Scope & packages
Three packages by tenant size and complexity. You receive a binding fixed-price quote for your scope.
- Baseline protection against ransomware & phishing
- Mandatory MFA for all employees (cyber insurance standard)
- Blocking insecure sign-ins (legacy auth & sign-ins from abroad)
- Setup of secure emergency access accounts (break-glass)
- Everything in Essentials
- 15+ enterprise Conditional Access policies (via IaC)
- Removal of permanent admin rights (least privilege)
- 7-day telemetry monitoring & supported go-live
- Everything in Corporate
- Multi-domain & complex Microsoft Entra Connect topologies
- Risk-based access (automatic response to risky sign-ins)
- Privileged Identity Management (PIM) with approval workflows
Technical details
Details for technical validation.
Policies (Enterprise Conditional Access)
A consistent architecture based on best practices, without the typical bypass gaps. I roll out a ready-made set of 15+ policies based on a block-first approach, mandatory device compliance and network-based rules.
- Production CA policy set (deployed via IaC)
- Phishing-resistant MFA enforcement
- Device-bound access controls
Admin (Admin Tiering & PIM)
Emergency access and admin concepts based on enterprise standards. Permanent “standing privileges” are eliminated and replaced with just-in-time (JIT) access for administration.
- Privileged Identity Management (PIM) setup
- JIT admin access workflows
- Isolated break-glass emergency access accounts
Hardening (Entra ID Hardening)
Protection against modern attack vectors and identity theft. Systematic preparation for disabling legacy authentication methods and automated routing for compromised accounts.
- Legacy authentication hard-block preparation
- Sign-in risk & user risk policies
- Password spray & brute-force protection
Enforcement (Log Analysis & Go-Live)
No half-finished work. I first roll out the policies in report-only mode, monitor the telemetry for anomalies for 7 days and then, in agreement with you, carry out the final switch to enforcement.
- 7-day report-only telemetry monitoring
- Identification of blocking risks (legacy apps)
- Final go-live by Flowbotics (end-to-end)
Benefits for your business
The ROI for management.
Frequently asked questions
What prerequisites must be met before the sprint starts?
This sprint strictly requires Microsoft Entra ID P1 (for Conditional Access) or P2 (for PIM & risk routing) licensing. The sprint starts (Day 1) as soon as you have fully provided these licenses and Global Administrator access (via PIM). Delays stop the project clock.
Won’t strict CA policies lock us out?
No. I safeguard the implementation with What If analyses and defined rollback scenarios. The core of the architecture is also the isolated break-glass accounts, which are consistently excluded from all blocking policies.
How will our IT admins work after the sprint?
Securely and with an audit trail. Permanent “Global Administrators” are removed except for the emergency access accounts (least privilege). Your IT uses Entra ID PIM to activate administrative rights when needed (just-in-time).
Will the hardening immediately bring legacy applications to a standstill?
No. Every policy is first rolled out in report-only mode via infrastructure as code (IaC). This lets me identify applications that would be blocked before block mode is switched on in agreement with you.
Read more in the knowledge article: Conditional Access for SMEs: The baseline policies