Consulting Module

Module 2 — M365 Identity Security

Identity is the perimeter. Every other control you deploy is downstream of whether the right people — and only the right people — can authenticate. This module makes your identity architecture explicit, enforced, and auditable.

What It Delivers

👥

Full Identity Census

Every user account, admin account, service principal, app registration, and guest identity enumerated and assessed. Orphaned accounts, over-privileged roles, and never-used service principals flagged and queued for remediation.

🏗️

Conditional Access Architecture

A complete, documented CA policy set covering MFA enforcement, legacy auth blocking, device compliance signals, named locations, and phishing-resistant authentication for admins. Staged deployment with report-only period before enforcement to prevent lockout.

🔒

MFA Enforcement and Legacy Auth Elimination

MFA enforced via Conditional Access (not per-user MFA). Legacy authentication protocols — IMAP, POP, SMTP AUTH, basic auth — blocked at the tenant level. These protocols bypass MFA entirely and are the entry point for the majority of credential-based attacks.

⏱️

PIM Deployment or JIT Process

Privileged Identity Management deployed so admin roles are activated on-demand with approval workflow and time-bounded access, rather than permanently assigned. Zero standing Global Admin access where feasible. Break-glass accounts established and documented.

📡

PULSAR Audit Log Intelligence

PULSAR deployed for continuous M365 audit log ingestion with indefinite retention. Search UI, alerting on high-risk events, and MCP server for AI-assisted queries. You gain the ability to answer "what happened, when, and by whom" — retrospectively and in real time.

🧹

Guest Access Audit and Governance

All guest identities enumerated. Stale guests (inactive, unknown owner, no project association) flagged and removed. External collaboration settings tightened. Guest access policy documented and a review cadence established.

Scope and Prerequisites

Duration30–60 days
EnvironmentM365 E3+
PrerequisitesGlobal Administrator access; existing CA policies inventoried
Natural follow-onModule 3 (M365 Security Hardening) builds on the identity baseline

Standards Alignment

Conditional Access and audit log retention map directly onto NIS2 Article 21 (access control, monitoring), DORA Article 9 (ICT security — identity and access management), GDPR Article 32 (appropriate technical measures), and ISO 27001 A.5.15–A.5.18 (access control).

Close the identity gaps

The most common kill chain starts with a compromised credential. Module 2 ensures that credential alone is not enough.