How a financial services firm locked down every sign in with Entra ID Conditional Access
A 30 person firm went from MFA switched on for some and skipped for others to every sign in checked and trusted, using the Microsoft licensing it already pays for.
MStack360 secured the sign ins at a 30 person financial services firm with Microsoft Entra ID Conditional Access, using licensing the firm already owned. We enforced MFA for everyone, built policies that weigh who, where, and what device on every sign in, trimmed admin rights to least privilege, and piloted it all so nobody was locked out of their work.
- Every sign in is now evaluated on who, where, and what device before access is granted
- MFA enforced across the whole tenant with no quiet exceptions, admin rights trimmed to least privilege, and stale guest accounts removed
- Built on Zero Trust principles using Microsoft licensing the firm already owned, with zero users locked out during the rollout
Sign in security that had grown by accident, not by design
A 30 person financial services firm came to us knowing something was off, but not sure how exposed they really were. They handle sensitive client records every day, yet their sign in security had grown by accident rather than by design.
MFA on for some, off for others
Multi factor was enforced for part of the team and quietly skipped for the rest.
A password alone was enough
No Conditional Access at all, so a valid password from anywhere on any device got in.
Admin rights everywhere
Several accounts carried far more admin than the work actually required.
Old guests still active
Accounts from finished projects and former partners could still reach company data.
The owner put it plainly. They knew enough to be worried, but not enough to fix it. In their industry a single bad sign in is the kind of scare that gets handled the week after rather than the week before. Our job was to handle it the week before.
A clear picture, then real control over every sign in
- A clear picture of who can sign in, from where, and on what device
- MFA enforced properly for everyone, not half the team
- Conditional Access policies that check the real context of each sign in
- Admin rights cut back to least privilege
- Stale guest access found, reviewed, and removed
- A rollout that does not lock anyone out of their work
Audit first, enforce properly, pilot before going wide
Audit the Entra ID environment first
We reviewed every account, every sign in pattern, and every existing policy, then showed the firm exactly where the gaps were in plain language. No jargon, just what is risky and what it takes to fix. We measured identity risk with Microsoft Secure Score so the before and after was on the record.
Enforce MFA properly
We closed the half enforced gaps so every user was covered, including admins and service accounts where appropriate. MFA only works when there are no quiet exceptions.
Build Conditional Access policies
This is the policy layer that makes MFA actually effective. We built rules that check who is signing in, where they are signing in from, and what device they are using, then grant, challenge, or block accordingly.
Cut admin rights to least privilege
We mapped admin roles to what each person genuinely needs and stripped the rest, so a single compromised account cannot do company wide damage.
Clean up stale guests
We found every dormant guest account, confirmed which were no longer needed, and removed them, so old relationships could no longer reach current data.
Pilot first, then roll out
We tested every policy with a small pilot group before going wide, caught friction early, and made sure nobody got locked out during the change.
A password is no longer the whole story
Before, a valid password from anywhere was enough to get in. Now every sign in is evaluated against who is asking, where they are, and what device they are on. Only a request that clears all of it is granted, and trusted.
Before: a valid password from anywhere on any device was enough to get in.
Identity security the firm can explain to its clients
A written gap report
Every identity risk listed in plain language with priority and effort, so the firm could decide with eyes open.
MFA across the whole tenant
Consistent enforcement with no quiet exceptions, the foundation everything else builds on.
Conditional Access policies live
Sign ins evaluated on who, where, and what device. The layer that turns MFA into real protection rather than a single checkbox.
Least privilege and a clean guest list
Admin rights trimmed to what each role needs, and stale external accounts reviewed and removed. Handed over in a record auditors, insurers, and clients can actually read.
The payoff for the firm
"We knew our sign in security was patchy, we just did not know how to fix it without breaking everyone's day. The pilot meant nobody got locked out, and now I can actually explain our security to our clients."
Operations lead, a financial services firm
Microsoft Entra ID Health Check
We audit your identity environment, enforce MFA properly, and build Conditional Access policies that check who, where, and what device. All on Zero Trust principles, using the Microsoft licensing you already own.
What people ask about this kind of project
Will Conditional Access lock my team out of their work?
Not when it is rolled out properly. We pilot every policy with a small group first, watch for friction, and only go wide once we know real sign ins pass cleanly. In this project nobody was locked out.
Do we need to buy new security products for this?
Almost always no. Conditional Access, MFA, and identity protection come with the Microsoft 365 plans most firms already pay for. We help you turn on and configure what you already own before anyone suggests buying more.
How is this different from just turning on MFA?
MFA proves who is signing in. Conditional Access decides whether that sign in should be trusted at all, based on where it comes from and what device it uses. It is the policy layer that makes MFA genuinely effective rather than a single checkbox.
Not sure how exposed your sign ins are?
Let us audit your identity setup and show you exactly where the gaps are, in plain language. The first call is on us.
Book a call