Skip to content
NexDefend IT services directory
14 destinations · EN + FR contact@nexdefend.com How listings work
Menu

Guide G16 Identity & access

Identity touches support, ownership, and security alike. Name who owns it.

Sign-in problems show up as a support ticket, account setup shows up inside managed IT, and MFA or Conditional Access policy shows up inside a security review - but identity is really one connected responsibility. Multi-factor authentication, single sign-on, SAML connections, and Conditional Access rules all depend on the same underlying question: who decides how people prove who they are, on whichever identity platform the business actually uses, and who reviews it.

G16 · Entry 01 Three different identity jobs

Start with who is affected and how often this recurs.

Someone is locked out right now

One person can't sign in, approve an MFA prompt, or reach an app through SSO. This is support, not a policy review.

MFA, SSO, or Conditional Access has no consistent owner

Policies were set up once, exceptions accumulated, and no one reviews who's enrolled, exempt, or actually covered today.

Leadership wants Conditional Access decided properly

A bounded review can define which apps use SSO/SAML, what Conditional Access rules apply, and what a phishing-resistant MFA policy should look like.

G16 · Entry 02 Decision matrix

Match the situation to the right first route.

Observed need Best first route Useful evidence Boundary
A user is locked out or an MFA prompt won't work Support User, app, device, error, timing Not a policy audit
MFA enrollment or exceptions are inconsistent Managed IT Enrollment coverage, exception list, last review date Not an instant fix for every account
Apps need SSO/SAML but it's set up ad hoc Managed IT or advisory App list, current auth method per app, priorities Not a vendor-specific setup guarantee
Leadership wants Conditional Access rules defined Bounded review or advisory Risk priorities, app criticality, current policy if any Not legal or compliance certification

G16 · Entry 03 Prepare the brief

Bring these facts to an identity conversation.

  • Which identity provider is in use: Microsoft Entra ID, Google Workspace, Okta, or another.
  • Whether MFA is enforced for everyone, and how exceptions are tracked.
  • Which applications use SSO/SAML today, and which still use separate logins.
  • Whether Conditional Access - or an equivalent - rules exist, and who last reviewed them.
  • Who updates access when someone joins, changes role, or leaves.
  • Keep passwords, recovery codes, and MFA secrets out of the brief itself.

G16 · Entry 04 What this covers

What this guide covers, and what it does not.

In scope
Naming who owns MFA enforcement, SSO/SAML connections, and Conditional Access policy, and the evidence a reviewer should ask for.
Out of scope
Resetting a specific account, vendor-specific configuration work performed by NexDefend, or compliance certification.
Possible next decision
Ongoing identity-policy ownership, a bounded Conditional Access/SSO project, or immediate account support.

G16 Next

Give identity policy a named, recurring owner.

Compare ongoing ownership routes for recurring MFA and access review, or read the email security guide for how identity controls fit into phishing defense.

Compare ongoing ownership routes Read the email security guide →