What It Delivers
Full Identity Census
Every user account, admin account, service principal, app registration, and guest identity enumerated and assessed. Orphaned accounts, over-privileged roles, and never-used service principals flagged and queued for remediation.
Conditional Access Architecture
A complete, documented CA policy set covering MFA enforcement, legacy auth blocking, device compliance signals, named locations, and phishing-resistant authentication for admins. Staged deployment with report-only period before enforcement to prevent lockout.
MFA Enforcement and Legacy Auth Elimination
MFA enforced via Conditional Access (not per-user MFA). Legacy authentication protocols — IMAP, POP, SMTP AUTH, basic auth — blocked at the tenant level. These protocols bypass MFA entirely and are the entry point for the majority of credential-based attacks.
PIM Deployment or JIT Process
Privileged Identity Management deployed so admin roles are activated on-demand with approval workflow and time-bounded access, rather than permanently assigned. Zero standing Global Admin access where feasible. Break-glass accounts established and documented.
PULSAR Audit Log Intelligence
PULSAR deployed for continuous M365 audit log ingestion with indefinite retention. Search UI, alerting on high-risk events, and MCP server for AI-assisted queries. You gain the ability to answer "what happened, when, and by whom" — retrospectively and in real time.
Guest Access Audit and Governance
All guest identities enumerated. Stale guests (inactive, unknown owner, no project association) flagged and removed. External collaboration settings tightened. Guest access policy documented and a review cadence established.
Scope and Prerequisites
| Duration | 30–60 days |
| Environment | M365 E3+ |
| Prerequisites | Global Administrator access; existing CA policies inventoried |
| Natural follow-on | Module 3 (M365 Security Hardening) builds on the identity baseline |
Standards Alignment
Conditional Access and audit log retention map directly onto NIS2 Article 21 (access control, monitoring), DORA Article 9 (ICT security — identity and access management), GDPR Article 32 (appropriate technical measures), and ISO 27001 A.5.15–A.5.18 (access control).
Close the identity gaps
The most common kill chain starts with a compromised credential. Module 2 ensures that credential alone is not enough.