Skip to main content

Back to Secure IT

Who may do what, and how you can tell

We build an identity model on Entra ID that handles joiners and leavers automatically, grants privileged rights only for a period, and holds up in an audit without extra work.

30 minutes · no sales pitch · an honest read on whether we fit

A fit when

  • Your access rights grew over years and nobody dares to clean them up
  • An audit or a customer questionnaire asks you to evidence permissions
  • Joiners and leavers cost your team time every week
  • You are introducing Zero Trust and need a foundation that holds

The situation

  • Joining and leaving is manual. Accounts stay active after someone leaves because nobody triggers the process.
  • Nobody can say at short notice who has access to which systems, or whether that is still justified.
  • Administrator rights are permanent because time-bound assignment was never set up.
  • Conditional Access consists of accumulated exceptions nobody dares to remove.

What we do

We design the access model along the roles that actually exist in your organisation and implement it in Entra ID: groups with a clear origin, Conditional Access with reasoned rules instead of accumulated exceptions, privileged roles granted only for a period and with approval, tested break-glass accounts, and a recertification that sits in your calendar rather than in someone's good intentions. Joiners and leavers are wired to the authoritative HR source so the process does not depend on somebody remembering.

What is included

  • 01Survey of the access modelWhich groups, roles and exceptions exist today, and which of them can be justified.
  • 02Entra ID as the leading directoryDirectory structure, naming conventions and group logic that are still readable in two years.
  • 03Automated joiners and leaversWired to the authoritative HR source, including role changes and what actually happens when someone leaves.
  • 04Conditional Access with a rationaleA rule set by risk, device and location, documented with the reason for each rule.
  • 05Time-bound privileged accessActivation with approval and expiry, tested break-glass accounts, and a traceable log.
  • 06Recurring recertificationAccess reviews with named owners, so the clean-up does not stay a one-off.

What you end up with

Documented access modelAutomated joiners and leaversPrivileged rights only for a periodRecertification in daily operation
Request a briefingA reply within 1 business day, from a person.