82 lines
4.2 KiB
Markdown
82 lines
4.2 KiB
Markdown
---
|
||
title: "Module 2 — M365 Identity Security"
|
||
description: "Full identity census, Conditional Access architecture, MFA enforcement, legacy auth elimination, PIM deployment, and PULSAR audit log intelligence for your M365 tenant."
|
||
eyebrow: "Consulting Module"
|
||
lead: "Identity is the perimeter. Every other control you deploy is downstream of whether the right people — and only the right people — can authenticate. This module makes your identity architecture explicit, enforced, and auditable."
|
||
actions:
|
||
- label: "Get in Touch"
|
||
url: "/about/#contact"
|
||
primary: true
|
||
- label: "View All Modules"
|
||
url: "/consulting/skills/"
|
||
---
|
||
|
||
## What It Delivers
|
||
|
||
<div class="feature-list">
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">👥</div>
|
||
<div class="feature-item-body">
|
||
<h4>Full Identity Census</h4>
|
||
<p>Every user account, admin account, service principal, app registration, and guest identity enumerated and assessed. Orphaned accounts, over-privileged roles, and never-used service principals flagged and queued for remediation.</p>
|
||
</div>
|
||
</div>
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">🏗️</div>
|
||
<div class="feature-item-body">
|
||
<h4>Conditional Access Architecture</h4>
|
||
<p>A complete, documented CA policy set covering MFA enforcement, legacy auth blocking, device compliance signals, named locations, and phishing-resistant authentication for admins. Staged deployment with report-only period before enforcement to prevent lockout.</p>
|
||
</div>
|
||
</div>
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">🔒</div>
|
||
<div class="feature-item-body">
|
||
<h4>MFA Enforcement and Legacy Auth Elimination</h4>
|
||
<p>MFA enforced via Conditional Access (not per-user MFA). Legacy authentication protocols — IMAP, POP, SMTP AUTH, basic auth — blocked at the tenant level. These protocols bypass MFA entirely and are the entry point for the majority of credential-based attacks.</p>
|
||
</div>
|
||
</div>
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">⏱️</div>
|
||
<div class="feature-item-body">
|
||
<h4>PIM Deployment or JIT Process</h4>
|
||
<p>Privileged Identity Management deployed so admin roles are activated on-demand with approval workflow and time-bounded access, rather than permanently assigned. Zero standing Global Admin access where feasible. Break-glass accounts established and documented.</p>
|
||
</div>
|
||
</div>
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">📡</div>
|
||
<div class="feature-item-body">
|
||
<h4>PULSAR Audit Log Intelligence</h4>
|
||
<p>PULSAR deployed for continuous M365 audit log ingestion with indefinite retention. Search UI, alerting on high-risk events, and MCP server for AI-assisted queries. You gain the ability to answer "what happened, when, and by whom" — retrospectively and in real time.</p>
|
||
</div>
|
||
</div>
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">🧹</div>
|
||
<div class="feature-item-body">
|
||
<h4>Guest Access Audit and Governance</h4>
|
||
<p>All guest identities enumerated. Stale guests (inactive, unknown owner, no project association) flagged and removed. External collaboration settings tightened. Guest access policy documented and a review cadence established.</p>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
## Scope and Prerequisites
|
||
|
||
| | |
|
||
|---|---|
|
||
| **Duration** | 30–60 days |
|
||
| **Environment** | M365 E3+ |
|
||
| **Prerequisites** | Global Administrator access; existing CA policies inventoried |
|
||
| **Natural follow-on** | Module 3 (M365 Security Hardening) builds on the identity baseline |
|
||
|
||
## Standards Alignment
|
||
|
||
Conditional Access and audit log retention map directly onto NIS2 Article 21 (access control, monitoring), DORA Article 9 (ICT security — identity and access management), GDPR Article 32 (appropriate technical measures), and ISO 27001 A.5.15–A.5.18 (access control).
|
||
|
||
<div class="cta-strip">
|
||
<h2>Close the identity gaps</h2>
|
||
<p>The most common kill chain starts with a compromised credential. Module 2 ensures that credential alone is not enough.</p>
|
||
<div class="actions">
|
||
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
|
||
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
|
||
</div>
|
||
</div>
|