Secure Defence / Case study

Zero Trust and identity on Entra ID.

A defence business moved from separate access arrangements to centralised authorisation on Entra ID, with single sign on, device lockdown and Conditional Access across its platforms.

Read the outcome

The access model

Users and devicesIdentity and device context
Entra IDSingle sign on + Conditional Access
Business platformsConsistent access rules
A conceptual view of the access model, without the client’s configuration.
Sector
Defence
Identity platform
Microsoft Entra ID
Controls
Device lockdown and Conditional Access

Client details anonymised. How we describe the work

The starting point

The challenge

Access had developed separately on each platform. That left the business with different ways of deciding who could use its systems, making the overall access model difficult to oversee.

The business needed a consistent way to establish identity, control which devices could connect and apply access rules across its platforms.

What we did

The work

  1. Centralise identity

    We built the access model around Entra ID, bringing authorisation into one place. The Zero Trust principle was to verify access rather than rely on a user being inside the network.

  2. Connect the platforms

    Single sign on connected the platforms to the central identity service, giving people a consistent way to authenticate.

  3. Apply device and access controls

    We locked down devices and applied Conditional Access policies across the platforms. Access decisions considered the user, device and request context.

What changed

The outcome

The business now operates a Zero Trust access model through Entra ID. Staff have a consistent sign-in experience, while the business has a central place to manage the rules for access.

Centralised decisions

Entra ID became the common point for authorisation.

Consistent sign-in

Full single sign on connected the client’s platforms.

Access controls in place

Device lockdown and Conditional Access were applied throughout the environment.

The client in this record is described by sector rather than named. Why we describe our work that way.

Your project

Discuss your access controls.

We can review your identity services, device management and access policies before agreeing the work.

Reading, Berkshire  /  scope and next steps agreed with you  /  reply within one working day