What this covers
- Identity: MFA, Conditional Access-style policies where appropriate, and safer sign-in paths for email and admin.
- Endpoints: Defender (or equivalent) alignment, patching expectations, and device compliance that matches your stack.
- Password managers: rollout, policies, shared vaults, and habits that stick.
- Account lifecycle: onboarding and offboarding, stale admins, shared accounts, and recovery methods that do not create gaps.
- Device management: practical MDM/RMM choices and baselines when you need consistency across laptops and mobile.
What we're usually brought in to fix
- Passwords are shared in chat or stored in spreadsheets.
- MFA is inconsistent or "optional" for some users.
- You want improvements your team will actually use.
How we work
- Quick discovery: what apps matter, who has access, and where risk shows up.
- Rollout plan: scope, owners, and steps to avoid disrupting daily work.
- Handoff: plain-language notes, quick references, and a simple maintenance checklist.
Scope note: Compliance audits and formal certification work are separate scoped engagements.