1Security + One Identity Active Roles

Active Roles creates the account correctly. 1Security shows what that account can open.

One Identity Active Roles runs your Active Directory, Entra ID and Microsoft 365 administration by policy: accounts provisioned right, groups set by rule, admin work delegated without standing privilege, leavers removed on time. Once the account exists, it spends its working life in SharePoint, Exchange and Teams, and in a typical tenant an ordinary account can open 200,000 files. 1Security resolves that reach for every identity, keeps three years of what it did, and stages the cleanup behind a review window.

  • 200,000
    files an ordinary Microsoft 365 account can typically open
  • 10-30%
    of paid licenses typically sit on accounts nobody uses
  • 10 min
    from a provisioned account to everything it can reach

What Active Roles does

Directory administration, done by policy.

One console for Active Directory, Entra ID and Microsoft 365, with a rule behind every change and a record of every operation.

  • One console for the hybrid directory

    Active Directory, Entra ID and Microsoft 365 administered from one place, across domains, tenants and multi-forest environments. Workflow automation keeps every change inside the policy you defined, so a new account looks the same whoever created it.

  • Delegation without standing privilege

    Access Templates hand out exactly the admin rights a role needs and nothing more, and zero standing privilege means those rights are not sitting active around the clock. Help desk resets passwords; it does not hold Domain Admin.

  • A lifecycle that ends cleanly

    Least privilege from day one, dynamic groups that follow attributes, and deprovisioning that finishes the job: memberships removed, objects relocated, deleted for good. Every operation performed or attempted lands in the audit trail.

The rest of the picture

The account is created right. What does it open two years later?

Active Roles gets the moment of change right: the account, the group, the delegated permission, the removal. Between those moments the identity lives inside the workload. It opens files, receives sharing links, joins Teams whose sites inherit whole libraries, and accumulates access that no directory attribute describes. A membership set correctly in 2024 can open 40,000 files in 2026 without anyone touching the account.

That is where the questions come from that a directory alone cannot answer: which of these permissions were ever used, from which device, what a phished account could actually reach, which of the 10-30% of licensed accounts nobody signs into still hold access to sensitive sites.

1Security is built for exactly this layer: what every identity can open in Microsoft 365, how it got that access, what it did with it, and what to clean up. It does not administer the directory. It shows what the directory objects Active Roles manages actually unlock.

What 1Security adds

Every account, what it can open, and what it did.

1Security connects to your Microsoft 365 tenant read-only and builds the access picture behind every account Active Roles provisions.

  1. 01

    Resolve what each account can open

    Every file, site and mailbox an account can reach through direct grants, sharing links, nested groups and inheritance, resolved in minutes. Open Users, sort by files reachable, and the account Active Roles created this morning already shows the 40,000 files its department memberships opened.

  2. 02

    Keep three years of what happened

    Every action attributed to a user, file, device and location, kept for up to three years on standard Microsoft 365 licenses. Each account has its own activity baseline, so 340 downloads on a normal-is-12 account shows up as an anomaly episode, not as a row in an export.

  3. 03

    Trim the excess behind a review window

    Dormant accounts still holding reach, licenses on people who left, guests idle for a year, anyone links on sensitive files: each cleanup is staged as a proposal with a 72-hour review window by default, owner review available, every executed action logged. Nothing irreversible happens without a person deciding.

How the two fit together

Active Roles runs the directory. 1Security shows what the directory unlocks.

Active Roles keeps doing what it does today: provisioning accounts and groups by policy, delegating administration without standing privilege, deprovisioning on time, recording every operation. 1Security connects to the same Microsoft 365 tenant with read-only consent - no agents, standard licenses, first findings the same day - and resolves what each of those accounts and groups can actually open, what it did, three years back, and what should be cleaned up. Neither product changes how the other works. Together you get the account done right and the proof of what it reaches.

NIS2 in practice

Access control policy, and the evidence it works.

NIS2 Article 21(2)(i) lists access control policies among the risk-management measures essential and important entities must have in place, and auditors ask for proof that the policy matches what is happening in the tenant.

Active Roles evidences the policy side: access granted by rule, delegated without standing privilege, removed on schedule, every directory operation on record. 1Security evidences the practice side: what those grants can actually open across Microsoft 365, which of that access was ever used, and what was trimmed, with the review trail attached.

When the auditor asks whether your access control policy matches reality, the answer is a report from both products, not a project.

See what every account you provision can open.

Keep Active Roles running the directory. Connect 1Security read-only and see, the same day, what each account and group actually unlocks in your tenant.

Or keep assuming a well-made account is a well-used one.