Who may sign in, from which device, and what are they allowed to run on it? Those three answers decide whether a stolen password ends as a serious incident or as one refused line in a log. Multi-factor authentication is named outright among the baseline measures NIS2 expects, and insurers now ask about it in the questionnaire before writing cyber cover. The rest, admin rights and approved applications, decides what an attacker can do once inside.
Not every company needs the full set from day one. Where a customer or an insurer demands it, we deliver the lot; otherwise we begin with the parts that cut off the most common attack routes.
Microsoft Authenticator with number matching, or FIDO2 keys for the leadership and the finance team. Conditional access rules turn away sign-ins from countries where you do no business and devices the company has never seen.
Device compliance
Intune checks that a laptop is encrypted, patched and protected. Only then does it reach the mailbox, Teams and shared documents.
Administrator rights
Staff stop being administrators of their own machines. Local administrator passwords are rotated automatically by Windows LAPS, so each one is unique and changed on a schedule.
Application control
App Control for Business or AppLocker allows only approved programs to run. An executable that arrived as an attachment simply will not start, however determinedly somebody clicks it.
USB media
A list of permitted sticks and drives, blocking or read-only for everything else, and a record of each connection so a sequence of events can be reconstructed later.
Privileged accounts
Separate accounts for administration, elevation granted for an hour rather than for ever, and a quarterly review of who still holds it.
The way an engagement runs
Each mechanism is switched on separately and remotely, watching whether anyone ends up stuck. The timetable follows the number of machines and is agreed at the start.
01
Inventory
Accounts, devices, licences and the software each department genuinely uses. We separate what a contract or an audit demands from what you would do of your own accord.
02
Audit mode
Application control and conditional access rules begin by reporting only. After a few weeks you can see exactly what would be blocked before anything is blocked.
03
Pilot group
A handful of people from different departments, because the workshop, the payroll office and the sales team use entirely different tools. Exceptions are settled before the change touches everyone.
04
Roll-out and after
Extension across the company, then handling requests for new software and reviewing the blocks in a periodic report.
The phone carrying the authenticator app will eventually be lost or replaced, and the procedure has to exist before that day. Without it, the head of finance loses half a day in the middle of a month-end close. During the roll-out we therefore agree who verifies the person's identity over video, who issues them a temporary access pass, and where the spare keys are kept.
Questions and answers
With a second factor on every account and with closing the legacy sign-in protocols that quietly bypass it. That usually needs no extra licence at all. Application control gives a lot back but demands sustained discipline, so it comes second.
It depends on your Microsoft 365 plan. Conditional access, device management and privileged identity management appear only in certain plans or add-ons. We look at what you already pay for before suggesting a single euro of extra spend.
For the first few days a handful of requests arrive, mostly from departments used to installing their own tools. We prepare a catalogue of common software installed in advance, plus a controlled temporary elevation for the odd case. After a fortnight the subject fades away, and so do infections from downloaded executables.
Yes, without taking over the device. App protection separates work data from the rest of the phone: company mail is encrypted, copying into a private app is blocked, and only the work side is wiped when someone leaves. That boundary belongs in your IT charter.
With accounts that carry an end date from the moment they are created, and rights based on a standard job profile rather than copied from a colleague. The account closes itself on the agreed date, which avoids the roll of ghost accounts we find in almost every first inventory.
When we are around Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through A call on Teams or Google Meet, whenever writing is not enough
Message received
An answer follows inside one working day. Report an outage that is stopping people working and it moves ahead of everything else.
Anything unclear gets asked. Where a figure needs detail we do not have, expect an e-mail or an offer of a short call on Teams or Google Meet.
A proposal follows. What is covered, the figure in euros excluding VAT, and a start date that will hold. Nothing hides beneath an asterisk.
Then it is your call. The proposal sits in your inbox for as long as you need. Query any line of it, and decide once you are satisfied.
Which city are you in?
Nothing here under that name. Check the spelling, or simply choose the nearest large city instead. Since every engagement runs remotely, whichever you pick changes nothing about what we do for you.
We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.