I

Advisory / Entra ID Security Assessment (Azure)

Do your identity and
cloud controls behave
the way leadership
believes they do?

Most identity problems
are not discovered
until something
fails.

Microsoft environments accumulate risk quietly. Conditional Access policies that look enforced but have legacy authentication bypasses. Privileged roles assigned to accounts that nobody actively monitors. Admin consent granted to third-party applications that retain persistent access. Standing privilege that was temporary and never revoked.

Leadership believes these controls are working because nobody has told them otherwise. The controls are in the dashboard. The policies are named. The MFA is enabled. None of that confirms whether the controls are actually enforced, or what an account compromise in that environment would grant access to.

This assessment answers the question that security dashboards cannot: do the controls behave the way the organisation believes they do, and where does the actual blast radius sit?

The assessment is conducted on Microsoft Entra ID and Azure environments only. Dettogni does not claim platform agnosticism, and engagements outside that footprint are declined.

Identity compromise is
recoverable. It is not cheap.

A contained identity compromise in a Microsoft-dependent organisation of 50 to 200 people typically incurs costs across several categories simultaneously. The floor is rarely below £25,000. The ceiling depends on how long access persisted before detection.

i

Cost category

Forensics and investigation

Understanding what was accessed, when, and by whom. Required before you can make any claim about the scope of a breach or notify affected parties with confidence.

ii

Cost category

UK GDPR notification

72-hour reporting obligation to the ICO if personal data is involved. Legal costs to assess notification scope, draft communications, and manage the regulatory process under pressure.

iii

Cost category

Re-provisioning and downtime

Resetting credentials across the environment, re-enrolling MFA, revoking persistent access tokens, rebuilding trust in the identity platform. Measured in days, not hours.

iv

Cost category

Reputational and pipeline damage

Customer confidence, supplier trust, and open commercial conversations disrupted during and after a visible incident. Harder to quantify. Rarely zero.

Six assessment areas.
One decision framework.

The assessment focuses on the security control plane: the identity, access, and configuration decisions that determine blast radius when something goes wrong. It does not cover endpoint security, network architecture, or application-layer vulnerabilities.

What this engagement
deliberately does not include.

The assessment is focused on the identity and cloud control plane. It does not include:

  • - Penetration testing or active exploitation attempts
  • - Endpoint security review or device management assessment
  • - Network architecture or internal infrastructure assessment
  • - Compliance audit or certification work (ISO 27001, Cyber Essentials, etc.)
  • - Remediation, implementation, or configuration changes
  • - Non-Microsoft environments (AWS, GCP, Okta)
  • - Environments running only on-premises Active Directory with no Entra ID footprint

The assessment produces a decision framework, not an implementation plan. What is done with the output is the organisation's decision. Engagements that end in implementation dependency are not advisory.

What buyers
ask before engaging.

  • Q

    What access does this require to our Microsoft tenant?

    A read-only application is registered in your Entra ID tenant with client approval before the engagement begins. It is scoped to configuration and audit data: no email content, no documents, no user data. The application is removed at the close of the engagement. The specific permissions required are shared before any access is established.

  • Q

    Is this the same as an Entra ID security audit?

    No. An audit measures configuration against a compliance standard and produces a certification-style output. This is a decision-grade assessment: it measures whether your controls actually enforce the way leadership believes they do, and produces a prioritised set of decisions rather than a compliance score. If you need formal certification work such as ISO 27001 or Cyber Essentials, that is out of scope here.

  • Q

    Do you assess Okta or other non-Microsoft identity platforms?

    No. This assessment is scoped to Microsoft Entra ID and Azure environments only. Dettogni does not claim platform agnosticism, and engagements outside that footprint are declined rather than delivered at reduced depth.

  • Q

    Do you only work with businesses in London, or is this available UK-wide?

    Engagements are remote and available UK-wide. Location has no bearing on delivery. The assessment is conducted against your Microsoft tenant regardless of where your organisation is based.

  • Q

    We have a Secure Score of over 70. Does that mean this engagement is unnecessary?

    Secure Score measures configuration against Microsoft's recommended baseline. It does not measure whether Conditional Access policies actually enforce, whether privileged roles create blast radius in your specific environment, or whether your logging and detection capability would surface a real incident. A high Secure Score and a significant undetected exposure can and frequently do coexist.

  • Q

    Our IT provider manages Microsoft 365 for us. Why would we need this?

    IT providers manage operation: user provisioning, licence management, support tickets. Security advisory assesses posture: whether the configuration choices made over time create risk that nobody has named. These are different activities. An IT provider's job is to keep things running. This assessment asks whether the way they are running creates exposure that the organisation has not consciously accepted.

  • Q

    Why does this engagement cost £4,950?

    Because the alternative is priced by an incident. A contained identity compromise in a Microsoft-dependent organisation of 50 to 200 people typically costs £25,000 to £100,000 or more across forensics, UK GDPR notification, re-provisioning, and reputational damage. The assessment produces a defensible understanding of that risk before the cost is incurred. The price reflects the access required, the depth of the work, and the decision-grade output.

  • Q

    Should we do the Security Posture Baseline first?

    If you already know that identity and cloud security is the area of greatest concern, no. The Security Posture Baseline is for buyers who do not yet know where their risk sits. If a board conversation, a near-miss, or an IT provider review has already pointed toward identity and cloud controls as the gap, this assessment addresses that directly.

  • Q

    What happens after the assessment is delivered?

    The engagement ends. The deliverable and the working session are the complete scope. There is no monitoring, no follow-on retainer, and no dependency created. Some organisations engage Dettogni operationally after advisory work when transferring continuous responsibility materially reduces risk. That is always a separate decision with explicit scope.

Begin here

Seven days
to a defensible
posture answer.

The first step is a short Discovery Call. Twenty minutes. Used to confirm fit, understand the environment, agree on access requirements, and set the start date.

The assessment is carried out personally by Alex Ulfeldt, the security engineer who operates Dettogni. No handoffs, no junior analysts.

If the Microsoft Identity and Cloud Security Assessment is not the right engagement for your situation, the call will surface that. A clear outcome either way is more useful than a commitment to the wrong engagement.

Book a Discovery Call See all advisory engagements

Dettogni advisory is fixed in scope, fixed in price, and designed to end.
United Kingdom · Microsoft environments only · Remote engagements