IAM & Active Directory

Make identity a central control, including when the directory is under attack.

IKNSA connects entitlement governance, identity architecture, privileges, monitoring and recovery to reduce implicit access and critical dependencies.

Engineering trajectoryDesign · build · hand over
  1. Decision
  2. Architecture
  3. Delivery
  4. Operations

The decision point

Control of identities is verified from recruitment through to recovery after compromise.

The workstream starts from the most sensitive populations, roles and assets. It addresses human and service accounts, privileges, third-party access and administration paths, then organises the reviews and evidence produced by real running.

TriggerAccumulated access, diffuse privileges or a fragile directory
ScopeIdentities, accounts, roles, directories and applications
Expected outputA target architecture and prioritised reduction of attack paths

Working scope

The dimensions examined together.

The framing avoids treating separately subjects that condition one another. The final scope remains adapted to the organisation and its priorities.

  1. Joiners, movers and leavers
  2. MFA, authentication and federation
  3. Roles, entitlements and reviews
  4. Privileged accounts and administration workstations
  5. Service accounts, secrets and third parties
  6. Monitoring, backup and directory recovery

A usable result

Justifiable access and a recoverable administration.

The trajectory first reduces the attack paths that give access to critical assets. It attaches each measure to an owner, a control frequency and evidence usable by the cyber and compliance teams.

  1. 01Identity map and privileged paths
  2. 02Target model of roles and entitlements
  3. 03Directory and administration hardening plan
  4. 04Programme of reviews, monitoring and recovery

Method

An engagement that stays readable from scope to decision.

01

Qualify

Connect the need to the processes, the users, the dependencies and the success criteria.

02

Design

Arbitrate the architecture, the responsibilities, the risks and the trajectory before committing to delivery.

03

Implement

Deliver in controlled stages with acceptance criteria, evidence and regular visibility.

04

Hand over

Document operations, decisions and reversibility to avoid any implicit dependency.

Point of vigilance

What the engagement must make explicit.

Deploying strong authentication does not fix dormant accounts, excessive privileges, uncontrolled secrets or the absence of a directory recovery scenario.

The first conversation verifies the context, the level of urgency, the stakeholders and the output genuinely expected.

Frame this engagement See the Cybersecurity practice Start with a guided assessment

First conversation

Let’s discuss the next point of control for your information system.

A project to frame, operations to take over, compliance to demonstrate? Describe the context. You will get a first considered reading — not a generic brochure.