Identra

Methodology

How we work

Five phases. Each one is scoped before it begins, with a clear definition of done and a way to roll it back.

01

Assess

We review the current configuration across Entra, Defender and Purview: Conditional Access coverage, MFA registration, privileged roles, alert routing and the status of labels and DLP. The result is a written list of gaps, ordered by risk.

  • +Tenant configuration export
  • +Conditional Access gap matrix
  • +Privileged-role inventory
  • +Risk & exposure ranking
02

Design

We write up the target configuration for you to approve before any changes are made: the Conditional Access model, role and PIM design, detection priorities and data-protection settings. Changes are sequenced so each one can be reversed.

  • +Conditional Access policy set
  • +Role & PIM model
  • +Detection & response plan
  • +Rollout sequence + rollback
03

Deploy

We roll changes out in stages, starting in report-only mode and with pilot groups, so the impact is measured before wider release. Emergency access accounts are tested before any policy is enforced.

  • +Report-only validation
  • +Pilot ring rollout
  • +Staged enforcement
  • +Break-glass verified
04

Enable

We hand over runbooks, the detection queries and documentation that explains why each policy is set the way it is, so your team can run and adjust the configuration without us.

  • +Admin runbooks
  • +Analyst playbooks
  • +KQL query pack
  • +Knowledge-transfer sessions
05

Operate

Optional ongoing support: reviewing incidents and false positives, adjusting policies as the environment changes, and regular reporting. Scoped as a fixed monthly engagement.

  • +Incident & false-positive review
  • +Policy tuning
  • +Posture reporting
  • +Quarterly access reviews

The assessment comes first, and it is a small, fixed piece of work.

A short call is enough for us to scope it and give you a price.