Service · Cybersecurity

Access control and endpoint security

Most break-ins at SMEs start with a password, not a virus. Someone types it into a fake page that mimics the Microsoft 365 sign-in, reused it on an online shop that was breached, or had it guessed because it was the company name followed by the year. With that password and no second factor, the attacker gets into the mailbox, creates a rule that hides replies and starts sending customers invoices with a changed IBAN. This service shuts that door and the next one: who can sign in, from which device, under which conditions and with what privileges on the machine. It applies equally to people in the office, to those working from home three days a week and to the personal phone used to check work email.

100 % of accounts
with MFA, no exceptions
Intune
for Windows, Mac and phones
0 local admins
on workstations
Risk-based
blocking of sign-ins from odd places

What falls within the scope of this service

We mostly work with Microsoft 365, Entra ID and Intune, and with Google Workspace and its endpoint management. If you use another management platform, we build on it.

Pin down the details with one of our engineers

MFA for everyone

Microsoft Authenticator, passkeys or FIDO2 hardware keys for critical roles. SMS is kept as a last resort. That includes senior management, who are usually the most reluctant.

Conditional Access

Policies that require a managed device to open company data, block sign-ins from countries where you do not operate and demand a stronger second factor from administrators.

Device management

Windows laptops and Macs enrolled in Intune, with encryption, updates, firewall and antivirus checked. A device that fails the checks cannot reach data until it is fixed.

Phones and personal devices

On employees' own phones only the work apps are protected; photos and private messages are left alone. When someone leaves, company data is wiped and nothing else.

Least privilege

Local admin rights are removed. Installs go through a catalogue of approved apps, and local admin passwords rotate automatically with LAPS.

Joiners, leavers and movers

A procedure so a new starter's laptop is ready on day one, sent by courier and set up simply by switching it on, and so a leaver loses access that same day.

How the engagement unfolds, one stage at a time

MFA is rolled out group by group with a short guided session. Conditional Access starts in report-only mode so we can see what it would have blocked.

01

Account review

Active accounts, former staff, administrators, service accounts and sign-in methods. Anything surplus is cleaned up.

02

MFA

Registration department by department, with simple instructions and video-call help for anyone who gets stuck.

03

Devices

Enrolment in Intune, compliance policies in report mode and gradual enforcement.

04

Conditional Access

Policies switched on after reviewing the report, with a protected and documented break-glass account in case something goes wrong.

MFA by text message or push approval is no longer enough against the latest fake login pages. Modern phishing kits capture the session in real time, code and all. Passkeys and FIDO2 keys cannot be relayed through a fake site, which is why we recommend them for directors, administration and finance.

Common questions

It can be used with the employee's agreement, and the authenticator app sees nothing of what is on the phone. If someone would rather not use their own phone, the alternative is a FIDO2 hardware key supplied by the company. It is worth recording this in the device use policy and, for remote staff, in the remote-work agreement required by Law 10/2021.

Conditional Access allows temporary exceptions: the employee lets you know, the country is enabled for the trip and closed again on return. The general block stays in place without leaving anyone stranded at a trade fair on another continent.

We remove standing rights, not their ability to work. They can request a one-off elevation that is logged, or use a separate admin account distinct from their everyday one. A malicious email opened in the normal account then arrives without privileges.

Windows Home does not support full Intune management or managed BitLocker. The licence can be upgraded to Pro remotely without reinstalling. We include this in the inventory and tell you how many machines are affected before we start.

Shut the door on stolen passwords

Tell us how many users and devices you have, which platform you use and whether people work remotely. We will reply with a phased plan for MFA and device management.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.