Identra

Microsoft security consultancy · Entra · Defender · Purview

Microsoft security engineering for the licences you already own.

Identra is a consultancy that sets up Conditional Access, Defender XDR, Sentinel and Purview. We work with what is already in your Microsoft 365 tenant, so there is nothing new to buy. Most projects begin with controls that were licensed but never configured.

Focus
Microsoft 365 E3 / E5 · Entra Suite
Engagements
Fixed scope, fixed price
Principle
Verify explicitly · least privilege
ACCESS DECISIONfig.01SIGN-IN REQUESTuser · device · appsign-in riskEntra ID Protectiondevice complianceIntunesession / locationcontinuous evalCONDITIONAL ACCESSpolicy engine · evaluate every requestgrant · session · risk thresholdsALLOWcompliant + low riskSTEP-UP MFAelevated riskBLOCKnon-compliant device→ signals correlated in Defender XDR + Sentinel

01 / The gap

Most tenants are licensed for far more than they enforce.

The features are present in the tenant but left at their defaults, only partly configured, or switched off. A few patterns come up on almost every review:

  • 01Conditional Access policies sit in report-only mode, so risky sign-ins are logged but never blocked.
  • 02Defender is licensed and raising alerts, but no one is assigned to work the queue.
  • 03Purview labels are published while the matching DLP rules are still in test mode.

We identify these gaps and fix the configuration in your existing tenant. There is no migration and no new software to deploy.

Services

What we do

01

Identity & access

Conditional Access policies based on sign-in risk and device compliance, plus access reviews and Privileged Identity Management to stop admin rights building up over time.

  • Entra ID
  • ID Protection
  • Intune
  • PIM
02

Threat detection & response

Defender XDR set up so that alerts from endpoints, identities, email and cloud apps are correlated into single incidents, with Sentinel for investigation and automated response.

  • Defender XDR
  • Sentinel
  • KQL
03

Data governance & compliance

Purview sensitivity labels and Data Loss Prevention rules running in enforcement mode, with audit logging and eDiscovery configured for when you need them.

  • Purview
  • DLP
  • Audit

Method

Five phases, each scoped before it starts.

  1. 01

    Assess

    tenant + gap review

  2. 02

    Design

    policy architecture

  3. 03

    Deploy

    phased rollout

  4. 04

    Enable

    handover + runbooks

  5. 05

    Operate

    tune + review

US regulated industries

Built for the frameworks that govern your data.

Every engagement produces a control-by-control mapping that names the framework article, the Microsoft tenant setting that satisfies it, and the evidence an auditor will accept.

HIPAA
Conditional Access with device compliance and MFA meets the access-management administrative safeguard at 45 CFR §164.308(a)(4). Purview DLP with the medical-records sensitive-info types catches PHI leaving the tenant, addressing the technical safeguard around transmission security at §164.312(e)(1). Audit logging with 6-year retention is turned on at the tenant level.
SOX
Privileged Identity Management turns Global Administrator into a just-in-time, approved, audited role, which is what Section 404 asks for around financial-system access. Sentinel produces the audit trail evidence the auditors ask for on ITGC change-management and access reviews.
NIST 800-53 Rev 5
Conditional Access and PIM cover the AC family. Defender XDR and Sentinel cover the SI and IR families. Purview covers MP and SI-7. On close we hand over a control-by-control mapping document that names each 800-53 control against the specific tenant setting that satisfies it.
CJIS
Advanced Authentication (§5.6.2.1) is met with FIDO2 or Windows Hello for Business enforced through Conditional Access. Audit logging (§5.4) is covered by Purview and Sentinel. Personnel security screening (§5.12) is met by Entra access reviews tied to the customer HR system.
FedRAMP-adjacent
For Microsoft 365 GCC and GCC High tenants the platform already handles most SC and CM baseline controls. Identra configures the customer-responsibility controls in the AC, AU, and IA families, produces the SSP-ready evidence pack, and helps the customer answer the 3PAO on Entra and Purview questions.

We do not sell licences and we do not audit. We configure the tenant so that the auditor you already work with can sign the report faster.

Start with a look at your current tenant.

A scoping call takes about 30 minutes. We go through your tenant and tell you which gaps are worth addressing first.