What the service covers

We treat each application both as a store of your data and as a channel through which that data can leave.

Talk it through with us

Roles and rights

Access based on job function instead of full access. A salesperson has no reason to export the entire customer base in one go.

Integration accounts

Every integration gets its own account or Entra ID app registration with exactly the permissions it uses.

API keys

Keys are moved out of config files into a key vault, restricted by IP address and rotated on a fixed plan.

App consent

We review which third-party apps users have allowed into your Microsoft 365 data and tighten the rules for new ones.

Audit log

Who edited, who exported. Without a record there is nothing to investigate when something goes wrong.

Updates

A set routine for security updates, tested in a staging environment before they reach production.

How we deliver it

The hardest part is rarely technical. It is agreeing who genuinely needs to see what.

01

Inventory

Which applications are in use, by whom, what data they hold and where they send it.

02

Role matrix

Together with department heads we define the roles and what each one contains.

03

Configuration

Roles go live, integrations move to their own accounts and logging is enabled.

04

Recertification

Every six months rights are compared with job titles. People change roles internally and old access tends to follow them.

An integration running with admin rights is a gift to an attacker. All it takes is for the password to turn up in a config file or an old script, and the whole finance system is exposed. A separate account limited to the functions it really needs takes half an hour to set up.

Common questions

Through department heads, not IT. They know what their people need to do the job. Two or three short meetings are usually enough, and the result is a spreadsheet you can keep up to date.

Block them on the day, but do not delete them straight away, as a deleted account takes its history with it. Blocking now and cleaning up after a month is the safer pattern.

We review configuration, permissions and integrations. A proper hunt for vulnerabilities in the code itself falls under penetration testing, which can be ordered separately.

The vendor patches the platform, but settings, users, integrations and add-ons you have bought are your responsibility. That is where we help keep order.

Clean up your permissions

Tell us which systems you use. We will see who can view what and where integrations hold more rights than they need.

Coverage
All of Denmark, delivered remotely

This site uses only essential cookies: they keep pages working and store your chosen town. Read more in our privacy policy.