Services

One product: a monthly identity governance audit of your Microsoft tenants. Here is what it covers, what it consumes, what is priced separately, and what it deliberately does not do.

In scope

Collected every cycle, reconciled against the previous cycle, and reported with evidence.

Microsoft Entra ID
  • Account inventory and lifecycle state
  • Privileged role assignments and standing privilege
  • PIM configuration, with eligible-versus-active analysis
  • Conditional Access policy inventory, gap analysis, and coverage mapping
  • Entra ID Protection risk posture
  • MFA and authentication method registration coverage
  • Group membership, nesting, and dynamic membership rules
  • App registrations and service principals, including credential and certificate expiry
  • Enterprise application OAuth consent and permission grants
  • Guest and B2B collaboration posture
  • Cross-tenant access settings
Microsoft Intune
  • Device enrollment and join-state posture: Entra joined, hybrid joined, registered
  • Compliance policy inventory and non-compliant device analysis
  • Configuration profile drift and conflict detection
  • Windows LAPS coverage and local administrator exposure
  • The device-compliance-to-Conditional-Access dependency chain

Supplemental, read-only

These products' findings are consumed into the audit. We do not operate, tune, monitor, or respond to them.

Microsoft Defender for Identity

Posture assessments are consumed and triaged into the audit, mapped to the same identity graph as everything else so a Defender finding and an Entra finding about the same object appear together.

Microsoft Defender for Cloud Apps

OAuth application governance, consent grant review, and the shadow-IT identity surface: which third-party applications hold delegated or application permissions in your tenant, granted by whom, and with what reach.

Licensing

Both require you to hold the relevant Microsoft license. Where you do not, those sections of the report become a licensing recommendation instead of a finding set. Findings across the whole audit are bounded by what your licensing exposes: PIM, access reviews, and Entra ID Protection need Entra ID P2 or the Entra ID Governance add-on.

Priced separately

On-premises Active Directory and hybrid identity

Priced per forest. Covers:

  • AD account and group hygiene
  • Entra Connect sync health and scoping
  • Hybrid join posture
  • Privileged AD group membership
  • Stale objects
  • Delegation review
Additional Microsoft tenants

Each distinct tenant is a pricing unit. Organizations running a commercial tenant alongside a GCC or GCC High tenant are common in our market. Reconciling them into one report, with the sovereign cloud collected through its own endpoint and its own app registration, is a core competency rather than an exception.

Pricing for add-ons and additional tenants →

We do one thing. Here's what we don't do.

Published so nobody has to find out during a sales call.

No detection, monitoring, alerting, or incident response

The audit tells you what your identity posture is and how it changed. It does not watch for attacks, and nobody is on the other end of a pager.

No Defender for Endpoint operation or alert triage

Endpoint detection is a separate discipline with a separate operating rhythm. We do not run it.

No email security or anti-phishing operation

Exchange Online Protection and Defender for Office 365 configuration and response are out of scope.

No Azure resource posture management or CSPM

Subscriptions, resource groups, storage, networking, and workload configuration are not part of the audit. Identity that reaches into Azure through Entra is.

No SOC services, no on-call, no round-the-clock coverage

Response commitments on the retainer cover governance requests during business hours. They are not an incident line.

No general Microsoft 365 administration, licensing procurement, or helpdesk

We will tell you what to fix and, within the included hours, help fix it. We do not run your tenant day to day.

See what the audit actually produces

The methodology page walks through collection, snapshots, reconciliation, rules, and reproducibility step by step.

How it works