Capability

Identity and access

Identity is the control plane for everything else in the Microsoft stack. Get it wrong and the rest of your controls are decoration.

Nearly every incident we see in a Microsoft estate starts with an account rather than an exploit. A password that was reused somewhere else, an MFA prompt approved by a tired person, a legacy protocol nobody switched off, or an admin role granted permanently three years ago for a project that finished two years ago. Identity is where the effort pays back fastest.

What we assess

  • Conditional Access coverage. Which users, applications and platforms are genuinely covered, and what the accumulated exclusions actually add up to. Almost every tenant has more exclusions than anyone realises.
  • Authentication strength. Which methods are in use, which phishing-resistant options you are licensed for and have not deployed, and whether SMS is still doing real work.
  • Legacy authentication. Whether protocols that bypass modern controls entirely are still permitted, and which accounts are relying on them.
  • Privileged access. Standing administrative rights, role assignment sprawl, whether Privileged Identity Management is deployed or merely licensed, and whether the break-glass accounts have ever been tested.
  • Applications and consent. Third-party applications holding tenant-wide permissions, granted at some point by someone, and never reviewed since.
  • Guest and external access. Who can reach your tenant from outside it, what they can see, and whether anyone reviews that list.

What we do

  • Conditional Access design and rollout, staged and reported so nobody gets locked out on a Friday afternoon
  • Phishing-resistant MFA deployment, including passkeys, Windows Hello for Business and certificate-based authentication
  • Legacy authentication decommissioning, with the awkward service accounts identified and handled properly rather than left as a permanent exemption
  • A privileged access model that holds: role tiering, just-in-time activation, approval workflows and tested break-glass
  • Application consent policy and governance, so the next tenant-wide grant cannot happen silently
  • Guest access review and lifecycle, including the ones who left the partner organisation months ago

Found: Six of nine global administrators held permanent role assignments, and every one of those accounts sat inside a Conditional Access exclusion group created for a migration that finished in 2023.

Fixed: Privileged Identity Management rolled out with just-in-time activation and approval, permanent assignments removed, the stale exclusion group retired, and break-glass accounts documented and added to a quarterly test.

Neither half of this is unusual on its own. Together they meant the most privileged accounts in the tenant were also the least protected, which is the kind of thing you only see by looking at both at once.

The rest of the stack

This does not sit on its own

The findings that matter most usually cross between these areas. We look at all of them, whether or not that is what you asked us to look at.

Want a look at your identity and access?

An assessment can be scoped to this area alone, or to the whole estate. Tell us what is worrying you and we will tell you which is worth paying for.