専門性 / もっと近くで
身元と入場管理
全積みにEntra ID、SSO、最小入場 — 入りから監査まで正しい身元。
向いているのは
身元(Entra ID)Organisations on Microsoft 365 or Azure AD/Entra ID that need SSO across apps, conditional access, role hygiene and audit-ready access reviews — especially before an enterprise or regulated engagement.
案件を相談する機会
次の一歩を
より良い一歩に。
Access sprawl is invisible until it isn't: ex-contractors still in the tenant, service principals with owner-level roles, MFA enforced on some apps and not others, and nobody able to say who can reach what. Audits catch it; attackers catch it first.
We map who and what accesses which system, then implement in order of risk: MFA and conditional access first, app SSO via Entra ID second, role and service-principal cleanup third. Break-glass accounts, PIM-style elevation and a recurring access-review cadence are set up so the posture holds after we hand over — documented to the standard security review boards expect.
- 協働
- 指名デリバリーリード + チーム
- 時期
- Hardening in 2–3 weeks; full rollout scoped per estate
納品物
正しいことに集中。
- Entra ID tenancy hardening: MFA, conditional access, break-glass
- SSO/SAML/OIDC single sign-on across your application estate
- Role-based access design and least-privilege cleanup
- Access reviews, audit trails and documentation packs
持ち帰るもの
運用できるもの。
- Identity and access map with risk-ranked remediation
- Conditional access + SSO implemented and tested
- Least-privilege role model, documented
- Access-review cadence + audit-ready documentation
始める前に
少しの明確さが
遠くまで届く。
01始めるのに何が必要ですか?
課題の短い説明、あれば現サイト・ツールのリンク、役立つ成果の姿。完成した仕様書は不要です。範囲が固まればアクセス、DPA/NDA、コンテンツ要件を決めます。
02今のものを使って進められますか?
はい。現状と制約から始めます。的を絞った改善や連携が作り直しに勝ることも — 約束前に費用付きの選択肢と得失を説明します。
03費用・時期・SLAはどう決めますか?
調査後に明確な提案:成果物、マイルストーン、時期、支援、SLA条件。署名で開始。変更は追加作業の前に文書で再定義します。
つながる専門性