1Security + Entra ID Governance
Entra ID Governance decides who gets access. 1Security shows what that access opens.
Access packages, approvals, access reviews and lifecycle workflows are how a well-run tenant grants and recertifies access. 1Security adds the layer underneath: the files, sites and mailboxes one group membership really opens - often 40,000 files through nesting and inheritance - and whether anyone used them in the last three years. Reviewers approve with the numbers in front of them.
- 40,000files one group membership can open in a typical tenant
- 3 yearsof activity history next to every entitlement
- 10 minto answer what an account can reach, and what it touched
What Entra ID Governance does
Access as a process, not a ticket queue.
Entra ID Governance turns four hard questions into a running process: who should have access, what are they doing with it, are the controls in place, and can an auditor verify them.
Access packages
The groups, Teams, apps and SharePoint sites a role needs, bundled into one package - requested with multi-stage approval, time-limited by policy. Partners come in as B2B guests on approval and leave automatically when the access expires.
Lifecycle workflows
Joiner, mover and leaver events run straight from HR systems such as Workday and SuccessFactors, and provisioning connectors reach hundreds of cloud and on-premises applications. Day-one access on day one, a clean exit on the last day.
Access reviews and PIM
Recurring reviews put group memberships, application access and role assignments in front of the people who can judge them, with recommendations built in. Privileged Identity Management adds just-in-time elevation and alerts on role changes.
The question this pairing answers
A reviewer certifies a membership. What does that membership open?
Governance works at the level of the entitlement: a group, a role, an access package. That is the right level for deciding intent - model the access, route the approval, expire what is not renewed. It is what makes governance repeatable.
Inside Microsoft 365, each entitlement then fans out. One group membership passes through nested groups and site inheritance into thousands of files. Sharing links add access that never went through a package or an approval. So the two questions under every review are: what does this membership actually open, and has any of it been used?
1Security answers both, per file and per action, and puts the answer next to the review: an ordinary account in a typical tenant can open 200,000 files, and reviewers can now see which of those were touched in the last year and which never were.
What 1Security adds
The evidence under every entitlement.
1Security maps every identity in Microsoft 365 - person, guest, app, AI agent, device - to what it can open and what it actually did, and keeps three years of it.
- 01
Entitlements resolved to files
Open the group in Groups: every site, file and mailbox it opens - through direct grants, sharing links, nested groups and inheritance - with the count of people it really contains. The membership on the review stops being a name and becomes a list you can scroll.
- 02
Usage next to the grant
Up to three years of activity per identity on standard licenses, with each account scored against its own baseline. The reviewer sees "opened 30 of these 4,000 files in the last year" before clicking approve, and can trim with confidence.
- 03
Cleanup behind a review window
Remove access, expire links, revoke sessions - staged as per-resource proposals behind a 72-hour window (instant, 24 hours and 7 days also available), owner review optional, every action logged. Nothing irreversible happens without a person deciding.
How the two fit
Governance decides. 1Security supplies the evidence.
Entra ID Governance stays the system that decides, provisions and recertifies access at the entitlement level. 1Security connects to the same tenant read-only, with no agents and on standard Microsoft licenses, and resolves the layer underneath: every identity, everything it can open, three years of what it did. Governance decisions get made on reach and usage instead of on names, and the first findings land the same day you connect.
DORA, together
Least privilege you can demonstrate.
DORA - Regulation (EU) 2022/2554 - asks financial entities to restrict access to ICT assets and data to what legitimate functions actually need, and to keep that restriction demonstrable as part of ICT risk management under Article 9.
Entra ID Governance supplies the control: entitlements modelled as access packages, approvals recorded, access recertified on schedule, privileged roles elevated just in time. 1Security supplies the evidence: what each entitlement effectively opens inside Microsoft 365, which of those permissions were used across three years of activity, and reviewed, reversible automations to trim what was not.
The regulator asks for control and evidence. Together, this pairing gives both.
Put the files under every access review.
Keep Entra ID Governance deciding who should have access. Connect 1Security read-only and see, the same day, what that access really opens and how much of it is used.
Or keep approving memberships by name.