IAM & Active Directory
Make identity a central control, including when the directory is under attack.
IKNSA connects entitlement governance, identity architecture, privileges, monitoring and recovery to reduce implicit access and critical dependencies.
- Decision
- Architecture
- Delivery
- Operations
The decision point
Control of identities is verified from recruitment through to recovery after compromise.
The workstream starts from the most sensitive populations, roles and assets. It addresses human and service accounts, privileges, third-party access and administration paths, then organises the reviews and evidence produced by real running.
Working scope
The dimensions examined together.
The framing avoids treating separately subjects that condition one another. The final scope remains adapted to the organisation and its priorities.
- Joiners, movers and leavers
- MFA, authentication and federation
- Roles, entitlements and reviews
- Privileged accounts and administration workstations
- Service accounts, secrets and third parties
- Monitoring, backup and directory recovery
A usable result
Justifiable access and a recoverable administration.
The trajectory first reduces the attack paths that give access to critical assets. It attaches each measure to an owner, a control frequency and evidence usable by the cyber and compliance teams.
- 01Identity map and privileged paths
- 02Target model of roles and entitlements
- 03Directory and administration hardening plan
- 04Programme of reviews, monitoring and recovery
Method
An engagement that stays readable from scope to decision.
Qualify
Connect the need to the processes, the users, the dependencies and the success criteria.
Design
Arbitrate the architecture, the responsibilities, the risks and the trajectory before committing to delivery.
Implement
Deliver in controlled stages with acceptance criteria, evidence and regular visibility.
Hand over
Document operations, decisions and reversibility to avoid any implicit dependency.
Point of vigilance
What the engagement must make explicit.
Deploying strong authentication does not fix dormant accounts, excessive privileges, uncontrolled secrets or the absence of a directory recovery scenario.
The first conversation verifies the context, the level of urgency, the stakeholders and the output genuinely expected.
Frame this engagement See the Cybersecurity practice Start with a guided assessmentFirst conversation
Let’s discuss the next point of control for your information system.
A project to frame, operations to take over, compliance to demonstrate? Describe the context. You will get a first considered reading — not a generic brochure.