What the service covers

Which controls matter depends on the goal. A customer requirement or a cyber insurance policy often demands the full set, while practical protection can start with part of it.

Talk it through with us

MFA and conditional access

Microsoft Authenticator or FIDO2 keys for everyone, and Conditional Access rules that refuse sign-ins from unexpected countries and unmanaged devices.

Device compliance

Intune checks that a PC is encrypted, patched and running antivirus before it can reach mail and data.

Local admins

Users lose admin rights on their own PCs, and local admin passwords become unique per machine with Windows LAPS.

Allowed software

Only programs on the list can start. Ransomware on such a machine simply fails to launch.

USB and peripherals

An approved list of USB devices, a block on everything else and a log of connections.

Logging

User actions are recorded centrally, and the log is protected against local deletion.

How we deliver it

We switch the controls on one at a time, so we can see the effect on people's work at every step.

01

Priorities

We separate what rules and contracts require from what we add for practical benefit.

02

Pilot

A handful of machines from different departments, because each team has its own software and habits.

03

Rollout

Step by step through Intune and Entra ID, with rules adapted to each department.

04

Ongoing care

New software is added to the list and blocked attempts are reviewed.

Phones go missing and keys get left at home, so plan for it. Without a written procedure for temporary access, a lost phone means the bookkeeper cannot work for half a day. A time-limited fallback via Temporary Access Pass is designed during the rollout, not in a moment of panic.

Common questions

MFA everywhere and an allow list for software. MFA stops most attacks built on stolen passwords, and application control stops anything unfamiliar, including threats no antivirus database knows yet. The price is discipline: new programs must be approved.

Laptops get the same rules plus disk encryption and conditional access that checks device health. Turning protection off for a trip is the worst possible answer.

Mainly licences and time spent approving new programs. Many firms already have Intune and Entra ID P1 through Business Premium. The first month is the busiest, after which requests drop sharply.

Yes, from a company portal of approved programs. Anything else needs a request that IT signs off. It takes a little getting used to, but most people soon realise they use the same few programs every day.

Tighten access to your devices

Tell us what needs locking down and how many workstations you have. We will propose an approach and start with a pilot.

Coverage
All of Denmark, delivered remotely

This site uses only essential cookies: they keep pages working and store your chosen town. Read more in our privacy policy.