public to whoever holds the URL.
- Shared with the organization - every employee can open it. This is how an "internal" payroll spreadsheet ends up in enterprise search results and Copilot answers.
- External users - named guests from outside your tenant hold access.
- SharePoint-only guests - external identities that live only in SharePoint and never appear in an Entra ID guest review.
- Apps with access - third-party applications and AI agents that can read the file.
Sensitivity comes from two engines - Microsoft Purview detections and 1Security's own content scan (300+ pattern detectors plus OCR for images), each detection carrying a confidence level. See Sensitivity Scanning.
The File List
Columns are grouped around the questions investigators actually ask:
- Exposure - users with access (and specifically with edit access), groups with access, external-sharing flags, sharing links, and the users reaching the file through those links.
- Sensitivity - detected sensitive information and how much of it, applied sensitivity labels, and whether real protection such as encryption is in force.
- Email trail - how many times the file was uploaded or linked in email and when it last left through one. A download is not the only way data leaves.
- Lifecycle - who created and last modified it and when, size, location, and an activity sparkline that makes a suddenly-busy dormant file jump out.
Click any file to open its detail drawer for the full permission breakdown - then act on it without switching tools.
The filter drawer goes deeper than any native admin view: link scope (anyone / specific users / organization), link type (view / edit / review), links without passwords, links past their expiration date, disabled links, specific sensitive info types, minimum detection counts, file containers (personal OneDrives vs. SharePoint sites), and files accessible to a specific user.
Remediation Built In
Remediation spans the same zoom range as the visibility: fix tenant-wide oversharing or remove one user's access to a single file. Select the files and choose Remove access - 1Security lists every user, group, and sharing link with access to the selection, lets you pick exactly which grants to strip, and pushes the change to Microsoft 365. Run actions triggers your automation workflows on the same selection. Write operations are opt-in by design - the platform runs read-only until you deliberately enable remediation.
Investigative Patterns
Public + sensitive + permanent: filter Shared with anyone + with sensitive info + links without expiration. This is your genuine "already exposed" list - most teams find in minutes what manual audits missed for years.
- Offboarding sweep - filter Files accessible to user for a departing employee or contractor and see everything they can still open, including access inherited through groups and links.
- Purview gap audit - with sensitive info + without label: the exact files where your classification policy exists on paper but not on the data.
- Link hygiene - links without password or past expiration on files with sensitivity detections; tighten or remove them straight from the selection.
Users
Every identity in the tenant - employees, guests, and the accounts nobody has signed into for a year - with what each one can reach, what it did, and whether it should still exist.
Sites
See every place your data actually lives - every SharePoint site, Teams site, and personal OneDrive - and find the ones that are abandoned, wide open, or feeding your AI.