When does access need to be brought under control?
Problems we help solve
User access is one of the most important areas of security. If accounts, groups and roles are created on an ad hoc basis, a business quickly loses control over who can view data, change configurations and use applications.
- There is no clear record of who has access to folders, applications and administration consoles.
- Former employees' accounts remain active or retain outdated permissions.
- Groups and roles are created without naming conventions, owners or reviews.
- Sign-in to Microsoft 365, the VPN and business systems is not governed by consistent policies.
- Administrators spend time making repetitive access changes manually.
Fit
Who is this service for?
Businesses using Active Directory
We organise domains, OUs, groups, GPOs and access to on-premises resources.
Organisations with Microsoft 365
We combine account management with Entra ID, MFA, licences and cloud services.
Rapidly growing businesses
We simplify environments where permissions have accumulated over years without review.
Teams with security requirements
We introduce controls for privileged accounts, exceptions and remote access.
Service scope
What does user and access management involve?
Accounts and groups
We review the structure of user accounts, groups and organisational units.
- account and group naming conventions,
- roles and access owners,
- management of inactive accounts.
Permissions
We review access to resources and restrict permissions to what is required.
- folders, applications and email,
- privileged accounts,
- review of exceptions.
MFA and sign-in
We strengthen authentication and access policies.
- MFA for critical services,
- password and account lockout policies,
- remote access and devices.
HR processes
We align access management with onboarding, changes of role and employee departures.
- starter and leaver checklists,
- revocation of permissions,
- change documentation.
Outcomes
What will you receive?
- a clearer structure for accounts, groups and roles,
- fewer excessive and legacy permissions,
- consistent policies for MFA, passwords and remote access,
- a process for granting, changing and revoking access,
- configuration documentation and recommendations for further improvements.
The scope may include a one-off access review, configuration clean-up or ongoing account administration.
Delivery approach
How is the service delivered?
- Discovery. We identify the systems, account types, user roles and current method of granting access.
- Audit. We check active accounts, groups, roles, exceptions and privileged accounts.
- Plan. We identify risks, quick wins and changes that require agreement with the team.
- Remediation. We make the agreed changes to groups, accounts, MFA and access policies.
- Testing. We test sign-in, access to resources and key working scenarios.
- Documentation. We provide details of the configuration and processes, together with recommendations for periodic reviews.
Delivery standards
How do we limit access risk?
- We do not leave administrative accounts without a named owner and justification.
- We restrict access by role, not by historical exceptions.
- We establish a process for approving new permissions and role changes.
- We implement MFA where the risk of account takeover is highest.
- We document the policies so that future changes remain consistent.
Cost
What determines the price?
The price depends on the number of users, systems and groups; the complexity of the domain or Microsoft 365 tenant; the number of exceptions; the level of documentation required; and the scope of changes to MFA, GPOs or Entra ID.
FAQ
Frequently asked questions
Does the service include Active Directory and Microsoft Entra ID?
Yes. We can work with a traditional on-premises domain, a Microsoft 365 environment or a hybrid model.
Can we start with an access review only?
Yes. A review of accounts, groups and permissions is a good first step before a broader clean-up.
Can implementing MFA cause problems for users?
It may require user communications and carefully managed exceptions. We therefore roll it out in stages and test common sign-in scenarios.
Can you prepare a process for new employees?
Yes. We can align access management with onboarding, offboarding and changes of role.
Do you delete old accounts?
We first identify them and agree what should happen. Some accounts should be disabled, some archived and others deleted once approval has been given.