Files
website/content/en/consulting/module-2.md
T

4.2 KiB
Raw Blame History

title, description, eyebrow, lead, actions
title description eyebrow lead actions
Module 2 — M365 Identity Security Full identity census, Conditional Access architecture, MFA enforcement, legacy auth elimination, PIM deployment, and PULSAR audit log intelligence for your M365 tenant. Consulting Module Identity is the perimeter. Every other control you deploy is downstream of whether the right people — and only the right people — can authenticate. This module makes your identity architecture explicit, enforced, and auditable.
label url primary
Get in Touch /about/#contact true
label url
View All Modules /consulting/skills/

What It Delivers

👥

Full Identity Census

Every user account, admin account, service principal, app registration, and guest identity enumerated and assessed. Orphaned accounts, over-privileged roles, and never-used service principals flagged and queued for remediation.

🏗️

Conditional Access Architecture

A complete, documented CA policy set covering MFA enforcement, legacy auth blocking, device compliance signals, named locations, and phishing-resistant authentication for admins. Staged deployment with report-only period before enforcement to prevent lockout.

🔒

MFA Enforcement and Legacy Auth Elimination

MFA enforced via Conditional Access (not per-user MFA). Legacy authentication protocols — IMAP, POP, SMTP AUTH, basic auth — blocked at the tenant level. These protocols bypass MFA entirely and are the entry point for the majority of credential-based attacks.

⏱️

PIM Deployment or JIT Process

Privileged Identity Management deployed so admin roles are activated on-demand with approval workflow and time-bounded access, rather than permanently assigned. Zero standing Global Admin access where feasible. Break-glass accounts established and documented.

📡

PULSAR Audit Log Intelligence

PULSAR deployed for continuous M365 audit log ingestion with indefinite retention. Search UI, alerting on high-risk events, and MCP server for AI-assisted queries. You gain the ability to answer "what happened, when, and by whom" — retrospectively and in real time.

🧹

Guest Access Audit and Governance

All guest identities enumerated. Stale guests (inactive, unknown owner, no project association) flagged and removed. External collaboration settings tightened. Guest access policy documented and a review cadence established.

Scope and Prerequisites

Duration 30–60 days
Environment M365 E3+
Prerequisites Global Administrator access; existing CA policies inventoried
Natural follow-on Module 3 (M365 Security Hardening) builds on the identity baseline

Standards Alignment

Conditional Access and audit log retention map directly onto NIS2 Article 21 (access control, monitoring), DORA Article 9 (ICT security — identity and access management), GDPR Article 32 (appropriate technical measures), and ISO 27001 A.5.15–A.5.18 (access control).

Close the identity gaps

The most common kill chain starts with a compromised credential. Module 2 ensures that credential alone is not enough.