Identity & Access Management

14 - Identity

Identity & Access
Management

Control who can access your systems, data and applications. Identity is one of the most important parts of cyber security - if access isn't managed properly, attackers use compromised accounts, excessive permissions or weak authentication to reach sensitive systems. RTCS reviews IAM across users, administrators, cloud platforms, SaaS and privileged accounts.

  • Entra ID and Microsoft 365 access review
  • Active Directory access and privilege review
  • Privileged Access Management (PIM / PAM) review
  • Multi-factor authentication and Conditional Access review
  • Single sign-on, RBAC and role design review
  • Joiner, mover and leaver process review
  • Guest, external and contractor access review
  • Service account, SaaS and OAuth permission review
  • Access certification, recertification and governance roadmap
Discuss This Service
Platforms
Entra ID - Microsoft 365 - Active Directory - Okta - Google Workspace - SaaS - third-party IdPs
Review Areas
Users - admins - service accounts - privileged roles - MFA - CA - SSO - guests - OAuth - JML
Engagement Types
Access review - privileged access review - JML process - governance roadmap - access certification
Outputs
Risk-rated findings - access governance roadmap - remediation plan - executive summary
Essential Eight ISO 27001 NIST CSF ISM / PSPF
Entra
M365 & Entra ID Review
AD
Active Directory Review
PAM
Privileged Access Review
AU
Onshore Delivery
01 / Context

Identity is the new perimeter.

Identity and Access Management is the process of managing who has access to systems, applications and data - user accounts, privileged access, MFA, SSO, role-based access, joiner/mover/leaver processes, access reviews and identity governance. A strong IAM program ensures the right people have the right access at the right time.

02 / Common Gaps

Most cyber incidents involve identity in some way.

Attackers target passwords, session tokens, admin accounts, service accounts, OAuth permissions and weak access controls because identity provides a direct path into business systems.

G1

Users having more access than they need

G2

Admin accounts not properly protected

G3

MFA not enforced consistently

G4

Shared or unmanaged accounts

G5

Poor joiner, mover and leaver processes

G6

Stale accounts remaining active

G7

Guest users not being reviewed

G8

SaaS apps connected without approval

G9

Service accounts with excessive permissions

G10

Access reviews not being performed

G11

Conditional Access policies incomplete or inconsistent

03 / Entra ID & M365

Entra ID and Microsoft 365 access review.

Entra ID and Microsoft 365 are central to access control for most organisations. RTCS reviews configuration, access controls and administrative settings to identify weaknesses that increase the risk of account compromise or unauthorised access.

MFA enforcement Conditional Access policies Privileged roles PIM configuration Guest & external access Enterprise applications App consent settings Legacy authentication SharePoint & Teams access Admin account protection Security logging & alerting

Pair with Cloud Security for configuration and exposure review of the same M365 / Azure tenant.

04 / Active Directory

Years of accumulated access. Time to clean it up.

Active Directory often contains legacy groups, excessive privileges and weak account controls. RTCS reviews AD to identify risky permissions, privilege escalation paths and stale or over-permissioned objects.

Domain admin & privileged groups Nested group review Stale account review Service account review Password policy review Local administrator exposure Delegation risks Group Policy review Access to critical systems Privilege escalation paths

For offensive validation of AD attack paths (Kerberoasting, delegation abuse, BloodHound mapping), pair with Penetration Testing.

05 / Privileged Access

Privileged accounts need stronger controls.

RTCS reviews how privileged access is assigned, approved, monitored and removed - so the accounts that can damage the most are also the most controlled.

Privileged Account Review

Admin account inventory, privileged role assignments, PIM / PAM configuration, break-glass account review and administrative separation.

Approval & Monitoring

Access approval workflows, privileged session monitoring, least-privilege recommendations and periodic privileged access reviews.

06 / Joiner, Mover, Leaver

Access should change when the person does.

RTCS reviews JML processes to identify gaps that leave users with unnecessary or active access after they've moved roles or left the organisation.

