Skip to main content
Falstech.
Microsoft cloud service

Security & Compliance

A documented control baseline and evidence set for review by your independent assessor.

All services
When this fits

Signs you need this.

  • A customer or assessor is asking for control evidence that is difficult to produce.
  • MFA and conditional access are partial, inconsistent, or missing entirely.
  • You have no single, credible answer for who can access what.
  • Security findings pile up with no owner and no remediation queue.
  • Gathering evidence for an audit means a frantic screenshot scramble each time.
First

What we assess.

  • Entra identity posture — MFA coverage, conditional access, and privileged roles.
  • Defender for Cloud secure score and the highest-impact recommendations.
  • Endpoint and workload hardening against a documented baseline.
  • Current controls mapped to the framework you're targeting (SOC 2 / HIPAA / ISO).
  • Logging, retention, and whether audit evidence can actually be produced.
Then

What we implement.

  • Conditional access and MFA rollout with a tested break-glass path.
  • The Defender and endpoint baseline included in the agreed scope.
  • Control mapping to your target framework, with gaps assigned owners.
  • An evidence index that organizes the policies, logs, and screenshots produced for review.
  • A remediation backlog with owners and a review cadence agreed in scope.
Deliverables

What you get.

  • Conditional-access and MFA implementation plan
  • Defender or endpoint baseline included in scope
  • Control mapping for the assessor's stated framework
  • Evidence index and supporting artifacts
  • Prioritized remediation backlog with ownership

What the engagement requires and where it ends.

Typically a focused control assessment followed by fixed-scope remediation. Advisory support can be reserved for defined architecture or evidence questions.

Client inputs

  • The assessor's request list or the specific framework and control scope
  • Read access to the relevant Entra, Microsoft 365, Azure, or Defender configuration
  • Existing policies, findings, evidence, and named control owners
  • Change constraints, pilot groups, and approval paths

Explicit exclusions

  • Certification, legal interpretation, or an audit opinion
  • A guarantee that an independent assessor will accept a control or artifact
  • 24/7 SOC monitoring or incident response unless separately contracted

Handoff

  • Control map, assumptions, and evidence index
  • Configuration and implementation artifacts included in scope
  • Decision records and exception notes
  • Remediation backlog with owners and next actions
Stack

Technologies.

Microsoft Entra IDConditional AccessMicrosoft Defender for CloudMicrosoft SentinelAzure PolicyPrivileged Identity ManagementKey Vault
Questions

Frequently asked.

Can you get us certified?
No. We can help prepare relevant controls and organize evidence for review. Certification and the final determination remain with your independent assessor.
What is a break-glass account and why does it matter?
It is an emergency administrative access path designed for recovery when normal controls or identities are unavailable. Its configuration, monitoring, and exclusions must be tested against the tenant's own requirements before broader policy enforcement.
How disruptive is a conditional-access rollout to end users?
The rollout approach depends on the tenant and policy. A common pattern is to review impact in report-only mode, define exclusions and emergency access, pilot with a limited group, then expand through approved change windows.

Ready to start?

Start with a focused discovery conversation about the environment, pressure, access, and outcome. Pricing is provided after that conversation or a paid assessment when more evidence is required.