When you need it
Your admins use the same account and laptop for email, browsing and production changes. Several hold permanent Global Administrator or Owner rights, so one phished session could reach everything.
What sets the quote
- Sized by privileged identities, the privileged roles they hold and the number of privileged access workstation (PAW) devices.
- A typical engagement covers one Entra tenant, up to 20 admins, 40 privileged role assignments in Entra ID and Azure, and 10 PAW devices, in 2–3 weeks.
- Azure roles in scope include Owner, User Access Administrator and other privileged roles at management group and subscription scope.
- More admins, more tenants and on-premises Active Directory tier 0 are quoted after sizing.
What changes
- Admin work happens in separate admin accounts on dedicated workstations, away from email and web browsing.
- Admin rights are activated just in time, with approval for the most critical roles, and expire when the task is done.
- Conditional Access lets admins in only from compliant PAWs with phishing-resistant MFA.
- Two break-glass accounts give you a tested way back in if everything else fails.
What you get
- Admin tier model based on Microsoft's enterprise access model, with separate admin accounts per tier
- PAW design and Intune build for up to 10 Windows devices, enrolled through Windows Autopilot, with a hardened baseline, application allow-listing and restricted web access
- PIM for Entra and Azure roles, with approvals, time limits, notifications and access reviews
- Conditional Access for admins that requires phishing-resistant MFA and a compliant PAW
- Two break-glass accounts with FIDO2 security keys, sign-in alerts and a tested procedure
- Standing admin rights removed, with each remaining exception recorded and owned
- Admin runbook and a handover session
Choose this package when one phished admin session is your biggest risk. The Microsoft 365 security baseline already covers PIM and break-glass accounts. This package adds separate admin accounts per tier, dedicated workstations and Conditional Access that refuses admin sign-ins from anywhere else.
Not included
- Hardening on-premises Active Directory tier 0 (domain controllers, AD CS and Entra Connect servers), quoted after sizing
- Reworking service accounts and applications that hold admin rights; we list them and quote the fix
- A separate privileged access management product, such as a password vault or session recording
- PAW hardware and licences (PIM needs Entra ID P2 or Entra ID Governance)
What we need from you
- Entra Global Reader and Azure Reader at the root management group, to map current access.
- For the rollout, time-limited: Privileged Role Administrator, Conditional Access Administrator and Intune Administrator in Entra ID, and User Access Administrator in Azure.
- Windows devices for the PAWs, and two admins to pilot them.
- A named owner who approves each rollout stage.
How it works
Free 30-minute call, then the counts that size the work (admins, privileged role assignments, PAW devices) and a written fixed quote.
Map every admin account, its roles and where it signs in from, then set up and test the break-glass accounts before any blocking policy.
Design the tier model, PAW build and PIM roles with your team, then roll out in stages from the highest tier.
Remove standing rights and hand over the runbook.
At a glance
- Duration
- 2–3 weeks
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
PKI review
A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.
Domain and external attack surface check
A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.
Microsoft 365 security baseline
Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.