1Security + CyberArk
CyberArk secures the accounts that run your systems. 1Security shows what every account can open in Microsoft 365.
Vaulted credentials, isolated and recorded sessions, just-in-time privilege: CyberArk is how the powerful accounts stay safe. The other 99% of access in a Microsoft 365 tenant is ordinary - sharing links, group memberships, app consents - and an ordinary account can open 200,000 files. 1Security resolves that access for every identity, human or not, keeps three years of what it did, and stages the cleanup behind a review window. Together you see both kinds of access in one place.
- 200,000files an ordinary Microsoft 365 account can typically open
- 3 yearsof activity history behind every identity
- 10 minfrom "this account is compromised" to its full blast radius
What CyberArk does
Privileged access, handled properly.
Privileged access is where a single mistake becomes an incident, and CyberArk treats it with the seriousness it deserves.
Credentials vaulted and rotated
Admin, service and root credentials live in the vault, get rotated automatically and are checked out under policy. The password an attacker most wants is not sitting in a spreadsheet, and it has probably already changed.
Sessions isolated and recorded
Sensitive sessions across infrastructure and SaaS run through a broker, isolated from the endpoint and recorded end to end, with anomalous commands flagged as they happen. When an auditor asks what the admin did, there is a recording.
Privilege only when it is needed
Standing admin rights are replaced with just-in-time entitlements that are created for a task and removed when it ends, across cloud platforms and Kubernetes. Fewer permanent keys means fewer keys to steal.
The rest of the picture
Most access in Microsoft 365 is not privileged. It still opens the data.
CyberArk is built for accounts that are rare, powerful and worth ceremony. Everyday access in Microsoft 365 is the opposite shape: sharing links created with a click, group memberships that quietly inherit whole sites, OAuth consents granted on a Tuesday, guests who stay for years. Millions of small permissions held by ordinary accounts, none of them a candidate for a vault.
That is where breaches actually travel. A phished sales account holds no privilege, but in a typical tenant it can open tens or hundreds of thousands of files through the groups it belongs to and the links it was sent. Nobody has a list of those files. Nobody reviews the memberships that produced them.
1Security is built for exactly this layer: what every identity can open, how it got that access, and what it did with it. It does not compete with the vault; it answers the question the vault was never asked.
What 1Security adds
Every identity, what it can open, and what it did.
1Security connects to your Microsoft 365 tenant read-only and builds the access picture CyberArk sits on top of.
- 01
Resolve what each identity can open
Users, guests, apps, AI agents and devices, each with the files, sites and mailboxes it can reach through direct grants, sharing links, nested groups and inheritance. Open Users, sort by files reachable, and the top of the list is where a stolen password would hurt most.
- 02
Answer the blast-radius question in minutes
When CyberArk flags a suspicious privileged session, or a phishing report names an ordinary account, one screen shows everything that identity could reach and everything it touched - which files, from which device, from where. Ten minutes instead of a day of exports.
- 03
Keep three years of what happened
Every action is attributed to a user, file, device and location and kept for up to three years on standard Microsoft 365 licenses. Each identity has its own activity baseline, so 340 downloads on a normal-is-12 account shows up as an anomaly, not as a row.
- 04
Trim the excess behind a review window
Expire anyone links, remove idle guests, revoke unused app consents, disable dormant accounts - each staged as a proposal with a 72-hour review window by default, owner review available, every executed action logged. Nothing irreversible happens without a person deciding.
How the two fit together
CyberArk protects the keys. 1Security shows the rooms every key opens.
CyberArk keeps doing what it does today: vaulting credentials, brokering and recording privileged sessions, issuing privilege just in time. 1Security connects to the Microsoft 365 tenant with read-only consent - no agents, standard licenses, first findings the same day - and resolves everyday access for every identity: every grant, every link, every membership, every action, three years back. Neither product changes how the other works. Together they cover the accounts that run the systems and the accounts that read the data.
NIS2 in practice
Access control you can show an auditor.
NIS2 Article 21(2)(i) requires essential and important entities to run access control and asset management as part of their risk measures, and Article 23 gives them 24 hours to file an early warning once a significant incident is detected.
CyberArk evidences the privileged half: who could use the powerful accounts, when, under which policy, with rotation logs and session recordings as proof. 1Security evidences the everyday half: which identities could reach which data across Microsoft 365, which of that access was ever used, and what was cleaned up, with the review trail attached.
When the 24-hour clock starts, the first question is scope. A blast-radius answer in ten minutes is the difference between an early warning written with facts and one written with adjectives.
See both kinds of access in one place.
Keep CyberArk on the privileged accounts. Connect 1Security read-only and see, the same day, what every ordinary account in your tenant can open.
Or keep guessing what a phished account could reach.