Identra

Identity-first security — Entra · Defender · Purview

Identity is the perimeter now. We engineer Microsoft to hold it.

Identra configures Conditional Access, Defender XDR, Sentinel and Purview for organisations that already pay for E5 and never saw the controls switched on. No new vendors — your Microsoft estate, set to enforce least privilege and surface the attacks that inbox rules miss.

Focus
Microsoft 365 E3 / E5 · Entra Suite
Engagements
Fixed scope, fixed price
Principle
Verify explicitly · least privilege
ACCESS DECISIONfig.01SIGN-IN REQUESTuser · device · appsign-in riskEntra ID Protectiondevice complianceIntunesession / locationcontinuous evalCONDITIONAL ACCESSpolicy engine · evaluate every requestgrant · session · risk thresholdsALLOWcompliant + low riskSTEP-UP MFAelevated riskBLOCKnon-compliant device→ signals correlated in Defender XDR + Sentinel

01 — The gap

Owning the licences is not the same as being defended.

Most teams we meet have the right SKUs and the wrong configuration. The capability is already in the tenant — paid for, switched off, or half-applied:

  • 01Conditional Access left in report-only — logged, never enforced.
  • 02Defender licences assigned; alerts land in a queue nobody owns.
  • 03Purview labels published; DLP policies still running in test mode.

We find these gaps, then close them — with the tenant you already have, not a migration you do not need.

Services

What we engineer

01

Identity & access

Risk-based Conditional Access that gates every sign-in on identity risk and device compliance — backed by access reviews and PIM so standing privilege stops quietly accumulating.

  • Entra ID
  • ID Protection
  • Intune
  • PIM
02

Threat detection & response

Defender XDR wired so endpoint, identity, email and cloud-app alerts correlate into one incident — then routed, triaged and answerable from a single queue in Sentinel.

  • Defender XDR
  • Sentinel
  • KQL
03

Data governance & compliance

Purview sensitivity labels and DLP that actually block exfiltration instead of logging it, with audit and eDiscovery you can stand behind when someone asks for evidence.

  • Purview
  • DLP
  • Audit

Method — five phases

A scoped sequence, not an open-ended retainer.

  1. 01

    Assess

    tenant + gap review

  2. 02

    Design

    policy architecture

  3. 03

    Deploy

    phased rollout

  4. 04

    Enable

    handover + runbooks

  5. 05

    Operate

    tune + review

Bring the licences. We’ll bring them online.

A scoping call is 30 minutes: we look at your tenant, name the gaps, and tell you whether there is work worth doing. No deck.