Get in touch
Identity and MFA

Identity and MFA: protect accounts before they are targeted

Passwords get stolen, guessed and reused. We set up identity in Microsoft Entra, with multi-factor authentication and access rules, so a stolen password is not enough.

In most businesses Microsoft 365 holds the email, the documents and the communication. Whoever gets into a user's account gets into all of it. That is why protecting identity is one of the first measures we recommend.

Microsoft Entra is the identity service of Microsoft 365. Depending on the licence you have (for example Business Premium includes Conditional Access), we set up MFA, access rules and sign-in monitoring.

What is included
  • MFA for all users, with a guide for staff
  • Conditional Access: rules for when, from where and with what device sign-in is allowed
  • Blocking legacy sign-in methods that bypass MFA
  • Protection of administrator accounts
  • A process for joiners and leavers
  • Monitoring and alerts for suspicious sign-ins
  • Licence review: what of the above is already included in your licence

Frequently asked questions

Does MFA annoy users?

Set up properly, it asks for confirmation rarely, for example from a new device or location. We design the experience so it does not get in the way of work.

Do I need a more expensive licence?

It depends. The basics of MFA are available in all licences, while the more flexible rules need specific ones. We tell you what is worth it in your case.

Is MFA enough on its own?

No. It is one of the essential measures. See also the security bundle, which combines it with device protection, email, updates and backup.

Is it related to NIS2?

Yes. NIS2 explicitly mentions the use of multi-factor or continuous authentication, where appropriate, among the risk-management measures.