SECURITY · IDENTITY & ZERO TRUST
Risky admin accounts, older sign-in methods, and MFA gaps are open in Microsoft Entra ID right now. Close them with a tested Zero Trust access model.
A fixed-fee sprint that rebuilds Conditional Access as tested, version-controlled policy, retires legacy authentication, and rolls out phishing-resistant MFA, so every access decision is enforced and auditable.
The deliverable
Identity Attack Surface Map, on your desk
A representative deliverable. Yours is built on your own environment, with names and figures redacted here.
This is for you if
Built for the Owner, IT Director, or CISO.
Nobody can say which sign-in rules are in force today, or who is excluded from them. Legacy authentication is still open and MFA exceptions will not satisfy insurers. An account was compromised, or an audit flagged the gaps, and it has to be fixed now.
What you receive
Identity Attack Surface Map
Which accounts keep admin powers switched on all the time, and where older sign-in methods still bypass your rules, mapped before anything changes.
CA Coverage Matrix
Conditional Access mapped across personas and conditions, with the gaps closed.
Tested, version-controlled policy
The rules kept in version control, released to a pilot group first, with a documented way to put them back.
Typical timeline
1-2 weeksIncluded
- Conditional Access rebuilt and released to a pilot group first
- Older sign-in methods switched off
- Phishing-resistant MFA rollout
- Tested rollback and documentation
Assumptions
- One Microsoft Entra ID tenant
- Agreed policy scope before changes
Not included
- Redesigning applications that still depend on older sign-in methods
- Privileged access program redesign
Scoped separately here: Fix & improve.
Required access
- Entra ID admin access
- A pilot group for staged rollout
- A 30-minute kickoff with security or IT
Engagement complete when
The engagement is complete when the attack surface map, CA coverage matrix, and tested policy are delivered and live.
Get an access model you can show an auditor, with a tested way back if something breaks.
One fixed fee, agreed in writing before any access is granted. The timeline above is the whole engagement, and what you keep is documentation your team can act on. One senior engineer scopes and delivers it.
The fee depends on what is actually in your environment rather than your headcount. The scope-fit check tells you where you land →