Know exactly whohas access to what.Every month.With proof.
Microsoft Entra ID and Intune identity governance for organizations without an IAM team.
The question nobody can answer
Most organizations running Microsoft can't say who has access to what. Terminations remove the mailbox and leave the service principal. Global Administrator gets assigned permanently because PIM was licensed but never configured. Access reviews happen once a year as a spreadsheet nobody reads.
None of this is exotic. It's just nobody's job.
What we do
A monthly identity governance audit. That is the product.
Every month, we collect the full identity picture from your Microsoft tenants, reconcile it, and compare it to last cycle. You get a report showing exactly who holds what access, what changed, what drifted from policy, and what to do about it — with the evidence an auditor or examiner will ask for already attached.
Commercial and GCC or GCC High tenants are reconciled together in one report. Most tooling, and most consultants, handle one cloud at a time.
Every figure in every report traces to a stored, hashed collection snapshot and a specific rule set version. Re-running a past cycle produces identical numbers.
Your identity data is collected read-only, is never processed by a third-party AI service, and never leaves systems under our control.
We do one thing. Here's what we don't do.
Scope is published so the sales conversation starts in the right place.
In scope
- Microsoft Entra IDAccounts and lifecycle, privileged roles and PIM, Conditional Access coverage, MFA registration, groups, app registrations and service principals, OAuth consent, guest and cross-tenant access.
- Microsoft IntuneEnrollment and join state, compliance policies and non-compliant devices, configuration profile drift, Windows LAPS coverage, and the device-compliance-to-Conditional-Access dependency chain.
- Defender for Identity and Defender for Cloud AppsRead-only. Their posture assessments and OAuth findings are consumed and triaged into the audit. We don't operate them.
- On-premises Active Directory and hybrid identityPriced per forest. AD hygiene, Entra Connect sync health, hybrid join, privileged AD groups, stale objects, delegation.
- Additional Microsoft tenantsEach distinct tenant is a pricing unit. Commercial plus GCC or GCC High is common in our market, and a core competency.
Not in scope
- No detection, monitoring, alerting, or incident response
- No Defender for Endpoint operation or alert triage
- No email security or anti-phishing operation
- No Azure resource posture management or CSPM
- No SOC services, no on-call, no round-the-clock coverage
- No general Microsoft 365 administration, licensing procurement, or helpdesk
How clients engage
Three stages. Each one stands on its own.
Free discovery scan
Automated, read-only, one tenant. You run a signed PowerShell script in your own tenant and send us the output file; no access to your tenant is granted. You get an 8–12 page report and a 30-minute readout. One per organization, ever.
One-time IAM audit
Fixed price, roughly two weeks, no ongoing commitment. The full deliverable set, walked through in a live working session. The audit fee credits in full toward retainer onboarding if a retainer is signed within 60 days.
Monthly retainer
12-month term. Monthly audit cycle, drift detection between cycles, access certification campaigns, joiner-mover-leaver runbook maintenance, evidence packaging, and a combined monthly consult-and-remediation hour bucket.
Why the numbers can be trusted
The pipeline is deterministic by design. That is the point.
Microsoft Graph, through a per-client Entra app registration authenticated by certificate, with narrowly scoped permissions. The consent grant is documented and handed to you for your own records.
Raw collection output is hashed and timestamped before any processing. The snapshot is the evidence; everything downstream derives from it.
Findings come from versioned, declarative rules held in version control, each with a stable identifier, a severity, a compliance framework mapping, and remediation guidance. Not from judgment, and not from a language model.
Every report cites the collection hash and rule set version it ran under. Re-running a past cycle produces identical numbers.
Client identity data is never processed by a third-party AI service and never leaves systems under TrogSec's control. No model providers, no subprocessor chain. This is a contractual commitment.
Published pricing
You should be able to budget this without a sales call. Compare it to an IGA platform license, or to what a full-time identity administrator costs.
Retainer from $1,800/mo
Retainer from $3,500/mo
Retainer from $6,500/mo
The feature set is identical across all three tiers. What changes is the included hour bucket, drift detection frequency, certification cadence, readout length, and response commitment. Prices are per month for one tenant, before Hawaii General Excise Tax.
Start with the free scan
Read-only, run by you in your own tenant, against CISA's SCuBA baselines plus our own identity-hygiene checks. An 8–12 page report and a 30-minute readout. It reports configuration gaps; the full access reconciliation is the paid audit.
Contact
Based in Honolulu, Hawaii. Clients nationwide.
Email is answered within one business day. For a scoped quote, the pricing calculator can pre-fill the contact form with your numbers.
If you have found a vulnerability in something we run, our disclosure policy is published at /.well-known/security.txt.