New starter access approvals Role changes & access updates Departing staff disablement Contractor offboarding Access request workflows HR & IT process alignment Evidence of access changes Periodic access reviews
07 / SaaS & Third-Party

SaaS access often happens outside central IT.

RTCS reviews SaaS and third-party access to identify unmanaged applications, excessive permissions and weak access controls that bypass your central identity program.

SaaS user access Admin roles External collaborators SSO coverage MFA enforcement App integrations OAuth permissions Data sharing settings Supplier & contractor access

For deeper third-party security and contractual risk, see Supply Chain Risk.

Understand to Improve

A practical, staged engagement that turns identity sprawl into a clean, evidenced and governable access program.

01
Understand

Review your identity platforms, business systems, access processes and risk priorities.

02
Assess

Assess accounts, groups, roles, permissions, authentication controls and access governance processes.

03
Identify Gaps

Identify excessive access, weak controls, stale accounts, risky permissions and governance issues.

04
Prioritise

Provide clear actions based on risk, business impact and remediation effort.

05
Improve

Strengthen identity controls, access reviews, privileged access and ongoing governance.

08 / Who It's For & What You Receive

Who It's For & What You Receive

Who This Service Is For

  • Need to reduce identity and access risk
  • Use Entra ID, Microsoft 365 or Active Directory
  • Need to review privileged access
  • Need stronger MFA or Conditional Access
  • Need to clean up excessive permissions
  • Need to improve JML processes
  • Need to review guest, contractor or supplier access
  • Need access evidence for audits or assurance
  • Want practical IAM improvements without complexity

Typical Deliverables

  • IAM assessment report
  • Entra ID access review
  • Active Directory access review
  • Privileged access findings
  • MFA and Conditional Access findings
  • Service account review
  • Guest and external user review
  • JML process findings
  • SaaS access review
  • Risk-rated recommendations
  • Access governance roadmap
  • Executive summary & prioritised remediation
09 / Related Services

Where IAM connects to the rest of the program.

Cloud Security

Configuration, exposure and identity review across the same Azure, AWS, GCP and M365 tenants.

Penetration Testing

Offensive validation of AD, Entra ID and cloud identity attack paths.

Zero Trust Architecture

Identity-first design principles that translate IAM findings into architecture decisions.

Detection & Response

Identity signals (sign-ins, privileged activity, consent) feeding your SIEM and triage workflow.

Supply Chain Risk

Supplier, SaaS and contractor access controls and contractual obligations.

Governance, Risk & Compliance

Access evidence for ISO 27001, Essential Eight, ISM, PSPF and customer assurance reviews.

Security Architecture

Identity, SSO and access-control patterns built into broader security design.

vCISO & Security Advisory

Executive-level ownership of the identity program and its integration into the security roadmap.

Identity is often the easiest path into an organisation. Talk to us about an IAM assessment, Entra ID review, Active Directory access review, privileged access review or joiner mover leaver process review.

Common Questions

What is IAM?

IAM stands for Identity and Access Management. It is the process of managing who can access systems, applications and data.

Why is IAM important?

IAM helps reduce the risk of account compromise, excessive access, unauthorised access and privilege misuse.

Do you review Entra ID?

Yes. RTCS can review Entra ID controls, including MFA, Conditional Access, privileged roles, PIM, guest users, enterprise applications and app consent.

Do you review Active Directory?

Yes. RTCS can review Active Directory users, groups, privileged access, service accounts, Group Policy and risky permissions.

Can you help with privileged access?

Yes. RTCS can review privileged accounts, admin roles, PIM or PAM controls, break glass accounts and access approval processes.

Can you review joiner, mover and leaver processes?

Yes. RTCS can review how access is requested, approved, changed and removed across the employee and contractor lifecycle.

Can you help with access reviews?

Yes. RTCS can help design or improve access review processes for users, privileged accounts, SaaS applications, guest users and critical systems.

Available across Australia.

RTCS provides identity and access management review for Australian organisations using Microsoft 365, Entra ID, Active Directory and cloud platforms. See cyber security services across Australia for national delivery context.