Engineering sprint · Identity

Entra ID
Identity Hardening

The foundation against ransomware and compromised accounts. I implement the Microsoft tiering model, block legacy protocols and roll out Conditional Access policies as infrastructure as code.

2
weeks
Fast delivery
End-to-End
Enforcement
Including go-live
Entra ID Icon

Scope & packages

Three packages by tenant size and complexity. You receive a binding fixed-price quote for your scope.

Essentials
Fixed price on request
Up to 25 users
Identity protection against ransomware and phishing for small teams. Baseline security that meets cyber insurance requirements.
Deliverables
  • Baseline protection against ransomware & phishing
  • Mandatory MFA for all employees (cyber insurance standard)
  • Blocking insecure sign-ins (legacy auth & sign-ins from abroad)
  • Setup of secure emergency access accounts (break-glass)
Corporate
Fixed price on request
Up to 500 users
Enterprise Conditional Access with IaC deployment and a supported rollout.
Deliverables
  • Everything in Essentials
  • 15+ enterprise Conditional Access policies (via IaC)
  • Removal of permanent admin rights (least privilege)
  • 7-day telemetry monitoring & supported go-live
Enterprise
Fixed price on request
500+ users
Complex multi-domain architectures with PIM and risk-based access.
Deliverables
  • Everything in Corporate
  • Multi-domain & complex Microsoft Entra Connect topologies
  • Risk-based access (automatic response to risky sign-ins)
  • Privileged Identity Management (PIM) with approval workflows
Not included & risks

Benefits for your business

The ROI for management.

Cyber insurance readiness
Cyber insurers increasingly require a validated identity and tiering concept (MFA, PIM, legacy auth disabled) when you take out or renew a policy.
Protection against ransomware
Stop attackers at the front door. Phishing-resistant MFA and device-bound policies prevent the initial intrusion and lateral movement within the network.
Foundation for Swiss FADP (revDSG) & NIS2
The architecture covers key technical access controls that help you implement data security under the Swiss Federal Act on Data Protection (FADP) and, for companies with ties to the EU, under the NIS2 Directive.
No support chaos
Thanks to the audit-first principle and deploying the CA policies in report-only mode, the impact becomes visible before activation. This is how I minimize outages and support escalations for your end users.

Frequently asked questions

What prerequisites must be met before the sprint starts?

This sprint strictly requires Microsoft Entra ID P1 (for Conditional Access) or P2 (for PIM & risk routing) licensing. The sprint starts (Day 1) as soon as you have fully provided these licenses and Global Administrator access (via PIM). Delays stop the project clock.

Won’t strict CA policies lock us out?

No. I safeguard the implementation with What If analyses and defined rollback scenarios. The core of the architecture is also the isolated break-glass accounts, which are consistently excluded from all blocking policies.

How will our IT admins work after the sprint?

Securely and with an audit trail. Permanent “Global Administrators” are removed except for the emergency access accounts (least privilege). Your IT uses Entra ID PIM to activate administrative rights when needed (just-in-time).

Will the hardening immediately bring legacy applications to a standstill?

No. Every policy is first rolled out in report-only mode via infrastructure as code (IaC). This lets me identify applications that would be blocked before block mode is switched on in agreement with you.

Read more in the knowledge article: Conditional Access for SMEs: The baseline policies

Ready for a Zero Trust foundation?

By submitting, you agree to the privacy policy.

You will receive a reply by email within one business day.