Identity & Privilege
Administrative roles, permanent privileges, MFA, Conditional Access, PIM, break-glass design and dormant identities.
Review identity, privileged access, user lifecycle, endpoint posture and audit evidence across Entra ID, Microsoft 365, Intune and Defender where in scope.
Scope is confirmed before evidence collection. Read-only access, exports, screen-share or client-generated evidence can be used depending on the engagement.
Administrative roles, permanent privileges, MFA, Conditional Access, PIM, break-glass design and dormant identities.
Provisioning, role change, offboarding, guest users, service accounts and stale access.
External sharing, site permissions, M365 groups, Teams and ownership patterns.
Compliance, BitLocker, security baseline, device inventory, patch posture and configuration evidence.
Security configuration, alerting, audit logs and evidence retention where licensed and in scope.
Access reviews, approvals, exception records, change history and repeatable evidence generation.
Configuration screenshots are not the end product. The assessment connects configuration state to control objective, evidence quality, risk and corrective action.
Condition: Multiple permanent privileged role assignments exist without recent review evidence.
Risk: Excessive or stale administrative access can enable unauthorised changes and weakens accountability.
Action: Validate business need, reduce standing privilege, implement an appropriate review cadence, and retain approval evidence.