Identra

Locations / Austin, Texas

Microsoft security consulting for Austin organisations.

Austin is a Microsoft 365 town: state agencies at 1100 San Jacinto, healthcare systems along Mopac, tech companies from South Congress to the Domain, and semiconductor manufacturers in the Northeast corridor. Identra works with Austin organisations to configure Entra, Defender XDR, and Purview to the level a HIPAA audit, a State of Texas security assessment, or a SOC 2 review actually expects. Delivered remote-first with Austin-local pattern knowledge.

Service area
Austin, Round Rock, Cedar Park, Georgetown, Pflugerville
Delivery mode
Remote-first, on-site available
License footprint
M365 E3 or E5, GCC for state agencies
Delivery
Fixed scope, fixed price

01 / What we configure

Four practice areas for Austin buyers.

  • 01

    Healthcare (HIPAA)

    Austin healthcare organisations from St David HealthCare to smaller specialty practices run Microsoft 365. Identra configures HIPAA-aligned Conditional Access, PHI DLP, and 6-year audit retention. Preparation for OCR investigation and Business Associate assessment.

    HIPAAPHI DLPOCR readiness
  • 02

    State of Texas agencies (TAC 202)

    State agencies subject to Texas Administrative Code Title 1 Chapter 202 use Microsoft 365 in GCC or commercial cloud. Identra configures the tenant against TAC 202 and DIR security control standards, with evidence for the DIR annual security assessment.

    TAC 202DIR standardsAnnual assessment
  • 03

    Tech and SaaS (SOC 2)

    Austin tech companies chasing SOC 2 Type II run Microsoft 365 as the corporate backbone. Identra configures the AICPA Trust Services Criteria on the tenant side: security, availability, confidentiality, and privacy. Auditor evidence pack aligned to the CPA firm working papers.

    SOC 2Trust Services CriteriaCPA working papers
  • 04

    Semiconductor and manufacturing (IP protection)

    Semiconductor and advanced manufacturing IP is a top target for state-sponsored theft. Identra configures Purview Insider Risk, sensitivity labels on design files, and Defender for Endpoint on engineering workstations. Departing-engineer workflow integrated with HR.

    Insider RiskSensitivity labelsDeparting user

02 / What it looks like

Three Austin engagements.

Different Austin sectors, same Microsoft 365 platform, different regulator asks.

CISO at an Austin healthcare provider

Situation. Multi-clinic practice with staff working across three locations plus telehealth. Personal-device use is high. HIPAA audit scheduled in six months.

Outcome. App protection policy on personal devices. Sign-in risk policy enforced. Six-year audit retention configured. HIPAA audit closed with no material findings.

IT Director at an Austin SaaS company

Situation. Preparing for SOC 2 Type II. Auditor asked for evidence of MFA on all administrative access and a documented access-review cadence. Compliance team hand-drafting in a spreadsheet.

Outcome. PIM turned on for privileged Entra roles. Quarterly access reviews scheduled. Sentinel workbook produces the SOC 2 evidence pack in the CPA working-paper format. Type II observation window ran clean.

Security Officer at a state agency in downtown Austin

Situation. DIR annual security assessment approaching. Tenant configuration inherited from a predecessor with limited documentation. TAC 202 mapping never done.

Outcome. Tenant assessed against TAC 202 and DIR standards. Gaps closed in configuration. Evidence pack matched the DIR template. Annual assessment accepted on first submission.

03 / Frequently asked

What buyers ask first.

Are you Austin-based?
Identra operates remote-first across the United States. Our engagement model is remote configuration and evidence delivery, with on-site presence available for workshops, walkthroughs, and executive briefings when Austin proximity is helpful. Most Austin customers do not require on-site work day-to-day.
How does Texas Administrative Code Title 1 Chapter 202 apply?
TAC 202 sets the information security standards for state agencies and higher education institutions in Texas. It references the Texas DIR (Department of Information Resources) security control standards, which in turn map to NIST 800-53. Agencies file an annual security assessment against the DIR standards. Identra covers the Microsoft 365 portion of that assessment.
What about the Texas HB 300 privacy add-on to HIPAA?
Texas House Bill 300 (2011) added state-level obligations on top of HIPAA for Covered Entities operating in Texas: broader Covered Entity definition, biennial training requirements, and stricter breach notification. The Microsoft 365 tenant controls that satisfy HIPAA also satisfy HB 300; the difference is in policy documentation and training records. Identra evidence packs include the HB 300 add-on for Texas healthcare customers.
Do you work with the University of Texas system?
Identra works with public and private research universities. UT system institutions have their own IT organisation (UTS) and often UT Austin has additional local IT groups. Engagements are scoped to the specific institutional IT organisation and the research or clinical workload in question. TAC 202 applies to public universities.
What is the typical Austin engagement size?
Most Austin engagements run 8 to 16 weeks. Healthcare providers and state agencies typically run 12 to 16 weeks (regulator scope adds time). SaaS company SOC 2 preparation runs 8 to 12 weeks. Fixed scope, fixed price, no hourly bill-outs.

Next step

Book an Austin scoping call.

Thirty minutes on your Microsoft 365 posture and the regulator or auditor asking about it. Written scoping note within two business days.