
Identity & Access Management with Microsoft Entra
Protect business systems with modern authentication, conditional access and identity governance controls.
Identity is where most breaches actually start.
Firewalls and endpoint protection get most of the budget attention, but the entry point in the majority of incidents we're called to investigate is a compromised set of credentials — a phished password, a reused login, or MFA that was never turned on for that particular account. Identity is the front door, and in many organisations it's still the least controlled part of the estate.
The problem compounds with scale. A 60-user law firm might manage this reasonably well through informal knowledge of who has access to what. An organisation with 300 staff, several departments and a handful of third-party contractors loses that visibility fast, and nobody can say with confidence who holds administrative rights, which accounts are still active for people who left months ago, or which applications a departing employee still has a live session with.
Privileged accounts are a particular concern. Standing administrative access — an account that's always an admin, all the time — is a high-value target, because compromising it gives an attacker the same reach an IT administrator has. Most organisations have more of these accounts than they realise, often created for a one-off project and never downgraded afterwards.
The joiner, mover and leaver process is where a lot of this becomes visible. New starters wait days for access because provisioning is manual. Staff who change role keep permissions from their old one because nobody remembers to remove them. Leavers retain access to email and files for days or weeks after their last day, because the process depends on someone in HR remembering to tell IT.
- Accounts without MFA remain the most common route into a breach
- Standing administrative access held by more accounts than intended
- Manual leaver processes leaving access live after someone departs
- No consistent view of who has access to what across departments
We treat identity as a control system, not a login screen.
We start with multi-factor authentication, enforced across every account without exception — including service accounts and administrative accounts, which are often quietly excluded and become the weakest point in an otherwise well-protected environment. We use modern authentication methods rather than SMS, which is vulnerable to interception.
Conditional access is layered on top, so sign-in decisions take account of device compliance, location and risk signals rather than treating every login the same. A user signing in from a managed laptop in the office is a different risk profile to the same credentials being used from an unrecognised device overseas at 3am, and the access policy should reflect that difference.
For administrative access, we implement Privileged Identity Management so admin rights are granted just in time, for a defined period, with approval and logging, rather than sitting permanently active on accounts that rarely need them. This alone meaningfully limits what an attacker can do even if they compromise credentials.
Joiner, mover and leaver processes get automated wherever the underlying systems allow it, ideally integrated with your HR platform so access changes happen the moment employment status changes, not days later based on someone remembering to raise a ticket. Where full automation isn't feasible, we build a clear, auditable manual process instead.
- MFA enforced across every account, including admin and service accounts
- Conditional access policy based on device, location and risk, not blanket rules
- Privileged Identity Management replacing standing admin access
- Joiner/mover/leaver automation tied to HR events where possible
Everything in the engagement, set out up front.
Identity and access management scoped around your existing Microsoft 365 and Azure estate.
MFA rollout
Modern authentication enforced across every account, prioritised by risk and rolled out with proper user communication.
Conditional access policy design
Sign-in rules based on device compliance, location and risk, tailored to your actual working patterns.
Privileged Identity Management
Just-in-time, time-limited administrative access replacing standing admin accounts, with approval and audit logging.
Joiner/mover/leaver automation
Access provisioning and revocation tied to employment events, reducing reliance on manual tickets.
Identity governance review
A baseline audit of who has access to what, surfacing stale accounts and unexplained privilege.
Ongoing monitoring
Sign-in risk alerts and periodic access reviews to catch drift after the initial rollout.
What you receive.
- MFA enforcement rollout plan and completion report
- Conditional access policy set, documented and tested
- Privileged Identity Management configuration for admin roles
- Joiner/mover/leaver process design or automation build
- Identity governance baseline report
- Stale and orphaned account remediation list
- Sign-in risk monitoring and alerting setup
- Access review schedule and ownership document
Built for organisations that need the work done properly.
Organisations without enforced MFA
Businesses that assume MFA is on because it's available, without having actually enforced it everywhere.
Growing organisations losing access visibility
Firms that have outgrown informal knowledge of who has access to what across departments and systems.
Regulated businesses needing governance evidence
Financial services and healthcare organisations that need to demonstrate access control to auditors or regulators.
Businesses with slow or inconsistent HR-to-IT handover
Organisations where joiner, mover and leaver access changes depend on someone remembering to raise a ticket.
