Multi-factor sign-in
An authenticator app, and for high-risk accounts passkeys or hardware security keys that resist phishing. Legacy sign-in methods without multi-factor support are turned off.
We build up access control in stages, each worthwhile in its own right. The order depends on your risk and on what your team will accept.
An authenticator app, and for high-risk accounts passkeys or hardware security keys that resist phishing. Legacy sign-in methods without multi-factor support are turned off.
Entra ID policies: company data only from managed devices, extra verification for sign-ins from unusual countries, blocks when risk is detected. Break-glass accounts are stored securely.
Every company laptop and phone enrolled in Intune, with consistent policies for encryption, screen lock, updates and antivirus. New devices configure themselves through Autopilot when the employee unboxes them.
App protection policies for Outlook and Teams on personal phones: company data stays inside company apps, cannot be pasted into private ones and can be wiped selectively when someone leaves, without touching their photos.
No local admin rights for everyday work, separate accounts for administrative tasks, time-limited elevation for management tasks.
Where the risk warrants it, workstations run only approved programs. This stops many attacks that start with a downloaded tool.
Access control touches everyone in the company, so we plan the roll-out so that nobody loses a working day.
Which accounts exist, which lack multi-factor, which devices connect and which are managed. Plus the list of special cases: scanners, service accounts and colleagues without a work phone.
Registration of all users with a guide and video support, set-up of emergency accounts, retirement of legacy sign-in.
Company devices are brought under management remotely, policies first in report mode, then enforced. Personal devices receive app protection.
Conditional access is switched on step by step, and reports show who would be affected. A policy becomes mandatory only when that list is empty.
Multi-factor by text message beats none at all, but it is not the finish line. Phishing kits now intercept one-time codes and relay them in real time. For management, accounting and IT admins we therefore recommend passkeys or security keys. They only work on the genuine sign-in page and are practically useless to an attacker.
That is understandable. Alternatives are a security key on the keyring or a work phone. What matters is that everyone has a workable option, otherwise exceptions creep in and stay forever.
They contact IT, or us via helpme@apply.at; the old registration is removed and a new second factor is set up within the response time of your plan. Company data on the lost device is wiped remotely.
Yes. Google offers 2-Step Verification, context-aware access and endpoint management. The feature set depends on the Workspace edition. We configure either platform.
Yes, Intune handles macOS, iOS and Android. For a larger Apple estate a dedicated Apple management tool may be the better choice, which we then connect to Entra ID.
Give us the number of users and devices and describe how people work. We will propose an order of steps that makes you markedly safer within a few weeks.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.