Know exactly whohas access to what.Every month.With proof.

Microsoft Entra ID and Intune identity governance for organizations without an IAM team.

The question nobody can answer

Most organizations running Microsoft can't say who has access to what. Terminations remove the mailbox and leave the service principal. Global Administrator gets assigned permanently because PIM was licensed but never configured. Access reviews happen once a year as a spreadsheet nobody reads.

None of this is exotic. It's just nobody's job.

What we do

A monthly identity governance audit. That is the product.

Every month, we collect the full identity picture from your Microsoft tenants, reconcile it, and compare it to last cycle. You get a report showing exactly who holds what access, what changed, what drifted from policy, and what to do about it — with the evidence an auditor or examiner will ask for already attached.

Commercial and GCC or GCC High tenants are reconciled together in one report. Most tooling, and most consultants, handle one cloud at a time.

Every figure in every report traces to a stored, hashed collection snapshot and a specific rule set version. Re-running a past cycle produces identical numbers.

Your identity data is collected read-only, is never processed by a third-party AI service, and never leaves systems under our control.

We do one thing. Here's what we don't do.

Scope is published so the sales conversation starts in the right place.

In scope

  • Microsoft Entra IDAccounts and lifecycle, privileged roles and PIM, Conditional Access coverage, MFA registration, groups, app registrations and service principals, OAuth consent, guest and cross-tenant access.
  • Microsoft IntuneEnrollment and join state, compliance policies and non-compliant devices, configuration profile drift, Windows LAPS coverage, and the device-compliance-to-Conditional-Access dependency chain.
  • Defender for Identity and Defender for Cloud AppsRead-only. Their posture assessments and OAuth findings are consumed and triaged into the audit. We don't operate them.
  • On-premises Active Directory and hybrid identityPriced per forest. AD hygiene, Entra Connect sync health, hybrid join, privileged AD groups, stale objects, delegation.
  • Additional Microsoft tenantsEach distinct tenant is a pricing unit. Commercial plus GCC or GCC High is common in our market, and a core competency.

Not in scope

  • No detection, monitoring, alerting, or incident response
  • No Defender for Endpoint operation or alert triage
  • No email security or anti-phishing operation
  • No Azure resource posture management or CSPM
  • No SOC services, no on-call, no round-the-clock coverage
  • No general Microsoft 365 administration, licensing procurement, or helpdesk

Full scope detail →

How clients engage

Three stages. Each one stands on its own.

01

Free discovery scan

Automated, read-only, one tenant. You run a signed PowerShell script in your own tenant and send us the output file; no access to your tenant is granted. You get an 8–12 page report and a 30-minute readout. One per organization, ever.

02

One-time IAM audit

Fixed price, roughly two weeks, no ongoing commitment. The full deliverable set, walked through in a live working session. The audit fee credits in full toward retainer onboarding if a retainer is signed within 60 days.

03

Monthly retainer

12-month term. Monthly audit cycle, drift detection between cycles, access certification campaigns, joiner-mover-leaver runbook maintenance, evidence packaging, and a combined monthly consult-and-remediation hour bucket.

Why the numbers can be trusted

The pipeline is deterministic by design. That is the point.

Read-only collection

Microsoft Graph, through a per-client Entra app registration authenticated by certificate, with narrowly scoped permissions. The consent grant is documented and handed to you for your own records.

Immutable snapshots

Raw collection output is hashed and timestamped before any processing. The snapshot is the evidence; everything downstream derives from it.

Rule-based findings

Findings come from versioned, declarative rules held in version control, each with a stable identifier, a severity, a compliance framework mapping, and remediation guidance. Not from judgment, and not from a language model.

Reproducible

Every report cites the collection hash and rule set version it ran under. Re-running a past cycle produces identical numbers.

No AI on your data

Client identity data is never processed by a third-party AI service and never leaves systems under TrogSec's control. No model providers, no subprocessor chain. This is a contractual commitment.

The full methodology →

Published pricing

You should be able to budget this without a sales call. Compare it to an IGA platform license, or to what a full-time identity administrator costs.

Tier 1 0–149 users

Retainer from $1,800/mo

  • One-time audit from $2,750
  • 4 included hours per month
  • Weekly drift detection
Tier 2 150–500 users

Retainer from $3,500/mo

  • One-time audit from $5,500
  • 8 included hours per month
  • Daily drift detection
Tier 3 501+ users

Retainer from $6,500/mo

  • One-time audit from $9,500
  • 14 included hours per month
  • Daily drift detection, quarterly executive review

The feature set is identical across all three tiers. What changes is the included hour bucket, drift detection frequency, certification cadence, readout length, and response commitment. Prices are per month for one tenant, before Hawaii General Excise Tax.

Full pricing and calculator

Start with the free scan

Read-only, run by you in your own tenant, against CISA's SCuBA baselines plus our own identity-hygiene checks. An 8–12 page report and a 30-minute readout. It reports configuration gaps; the full access reconciliation is the paid audit.

Get your free scan

Contact

Based in Honolulu, Hawaii. Clients nationwide.

Email is answered within one business day. For a scoped quote, the pricing calculator can pre-fill the contact form with your numbers.

If you have found a vulnerability in something we run, our disclosure policy is published at /.well-known/security.txt.