Skip to content

    Identity is your new perimeter — we set it up properly

    Entra ID, MFA and Conditional Access govern access using identity, device, location and risk. We design traceable policies and test them before rollout.

    Microsoft Entra sign-in log with activity details open for a sign-in event.
    Microsoft Entra IDSign-in events expose status, authentication requirement and additional signals.

    One sign-in. Four signals. One clear decision.

    Three real product views show where sign-in signals, policy decisions and evidence become visible.

    Every sign-in carries context.

    Entra ID evaluates the user, device compliance, location and known risk signals together.

    Microsoft Entra sign-in log with activity details open for a sign-in event.
    Microsoft Entra IDSign-in events expose status, authentication requirement and additional signals.
    Passwordless as the goal, not a dream

    Windows Hello, FIDO2 keys and passkeys make the password obsolete — more secure and noticeably easier day to day. Fewer password resets, faster sign-in, no reusing weak passwords.

    Least privilege and a clean lifecycle

    We harden admin roles with PIM, set up access reviews and ensure clean onboarding and offboarding. So if something goes wrong, the damage stays contained — and nothing is left open when someone leaves.

    Microsoft 365 is not secure out of the box

    The default settings still allow legacy protocols that bypass MFA entirely, and much of what you pay for sits unused. Only 42 percent of Swiss SMEs feel adequately protected — and those exact gaps are what token theft, consent phishing and CEO fraud exploit. You are paying for protection that was never switched on.

    A visible change, not another tool rollout.

    Before: blanket accessA password and default rules decide without enough context.
    After: conditional accessDefined signals and policies govern every sign-in with a traceable decision.
    Deliverables
    Project handoverIdentity Baseline

    Entra ID · MFA · Conditional Access · Emergency access

    1. 01Entra ID as your identity control planeSetup of Microsoft Entra ID (formerly Azure AD) as the central control over access, sign-ins and identities — the foundation for everything else.
    2. 02Conditional Access on Zero Trust principlesGranular policies over signals like device compliance, location and sign-in risk. Included in M365 Business Premium (Entra ID P1) — we roll them out in report-only mode first, without disrupting your operations.
    3. 03MFA and passwordless sign-inAuthentication strengths, FIDO2 keys, Windows Hello for Business, passkeys, Microsoft Authenticator and Temporary Access Pass — all under Entra ID P1, which you most likely already own.
    4. 04Risk-based protection with Entra ID P2Where needed we add risk-based Conditional Access and Entra ID Protection (risky users and sign-ins, alerts). This requires Entra ID P2 — available via the Microsoft Defender Suite for Business Premium add-on (formerly Microsoft 365 E5 Security). We tell you honestly when it is worth it.

    Your identity baseline.

    A documented set of policies, roles, emergency access and a rollout plan.

    • Entra ID as your identity control planeSetup of Microsoft Entra ID (formerly Azure AD) as the central control over access, sign-ins and identities — the foundation for everything else.
    • Conditional Access on Zero Trust principlesGranular policies over signals like device compliance, location and sign-in risk. Included in M365 Business Premium (Entra ID P1) — we roll them out in report-only mode first, without disrupting your operations.
    • MFA and passwordless sign-inAuthentication strengths, FIDO2 keys, Windows Hello for Business, passkeys, Microsoft Authenticator and Temporary Access Pass — all under Entra ID P1, which you most likely already own.
    • Risk-based protection with Entra ID P2Where needed we add risk-based Conditional Access and Entra ID Protection (risky users and sign-ins, alerts). This requires Entra ID P2 — available via the Microsoft Defender Suite for Business Premium add-on (formerly Microsoft 365 E5 Security). We tell you honestly when it is worth it.
    • Defender and Purview as complementary pillarsMicrosoft Defender (Safe Links, Safe Attachments, anti-phishing) protects against malicious content; Purview handles DLP, sensitivity labels and audit logs for your evidence trail.
    • Operational safety and handoverBreak-glass emergency accounts, documented policies and training for your people. Because technology alone changes nothing — adoption across the team is what decides.

    What the new working model should achieve.

    Zero Trust
    MFA and Conditional Access applied consistently
    Day 1
    baseline protection via Security Defaults active immediately
    revDSG
    demonstrable compliance via audit logs and access control

    The effect is reviewed in report-only mode before the policies are introduced in a controlled rollout.

    Frequently asked questions

    Does our identity data stay in Switzerland?

    Honestly: not exclusively. Entra identity data follows the EU Data Boundary (EU plus EFTA — Switzerland is included), not a Switzerland-only arrangement. Core Office 365 content, by contrast, can be pinned to the Switzerland Geo. One caveat: SMS, voice and push notifications can be processed outside that boundary — OATH hardware tokens keep the data inside. We draw this line correctly for you.

    Do we need expensive add-on licences?

    Usually not. Most of it — Conditional Access, FIDO2, Windows Hello, passkeys, authentication strengths — sits in Entra ID P1, which is included in Microsoft 365 Business Premium. It just needs configuring correctly. Only risk-based protection and Entra ID Protection require P2. We recommend an add-on only when it concretely helps you.

    Will the change disrupt daily operations?

    No. We roll out Conditional Access in report-only mode first and see what would happen before anything is blocked. Emergency break-glass accounts stay excluded so you can never be locked out. The transition is gradual and coordinated.

    Does this help with cyber insurance?

    Yes. Many insurers require MFA and Conditional Access and ask about them in their questionnaires. With protection set up correctly and audit logs in place, you meet these requirements demonstrably — which often lowers the premium and makes the policy possible at all.

    Let's talk about your workplace.

    Whether it's migrating to Microsoft 365, zero-trust security or a Copilot rollout — together we'll find the right path.

    We use cookies and external services (e.g. Google Maps) to provide you with the best experience on our website. For more information, see our Privacy Policy.