Security & Identity · Access management
Identity & Entra ID
Conditional access, phishing-resistant authentication, and privileged access designed to be defensible.
Identity is where the overwhelming majority of business compromises begin. It is also the control layer with the best return on effort — a well-designed conditional access policy set prevents more harm than most tooling purchases.
We design policy that holds up under scrutiny: enforced, exception-managed, and documented well enough that someone else could maintain it.
Outcomes
- Multi-factor enforced without breaking legitimate workflows
- Legacy authentication disabled and verified
- Administrative access time-bound rather than standing
- Access reviews running on a defined cadence
Capabilities
How we approach it
Conditional access design
A policy set built from a documented model — personas, locations, device state, and risk — rather than accumulated one-off rules nobody can safely change.
Phishing-resistant authentication
Moving from SMS and app-notification MFA toward passkeys and certificate-based authentication for the accounts that warrant it. Not all MFA is equivalent.
Privileged access
Just-in-time elevation, approval workflows, and separation of administrative accounts from daily-use identities. Standing global administrator access is the single most common serious finding we make.
Lifecycle and access reviews
Joiner, mover, and leaver processes with periodic attestation, so access granted for a project three years ago does not quietly persist.
Deliverables
What you receive
Written, handed over, and yours permanently — whether or not the engagement continues.
- 01Conditional access design document with a persona model
- 02Break-glass account procedure, tested
- 03Privileged access model with role assignments
- 04Access review schedule and attestation process
FAQ
Common questions
Is multi-factor authentication enough on its own?
It is the single highest-value control, but not sufficient alone. Adversary-in-the-middle phishing defeats app-notification MFA routinely, which is why phishing-resistant methods matter for privileged accounts.
How do we avoid locking ourselves out?
Break-glass accounts excluded from conditional access, stored securely, monitored for use, and tested before enforcement. Every conditional access rollout we run includes this first.
Do we need Entra ID P2?
P2 adds identity protection, privileged identity management, and access reviews. Licensing it for administrators and executives while the wider organization sits on P1 is often the pragmatic answer.
Related services
Talk to us about Identity & Entra ID.
Tell us what you run today and what is prompting the change. We come back with a written recommendation and a scoped quotation.