Identra

Services

What we do

Three areas of work, all within Microsoft 365. Each engagement is fixed in scope and priced before it starts.

01

Identity & access

Microsoft Entra configured so that access depends on who is signing in, the device they use and how risky the sign-in looks.

Conditional Access & risk policies

  • Entra ID
  • ID Protection
  • Intune

Sign-ins are evaluated by Entra ID Protection for risk and checked against Intune device compliance. Higher-risk sign-ins are asked for additional verification, and non-compliant or unmanaged devices are denied access.

Phishing-resistant authentication

  • Passwordless
  • FIDO2
  • MFA

Passkeys, Windows Hello for Business and FIDO2 rolled out through registration campaigns. We also disable legacy authentication, which can be used to bypass MFA.

Privileged Identity Management

  • PIM
  • JIT
  • Approval

Administrator roles are granted just in time, for a limited period, with approval and an audit record. This removes permanent Global Administrator assignments from everyday accounts.

Identity governance

  • Access reviews
  • Lifecycle

Access reviews, entitlement management and joiner/mover/leaver automation, so that access stays aligned with people’s current roles.

02

Threat detection & response

Defender XDR and Sentinel set up so that alerts are correlated, prioritised and assigned to a person.

Defender XDR correlation

  • Defender XDR
  • AIR

Signals from endpoints, identities, email and cloud apps are correlated into single incidents, with automated investigation and remediation for common alert types.

Microsoft Sentinel

  • Sentinel
  • KQL
  • SOAR

A SIEM running in the unified Defender portal, with KQL detection rules tuned to your environment, log ingestion from non-Microsoft sources and automated response playbooks.

Defender for Endpoint

  • EDR
  • ASR

Endpoint detection and response, attack-surface-reduction rules and vulnerability management. Device risk is reported back to Conditional Access, so a compromised device loses access automatically.

Defender for Office 365

  • Email
  • Anti-phish

Safe Links, Safe Attachments, anti-phishing policies and automated investigation for email and Teams.

03

Data governance & compliance

Microsoft Purview configured to classify data, prevent it leaving and keep the audit trail you may later need.

Sensitivity labels & encryption

  • Purview
  • Information Protection

Automatic classification and labelling, with encryption applied to the file itself so it stays protected across devices and tenants.

Data Loss Prevention

  • DLP
  • Endpoint DLP

DLP policies in enforcement across Exchange, SharePoint, Teams and endpoints, with sensible exceptions so they do not get in the way of normal work.

Audit & eDiscovery

  • Audit
  • eDiscovery

Audit logging, legal hold and content search configured and retained, so the records are available if an investigation or regulator needs them.

Insider risk & retention

  • Insider Risk
  • Retention

Insider-risk policies for data theft around resignations, and retention rules that keep records for as long as they are required and delete them afterwards.

Not sure where to start? Begin with an assessment.

We review your tenant first and write up what we find. There is no obligation to carry on after that.