← Back to all resources

Field guide

2 min read

Identity is the new security perimeter.

A practical framework for strengthening access without creating unnecessary friction for users or administrators.

Verified identity network connecting users, devices, and applications

Access follows people beyond the office

Employees, contractors, and service accounts reach applications from many locations. A trusted office network is no longer enough context for deciding whether an access request is appropriate.

For organizations handling client files, financial information, or operational systems, identity needs the same attention traditionally given to the network perimeter.

Start with the access lifecycle

Techhands examines how accounts are created, approved, changed, and removed. Role changes deserve particular attention: employees can accumulate access long after the original reason disappears.

A practical review covers privileged users, external collaborators, shared accounts, and nonhuman identities. Each needs an owner and a reason to exist. Routine access requests should be easy to follow so staff are less tempted to work around the process.

Access review checklist

  • Identity: record the person or service, purpose, owner, and authentication method.
  • Permission: compare current access with the work the identity is approved to perform.
  • Lifecycle: test joiner, role-change, and departure steps, including downstream applications.
  • Exceptions: name the approver, reason, expiry, and compensating control.
  • Validation: test normal access, denied access, and emergency access before wider rollout.

Apply controls without losing usability

Multifactor authentication, separate administrative accounts, and periodic access reviews provide a useful foundation. Microsoft Entra Conditional Access can combine signals to apply access policies, such as requiring additional verification in defined circumstances.

Roll out changes through a pilot and review the effect on real work. Preserve tested emergency access arrangements and document how support will handle a legitimate user who cannot complete the usual sign-in process.

Microsoft: Conditional Access

Measure whether access stays appropriate

Useful measures include orphaned accounts, overdue access reviews, privileged access exceptions, and the time required to remove access after departure. A successful rollout also considers avoidable user friction.

The goal is an access model that remains understandable as the business changes. Identity controls need maintenance, clear ownership, and communication as much as they need technical configuration.

LET'S MOVE FORWARD

Make your next technology decision with confidence.

Tell us what needs to improve, what must keep working, and the decision you need help making.

Start a Conversation  →

A focused conversation to understand the need and agree whether there is a useful next step.

WHAT WE’LL DISCUSS
01

Your priority

The problem, its business impact, and what a useful result would look like.

02

Your environment

The systems, people, providers, and constraints already in place.

03

A sensible next step

Whether discovery, advice, a project, or operational support fits the need.