Know exactly who can reach what, and be able to prove it.

Every account and every admin right, mapped and recorded, so the answer is written down rather than carried in someone's head. We straighten out Active Directory and Entra ID, set conditional access that matches how your people work, and make sure access ends the day someone leaves. Ask us to assess it, fix it, or run it for good.

You do not need a crisis to engage us.

Perhaps an auditor has asked who holds access to a given system, and you cannot answer with confidence. Most estates carry the same weight: accounts still live for people who left, guest access from collaborations that ended years ago, admin rights nobody has reviewed, entitlements that have crept over long tenures. Or everything works as it should, and you want it brought to a higher standard before anyone asks. Either way we start by mapping the estate as it stands. Every group, role, guest and exception is checked against what it was meant to allow. The plan is built on that, not on an out-of-date diagram.

Entra ID and Active Directory, put right end to end.

Conditional access shaped around how your people actually work. Who they are, where they are, and whether the device can be trusted all feed the decision, and the reasoning is written down rather than buried in a setting no one remembers turning on. Where Active Directory on-site still underpins everything, we rebuild the link to Entra ID cleanly rather than leaving the wiring as it was set up years ago.

Conditional access policies anyone on your team can read top to bottom, exceptions included. Every exception says whose account it covers, why it exists, what keeps it safe, and when it gets checked again. The break-glass accounts that get you back in when all else fails sit outside the policies and are watched on their own.

No standing admin rights left permanently active and exposed. With Privileged Identity Management (PIM), administrators elevate only for the task at hand, with approval and an audit record where it matters, and the rights are withdrawn once the task is done. Ordinary day-to-day logins stop carrying admin at all, and the automated accounts your systems run on are held to the same line.

Joining, changing role and leaving are run as one defined process, joiner-mover-leaver, rather than an ad-hoc handover between HR and IT. Routine cases are handled consistently, access reviews catch anything missed, and a leaver loses every form of access on the day they depart, not only the obvious one.

Sign-in rules decided on purpose.

We answer three questions before any conditional access policy goes live, so your team can follow the decision and defend it.

When to ask for stronger proof

Turning on an admin role, opening your most sensitive data, signing in from somewhere unexpected. We tie phishing-resistant MFA to those moments and write it into the policy ahead of time, so the decision is settled in advance, not made under pressure during an incident.

When to rein a session in

A browser on a machine you do not manage, someone's own phone, a contractor reaching in from outside. We set how long the session lasts, whether files can be downloaded, and when to ask again, matched to the risk, so controls hold without obstructing day-to-day work.

When a trusted device earns less friction

A company laptop that is managed, up to date and checking out clean. When the device itself is sufficient proof, we remove the extra checks, so scrutiny falls where the genuine risk is.

What you receive, in writing.

Deliverable

A straight answer to who holds admin.

Every admin right laid out, however it was granted, whether handed to a person, inherited through a group, or held by an account your systems run on. We check it against what is live today and put the cuts in the order that lowers your risk fastest, not the order that is easiest.

Deliverable

A clean set of access rules you can defend.

Policies anyone can audit, with every exception logged and dated, the right checks where they belong, brought in a stage at a time so your team can follow every change as it lands.

Deliverable

A leaver process that shuts every door.

The same steps run every time someone leaves, with access reviews to catch any account that is missed, so no former employee retains an active login.

An identity review, agreed and priced before we start.

What you get

A plain written report and a fix-it plan in the order that matters most.

Your accounts and access, read against what is live right now.

We look at Active Directory and Entra ID, the conditional access policies and who can override them, the admin rights and how they are held. We cover guests and outside parties, the accounts your systems log in with, and the joiner-mover-leaver process where that is included. It comes back with the fixes ranked by what reduces your exposure most while causing your people the least disruption.

Scope
Set with you on the first call, and priced, before any work starts.
Deliverables
The report, the ranked list of what to change, and a walk-through with the people who will carry it out.
Continuity
If you take the fixes or ongoing care further, the same lead stays on it.
Book the identity review

Most incidents start at a sign-in. Factor1 watches identity day and night, and acts on what it sees.

Identity is one piece. We look after the whole.

Under one agreement, the estate is watched, maintained and documented as a single thing, by the team behind this page.

Microsoft 365IdentityWindows ServerNetworks & accessEndpoint securityBackup & DREmailDevices

…and everything between.

Book an identity review

Cardiff based, working remotely. A senior engineer is on the call from the outset.

Show us your access the way it really is.

A first call with a senior engineer who would run the job. Tell us what you know about the setup, including the parts that were never documented and the areas you are least comfortable with. You will leave the call knowing whether this is work we should take on, and where we would start.

Centraline logo Built from scratch & fully managed by Centraline