Entra ID and Conditional Access without brittle lockouts
Map the access paths first, then tighten MFA, admin roles, Conditional Access and device trust with report-only testing, named exceptions and rollback notes. Initial review: £1,500 to £2,500; usually 5 working days.
What this fixes
Start with the control problem or outcome you need to make clear.
Where access control drifts
Legacy authentication, stale admin roles, unreviewed exclusions, weak break-glass access and policies that nobody can explain or safely enforce.
Scope, output and handover
Review MFA methods, admin roles, Conditional Access, legacy authentication, break-glass accounts, app access and audit evidence. Output: access map, exception register and enforcement sequence.
Not sure where to start?
Use the next useful check before you book the work.
- Access-path map across users, devices and applications.
- MFA and Conditional Access exception register.
- Privileged-role and break-glass gap list.
- Enforcement sequence with report-only testing and rollback notes.
- Internal ownership notes for recurring access reviews.
Questions teams ask before the work
Can Conditional Access be fixed without locking people out?
Yes — report-only, careful scope, monitoring and working break-glass before enforce.
What does the initial identity review cost and take?
It is normally scoped within the Microsoft 365 Security Review at £1,500 to £2,500 and usually takes five working days. Remediation timing depends on exclusions and rollout risk.
Related work
Scope the next step.
Send user count, MFA state, policy count and known exclusions.