What changes once the work is done.
What changes once identity is governed rather than left to default settings.
Fewer successful phishing outcomes
Enforced MFA and conditional access stop a stolen password from being enough on its own.
Limited blast radius from compromise
Just-in-time privileged access means a compromised account can't act as a standing administrator.
Same-day leaver revocation
Access ends when employment ends, closing a gap that's frequently exploited or simply forgotten.
Audit-ready access records
A clear, logged record of who has access to what and why, ready for regulatory or client scrutiny.
Faster, safer onboarding
New starters get the right access from day one without manual delay or over-provisioning.
Reduced administrative overhead
Automation removes repetitive manual access changes from IT's day-to-day workload.
Why organisations choose Secure Chain for identity work.
Identity and access management sits at the centre of both cyber security consultancy and Microsoft security partner work, and we treat it that way rather than as a licensing configuration exercise. Getting conditional access and PIM right requires understanding how your organisation actually works day to day, not just what the Microsoft documentation recommends by default.
We regularly find that organisations already hold the Entra ID licensing needed for conditional access and PIM through their existing Microsoft 365 plan, and simply haven't switched the capability on. Part of our initial review is checking what you already have before recommending anything additional.
We support organisations across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, including law firms managing client confidentiality obligations, NHS suppliers with data protection requirements, and fintech firms with FCA expectations around access control and audit trail.
Identity work often surfaces uncomfortable findings — accounts nobody remembers creating, admin rights nobody can justify, leavers still technically able to log in. We report these plainly and help you fix them in a sensible order, rather than presenting a lengthy report that sits unread while the underlying gaps remain.
Questions we are asked most often.
What is Microsoft Entra ID?
It's Microsoft's identity and access management platform, formerly known as Azure Active Directory. It controls who can sign in to your Microsoft 365, Azure and connected third-party applications, and under what conditions — device compliance, location, risk level — rather than a password being the only barrier.
Is multi-factor authentication really that important?
Yes. The overwhelming majority of account compromises we investigate involve an account without MFA enabled, or MFA that can be bypassed through a weak method such as SMS. Enforcing modern MFA methods across every account, including service and admin accounts, remains one of the highest-value security controls available.
What is conditional access and how is it different from MFA?
MFA asks for a second factor at sign-in. Conditional access decides when to ask, and what else to require, based on context — is the device compliant, is the sign-in from an unusual location, is the account requesting access to a sensitive application. It turns identity from a single gate into a set of proportionate checks.
What is Privileged Identity Management and do we need it?
Privileged Identity Management (PIM) grants administrative rights only when needed and for a limited time, rather than leaving accounts permanently privileged. If your organisation has more than a handful of admin accounts, or has never reviewed who holds standing admin access, PIM meaningfully reduces the damage a compromised account can do.
How does Entra ID handle joiners, movers and leavers?
Entra ID can automate access provisioning when someone joins, adjust it when they change role, and revoke it immediately when they leave, provided the underlying process and group structure is designed properly. Manual leaver processes are one of the most common gaps we find during identity reviews — accounts left active weeks after someone has departed.
Do we need Entra ID Premium licensing for this?
Conditional access and PIM require Entra ID P1 or P2 licensing, often already included in Microsoft 365 E3 or E5 plans many organisations hold. We review your existing licensing first, since you may already have entitlement to capability you're not using rather than needing to buy more.
Can this work alongside our existing HR system?
Yes, and for joiner/mover/leaver automation it's the ideal setup. Integrating Entra ID with your HR platform means access changes are triggered by the same event that updates someone's employment record, removing the gap where IT finds out about a leaver days after they've gone.
How long does an identity governance project take?
A baseline conditional access and MFA rollout typically takes two to four weeks. Full identity governance including PIM and joiner/mover/leaver automation usually takes six to twelve weeks, depending on how many applications and how much manual process needs to be replaced.
Microsoft Azure consulting
Cloud infrastructure secured with the same identity governance discipline.
Managed security services
Ongoing monitoring and response that extends beyond identity into the full estate.
Financial services
How fintech and financial services firms meet FCA expectations around access control.
Not sure how exposed your current identity setup is?
Book a free identity governance review and we'll show you exactly where MFA, conditional access and privileged access stand today.
Book a free identity review