Can the business prove who can sign in, who can administer it, and how that access is controlled?
Stop weak sign-in, standing admin rights, and unclear access ownership.
Accounts & Access
Authentication grew one exception at a time: some users on app prompts, some on codes, a few on nothing. Administrators hold permanent rights because removing them felt risky, emergency access was never set up, and Microsoft is retiring its own SMS and voice code delivery, which some staff still depend on.
What gets delivered
The sign-in methods, admin roles and policy set are put into one enforced, tested state: approved methods rolled out group by group, standing admin rights reduced to eligible assignments, emergency access created and tested, and every exception recorded with an owner.
What made you look today?
Common reasons this becomes urgent
Microsoft retires its own SMS and voice code delivery on February 1, 2027
Affected users are identified, approved methods are configured and piloted, adoption is measured, and exceptions are recorded before the deadline forces the change mid-quarter.
An insurer, auditor, or client questionnaire asks how access is controlled
The answers are verified against the tenant, the agreed identity controls are implemented and tested, and the evidence is assembled in the form the questionnaire asks for.
Administrators hold permanent roles nobody remembers granting
Standing roles are reduced, eligible assignments are configured, emergency access is created and tested, and the role register is handed over.
How the work runs
The current sign-in methods, admin roles, policies and exceptions are inventoried, and the target enforcement state is agreed as a fixed scope. Then: Enforcement is staged with a pilot group first, exceptions are recorded with owners, and the tested state is documented and handed over.
Where this is priced
Each engagement below carries its own fixed scope. The price is agreed before any work begins, and the fixed proposal contains the delivery calendar and the completion date.
Implementation engagements
Bounded production work with a completion test.
Microsoft 365 Passkey Migration Sprint
The users still on SMS or voice are identified, the authentication method policy is configured, a pilot ring completes registration, adoption is measured against the affected population, and every exception is recorded with an owner.
MFA and Conditional Access Hardening
Authentication methods, administrator roles, emergency access, and a bounded Conditional Access policy set are configured, piloted, enforced, and tested.
Also delivered in this area, as custom projects
Work in this list is deliberately not packaged: the scope varies too much for one honest price. The route, the risks, the completion test and the fixed price are agreed before anything begins.
- Privileged Admin & PIM Hardening
- Cyber-Insurance Identity Control Closure
- Entra Connect & Hybrid Identity Stabilization
- Guest & Application Access Cleanup
- Scheduled Microsoft 365 Access Investigation
Related guides
Microsoft Is Retiring SMS and Voice MFA: Who Breaks on February 1, 2027 and How to Check Your Tenant
10 Min Read
PIM Eligible vs Active: Can You Still Assign Permanent Admin Roles in Microsoft 365?
10 Min Read
Per-User MFA vs Security Defaults vs Conditional Access: Which Microsoft MFA Should You Use?
9 Min Read
The finished state
What is true when it is done
Every account signs in through an approved method, admin rights are held only while they are being used, emergency access exists and alerts when touched, and the exception list has named owners.
What you keep
Everything below is yours to keep whatever happens next, including handing it to your own team or another vendor.
- The authentication method inventory, before and after
- The Conditional Access policy register with the reason each policy exists
- The admin role register and the eligible-assignment configuration
- The tested emergency-access procedure
- The exception list, each with an owner and a review date
For the full commercial shape of work in this area — scope, price treatment, definition of done — see a representative engagement: MFA & Conditional Access Hardening.
What moves the price
The fee is set by what is actually in the environment; headcount is only one of the inputs.
- User and administrator population
- Number of existing Conditional Access policies to reconcile
- Applications authenticating through Microsoft 365
- Hybrid identity and federation in the sign-in path
- Named-user exceptions to carry
Describe what happened
A reply comes within one business day with the most direct next step, or a clear answer that AZ Innovations is not the right fit.
Talk Through the Problem →