Meet Wiz for M365: Bringing SaaS into the Security Graph

Secure Microsoft 365 and the cloud it powers — one platform, one graph, complete context.

Microsoft 365 powers how many modern businesses collaborate, but it also connects deeply into the cloud environments that run those businesses. 

Today, we’re excited to announce that : Wiz for Microsoft 365 is now Generally Available (GA).

With GA, we’re extending the Wiz platform to Microsoft 365, bringing it into the Security Graph to provide unified visibility, context, and risk prioritization. Instead of viewing M365 in isolation, teams can now understand how configurations, access, and data exposures connect to real risk across their broader cloud environment, and take action to reduce it.. 

See risk in context — from SaaS to cloud

The first step is visibility that makes sense. Wiz surfaces Microsoft 365 posture and data risks directly in context — showing how a simple SaaS issue can open a real attack path in your cloud.

You’ll be able to answer questions like:

  • Which OneDrive or SharePoint sites contain sensitive data or secrets, and who can access them?

  • Are any of those resources shared externally or overexposed?

  • Which Microsoft 365 misconfigurations could expose connected cloud resources, and how do these issues connect to my workloads, identities, or AI pipelines?

  • Are data protection policies and sensitivity labels correctly applied and enforced?

  • What AI applications exist in my environment, what do they connect to, and what risk do they introduce?

  • What risks are introduced by AI Agents managed in Copilot Studio?

M365 Posture issue : High-Risk Data with Anonymous Access links
Risk issue highlighting an attack path

Inside Wiz for Microsoft 365

Wiz brings the same visibility and context that define its cloud security approach directly to Microsoft 365 — spanning posture, data, and access. Each capability below includes a visual example of how insights appear in the Wiz platform.

Posture & Access

Identify misconfigurations and access risks across your Microsoft 365 environment, aligned to CIS benchmarks, and understand how they contribute to broader cloud exposure.

  • Identify and remediate misconfigurations across Microsoft 365, including Exchange Online, SharePoint, OneDrive, and more

  • Continuously assess configurations against CIS Microsoft 365 benchmarks to maintain a secure baseline

  • Analyze identity risks through Microsoft Entra, including privileged roles and over-permissioned users

  • Understand access and sharing risks across SharePoint and OneDrive, including external and anonymous access to sensitive data

Data Security and Classification (DSPM)

Discover and classify sensitive data and secrets across Microsoft 365, and understand how it is exposed in the context of your broader cloud environment.

  • Scan SharePoint and OneDrive to discover sensitive data, including PII, PCI, PHI, and business-critical data

  • Detect and surface secrets and credentials embedded in files that could grant access to cloud infrastructure

  • Classify data using Wiz’s AI-powered classification engine to accurately identify sensitive content tailored to your business

  • Incorporate Microsoft Purview sensitivity labels to enhance visibility into data classification

  • Understand how data exposure connects to identities, permissions, and infrastructure to surface real risk

  • Apply AI driven classification methods to identify ‘sensitive’ data tailored to your business.

Secret exposure mapped on Security Graph

AI Applications ( Available in Preview)

Microsoft 365 is increasingly connected to AI applications, introducing new paths for risk.

Wiz provides early visibility into AI applications built with Microsoft Copilot Studio , helping teams understand how these applications connect across data, identities, and infrastructure.

  • Identify AI applications and what they connect to across your environment

  • Detect risks from misconfiguration, overexposure, and lack of guardrails

  • Understand how AI usage contributes to broader cloud risk

Support for Copilot Studio is available in private preview today, with broader AI application coverage continuing to expand as part of Wiz’s end-to-end approach to securing AI.

To learn more, see our AI application Protection Platform Blog.

Issue : Published AI agent can be accessed by unauthenticated users and uses a tool with high privileges

Remediation & Microsoft Purview

With GA, Wiz extends beyond visibility to help teams take action and enforce data protection at scale.

  • Take remediation actions directly within Wiz, with a range of options to reduce exposure across M365

  • Apply and validate sensitivity labels through Microsoft Purview

  • Strengthen data governance by incorporating and updating Purview classifications

Wiz integrates with Microsoft Purview to both incorporate existing labels and apply updates, helping ensure data is consistently classified, protected, and governed.

Sample remediation flow with labels

Turning visibility into actionable insights

Each Microsoft 365 finding in Wiz becomes more than just an alert — it’s a context-rich insight tied to real risk and impact.

Because M365 data, identities, and misconfigurations are part of the Wiz Security Graph, each can connect to issues across your broader cloud environment. For example:

  • A SharePoint site exposing regulated data linked to an Azure workload

  • A OneDrive folder containing secrets shared externally

  • A user identity with risky permissions spanning both M365 and cloud resources

These connections reveal the attack paths that matter most. By visualizing them in a single graph, security teams can prioritize faster, focus on the right fixes, and take action directly within Wiz.

With a range of remediation options — from native actions like applying and validating Microsoft Purview labels to guided fixes and integrations with existing workflows — teams can operationalize every Microsoft 365 finding.

This ensures risks move from insight to resolution, accelerating response while maintaining context across SaaS and cloud environments.

What’s next

With Microsoft 365 now part of the Wiz platform, teams can extend the same context-driven approach used for cloud security to this critical surface.

We will continue expanding coverage across Microsoft 365, including threat detection capabilities, deeper data insights, and broader support across the Microsoft ecosystem.

Our vision remains the same: one platform, one Security Graph, securing everything from code to cloud to SaaS — giving you the full context needed to understand and reduce risk with confidence.

Schedule a demo

Continuar leyendo

Obtén una demostración personalizada

¿Listo para ver a Wiz en acción?

"La mejor experiencia de usuario que he visto en mi vida, proporciona una visibilidad completa de las cargas de trabajo en la nube."
David EstlickCISO
"Wiz proporciona un panel único para ver lo que ocurre en nuestros entornos en la nube."
Adam FletcherJefe de Seguridad
"Sabemos que si Wiz identifica algo como crítico, en realidad lo es."
Greg PoniatowskiJefe de Gestión de Amenazas y Vulnerabilidades