Service · Cybersecurity

Access control and endpoint security

Who can sign in, from which machine, and what may they launch once they are on it? How you answer those three questions decides whether a phished password becomes an incident or just one more rejected attempt in a log. NIS2 lists multi-factor authentication by name among the minimum safeguards, and cyber insurers now put it on the questionnaire you fill in before they will quote.

Sign-in
password plus a second factor
Hardware
company-managed only
Software
vetted titles only
Admin
granted per task

Included in this service

Few firms need the full toolkit on day one. If a customer contract or your insurer insists on it, we put everything in. If the aim is simply less risk, we open with the controls that shut the most common attack routes.

Talk the scope through with an engineer

Second factor and sign-in policies

Microsoft Authenticator with number matching, or hardware FIDO2 keys for directors and the finance team. Conditional Access turns away logins from countries you do not trade with and from equipment the company has never enrolled.

Device compliance

Before a laptop gets anywhere near mail, Teams or SharePoint, Intune confirms the drive is encrypted, the OS is current and protection is running.

Admin rights

Staff stop being administrators of their own PCs. Windows LAPS rotates the passwords of local admin accounts, so each one is unique and changed regularly.

Application control

App Control for Business or AppLocker permits nothing but vetted programs. An executable pulled out of an email attachment simply refuses to launch.

USB storage

Named sticks and drives are permitted; the rest are refused or set to read-only, and every plug-in event lands in the log.

Privileged accounts

Separate identities for admin work, Privileged Identity Management, and elevated rights that expire after an hour instead of lasting forever.

How we work together

Each control goes live on its own, remotely, while we watch whether anyone has been blocked from doing their job. The timeline depends on the number of workstations and is agreed at the start.

01

Inventory

We list accounts, devices, licences and the programs each department really uses, and separate what a contract or audit demands from what is simply worth doing.

02

Report-only phase

Application control and sign-in rules start by logging, not enforcing. After an observation period it is clear what would have been stopped, before anything actually is.

03

Pilot group

A handful of people from different teams, because the warehouse, HR and sales rely on entirely different tools. Exceptions get fixed before the change reaches everyone.

04

Rollout and upkeep

The rules are extended company-wide, then we handle requests for new software and review blocks in a periodic report.

Somebody will lose the phone with their authenticator on it, so settle the procedure early. Without one, your chief accountant loses half a day in the middle of month-end close. During the rollout we agree who confirms an employee's identity on a video call and issues a one-off Temporary Access Pass, and where the spare FIDO2 keys are kept.

Questions and answers

Put a second factor on every account and switch off the legacy sign-in protocols that sidestep it. It often needs no extra licences. Application control pays off hugely but asks for more discipline, so it comes second.

That depends on your Microsoft 365 plan. Some features, such as conditional access, device management or Privileged Identity Management, come only with certain plans or add-ons. First we check what you are already paying for.

You can allow them into the browser version of Microsoft 365 only, with file downloads blocked. Full access to company data stays with hardware managed by Intune. It is a sensible compromise for remote and hybrid teams.

They request it through a form or the company portal. Anything already in the catalogue they install themselves in one click; new titles are approved once we have checked the source and the digital signature, within the response time of your plan.

The first week brings a few tickets, then things quieten down. Intune installs printers, drivers and updates, and a one-off elevation can be granted remotely for a specific job.

Tighten access to company devices

Say roughly how many desks you have and which Microsoft 365 plan you are on. We will propose an order of work and begin with a report-only pilot.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.