SECURITY · IDENTITY & ZERO TRUST

Risky admin accounts, older sign-in methods, and MFA gaps are open in Microsoft Entra ID right now. Close them with a tested Zero Trust access model.

A fixed-fee sprint that rebuilds Conditional Access as tested, version-controlled policy, retires legacy authentication, and rolls out phishing-resistant MFA, so every access decision is enforced and auditable.

Fixed priceCoverage matrix you keepTested rollbackAuditable

The deliverable

Identity Attack Surface Map, on your desk

A representative deliverable. Yours is built on your own environment, with names and figures redacted here.

This is for you if

Built for the Owner, IT Director, or CISO.

  • Nobody can say which sign-in rules are in force today, or who is excluded from them.
  • Legacy authentication is still open and MFA exceptions will not satisfy insurers.
  • An account was compromised, or an audit flagged the gaps, and it has to be fixed now.

What you receive

Identity Attack Surface Map

Which accounts keep admin powers switched on all the time, and where older sign-in methods still bypass your rules, mapped before anything changes.

CA Coverage Matrix

Conditional Access mapped across personas and conditions, with the gaps closed.

Tested, version-controlled policy

The rules kept in version control, released to a pilot group first, with a documented way to put them back.

Typical timeline

1-2 weeks

Included

  • Conditional Access rebuilt and released to a pilot group first
  • Older sign-in methods switched off
  • Phishing-resistant MFA rollout
  • Tested rollback and documentation

Assumptions

  • One Microsoft Entra ID tenant
  • Agreed policy scope before changes

Not included

  • Redesigning applications that still depend on older sign-in methods
  • Privileged access program redesign

Scoped separately here: Fix & improve.

Required access

  • Entra ID admin access
  • A pilot group for staged rollout
  • A 30-minute kickoff with security or IT

Engagement complete when

The engagement is complete when the attack surface map, CA coverage matrix, and tested policy are delivered and live.

Get an access model you can show an auditor, with a tested way back if something breaks.

One fixed fee, agreed in writing before any access is granted. The timeline above is the whole engagement, and what you keep is documentation your team can act on. One senior engineer scopes and delivers it.

The fee depends on what is actually in your environment rather than your headcount. The scope-fit check tells you where you land →