In Part 1, we talked about knowing where you stand. In nearly every assessment we conduct, the biggest cluster of findings centers on one area: identity. Not passwords specifically - we've already covered MFA in a previous article - but the entire system of how people prove who they are, what they're allowed to access, and what happens when they shouldn't have access anymore.
A decade ago, security meant protecting the network perimeter. Firewall rules. VPN access. Physical badges. If you were inside the network, you were trusted. That model is dead. Your data lives in Microsoft 365, Google Workspace, Salesforce, QuickBooks Online, Dropbox, Slack, and a dozen other cloud services. Your employees work from offices, homes, airports, and coffee shops. There is no perimeter anymore. Identity is the perimeter.
The Identity Lifecycle Problem
Every employee has an identity lifecycle: they join, they change roles, and eventually they leave. Most businesses handle the "join" part reasonably well - new employee, new accounts, here's your laptop. The "change roles" part gets messy. The "leave" part is often a disaster.
Consider what happens when a marketing coordinator gets promoted to marketing director. They need access to the marketing budget in QuickBooks, the social media management platform, and the analytics dashboard. They get those accounts. But do they lose access to the shared inbox they no longer manage? The project management board for the team they left? The file shares for their old role? Usually not. Access accumulates. Nobody subtracts.
Over a five-year career at a company, an employee might change roles two or three times. Each change adds access. Nothing gets removed. By the time they leave, they have access to systems spanning three departments, two of which they haven't worked in for years. This is called privilege creep, and it's everywhere.
Then comes offboarding. How fast can you disable all of that access? Not just Active Directory or Entra ID - every cloud service, every SaaS app, every shared account, every API key. We've tested this with clients. The average time to fully offboard an employee across all systems, when done manually, is 3-5 business days. That's 3-5 business days where a departed employee might still have access to company data, email, and systems.
Single Sign-On: One Door, One Key
Single sign-on (SSO) is the foundation of modern identity management. Instead of separate usernames and passwords for every application, employees authenticate once through your identity provider - Microsoft Entra ID (formerly Azure AD) for most of our clients - and that single authentication grants them access to all the applications they're authorized to use.
This isn't just a convenience feature. SSO fundamentally changes your security posture:
- One account to disable. When someone leaves, you disable their Entra ID account. That single action revokes access to every SSO-connected application simultaneously. Not in 3-5 days. Immediately.
- One place for MFA. MFA is enforced at the identity provider level, not application by application. You don't need to configure MFA separately in Salesforce, Dropbox, and your project management tool. It's handled once, at the door.
- Fewer passwords. Fewer passwords means fewer weak passwords, fewer reused passwords, and fewer passwords written on sticky notes. When your identity provider handles authentication, the individual applications never see a password at all.
- Audit trail. Every authentication goes through one system. You get a single, unified log of who accessed what, when, and from where. Trying to piece together access logs from 15 different SaaS applications is a nightmare. A centralized identity provider gives you one source of truth.
Not every application supports SSO - and some vendors charge a premium for it, which is a frustrating practice the industry calls the "SSO tax." But for the applications that do support it, enabling SSO is one of the highest-impact security improvements you can make.
Conditional Access: Context-Aware Security
MFA asks "can you prove who you are?" Conditional access asks "should you be allowed to do this, right now, from here, on this device?" It's the difference between checking someone's ID at the door and checking their ID, verifying they're on the guest list, confirming they're arriving at an expected time, and making sure they're not wearing a ski mask.
Conditional access policies in Microsoft Entra ID let you define rules based on context:
- Location. Allow sign-ins from the US without extra verification. Require additional verification from other countries. Block sign-ins from countries where you have no business presence entirely. We had a client in Orem who was seeing 200+ authentication attempts per week from Eastern Europe and Southeast Asia - all blocked automatically by a geo-based conditional access policy.
- Device compliance. Only allow access from devices that are managed by your organization, running current OS versions, with endpoint protection active. Unmanaged devices can be blocked entirely or given limited access - for example, they can view emails through webmail but can't download attachments or sync to Outlook.
- Risk level. Microsoft calculates a sign-in risk score based on factors like impossible travel (logging in from Salt Lake City and then Moscow 20 minutes later), anonymous IP addresses, leaked credentials found in breach databases, and atypical access patterns. High-risk sign-ins can be blocked or required to complete additional verification.
- Application sensitivity. Access to email from a compliant device might require standard MFA. Access to the HR system or financial applications might require phishing-resistant MFA (like a FIDO2 key) regardless of device or location.
Conditional access is where identity security gets genuinely powerful. It moves beyond the binary of "allowed or not" to a nuanced model that adapts to context. An employee accessing email from their managed laptop at the office is low risk. The same employee accessing the financial system from an unmanaged device on public Wi-Fi in another country is high risk. The response should be different, and conditional access makes it different automatically.
Password Management at Scale
SSO reduces the number of passwords, but it doesn't eliminate them. Applications that don't support SSO still need credentials. Personal accounts that employees use for work still need passwords. Service accounts and shared credentials still exist. This is where enterprise password management comes in.
We deploy 1Password for our managed IT clients as the standard password management solution. Every unique credential gets stored in a vault - personal vaults for individual accounts, shared vaults for team credentials. When someone on the marketing team needs the credentials for the company's social media scheduling tool, they access the shared marketing vault. They don't ask a coworker to text them the password. They don't look at a spreadsheet. They don't use the same password they use for everything else.
When an employee leaves, their access to shared vaults is revoked and credentials they had access to are rotated. When a credential is compromised, 1Password's Watchtower feature flags it. When someone tries to use a weak or reused password, the tool warns them. It's a small investment - typically $5-8 per user per month - that addresses one of the most persistent human factors in security.
Session Management: The Forgotten Piece
Here's something most businesses never think about: session duration. When an employee authenticates to Microsoft 365, how long does that session last before they need to re-authenticate? The default is often 90 days. That means a stolen session cookie - or a device left logged in at a hotel business center - provides access for three months without any additional authentication.
Session management policies should balance usability with security. Requiring re-authentication every hour is impractical. Allowing sessions to persist for 90 days is excessive. We typically configure sessions to require re-authentication every 12-24 hours for standard access and every 4-8 hours for sensitive applications. Token lifetime policies, sign-in frequency controls, and persistent browser session restrictions are all configurable in Entra ID.
Putting It Together
Identity management isn't a single tool or a single policy. It's the combination of SSO, conditional access, MFA, password management, lifecycle automation, and session controls working together. Each piece addresses a different aspect of the question "who is this person, and should they have access to this, right now?"
In Part 3, we'll build on this foundation and tackle the specific challenges of securing remote and hybrid workforces - because identity management gets significantly more complex when your employees are working from everywhere. If your business is struggling with identity sprawl, stale accounts, or offboarding gaps, let's talk. These are solvable problems.
