Service

Entra ID Hardening Sprint

Rebuild identity controls on Microsoft's current baseline — tested before anything is enforced.

Duration3–4 weeksInvestmentTypically $15,000–$30,000

The problem

Token theft, MFA fatigue, device-code phishing and help-desk social engineering all walk past basic MFA. Identity is now the most common way attackers get into Microsoft 365 and Azure.

Who it's for

Organizations with Entra ID P1/P2 whose Conditional Access grew ad hoc, or that still rely on Security Defaults.

What's included

  • Break-glass account setup and monitoring
  • Persona-based Conditional Access design, deployed in report-only mode first
  • Phishing-resistant MFA (passkeys / FIDO2) for administrators and high-risk users
  • Device code flow blocking and legacy authentication removal
  • Privileged Identity Management for admin roles
  • Help desk reset and MFA re-registration hardening
  • Before-and-after test results

Frequently asked questions

Will users be locked out?

Every policy runs in report-only mode first, and enforcement happens in planned waves with your approval.

Do we need Entra ID P2?

P1 covers most of the sprint. P2 adds risk-based policies and Privileged Identity Management, which we recommend for admins.