Identity & Access Management
Passwords stopped being enough a long time ago. GravIT sets up the controls that decide who can sign in to your business, from where, and on what device: multi-factor authentication, conditional access, single sign-on and clean offboarding, usually using licensing you are already paying for.
The front door is the password, and everyone knows it
Almost every serious incident we are called to starts the same way: someone's credentials end up somewhere they should not be. Rarely a dramatic hack. Usually a reused password from a breached shopping site, a convincing sign-in page, or a laptop nobody wiped. Once an attacker is holding a valid login, most systems politely let them in and log it as a normal Tuesday.
Identity work is the answer to that, and it is unglamorous in the best way. Rather than trying to spot the intruder after they are inside, you make the sign-in itself the thing that has to be proved, and you make the rules tight enough to matter but quiet enough that your staff barely notice them.
The MFA and conditional access we put in place
- Multi-factor authentication, properly rolled out. Across email, remote access and the awkward accounts people forget, configured so staff are not fighting it ten times a day. The most effective single control there is.
- Conditional access. Rules about where and how people can sign in. Block countries you never trade with, require a known device, ask for more proof when a sign-in looks unusual, leave normal work alone.
- Single sign-on. One work identity opening the applications connected to it, so there are fewer passwords in existence to leak in the first place.
- Self-service password reset. Staff unlock themselves safely instead of waiting on someone. It pays for itself in help-desk calls alone.
- Sign-in risk monitoring. Alerts when an account behaves like it has been taken over, which is the difference between finding out today and finding out from your bank.
- Clean offboarding. One identity disabled, everything attached to it closed, immediately.
You may already own this
Here is the part worth knowing before anyone quotes you: these controls come from licensing that plenty of small businesses already hold and have never switched on. We regularly open a tenancy and find protections sitting there unused, paid for every month.
So the first thing we do is check what you already have. If your existing plan covers what you need, we will say so and simply turn it on properly. If a step up genuinely earns its money, we will show you what it buys before you spend it. Same approach as our licensing work: the goal is the right licences, not more of them.
What's included
- Access and licensing review
- MFA rollout and tuning
- Conditional access policies
- Single sign-on for connected apps
- Self-service password reset
- Sign-in risk alerting
- Joiner and leaver process
Frequently asked questions
What is conditional access?
A set of rules about who can sign in, from where, and on what. Instead of a password being the only gate, you can require multi-factor authentication, block sign-ins from countries you never trade with, insist a device is known and up to date, or ask for extra proof only when something looks unusual. Most of it is invisible to staff doing normal work.
Isn't multi-factor authentication enough on its own?
It is the single most valuable control and the right place to start, but it is not the whole job. MFA proves who is signing in; conditional access decides whether that sign-in should be allowed at all. Attackers who get past MFA usually do it by wearing the user down with prompts or stealing a session, and those are the things the surrounding policies close off.
Do our staff need to remember another password?
Fewer, ideally. Single sign-on means one work identity opens the applications you have connected to it, and self-service password reset lets people fix their own lockouts without ringing anyone. Pairs naturally with a password manager for everything that cannot be connected.
Is this only for big companies?
No, and that is the common misconception. The licensing that carries these controls is included in plans many small businesses already pay for. We regularly find clients entitled to protections they have never had switched on. The first thing we do is check what you already own.
Why are insurers and larger customers asking about this?
Because stolen credentials are how most business email compromise starts, and identity controls are the cheapest effective defence. It is why they sit near the top of the ACSC Essential Eight, and why questionnaires from insurers and enterprise clients now ask about MFA and access control specifically.
What happens when someone leaves?
Disabling one identity closes everything attached to it, in one action, immediately, rather than trying to remember every system they ever had a login for. That is the entire argument for doing identity properly, and it is the same day-one benefit as a business password vault.
Find out who can get into what
Most businesses aren't, and the answer is usually more people than expected. An access review tells you exactly where you stand.