Discover
apps • identities • risksBaseline identities and apps, external users, and current Conditional Access posture. Agree quick wins.
Output: findings + success criteria.
Identity done right: Conditional Access, MFA (including passwordless), role design and lifecycle — so access is least-privilege and effortless.
Baseline identities and apps, external users, and current Conditional Access posture. Agree quick wins.
Output: findings + success criteria.
Design Conditional Access baselines/exceptions, MFA/passwordless, PIM elevation and lifecycle (join–move–leave).
Output: rollout rings + test plan.
Pilot CA/MFA, configure SSO for priority apps, tighten guest governance, and document changes.
Output: pilot sign‑off + dashboards.
Move to enforce, publish runbooks and break‑glass checks, and handover with owners and review dates.
Output: go‑live checklist + next steps.
We start in report-only, add monitored break-glass, pilot with IT and champions, then enforce by group — with clear rollback steps.
PIM for approval-based, time-bound elevation; separation of duties; activity logs and alerts. Standing Global Admins are removed or minimised.
We inventory apps, onboard to Entra ID (gallery/custom SAML/OAuth), and apply per-app CA policies with exceptions that expire.
Standard invite policies with justification, automatic expiry for inactive guests, periodic access reviews, and clear owners per workspace.
Sign-in and user risk signals to challenge or block; legacy auth blocked; device compliance (via Intune) required for sensitive apps.
Quick identity scan: CA/MFA baselines, risky sign-ins, admin roles and guest governance — with a 30/60/90-day plan. No obligation.
Start my health check