Identity and access · IAM

Who accesses what, when, and why.

Entra ID, Active Directory, identity governance: I design a centralised, automated and auditable identity foundation, aligned with your business processes and with Zero Trust.

Identity centralisation

Scattered identity multiplies risk and complicates compliance. Centralising means taking back control.

Access management

Define who accesses what, when and how, with business roles rather than exceptions.

Lifecycle

Joiner, mover, leaver: rights follow the person, automatically, from the HR system.

Single sign-on

Unified access to applications, fewer passwords, better security.

Zero Trust hardening

Conditional access, Phishing-resistant MFA, just-in-time privilege elevation.

Workflows and governance

Requests, approvals, access reviews and access packages that live with the organisation.

What I do for you

Identity & access

Strategy

IAM roadmap

  • Audit of the current state and risk mapping
  • Governance model: business roles, naming, service accounts
  • Phased trajectory, licences per persona, budget
Architecture

Entra ID architecture

  • HR-driven provisioning, Lifecycle Workflows
  • Entitlement Management, access reviews, PIM
  • SSO and SCIM for internal and SaaS applications
Foundations

Active Directory and hybrid identity

  • Entra Connect and Cloud Sync, complex topologies
  • Privilege hardening, Tiering model, PAW
  • Forest migration and consolidation
New

Non-human identities

  • Inventory of service accounts, applications and agents
  • Secret rotation, least privilege
  • Governance of AI agent identities

The method, applied

Six steps, one thread.

Where do you stand, pillar by pillar, against the CISA model?

Joiners, movers and leavers without a manual ticket.

Strong MFA, just-in-time elevation, admin workstations.

Method

  1. 01Scoping

    Understand the need, the stakes and the constraints. Set the scope, the actors and the expected results.

  2. 02Audit

    Observe the current state without assumptions: configurations, usage, documents, interviews and tool-based measurements.

  3. 03Analysis

    Confront the findings with frameworks and your objectives. Measure the gaps, qualify the risks, prioritise.

  4. 04Design

    Design the target and the path to reach it: architecture, governance, budget, licences, milestones.

  5. 05Transcription

    Translate the target into operational documents your teams and vendors can execute without me.

  6. 06Delivery

    Present, get stakeholder sign-off, transfer knowledge and support the implementation.

Show our Zero Trust maturity by pillar

Zero Trust maturityCISA ZTMM v2.0

Illustrative example · Today

Workshops and knowledge transfer

Dense, practical sessions that make your teams autonomous.

Introduction to Entra ID Entra Connect and Cloud Sync, advanced Entra ID Governance: lifecycle and reviews Conditional access: design and best practices Passwordless strategy Entra Global Secure Access Entra Permissions Management

Watch

What is moving on this topic

An automatic selection of recent articles from trusted sources, filtered to keep only what touches this specialty.

Loading the watch…

The CT Conseil briefing

Get this watch every week

One edition a week: the deadlines you must not miss, what is moving on Entra, Purview, Defender and compliance, and one practical tip. No advertising, one-click unsubscribe. Editions are written in French.

Gauge my level in 5 questions

Five questions to locate your identity maturity. No wrong answers, only leads.

Two minutes, no tricks. You leave with a level and concrete leads.

Question 1 of 5

Your administrators sign in…

Identities ready? Let's protect your data.

Identity opens the door; classification decides what may leave.

Data protection