Service

Identity & Zero Trust review

Entra ID architecture, Conditional Access, Global Secure Access, PKI and workload identity - reviewed against the access-control clauses every framework opens with, and remediated in code.

The problem this solves

Every control framework opens with access control, and every AI or cloud programme eventually stalls on it. Conditional Access policies accumulate for years without anyone able to say what the set does as a whole. Service principals hold standing secrets because that was the quick path in 2021. Break-glass accounts exist but have never been tested.

None of this shows up until an auditor asks, or until something is abused.

What I deliver

  • A readable map of your Conditional Access estate - what the policy set actually enforces in combination, where it overlaps, and where it has a hole.
  • Entra ID architecture review: tenant design, admin tiering, PIM, break-glass, guest and B2B exposure.
  • Workload identity migration: managed identities and federated credentials replacing stored secrets, so a workload can only ever act as itself.
  • Global Secure Access design where network access is in scope, including the certificate authority work behind TLS inspection - I have been through this end to end, including which approaches do not survive contact with GSA's requirements.
  • Remediation as Terraform, using the azuread provider, so the fixed state is the committed state.

What you have after the engagement

A findings document ranked by exploitability rather than by tool severity score, a Terraform branch implementing the uncontroversial fixes, and a short list of the decisions that are genuinely yours to make.

The Vault PKI post covers the certificate half of this in full detail - it is a fair sample of how I work and what the output looks like.

Want a second pair of eyes on your tenant?

Thirty minutes, no deck. Tell me what your teams have shipped and where the audit pressure is coming from, and I'll tell you what I'd look at first - whether or not you hire me.