Methodology
How we work
Five phases. Each one is scoped before it begins, with a clear definition of done and a way to roll it back.
Assess
We review the current configuration across Entra, Defender and Purview: Conditional Access coverage, MFA registration, privileged roles, alert routing and the status of labels and DLP. The result is a written list of gaps, ordered by risk.
- +Tenant configuration export
- +Conditional Access gap matrix
- +Privileged-role inventory
- +Risk & exposure ranking
Design
We write up the target configuration for you to approve before any changes are made: the Conditional Access model, role and PIM design, detection priorities and data-protection settings. Changes are sequenced so each one can be reversed.
- +Conditional Access policy set
- +Role & PIM model
- +Detection & response plan
- +Rollout sequence + rollback
Deploy
We roll changes out in stages, starting in report-only mode and with pilot groups, so the impact is measured before wider release. Emergency access accounts are tested before any policy is enforced.
- +Report-only validation
- +Pilot ring rollout
- +Staged enforcement
- +Break-glass verified
Enable
We hand over runbooks, the detection queries and documentation that explains why each policy is set the way it is, so your team can run and adjust the configuration without us.
- +Admin runbooks
- +Analyst playbooks
- +KQL query pack
- +Knowledge-transfer sessions
Operate
Optional ongoing support: reviewing incidents and false positives, adjusting policies as the environment changes, and regular reporting. Scoped as a fixed monthly engagement.
- +Incident & false-positive review
- +Policy tuning
- +Posture reporting
- +Quarterly access reviews