Policy design & baseline
- A baseline policy set designed for your business, not copied from a blog
- Device compliance requirements — only managed, healthy devices reach company data
- Location, sign-in risk and role-based conditions where they genuinely help
- Legacy authentication blocked tenant-wide — the door most attackers still try first
Safe implementation
- Report-only mode first — we see what a policy would do before it does it
- Staged rollout with break-glass accounts so nobody locks the business out
- Pilot groups before estate-wide enforcement
- Documentation your auditors and insurers can actually read
Beyond the basics
- Session controls and token protection for higher-risk roles
- Integration with Intune compliance so device state gates access
- Policies tuned for hybrid and multi-country working
- Alignment with Cyber Essentials Plus requirements
Review & response
- Review of existing Conditional Access estates — gaps, conflicts and dead policies
- Post-incident hardening — we’ve rebuilt access policy after a real compromise
- Sign-in log analysis to prove policies are doing their job
- Ongoing tuning as Microsoft’s features and attackers’ techniques evolve
Compromise-hardened
We implemented Conditional Access for a law firm after a genuine account compromise. This isn’t theory to us.
10 to 850 users
The same discipline applied from small professional firms to an 850-user construction group.
CE+ aligned
Our policy baselines map to Cyber Essentials Plus — the standard we hold and are audited against annually.
No lockout deployments
Report-only first, break-glass always. We’ve never locked a client out of their own tenant.
Complex estates welcome
Multi-site, multi-country, BYOD and field devices — we design for how you actually work.
Evidence you can show
Documentation and sign-in reporting that satisfies auditors, insurers and frameworks.
