Azure & Entra ID Financial services

How a financial services firm locked down every sign in with Entra ID Conditional Access

A 30 person firm went from MFA switched on for some and skipped for others to every sign in checked and trusted, using the Microsoft licensing it already pays for.

A financial services firm
Financial services
30 users
Phased pilot, then rollout
At a glance

MStack360 secured the sign ins at a 30 person financial services firm with Microsoft Entra ID Conditional Access, using licensing the firm already owned. We enforced MFA for everyone, built policies that weigh who, where, and what device on every sign in, trimmed admin rights to least privilege, and piloted it all so nobody was locked out of their work.

  • Every sign in is now evaluated on who, where, and what device before access is granted
  • MFA enforced across the whole tenant with no quiet exceptions, admin rights trimmed to least privilege, and stale guest accounts removed
  • Built on Zero Trust principles using Microsoft licensing the firm already owned, with zero users locked out during the rollout
What this story covers
  1. Patchy by accident
  2. How we locked it down
  3. Every sign in checked
  4. What we put in place
  5. Trusted sign ins
The Challenge

Sign in security that had grown by accident, not by design

A 30 person financial services firm came to us knowing something was off, but not sure how exposed they really were. They handle sensitive client records every day, yet their sign in security had grown by accident rather than by design.

MFA on for some, off for others

Multi factor was enforced for part of the team and quietly skipped for the rest.

A password alone was enough

No Conditional Access at all, so a valid password from anywhere on any device got in.

Admin rights everywhere

Several accounts carried far more admin than the work actually required.

Old guests still active

Accounts from finished projects and former partners could still reach company data.

The owner put it plainly. They knew enough to be worried, but not enough to fix it. In their industry a single bad sign in is the kind of scare that gets handled the week after rather than the week before. Our job was to handle it the week before.

What They Needed

A clear picture, then real control over every sign in

  • A clear picture of who can sign in, from where, and on what device
  • MFA enforced properly for everyone, not half the team
  • Conditional Access policies that check the real context of each sign in
  • Admin rights cut back to least privilege
  • Stale guest access found, reviewed, and removed
  • A rollout that does not lock anyone out of their work
Our Approach

Audit first, enforce properly, pilot before going wide

Audit the Entra ID environment first

We reviewed every account, every sign in pattern, and every existing policy, then showed the firm exactly where the gaps were in plain language. No jargon, just what is risky and what it takes to fix. We measured identity risk with Microsoft Secure Score so the before and after was on the record.

Enforce MFA properly

We closed the half enforced gaps so every user was covered, including admins and service accounts where appropriate. MFA only works when there are no quiet exceptions.

Build Conditional Access policies

This is the policy layer that makes MFA actually effective. We built rules that check who is signing in, where they are signing in from, and what device they are using, then grant, challenge, or block accordingly.

Cut admin rights to least privilege

We mapped admin roles to what each person genuinely needs and stripped the rest, so a single compromised account cannot do company wide damage.

Clean up stale guests

We found every dormant guest account, confirmed which were no longer needed, and removed them, so old relationships could no longer reach current data.

Pilot first, then roll out

We tested every policy with a small pilot group before going wide, caught friction early, and made sure nobody got locked out during the change.

How a sign in is judged now

A password is no longer the whole story

Before, a valid password from anywhere was enough to get in. Now every sign in is evaluated against who is asking, where they are, and what device they are on. Only a request that clears all of it is granted, and trusted.

What We Delivered

Identity security the firm can explain to its clients

A written gap report

Every identity risk listed in plain language with priority and effort, so the firm could decide with eyes open.

MFA across the whole tenant

Consistent enforcement with no quiet exceptions, the foundation everything else builds on.

Conditional Access policies live

Sign ins evaluated on who, where, and what device. The layer that turns MFA into real protection rather than a single checkbox.

Least privilege and a clean guest list

Admin rights trimmed to what each role needs, and stale external accounts reviewed and removed. Handed over in a record auditors, insurers, and clients can actually read.

Results

The payoff for the firm

100%
MFA enforced across the tenant, with no quiet exceptions
0
Users locked out during the phased rollout
Every sign in
Now checked on who, where, and device before access is granted

"We knew our sign in security was patchy, we just did not know how to fix it without breaking everyone's day. The pilot meant nobody got locked out, and now I can actually explain our security to our clients."

Operations lead, a financial services firm

The solution behind this story

Microsoft Entra ID Health Check

We audit your identity environment, enforce MFA properly, and build Conditional Access policies that check who, where, and what device. All on Zero Trust principles, using the Microsoft licensing you already own.

Conditional Access policies Least privilege admin Zero Trust by design
Common Questions

What people ask about this kind of project

Will Conditional Access lock my team out of their work?

Not when it is rolled out properly. We pilot every policy with a small group first, watch for friction, and only go wide once we know real sign ins pass cleanly. In this project nobody was locked out.

Do we need to buy new security products for this?

Almost always no. Conditional Access, MFA, and identity protection come with the Microsoft 365 plans most firms already pay for. We help you turn on and configure what you already own before anyone suggests buying more.

How is this different from just turning on MFA?

MFA proves who is signing in. Conditional Access decides whether that sign in should be trusted at all, based on where it comes from and what device it uses. It is the policy layer that makes MFA genuinely effective rather than a single checkbox.

Not sure how exposed your sign ins are?

Let us audit your identity setup and show you exactly where the gaps are, in plain language. The first call is on us.

Book a call