Skip to content
EJK Consultancy
Identity and Tenant Security

Conditional Access and Microsoft 365 Security Consultancy

EJK Consultancy helps UK businesses review and configure MFA, Conditional Access, admin roles and sharing policies in Microsoft 365. The aim is a baseline that protects the tenant without blocking the way people actually work.

A lot of Microsoft 365 tenants are still running on Security Defaults, a handful of global admins, and MFA that was enabled for some people after a phishing incident. That is leftover setup, not a security baseline.

Conditional Access needs named policies, documented exclusions and break-glass accounts that have been tested. Sharing, guest access and mailbox security need to match how the business works, not a template copied from somewhere else.

EJK Consultancy designs and implements that baseline, then hands it over in a form your IT team or MSP can support.

Planning Copilot? Oversharing becomes more visible once Copilot can find it. See the Copilot readiness assessment or the Microsoft 365 security checklist for SMEs.

Core Security Services

Identity first, then sharing and mailbox security.

Conditional Access Design

Named policies for admins, standard users, guests and service accounts, with MFA, location and device signals used where they actually help.

Admin Roles and Standing Access

Reviewing Global Administrator count, unused privileged roles and break-glass accounts that work when everyone else is locked out.

Sharing, Guests and Mailbox Security

Anyone-links, guest access, external forwarding and anti-phishing policies, including the Exchange Online settings identity policy cannot fix on its own.

MFA and Legacy Authentication

MFA for human accounts, a plan for the apps that still fail it, and legacy authentication blocked once the remaining clients are identified.

Guest Access and External Sharing

Guest expiry, sharing defaults that match how the business works, and clearer rules for sensitive libraries.

Incident-Driven Cleanups

Compromised mailbox, leaked admin or a board asking whether the tenant is actually protected. Scoped work to close the gap and leave a baseline behind.

What a Sensible Baseline Usually Includes

Controls that reduce risk without creating a queue of lockouts.

MFA for every human account
No standing Global Administrator for daily work
Named, owned Conditional Access policies
Break-glass accounts that have been tested
Guest accounts that expire
Anyone-links kept off sensitive libraries
Legacy authentication blocked after discovery
External forwarding reviewed
Admin roles reduced to what people actually need

Frequently Asked Questions

Common questions about Conditional Access and Microsoft 365 security.

If Conditional Access is blocking staff, or blocking nothing, it needs a proper design.

Book a short review. We will tell you whether this is a policy cleanup or a wider tenant hardening piece of work.