Identity & Access

Every account accounted for.

Identity is where modern attacks start and where auditors look first. We run Okta and Microsoft Entra ID as the front door to your company: SSO on every app, MFA for every person, and access that ends the minute someone leaves.

Users with MFA100%
Apps behind SSO41 / 41
Standing global admins0
Leaver access removed< 1 hour

What we aim for with every customer. Sample figures.

What we find most often

Identity gaps often go unnoticed until an audit or an incident.

Leavers who never left

Accounts disabled in one place but alive in five others. Sessions and tokens still valid weeks later.

MFA with gaps

Most people are enrolled, but not the shared mailbox, the old admin account or the app outside SSO.

Too many admins

Global admin rights handed out to get something done, and never taken back.

What's included

Identity managed by dedicated specialists.

Our engineers have years of hands-on experience with Okta, Entra ID, Conditional Access and Okta Workflows. We configure it correctly, then keep it that way.

OktaMicrosoft Entra IDOkta WorkflowsEntra PIMGoogle Workspace
  • Okta and Microsoft Entra ID administration
  • Single sign-on for every supported app
  • MFA for every user, phishing-resistant keys for admins
  • Conditional Access and Okta sign-on policies
  • Automated joiner, mover and leaver workflows tied to HR
  • Offboarding that revokes sessions and tokens, not just passwords
  • Time-limited admin access instead of standing admins
  • Cleanup of stale, guest and orphaned accounts
  • Service account and app permission inventory
  • Quarterly access reviews (with Compliance Operations)
Automated offboarding

The most overlooked step, performed consistently every time.

Every step is logged, so you have evidence for your auditor without collecting screenshots.

Step 01

HR marks a leaver

In your HR system or a simple request form.

Step 02

Access is removed everywhere

Account disabled, sessions and tokens revoked, MFA reset, app access removed.

Step 03

Data is handed over

Mailbox converted, files transferred to the manager.

Step 04

Device is locked

Laptop locked or wiped, with a second approval for wipes.

See it in action

When someone leaves, their access leaves too.

One request removes access from every connected app, locks the laptop, hands files to the manager and saves an audit log for your next review.

Leaver removed from every appIllustrative demo · not client data

Workflow · Leaver automation

  • Microsoft 365
  • Okta
  • Slack
  • Salesforce
  • GitHub
  • Zoom
  • Google Drive
  • HubSpot
  • 1Password
  • Dropbox
  • VPN
  • Jamf
Access removed everywhere12 of 12 apps revokedLaptop locked · files moved to manager · audit log saved

Find out where you stand in 10 days.

A Secure Workplace Assessment scores your identity, devices and Microsoft 365 or Google Workspace environment and delivers a 90-day remediation plan. Read-only access. Fixed fee.