Scope and boundary
We agree the systems, environments, data types, review period, and exclusions in writing before any evidence is collected, with a stated reason for each exclusion.
A point-in-time advisory review of where account takeover, standing privilege, and unreviewed access actually sit, and a sequenced path toward a Zero Trust target state. We work from the evidence you can produce, describe the target design and its trade-offs, and hand you a roadmap a named owner can execute against.
For the leader who owns identity risk. Advisory and readiness work. Not an implementation service, not an audit, not a certification.
Most of this work is vendor-neutral. Where the evidence in scope is a specific identity or productivity platform DSE is approved to name, the reviewed scope is stated in approved wording. The identity-directory scope reads: A structured, point-in-time manual advisory review of client-provided Microsoft Entra portal configuration and exports, with an evidence register, findings, and remediation priorities. The productivity-suite scope reads: A structured, point-in-time manual advisory review of client-provided Microsoft 365 portal configuration and exports, with an evidence register, findings, and remediation priorities.
This is an owner-approved advisory and evaluation scope with no independent certification, partner, or reseller status. Implementation, hardening, and monitoring require separate evidence and scope. Every other identity or productivity platform is advisory and evaluation context only and is scoped separately with evidence.
The Identity and Zero Trust Advisory Method follows DSE's bounded-evidence assessment method: a bounded evidence request, focused interviews, a business-context severity rating, and a roadmap with named owners. The lane-specific layer maps identity lifecycle, authentication strength, privileged access, application and device access, and segmentation against the Zero Trust tenets in NIST SP 800-207, framed as a staged roadmap rather than a single leap.
We agree the systems, environments, data types, review period, and exclusions in writing before any evidence is collected, with a stated reason for each exclusion.
A defined request for client-provided exports, screenshots, screen shares, and documents. We do not request administrator credentials and we do not run automated scans.
Short, targeted conversations with the people who own the controls, to test how the design actually operates rather than how a diagram says it should.
We rate each observed gap by likelihood and business impact, and record evidence strength alongside it. Severity is a business-context rating, not a vulnerability score, and the method is explained in the report.
Each finding states what we observed, why it matters, the supporting evidence, the recommended action, and a named accountable owner.
Immediate actions and a sequenced roadmap that balances risk reduction, dependencies, effort, and cost, with named owners and an executive readout for leadership.
Typical timebox: 3 to 5 weeks after kickoff and timely evidence access. Larger, multi-environment, or high-complexity engagements are scoped separately. Fees are scoped after the diagnostic and confirmed in writing before work begins.
We assess client-provided directory and identity exports, group and role membership exports, conditional-access or access-policy exports, privileged-role inventories, joiner-mover-leaver process documentation, and application access lists, supplemented by screen shares where a live view is faster than an export.
We do not request administrator credentials, we do not connect tooling to your environment, and we do not run automated scans. The review is manual and evidence-based, so it stays inside a boundary you can see and revoke.
Every identity and access control in scope with the evidence you produced, a business-context severity, an accountable owner, and a target date.
Standing privilege, orphaned accounts, shared administrative credentials, and break-glass paths reviewed against least-privilege intent, with the exposures that matter flagged.
Multi-factor coverage, legacy authentication paths, and conditional access or equivalent policy reviewed against the target posture, with the gaps that let account takeover through.
A staged read of your current posture against the NIST SP 800-207 tenets, so the roadmap targets the highest-leverage moves first.
The access lifecycle assessed for the reviews and revocations that actually happen versus the ones the policy assumes.
Immediate actions and a sequenced roadmap balancing risk reduction, dependencies, effort, and cost, with named owners and an executive readout.
Synthetic sample — not client data. It contains no client information and is not a finding about any organization.
The sample table scrolls horizontally on smaller screens. Keyboard users can focus the labeled table region and use horizontal navigation.
| Control area | Observed evidence | Severity | Recommended move |
|---|---|---|---|
| Privileged access | Several administrative roles are assigned permanently with no time-bound elevation or periodic recertification. | High | Move to time-bound elevation, set a recertification cadence, assign an owner. |
| Authentication | Multi-factor is enforced for most staff, but a legacy authentication path remains enabled for a shared mailbox. | High | Disable the legacy path, migrate the shared mailbox, confirm coverage evidence. |
| Access lifecycle | Leaver access is removed on a manual ticket with no periodic reconciliation of active accounts. | Moderate | Add a scheduled reconciliation of active accounts against current staff. |
Final ratings depend on the environment, the evidence, and the agreed method. We do not convert findings into a purported certification score.
We use the Zero Trust tenets of NIST SP 800-207 as the target model and NIST CSF 2.0 as the organizing structure. These frameworks shape how we describe outcomes; they do not make this an accredited assessment, and the roadmap is advisory.
DSE delivers through documented in-house expertise and qualified specialists from our expert network, selected for the technologies and risks in scope. DSE remains accountable for scope, quality, integration, and outcomes. Where specialist or partner delivery is involved, we disclose that role clearly.
Accountable owner: DSE delivery leadership.
This is a point-in-time assessment of the identity, access, and Zero Trust evidence and documentation in the agreed scope. It is not legal advice, not an audit, not a certification, and not an attestation. It does not guarantee compliance or any enforcement or examination outcome. It does not make your organization secure and does not prevent, detect, or reduce the likelihood of any security incident; it documents risk against a defined scope at a point in time. DSE does not operate a 24/7 security operations center, does not provide continuous monitoring or managed detection and response, does not perform live incident response or digital forensics and incident response (DFIR), does not run penetration tests, and does not resell licenses. Where you need any of those, we help you scope the requirement and select a provider you contract directly. Remediation implementation is performed only where it is separately scoped in writing. Counsel, auditors, and assessors retain their respective roles.