Service · IT security

Access control and endpoint protection

Most successful attacks on Microsoft 365 accounts need no malware at all. A password stolen from some other service is enough, or a phishing page that mimics the Microsoft sign-in screen convincingly. At the same time, people work from everywhere: in the office, at home under a telework agreement, on the train to Vienna, on a personal tablet at the kitchen table. The old idea of the company network as a safe castle no longer holds. Access control therefore rests on two questions. Is this really the person they claim to be? And is the device they are using in a trustworthy state? Only when both answers are yes does anyone reach email, files and applications. Consider a tax advisory firm in Graz with twelve staff: client data lives in the cloud, and practice software and BMD run on a terminal server. With multi-factor sign-in, conditional access and managed laptops, a stolen password there becomes only half a problem.

Multi-factor
for every account, management included
Conditional access
based on device, location and risk
Intune
or Google endpoint management for every company device
Personal devices
with a separated work area

Everything this covers

We build up access control in stages, each worthwhile in its own right. The order depends on your risk and on what your team will accept.

Settle the details with an engineer

Multi-factor sign-in

An authenticator app, and for high-risk accounts passkeys or hardware security keys that resist phishing. Legacy sign-in methods without multi-factor support are turned off.

Conditional access

Entra ID policies: company data only from managed devices, extra verification for sign-ins from unusual countries, blocks when risk is detected. Break-glass accounts are stored securely.

Device management

Every company laptop and phone enrolled in Intune, with consistent policies for encryption, screen lock, updates and antivirus. New devices configure themselves through Autopilot when the employee unboxes them.

Personal devices

App protection policies for Outlook and Teams on personal phones: company data stays inside company apps, cannot be pasted into private ones and can be wiped selectively when someone leaves, without touching their photos.

Admin rights

No local admin rights for everyday work, separate accounts for administrative tasks, time-limited elevation for management tasks.

Approved applications

Where the risk warrants it, workstations run only approved programs. This stops many attacks that start with a downloaded tool.

Our working method

Access control touches everyone in the company, so we plan the roll-out so that nobody loses a working day.

01

Stocktake

Which accounts exist, which lack multi-factor, which devices connect and which are managed. Plus the list of special cases: scanners, service accounts and colleagues without a work phone.

02

Multi-factor and break-glass

Registration of all users with a guide and video support, set-up of emergency accounts, retirement of legacy sign-in.

03

Enrol devices

Company devices are brought under management remotely, policies first in report mode, then enforced. Personal devices receive app protection.

04

Enforce the rules

Conditional access is switched on step by step, and reports show who would be affected. A policy becomes mandatory only when that list is empty.

Multi-factor by text message beats none at all, but it is not the finish line. Phishing kits now intercept one-time codes and relay them in real time. For management, accounting and IT admins we therefore recommend passkeys or security keys. They only work on the genuine sign-in page and are practically useless to an attacker.

Frequently asked questions

That is understandable. Alternatives are a security key on the keyring or a work phone. What matters is that everyone has a workable option, otherwise exceptions creep in and stay forever.

They contact IT, or us via helpme@apply.at; the old registration is removed and a new second factor is set up within the response time of your plan. Company data on the lost device is wiped remotely.

Yes. Google offers 2-Step Verification, context-aware access and endpoint management. The feature set depends on the Workspace edition. We configure either platform.

Yes, Intune handles macOS, iOS and Android. For a larger Apple estate a dedicated Apple management tool may be the better choice, which we then connect to Entra ID.

Make stolen passwords worthless

Give us the number of users and devices and describe how people work. We will propose an order of steps that makes you markedly safer within a few weeks.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.