Identity-first workspace. Audit-ready in 21 days.
Conditional Access policy-as-code, JIT admin and SCIM joiner-mover-leaver for Microsoft 365 and Google Workspace, shipped as a fixed-scope product with DORA, NIS2 and ISO 27001 evidence per control.
Your identity perimeter is a sieve. Quietly.
The average EU SME runs Microsoft 365 or Google Workspace with default policies, opt-in MFA and a backlog of OAuth grants no one has reviewed. Compromise comes from sessions and consents, not passwords.
Standing admin & dormant tokens
Permanent Global Admins, six-month-old service principals, OAuth grants nobody remembers consenting to. One phished session ends the company.
Shadow SaaS & ungoverned grants
Engineers wire Notion, Linear, Zapier and a dozen AI tools to corporate identities. Nobody owns the inventory and offboarding leaks data on day one.
Joiner-Mover-Leaver chaos
New hires wait three days for access. Leavers keep mailbox forwards live for weeks. Every audit finds it. Every quarter you promise to fix it.
Start free. Then fixed scope, never T&M.
Run the posture scan yourself in minutes, then step up to a fixed-scope implementation or a managed retainer. No hourly billing at any tier.
Workspace Posture Scan
Run it yourself. Walk away with the gap map. No call required.
- Inactive, blocked, guest and shared accounts flagged across Microsoft 365 / Google Workspace
- Shadow SaaS and OAuth-grant inventory, risky scopes ranked
- Connect Microsoft 365 read-only: live MFA, Conditional Access, admin-role and risky-sign-in posture
- DORA / NIS2 / ISO 27001 compliance gap map, scored per control
- Unified estate score plus a CFO-ready PDF you keep
Outcome
Your full identity posture and compliance gap map, free, today. The natural lead-in to the implementation.
Zero Trust Implementation
Ship the controls. End the standing access.
- Conditional Access baseline as code (Terraform + Microsoft Graph)
- JIT admin via PIM or Granted (CommonFate), zero standing privilege
- SCIM joiner-mover-leaver for the first 5 SaaS apps
- Device compliance baseline (Intune / Workspace endpoint)
- Unified audit log to S3 / Loki + Identity exposure dashboard
Outcome
100% MFA enforcement, zero standing admin within 30 days of go-live.
Managed IAM
We run access reviews. You ship product.
- Quarterly access reviews + evidence pack
- Joiner-Mover-Leaver SLA (provision in 4h, deprovision in 1h)
- Anomaly response on impossible travel & token theft
- OAuth-grant governance and SaaS additions
- One shared Slack channel with the engineer
Outcome
Continuous control evidence, audit prep that writes itself.
Concrete artefacts, not slide decks.
Conditional Access policy-as-code
Entra / Workspace policies in Terraform. MFA enforcement, geo-fencing, device compliance, risk-based session controls, all reviewable in pull requests.
JIT admin (zero standing privilege)
Privileged Identity Management or Granted Auth: admins request a role, approval flows to Slack, access auto-expires. No more permanent Global Admins.
Joiner-Mover-Leaver via SCIM
Hire-to-deprovision automation against your HRIS. Group-based entitlements, role catalogs, off-boarding playbooks signed by the engineer.
Device compliance baseline
Intune / Google Endpoint policies: disk encryption, screen lock, OS minimums, no jailbreak. Wired into Conditional Access so non-compliant = no access.
Identity exposure dashboard
Grafana over the unified audit log. MFA coverage, dormant accounts, admin session length, risky sign-ins, OAuth grant timeline, all in one pane.
DORA / NIS2 / ISO 27001 evidence pack
Each policy mapped to DORA Art. 9, NIS2 Art. 21(2)(i) and ISO 27001 Annex A.5 access controls. Copy-paste into your next audit or self-assessment.
What it looks like on the day you go live.
Lifted verbatim from the engagement SOP, then attached per control with portal and Grafana screenshots for your auditor.
DORA, NIS2 and ISO 27001, mapped per control.
Article 9: protection and prevention. Conditional Access, JIT admin and SCIM map directly to the ICT protection objectives.
Article 21(2)(i): access control policies and asset management. Joiner-Mover-Leaver SOP and quarterly reviews documented.
Annex A.5/A.8: access control, segregation of duties, privileged access. Mapped per policy for regulated operators.
Honest answers to the questions buyers actually ask.
Why not just buy Okta or Microsoft Entra P2 and call it done?
+
Licences are the easy part. They sit unused in 90% of the SMEs we audit. The hard part is policy design, exception handling, joiner-mover-leaver automation, and quarterly access reviews that produce real evidence. We bring the templates, the runbooks and the Terraform. Your existing licences finally start earning their keep.
How is the IAM Posture Scan safe? You are reading our directory.
+
The scan is read-only. You consent to a multi-tenant Microsoft Graph app (or a Google Workspace service account) with read-only scopes. We never receive password reset, write-policy or impersonation scopes. All evidence is stored encrypted in the EU (Hetzner Falkenstein) and destroyed on request.
We are mostly BYOD / contractors. Does Conditional Access still work?
+
Yes. We design two enforcement tiers: managed devices get full SSO + persistent sessions, BYOD and contractors get short-lived sessions plus app-protection policies. Sensitive scopes require a managed device or a hardware key regardless.
How is this different from Vanta, Drata or Secureframe?
+
Those products collect evidence; they do not configure controls. We ship the controls (Conditional Access, PIM, SCIM, device compliance) as Terraform you own, then optionally feed Vanta/Drata with the audit log so their dashboards turn green.
We are a FinTech regulated by an EU competent authority. How does this map to DORA?
+
Every Conditional Access policy, JIT approval flow and access review carries an explicit mapping to DORA Article 9, NIS2 Article 21(2)(i) and ISO 27001 Annex A.5/A.8. The implementation closes with an evidence pack formatted for your next supervisory review.
What happens if we cancel the managed retainer?
+
Nothing breaks. Every Conditional Access policy, SCIM mapping and dashboard lives in your Git repository. The Terraform state is yours. The runbooks are yours. We hand over a recorded engineer training session and the Slack channel stays open for 30 days.
Licences that can sit under Zero Trust Security.
ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.
Microsoft
Microsoft 365 Business Premium EEA (no Teams)
€19.54 / user / month
Monthly commit
Includes Defender for Business, Defender for Office 365 P1, Entra ID P1, Intune P1 - never double-sell these alongside BP.
View bundleMicrosoft
Microsoft 365 E3 EEA (no Teams)
€36.43 / user / month
Monthly commit
Microsoft
Microsoft 365 E5 EEA (no Teams)
€60.85 / user / month
Monthly commit
Microsoft
Microsoft Defender for Office 365 (Plan 1)
€2.08 / user / month
Monthly commit
Microsoft
Microsoft Entra ID P1
€7.32 / user / month
Monthly commit
Microsoft
Microsoft Entra ID P2
€10.44 / user / month
Monthly commit
Nord Security
NordLayer Business VPN (ZTNA)
Usage-based, quoted
Monthly commit
Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user network-access platform: apps plus browser extension, ZTNA/SASE, central gateway and logs. Business-correct alternative to consumer VPNs (Surfshark/NordVPN). Sold quoted/usage-based.
Nord Security
NordPass Business (password manager)
Usage-based, quoted
Monthly commit
Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user password manager with admin console and policy. Pairs with NordLayer in the Secure Remote Workforce / Zero Trust Starter bundles (planned). Sold quoted/usage-based.
Take the standing admin rights away, one role at a time.
The workshop lists who holds privilege today, decides which roles become eligible rather than permanent, and sets the break-glass path before anything is switched on.