Role model
Groups for functions such as reception, accounts, project management or warehouse. A new starter receives the matching role and with it the mailboxes, folders and applications they need.
The aim is a directory that mirrors your organisation rather than the history of your IT. To get there we work with management and whoever handles HR.
Groups for functions such as reception, accounts, project management or warehouse. A new starter receives the matching role and with it the mailboxes, folders and applications they need.
Accounts for seasonal staff, summer interns or project partners get an expiry date when they are created. Anyone who stays longer is extended; everyone else loses access without further action.
At reception, in the workshop or the warehouse we configure devices so each person signs in quickly with their own account, for example with Windows Hello or a FIDO2 key, instead of sharing a generic login.
Microsoft Authenticator, passkeys or hardware keys, depending on what your staff will accept. We roll it out department by department with a one-page guide.
Company data reachable only from managed or verified devices, risky sign-ins blocked and legacy authentication methods switched off.
Your tax adviser, an architecture practice or a software supplier receive guest access with precisely the rights they need, plus a periodic check on whether they still need them.
Tidying organisational units and Group Policy, synchronisation via Entra Connect, hardening the domain controllers and a plan for what moves to the cloud over time.
We change things without disrupting work. Every adjustment is tried with a handful of people before it applies to everyone.
All accounts, groups, admin roles, licences and sign-in methods. We flag what is orphaned, duplicated or over-privileged.
Together with you we set out functions, responsibilities and who may approve which permissions.
Roles, MFA and access rules one department at a time. Problems are solved within the pilot group, not across the whole company at once.
Every quarter the people in charge confirm the permissions in their area, and we correct any discrepancies immediately.
Shared accounts are convenient and dangerous in equal measure. A “reception” account with one password for everyone cannot be protected with MFA, because no second factor belongs to several people, and the audit log just says “reception” for every action. When a booking is deleted or an email sent, nobody knows who did it. Shared mailboxes combined with personal sign-ins fix both problems without slowing down the front desk.
As soon as we hear about it. A message to helpme@apply.at is enough: we block the account, end active sessions and revoke device access. The mailbox is kept as a shared mailbox until you decide how long to retain it.
With a FIDO2 key on a keyring or Windows Hello on the shared device. Neither needs a personal smartphone, and the cost per person is small.
That depends on what still relies on it. Older line-of-business applications, local file shares or Wi-Fi authentication often do. We list those dependencies and propose a way to retire them one by one.
Yes, as a guest in Entra ID with access to the shared folders only. It is safer than sending attachments by email. We set it up so the access has to be re-confirmed periodically and ends when the engagement does.
It does. Traceable permissions, personal accounts and sign-in logs are basics expected both under the GDPR and under NIS2 for essential and important entities. We do not provide the legal classification of your company, but we deliver the technical evidence.
How many people work for you, do you employ seasonal staff and how do they sign in today? We will reply with a proposal for the first step.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.