Areas covered
- Users, groups, guests and synchronisation.
- Phishing-resistant authentication with passkeys/FIDO2 and Windows Hello for Business.
- Conditional Access with appropriate authentication strengths to enforce phishing-resistant methods.
- Administrator roles, least privilege and separate administrative accounts.
- Access to enterprise applications and single sign-on.
- Device join and registration models.
- Employee onboarding, role changes and offboarding.
- Logging, emergency access accounts and recoverability.
Outcomes
Outcomes
suXus inventories identity sources, roles, applications and exceptions. Policies are first validated under controlled conditions to prevent unintended access blocks. The outcome includes documented access policies, tested exceptions, clear administrator roles and a prioritised improvement list.
Technology
Technology used in these services
- Microsoft Entra ID