Skip to content

Identity-first workspace. Audit-ready in 21 days.

Conditional Access policy-as-code, JIT admin and SCIM joiner-mover-leaver for Microsoft 365 and Google Workspace, shipped as a fixed-scope product with DORA, NIS2 and ISO 27001 evidence per control.

21 days
To Conditional Access go-live
100% MFA
Enforced post-implementation
Zero
Standing admin sessions
DORA · NIS2 · ISO
Evidence mapped per control
The Sprawl

Your identity perimeter is a sieve. Quietly.

The average EU SME runs Microsoft 365 or Google Workspace with default policies, opt-in MFA and a backlog of OAuth grants no one has reviewed. Compromise comes from sessions and consents, not passwords.

Standing admin & dormant tokens

Permanent Global Admins, six-month-old service principals, OAuth grants nobody remembers consenting to. One phished session ends the company.

Shadow SaaS & ungoverned grants

Engineers wire Notion, Linear, Zapier and a dozen AI tools to corporate identities. Nobody owns the inventory and offboarding leaks data on day one.

Joiner-Mover-Leaver chaos

New hires wait three days for access. Leavers keep mailbox forwards live for weeks. Every audit finds it. Every quarter you promise to fix it.

Productized engagements

Start free. Then fixed scope, never T&M.

Run the posture scan yourself in minutes, then step up to a fixed-scope implementation or a managed retainer. No hourly billing at any tier.

Workspace Posture Scan

Run it yourself. Walk away with the gap map. No call required.

FreeSelf-serve · minutes
  • Inactive, blocked, guest and shared accounts flagged across Microsoft 365 / Google Workspace
  • Shadow SaaS and OAuth-grant inventory, risky scopes ranked
  • Connect Microsoft 365 read-only: live MFA, Conditional Access, admin-role and risky-sign-in posture
  • DORA / NIS2 / ISO 27001 compliance gap map, scored per control
  • Unified estate score plus a CFO-ready PDF you keep

Outcome

Your full identity posture and compliance gap map, free, today. The natural lead-in to the implementation.

Run the free scan
Most popular

Zero Trust Implementation

Ship the controls. End the standing access.

Scoped to youFixed fee · 4-5 weeks
  • Conditional Access baseline as code (Terraform + Microsoft Graph)
  • JIT admin via PIM or Granted (CommonFate), zero standing privilege
  • SCIM joiner-mover-leaver for the first 5 SaaS apps
  • Device compliance baseline (Intune / Workspace endpoint)
  • Unified audit log to S3 / Loki + Identity exposure dashboard

Outcome

100% MFA enforcement, zero standing admin within 30 days of go-live.

Scope the implementation

Managed IAM

We run access reviews. You ship product.

Scoped to youMonthly retainer · 6 months min.
  • Quarterly access reviews + evidence pack
  • Joiner-Mover-Leaver SLA (provision in 4h, deprovision in 1h)
  • Anomaly response on impossible travel & token theft
  • OAuth-grant governance and SaaS additions
  • One shared Slack channel with the engineer

Outcome

Continuous control evidence, audit prep that writes itself.

Talk about managed IAM
What you actually get

Concrete artefacts, not slide decks.

Conditional Access policy-as-code

Entra / Workspace policies in Terraform. MFA enforcement, geo-fencing, device compliance, risk-based session controls, all reviewable in pull requests.

JIT admin (zero standing privilege)

Privileged Identity Management or Granted Auth: admins request a role, approval flows to Slack, access auto-expires. No more permanent Global Admins.

Joiner-Mover-Leaver via SCIM

Hire-to-deprovision automation against your HRIS. Group-based entitlements, role catalogs, off-boarding playbooks signed by the engineer.

Device compliance baseline

Intune / Google Endpoint policies: disk encryption, screen lock, OS minimums, no jailbreak. Wired into Conditional Access so non-compliant = no access.

Identity exposure dashboard

Grafana over the unified audit log. MFA coverage, dormant accounts, admin session length, risky sign-ins, OAuth grant timeline, all in one pane.

DORA / NIS2 / ISO 27001 evidence pack

Each policy mapped to DORA Art. 9, NIS2 Art. 21(2)(i) and ISO 27001 Annex A.5 access controls. Copy-paste into your next audit or self-assessment.

What it looks like on the day you go live.

