Need IT support?

Identity & Access Management

Identity is the perimeter now

When applications, data and users are spread across cloud and office, the only consistent control point left is who someone is and what they are allowed to reach.

  • Entra ID and Active Directory
  • MFA and conditional access
  • Privileged access
  • Joiner / mover / leaver

How it fits together

The account nobody disabled

Every identity review we run finds the same things: active accounts belonging to people who left, administrator rights granted for a project years ago, shared logins for a critical system, and service accounts with passwords that have never been rotated.

The diagram is illustrative. It shows the shape of the capability rather than any specific customer environment.

Microsoft platform model Users authenticating through the identity layer into the Microsoft cloud, which supports collaboration, productivity and infrastructure services. Users IdentityENTRA ID · MFA Microsoft cloudAZURE · 365 Collaboration Productivity Infrastructure

Overview

In practice

None of that is unusual, and none of it is anyone's fault in particular. Identity accumulates. Without a defined joiner, mover and leaver process it drifts, and each drift is a route in.

We put structure around it: a single authoritative directory, role-based access, enforced multi-factor authentication, conditional access aligned to risk, and a review cycle that keeps it accurate.

What changes

Outcomes we are measured on

The point of the work, stated as results rather than product names.

01

Access that ends when employment does

A defined offboarding process across directory, applications and devices.

02

Fewer passwords, better control

Single sign-on across applications so users have less to remember and you have more to monitor.

03

Administrator rights that are earned

Privileged access granted for a purpose and a duration rather than held permanently.

04

Evidence for access reviews

Reportable, reviewable access rights that hold up to internal audit questions.

Capabilities

What sits inside this practice

Capability areas we design, implement and support. Scope for any engagement is agreed and documented in writing.

Directory services

The authoritative source of identity.

  • Active Directory
  • Entra ID
  • Directory Services
  • Hybrid Identity
  • Directory Synchronisation
  • Group Policy
  • Domain Consolidation

Authentication and access

Proving who someone is.

  • Single Sign-On
  • Multi-Factor Authentication
  • Conditional Access
  • Authentication
  • Zero Trust Identity
  • Passwordless Options
  • Secure Remote Access

Governance

Keeping rights correct over time.

  • Identity Governance
  • Role-Based Access Control
  • Privileged Access
  • Joiner / Mover / Leaver
  • Identity Lifecycle
  • Access Reviews
  • Segregation of Duties
  • Service Account Management

How we deliver

A sequence, because order matters here

Each stage produces something you can review before the next one starts.

Audit

Full account inventory: active, dormant, privileged, shared and service accounts, mapped against current employment records.

Rationalise

Remove what should not exist, group what belongs together, and define roles that reflect how the organisation actually works.

Enforce

MFA, conditional access and privileged access controls rolled out in phases with communication and support.

Review

A recurring access review cycle with reporting, so the position stays accurate after the project ends.

Questions

The things people ask before signing anything

Configured badly, yes. Configured well, most users authenticate once per device and rarely see a prompt again. Conditional access lets you require additional verification only where risk justifies it — an unfamiliar location, an unmanaged device — rather than constantly.

Often yes, for file services, print, or line-of-business applications that authenticate against it. A hybrid identity model keeps both directories in step. Whether you can eventually retire the on-premises directory is worth assessing, but it is rarely the first move.

Not a product. It is the principle that no request is trusted purely because of where it comes from. In practice it means verified identity, device compliance checks, least-privilege access and segmentation — implemented incrementally, not as a single project.

Separate administrative identities from daily-use accounts, enforce MFA on them, limit standing privilege, and log their use. Where the platform supports just-in-time elevation, we implement it.

Related

Usually discussed alongside this

Cybersecurity

Not a wall of dashboards.

Explore

Microsoft Solutions

Most organisations already own more Microsoft capability than they use.

Explore

End-User Computing

Devices that arrive configured, get supported quickly, stay secure, and get replaced on a plan rather than when they finally die.

Explore
Technologies supporting this capability
Cloud & Productivity

Next step

Let's define what your technology should be doing.

Tell us what is not working, what is coming up, or what you are being asked to deliver. We will come back with a considered view — not a generic proposal.