Skip to content
Epic IT Support

Partner capability

Identity and access engineering, delivered under your brand

Identity is the project where a small mistake locks out an entire organization before lunch. It is also the one cyber insurers and auditors ask about first. We plan it, stage it, and roll it out with a rollback position at every phase — under your brand, through your change control.

  • Entra ID tenant design and hybrid identity
  • Conditional access and MFA staged from report-only
  • Domain, forest, and tenant-to-tenant migrations
  • AWS IAM least-privilege review and remediation
  • Privileged access tiering and just-in-time elevation
  • Access review evidence packaged for auditors

What we deliver

Microsoft Entra ID

Tenant design and hybrid identity — the layer everything else in a Microsoft estate depends on.

  • Entra ID tenant design, configuration, and hybrid join strategy
  • Entra Connect deployment, sync scoping, and filtering rules
  • Conditional access policy design with a staged rollout and break-glass accounts
  • Multi-factor authentication and passwordless deployment
  • Application registration, enterprise app SSO, and provisioning

Active Directory migration and remediation

Domain consolidations, divestitures, and cleanup of directories that have accumulated twenty years of exceptions.

  • Domain and forest migrations with object mapping and SID history
  • Tenant-to-tenant migrations following a merger or divestiture
  • Group Policy rationalization and privileged access tiering
  • Stale account, orphaned SPN, and permission sprawl remediation
  • Domain controller upgrades and functional level advancement

AWS IAM and cloud entitlements

Access models that survive an audit rather than granting everyone administrator and hoping.

  • IAM policy review against least privilege with concrete remediation
  • Role, trust relationship, and cross-account access design
  • Identity federation between Entra ID and AWS
  • Service account and access key lifecycle management
  • Entitlement review evidence packaged for auditors

Access governance

The recurring discipline that keeps identity from drifting back to where it started.

  • Joiner, mover, leaver process design and automation
  • Access review cycles with documented approver sign-off
  • Privileged access management and just-in-time elevation
  • Single sign-on rollout across the application portfolio
  • Identity-related findings mapped to insurance and audit requirements

Platforms we work in

Named platforms, not categories — so you can tell at a glance whether we already know your environment.

Microsoft identity
  • Entra ID
  • Entra Connect
  • Conditional Access
  • Active Directory
  • Group Policy
  • ADFS
Cloud entitlements
  • AWS IAM
  • IAM Identity Center
  • Azure RBAC
  • Azure Policy
Multi-factor & SSO
  • Microsoft Authenticator
  • Duo
  • SAML
  • OIDC
  • SCIM
Directory tooling
  • PowerShell
  • Microsoft Graph
  • ADMT
  • Quest Migration Manager

How it runs

From first call to sign-off

Every engagement is governed by a written statement of work naming deliverables, assumptions, and who is responsible for what.

  1. Current-state discovery

    We inventory what actually exists — domains, sync scope, conditional access, privileged groups, federated apps — before proposing any change.

  2. Target design and risk review

    A written design with an explicit rollback position, break-glass account plan, and named blast radius for every phase.

  3. Staged rollout

    Pilot group first, then progressive rings. Conditional access and MFA policies go to report-only before they go to enforce.

  4. Documentation and handover

    As-built configuration, policy inventory, and an operations runbook so your team owns it afterwards without calling us monthly.

Questions

What people ask

Identity and access engineering, delivered under your brand — questions

Why is identity work worth subcontracting rather than doing in-house?

Because the failure mode is total. A mis-scoped conditional access policy or a bad sync rule locks out every user at once, during business hours, with no way in. The work itself is not exotic; the consequence of getting it wrong is. Most partners would rather have someone who has done it fifty times drive the change window.

Can you migrate a directory during an acquisition?

Yes. Domain and forest migrations with SID history, tenant-to-tenant Microsoft 365 moves, and mailbox and OneDrive cutovers are recurring work for us. The technical migration is usually the easy half — the scheduling around business operations is where the engagement really lives.

Do you do conditional access rollouts without breaking things?

Every policy goes to report-only first, and we review the sign-in logs against it before enforcing. Break-glass accounts are created and excluded before any policy is written. The rollout is staged by ring, not flipped for the tenant.

Our client failed a cyber insurance questionnaire on access control. Can you help?

That is a common trigger for this work. We map the questionnaire items to concrete configuration changes — MFA coverage, privileged access separation, access review evidence, service account hygiene — and deliver the remediation plus the documentation the underwriter wants to see.

Will you work through our tooling and process?

Yes. Your PSA, your change control, your maintenance windows, your client communication. For identity work in particular we insist on your change control being followed, because unannounced identity changes are how outages happen.

Planning a directory change you would rather not do alone

Tell us the current state and the target. We will tell you where the blast radius is and how to stage around it.