Identity Exposure/ Grafana
Live · 24h
MFA coverage
98.2%
enforced via CA
Dormant accounts
14
no sign-in 90d
Permanent admins
2
break-glass only
High-risk sign-ins
3
last 30 days
OAuth grants90 days
MFA by groupenforced
Engineering
100%
Finance
100%
Sales
96%
Contractors (BYOD)
88%
Evidence pack/ control crosswalkexcerpt
ControlDORANIS2ISO 27001
MFA enforcement (CA-001)Art. 921(2)(i)A.5.15
Block legacy auth (CA-002)Art. 921(2)(c)A.5.16
Privileged strong auth (CA-003)Art. 921(2)(i)A.5.18
PIM eligibility (PIM-001)Art. 921(2)(i)A.5.18
SCIM JML (SCIM-001)Art. 921(2)(i)A.5.16
Audit fan-out (AUDIT-001)Art. 1121(2)(c)A.8.15

Lifted verbatim from the engagement SOP, then attached per control with portal and Grafana screenshots for your auditor.

Malta & EU compliance

DORA, NIS2 and ISO 27001, mapped per control.

DORA

Article 9: protection and prevention. Conditional Access, JIT admin and SCIM map directly to the ICT protection objectives.

NIS2

Article 21(2)(i): access control policies and asset management. Joiner-Mover-Leaver SOP and quarterly reviews documented.

ISO 27001

Annex A.5/A.8: access control, segregation of duties, privileged access. Mapped per policy for regulated operators.

FAQ

Honest answers to the questions buyers actually ask.

Why not just buy Okta or Microsoft Entra P2 and call it done?

+

Licences are the easy part. They sit unused in 90% of the SMEs we audit. The hard part is policy design, exception handling, joiner-mover-leaver automation, and quarterly access reviews that produce real evidence. We bring the templates, the runbooks and the Terraform. Your existing licences finally start earning their keep.

How is the IAM Posture Scan safe? You are reading our directory.

+

The scan is read-only. You consent to a multi-tenant Microsoft Graph app (or a Google Workspace service account) with read-only scopes. We never receive password reset, write-policy or impersonation scopes. All evidence is stored encrypted in the EU (Hetzner Falkenstein) and destroyed on request.

We are mostly BYOD / contractors. Does Conditional Access still work?

+

Yes. We design two enforcement tiers: managed devices get full SSO + persistent sessions, BYOD and contractors get short-lived sessions plus app-protection policies. Sensitive scopes require a managed device or a hardware key regardless.

How is this different from Vanta, Drata or Secureframe?

+

Those products collect evidence; they do not configure controls. We ship the controls (Conditional Access, PIM, SCIM, device compliance) as Terraform you own, then optionally feed Vanta/Drata with the audit log so their dashboards turn green.

We are a FinTech regulated by an EU competent authority. How does this map to DORA?

+

Every Conditional Access policy, JIT approval flow and access review carries an explicit mapping to DORA Article 9, NIS2 Article 21(2)(i) and ISO 27001 Annex A.5/A.8. The implementation closes with an evidence pack formatted for your next supervisory review.

What happens if we cancel the managed retainer?

+

Nothing breaks. Every Conditional Access policy, SCIM mapping and dashboard lives in your Git repository. The Terraform state is yours. The runbooks are yours. We hand over a recorded engineer training session and the Slack channel stays open for 30 days.

Provisioned stack

Licences that can sit under Zero Trust Security.

ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.

Microsoft

Microsoft 365 Business Premium EEA (no Teams)

€19.54 / user / month

Monthly commit

Includes Defender for Business, Defender for Office 365 P1, Entra ID P1, Intune P1 - never double-sell these alongside BP.

View bundle

Microsoft

Microsoft 365 E3 EEA (no Teams)

€36.43 / user / month

Monthly commit

Microsoft

Microsoft 365 E5 EEA (no Teams)

€60.85 / user / month

Monthly commit

Microsoft

Microsoft Defender for Office 365 (Plan 1)

€2.08 / user / month

Monthly commit

Microsoft

Microsoft Entra ID P1

€7.32 / user / month

Monthly commit

Microsoft

Microsoft Entra ID P2

€10.44 / user / month

Monthly commit

Nord Security

NordLayer Business VPN (ZTNA)

Usage-based, quoted

Monthly commit

Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user network-access platform: apps plus browser extension, ZTNA/SASE, central gateway and logs. Business-correct alternative to consumer VPNs (Surfshark/NordVPN). Sold quoted/usage-based.

Nord Security

NordPass Business (password manager)

Usage-based, quoted

Monthly commit

Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user password manager with admin console and policy. Pairs with NordLayer in the Secure Remote Workforce / Zero Trust Starter bundles (planned). Sold quoted/usage-based.

Take the standing admin rights away, one role at a time.

The workshop lists who holds privilege today, decides which roles become eligible rather than permanent, and sets the break-glass path before anything is switched on.