A security concept for Microsoft 365: time-limited admin rights, access rules and managed devices
An engineering firm secures its Microsoft 365 tenant to current standards without slowing its staff down day to day.
- Client
- Engineering firm
- Industry
- Engineering, Hamburg
- Period
- since October 2025, ongoing
Starting point
Microsoft 365 had been in use at the firm for years and had grown step by step over that period, without the security architecture ever having been planned as a whole. The management wanted to be able to answer the question “are we adequately protected?” with evidence, without making the engineers’ work more complicated.
Solution
After a review of licences and configuration, a concept brought the available features together: Privileged Identity Management, so administrator rights are only activated for the duration of a task. Conditional Access, so access is tied to user, device and location. Permission groups with a clear logic, and Intune for central device management. Delivery is step by step, with test and pilot groups before each wider rollout.
Outcome
The firm gets a Microsoft 365 environment in which rights, access and devices follow rules you can follow, and where security can be evidenced. The project is under way.