Identra

Services

What we do

Three areas of work, all within Microsoft 365. Take them as a short fixed-price project, an assessment, consultancy by the day, or ongoing support. Every engagement is scoped and priced before it starts.

01

Identity & access

Microsoft Entra configured so that access depends on who is signing in, the device they use and how risky the sign-in looks.

Conditional Access & risk policies

  • Entra ID
  • ID Protection
  • Intune

Sign-ins are evaluated by Entra ID Protection for risk and checked against Intune device compliance. Higher-risk sign-ins are asked for additional verification, and non-compliant or unmanaged devices are denied access.

Phishing-resistant authentication

  • Passwordless
  • FIDO2
  • MFA

Passkeys, Windows Hello for Business and FIDO2 rolled out through registration campaigns. We also disable legacy authentication, which can be used to bypass MFA.

Privileged Identity Management

  • PIM
  • JIT
  • Approval

Administrator roles are granted just in time, for a limited period, with approval and an audit record. This removes permanent Global Administrator assignments from everyday accounts.

Identity governance

  • Access reviews
  • Lifecycle

Access reviews, entitlement management and joiner/mover/leaver automation, so that access stays aligned with people’s current roles.

02

Threat detection & response

Defender XDR and Sentinel set up so that alerts are correlated, prioritised and assigned to a person.

Defender XDR correlation

  • Defender XDR
  • AIR

Signals from endpoints, identities, email and cloud apps are correlated into single incidents, with automated investigation and remediation for common alert types.

Microsoft Sentinel

  • Sentinel
  • KQL
  • SOAR

A SIEM running in the unified Defender portal, with KQL detection rules tuned to your environment, log ingestion from non-Microsoft sources and automated response playbooks.

Defender for Endpoint

  • EDR
  • ASR

Endpoint detection and response, attack-surface-reduction rules and vulnerability management. Device risk is reported back to Conditional Access, so a compromised device loses access automatically.

Defender for Office 365

  • Email
  • Anti-phish

Safe Links, Safe Attachments, anti-phishing policies and automated investigation for email and Teams.

03

Data governance & compliance

Microsoft Purview configured to classify data, prevent it leaving and keep the audit trail you may later need.

Sensitivity labels & encryption

  • Purview
  • Information Protection

Automatic classification and labelling, with encryption applied to the file itself so it stays protected across devices and tenants.

Data Loss Prevention

  • DLP
  • Endpoint DLP

DLP policies in enforcement across Exchange, SharePoint, Teams and endpoints, with sensible exceptions so they do not get in the way of normal work.

Audit & eDiscovery

  • Audit
  • eDiscovery

Audit logging, legal hold and content search configured and retained, so the records are available if an investigation or regulator needs them.

Insider risk & retention

  • Insider Risk
  • Retention

Insider-risk policies for data theft around resignations, and retention rules that keep records for as long as they are required and delete them afterwards.

How we work

Four ways to engage us

Not every problem needs a programme. Short projects and day-rate consultancy are as much of what we do as long engagements, and you can move between them.

A

Short project

A defined piece of work with a start, an end, and a fixed price.

Roll out Conditional Access. Migrate to phishing-resistant sign-in. Stand up Sentinel with a first detection set. Get PIM covering every privileged role. Scope is agreed and priced before the work starts, and the engagement closes when the definition of done is met. Typical projects run two to eight weeks.

  • Fixed scope
  • Fixed price
  • 2 to 8 weeks
B

Assessment

A review of your tenant, written up, with no obligation to continue.

We look at what is configured today against Microsoft security baselines and your own risk profile, then hand over the findings with a prioritised remediation plan you own. Many clients run the remediation themselves from there; others turn it into a short project. Either is fine.

  • Report
  • Prioritised plan
  • No lock-in
C

Consultancy and advisory

Access to the same engineers by the day, without a project wrapper.

Design review before you commit to an architecture. A second opinion on a licensing decision. Help through an audit or a security questionnaire. Cover while an internal hire is being recruited. Booked by the day or the half day, used when you need it, with no minimum retainer.

  • Day rate
  • Advisory
  • No minimum
D

Ongoing support

A monthly arrangement for tenants that need a hand on the tiller.

Policy tuning as the estate changes, alert triage, quarterly posture reviews, and someone to call when Microsoft ships a change that affects you. Scoped to the hours you actually need and reviewed every quarter, not locked to a multi-year term.

  • Monthly
  • Reviewed quarterly
  • Scoped hours

Not sure where to start? Begin with an assessment.

We review your tenant first and write up what we find. There is no obligation to carry on after that. If you already know the piece of work you want, ask for a short project or a day of consultancy instead.