1Security + SailPoint

SailPoint decides who should have access. 1Security shows what that access opens.

SailPoint Identity Security Cloud governs identities across every system you connect: entitlements shaped into roles, lifecycle states that provision and deprovision on their own, campaigns that keep certifying. 1Security adds the layer underneath one of those systems: the files, sites and mailboxes a Microsoft 365 entitlement really opens - often 40,000 files through nesting and inheritance - and whether anyone used them in the last three years. Reviewers certify with the numbers in front of them.

  • 40,000
    files one group membership can open in a typical tenant
  • 3 years
    of activity history next to every entitlement
  • 10 min
    to answer what an account can reach, and what it touched

What SailPoint does

Identity governance across every source, in one model.

One platform to manage and govern identities and their access, across every system you connect.

  • Governance across every source

    Connectors aggregate account data from the systems you run into one governed model - entitlements, access profiles and roles - so least privilege is decided in one place, for everything at once.

  • A lifecycle that runs itself

    Lifecycle states drive provisioning as people join, move and leave; access requests route through approvals; separation-of-duties policies catch conflicting access before it lands, and handle the violation rather than just flagging it.

  • Certification with intelligence

    Manager and source-owner campaigns put every access decision back in front of a human on schedule, and Identity Outliers and Access Intelligence point the reviewer at the identities that deserve the closest look.

The question this pairing answers

An entitlement says who holds access. The reviewer needs to know what it opens.

SailPoint works at the entitlement: a group membership, a role, a site permission, aggregated from Microsoft 365 and put in front of a reviewer on schedule. That is the right unit for governing hundreds of systems with one set of decisions.

Inside Microsoft 365, one entitlement has an interior. A group membership opens sites through nesting, sharing links reach files no role mentions, and inheritance carries a site permission down to every document library. In a typical tenant one membership opens 40,000 files, and an ordinary account can reach more than 200,000. Whether any of it was used - from which device, from where, how often - is a second question the entitlement alone does not answer.

1Security answers both. It resolves what every identity can reach through direct grants, links, groups and inheritance, keeps up to three years of attributed activity, and puts the numbers next to the entitlement SailPoint is certifying. The decision stays in SailPoint. The evidence comes from the tenant.

What 1Security adds

Three things a certification gets from the tenant itself.

1Security connects read-only to Microsoft 365, builds the permission graph and the activity history, and keeps both live for every identity SailPoint governs.

  1. 01

    The reach behind every entitlement

    Every file, site and mailbox an account can open - direct grants, sharing links, groups, inheritance - resolved in minutes. The line item a reviewer certifies becomes a count: 3 sites, 40,000 files, 2 shared mailboxes, 3,100 files with personal data.

  2. 02

    Usage evidence for every decision

    Up to three years of activity history on standard Microsoft 365 licenses, and a baseline for every identity. "Keep or revoke" stops being a memory test: the reviewer sees when the access was last used, from which device and where, and whether the account behaves like it always did.

  3. 03

    A fix that waits for a human

    When a review ends in a revoke, the change happens in 1Security behind a review window - remove the access, expire the links, revoke the sessions - staged per resource, 72 hours by default, and logged with who approved it. Nothing irreversible runs on an automation alone.

How the two fit

SailPoint decides. 1Security supplies the evidence.

SailPoint stays the system of record for identity governance: lifecycle, requests, certifications, separation of duties, across every source you connect. 1Security connects to your Microsoft 365 tenant with read-only consent - no agents, standard licenses, first findings the same day - and maintains what an entitlement export cannot: the resolved permission graph, per-identity usage and three years of attributed history. When a campaign puts a Microsoft 365 entitlement in front of a reviewer, 1Security shows what it opens and whether it was used; when the decision is revoke, the change runs behind a review window and lands in a log the auditor can read.

Together in practice

DORA asks whether access is limited to what is needed. Answer with a count.

DORA - Regulation (EU) 2022/2554 - requires financial entities to limit access to ICT assets to what legitimate, approved functions actually need, under Article 9(4)(c), and to keep proving that the limits hold.

SailPoint covers the decision side: access granted through roles and approvals, re-checked in certification campaigns, conflicting combinations blocked by separation-of-duties policy. 1Security covers the evidence side: what each Microsoft 365 entitlement really opens, which of those permissions were used in the last year, and the reviewed, reversible cleanup that trims the rest.

When the supervisor asks whether access is limited to what is required, the answer is a report with numbers in it - entitlements certified, files in reach before and after, permissions unused for a year and removed - not a project to find out.

Put the numbers next to every SailPoint certification.

Connect 1Security read-only and your next campaign shows what each Microsoft 365 entitlement opens and whether it was used - the same day.

Or keep asking reviewers to certify what they cannot see.