Virtus Group • Identity security pilot

Identity & Conditional Access Jumpstart

A focused pilot to strengthen sign-in protection, reduce account-takeover risk and validate safer access controls for one agreed tenant and user group.

Virtus Group logo

Protect sign-ins without boiling the ocean

MFA and Conditional Access are powerful, but poor rollout can create lockouts, exceptions, alert noise and frustrated users.

This pilot validates a practical baseline for a defined cohort before you commit to a wider identity programme or tenant-wide rollout.

What the pilot helps answer

Who should be protected first?

We define the pilot cohort and identify the users, groups or devices that make sense for the first step.

What controls are safe to apply?

Baseline MFA and Conditional Access settings are matched to licensing, user impact and rollback needs.

How should rollout continue?

You get known exceptions, risks and dependencies before extending controls more widely.

Common signs this is worth doing

MFA is inconsistent
some users are protected, others are not, and exceptions are unclear.
Admin access feels risky
privileged accounts, emergency access or break-glass controls need review.
Conditional Access exists partly
but coverage, exclusions or policy impact are not fully understood.
Risky sign-ins are hard to act on
alerts are noisy, unclear or not routed to the right people.

What we focus on

Scope is agreed before work begins. The pilot is normally limited to one tenant and one defined user, group or device cohort.

Tenant readiness

Current identity controls, licensing assumptions and practical rollout constraints.

Break-glass approach

Emergency access protection so the business does not lock itself out.

MFA and access policy

Baseline controls for the agreed cohort with validation and rollback awareness.

Sign-in visibility

Alert routing, useful signals and practical next-step recommendations.

What you get

Validated pilot cohort

A defined group with baseline MFA and Conditional Access working as intended.

Known exceptions and risks

Visibility of legacy clients, device-state issues, licensing gaps or policy constraints.

Rollout path

A practical staged path for broader identity hardening or managed identity care.

How the pilot works

1

Scope

We confirm tenant, cohort, access method, licensing and change window.

2

Prepare

We review readiness, break-glass approach and policy assumptions.

3

Validate

We apply or verify agreed baseline controls and check the user impact.

4

Decide

You choose whether to expand rollout, remediate gaps or move into managed identity care.

What this is not

Not a tenant-wide rollout

The pilot is limited to the agreed tenant and cohort unless separately scoped.

Not identity redesign

Identity lifecycle, SSO onboarding, HR integration and broad access redesign are separate work.

Not a lockout experiment

Change control, validation contacts and rollback expectations are agreed before implementation.

Quick questions

Which platforms can be considered?

Microsoft 365 / Entra ID is the most common fit. Equivalent managed identity platforms may be considered during scoping.

Do you need admin access?

Admin, security admin or equivalent delegated access is usually required for setup and validation. Access method and timing are agreed before work begins.

Will this affect all users?

No. The pilot is scoped around one defined user, group or device cohort unless broader rollout is explicitly agreed.

Are pilot prices published?

No. We confirm the estimate after scope, access requirements and deliverables are understood.

Want safer sign-ins without a risky big-bang rollout?

Start with a short conversation. We will help confirm whether the Identity & Conditional Access Jumpstart is the right first step, or whether a broader security review, project or managed identity pathway makes more sense.

No hard sell. Just clarity and next steps.

Start with a free 30-minute IT conversation

hello@services.virtusgroup.biz
0800 847 887 (VIRTUS)
virtusgroup.co.nz