Identity advisory assessment

Identity & Access
Health Check.

Understand where identity and access risk exists before it becomes an access, security or governance problem.

Establish the current position first.

MAITS provides a structured review of identity controls, architecture and governance, then converts the findings into practical priorities.

Assessment scope is agreed around the organisation’s environment, priorities and material identity risks.

Assessment model

Follow identity through every control that should protect it.

We assess how identities are established, authenticated, authorised, provisioned, governed, privileged, reviewed, changed and removed.

The Health Check connects identity controls and operating ownership to a prioritised view of risk, maturity and recommended action.

Why it matters

Identity risk accumulates between systems and owners.

Identity estates rarely fail because one setting is missing. Risk builds through excessive access, standing privilege, inconsistent authentication, weak lifecycle processes and legacy configuration.

The Health Check connects those technical weaknesses to architecture, operating ownership and governance. It helps expose stale access, unclear trust relationships, control gaps and complexity that makes the environment difficult to secure or explain.

Excessive accessStanding privilegeAuthentication gapsWeak lifecycleLegacy patternsUnclear ownership

What we review

A structured view across nine identity control areas.

The exact depth and system coverage are agreed for the engagement. Review areas are selected around material risk rather than treated as an unlimited audit.

01

Identity architecture

Understand how identity is established and where trust and ownership sit.

  • Identity sources and directories
  • Trust relationships
  • Identity ownership
  • Architecture complexity
02

Authentication

Review the strength, usability and resilience of authentication journeys.

  • MFA and authentication strengths
  • Phishing-resistant methods
  • Passkey readiness
  • Registration and recovery
03

Conditional Access

Assess whether access policy expresses the intended risk decisions.

  • Policy coverage and exclusions
  • Authentication requirements
  • Risk and device context
  • Privileged access conditions
04

Privileged access

Identify standing administration and weaknesses in privileged identity controls.

  • Eligibility and standing access
  • PIM and activation
  • Administrative personas
  • Privilege separation
05

Identity lifecycle

Trace identity and access through joiner, mover and leaver events.

  • Workforce and contractor lifecycle
  • Provisioning and change
  • Deprovisioning
  • Process hand-offs
06

Governance

Review how access decisions are owned, approved and reconfirmed.

  • Access reviews and entitlements
  • Approvals and ownership
  • Least privilege
  • Segregation of duties
07

External identity

Examine trust and lifecycle for parties outside the workforce boundary.

  • Guests and suppliers
  • Contractors and partners
  • External accounts
  • Sponsorship and expiry
08

Application integration

Assess how applications consume identity, claims, roles and lifecycle events.

  • OIDC and SAML
  • SCIM and provisioning
  • Roles and claims
  • Lifecycle integration
09

Monitoring & assurance

Determine whether identity control outcomes are visible and explainable.

  • Identity logging
  • Stale access visibility
  • Operational ownership
  • Auditability and evidence

What the organisation receives

Findings that support decisions, not a shelf document.

The outcome is proportionate to the agreed scope and designed to give leaders and identity teams a usable basis for action.

01

Clear findings

A concise view of material identity and access risks, weaknesses and ownership concerns identified within scope.

02

Prioritised recommendations

Separation of urgent remediation from longer-term identity modernisation opportunities.

03

Architecture observations

Identification of unnecessary complexity, legacy patterns, trust assumptions and control gaps.

04

Practical next steps

A sensible sequence for improving identity security, governance and operational maturity.

Current stateRisks & gapsPrioritiesRecommended actionsIdentity roadmap

A practical starting point

Useful before identity modernisation begins.

You do not need to know the solution before engaging MAITS. The Health Check establishes the current position first.

01Modernising Microsoft Entra or redesigning Conditional Access
02Planning passkeys or phishing-resistant authentication
03Reviewing privileged access and standing administration
04Improving access governance or dealing with stale access
05Integrating applications or migrating customer identity
06Preparing a broader IAM programme or target architecture

Professional scope

Focused enough to be useful. Bounded enough to be credible.

Assessment scope is agreed around the organisation’s environment, priorities and material identity risks. Relevant tenants, platforms, applications, populations and control areas are identified before review begins.

The Health Check is an identity advisory assessment. It is not a certification, formal audit or guarantee of compliance or security improvement.

Start a conversation

Understand the current identity position before choosing the solution.

Tell us what has changed, what feels least controlled, or which modernisation decision is approaching. We’ll agree a useful assessment scope.