Cloud and identity

Most cloud incidents are a configuration, not an exploit.

A review of how your Microsoft 365, Entra ID, Azure and AWS tenancies are actually configured — and of who can reach what.

Microsoft 365 and Entra IDAzure and AWSFixed price per scope

What we look at

Microsoft 365 and Entra ID

Conditional access, legacy authentication, privileged roles and how they are assigned, guest access, application consent, mailbox delegation and forwarding rules, and whether your logging would actually tell you an account had been taken over.

Azure and AWS

Identity and entitlement review, network exposure, storage and key handling, logging and retention, and the gap between what the tenancy permits and what anyone needs.

What you get

  • Findings ranked by what an attacker could reach, with the path written out
  • Configuration mapped to the ACSC Essential Eight where it applies
  • A remediation list ordered by effort against risk, so it can be scheduled
  • A walkthrough with the engineer who did the review

This is a configuration and identity review, carried out with read access. Where you need an adversarial test with exploitation and proof,penetration testing is the right engagement — and the two are often scoped together.

Not sure who has standing access to what?

A short conversation is usually enough to work out whether we can help, and what it would cost.