SaaS Security & Access Assessment

Phishing-resistant MFA, conditional access, and license right-sizing across the SaaS platforms your business actually runs on, scoped to what you use.

MFA Isn't a Checkbox: Not All of It Stops Phishing

Most organizations rolled out MFA years ago and haven't looked at it since. But SMS codes, one-time passcodes, and push notifications can all be defeated by adversary-in-the-middle phishing kits that relay a real login in real time, so the user thinks they're signing in normally, and the attacker walks away with a valid session.

Identity is the perimeter now. Getting it right means phishing-resistant authentication, conditional access policies built around actual risk and business need, and license tiers that include the features you're relying on, not ones that are missing them, or paying for ones nobody turned on.

Microsoft 365 and Google Workspace are usually the anchor, since one of them is your identity provider for everything else. But most businesses run critical work through other SaaS platforms too, such as Atlassian, Salesforce, GitHub, and whatever else holds your code, your pipeline, or your customer data. We scope the assessment to the platforms that actually matter for your business, not a fixed checklist.

This is different from a vendor risk assessment, which looks at whether the outside companies you depend on are secure. This engagement looks inward, at how your own accounts and configuration are set up across the SaaS platforms you use.

Signs Your Identity Layer Has Gaps

  • MFA is SMS or authenticator-app codes only, no phishing-resistant option in use
  • No conditional access policies, or a few one-off rules nobody remembers building
  • Every user gets the same access regardless of device, location, or risk level
  • Legacy authentication protocols that bypass MFA entirely are still enabled
  • Unsure whether your current license tier even includes conditional access
  • No single sign-on, so MFA enforcement is inconsistent across different apps

What We Assess

Authentication strength, access policy, identity consolidation, and the licensing underneath all of it, scoped across every SaaS platform your business depends on.

🔐
Phishing-Resistant Authentication

Where MFA relies on SMS, TOTP, or push notifications that can be relayed by phishing kits, and where FIDO2 security keys or passkeys can close the gap without disrupting how your team works.

🛡️
Conditional Access & Risk-Based Policies

Device compliance requirements, IP and geo restrictions, legacy authentication blocking, and risk-based sign-in rules, designed around your actual risk and business needs, not a generic template.

🔗
SSO & Identity Consolidation

Whether single sign-on is in place across the apps that matter, so MFA and access policy get enforced consistently instead of varying app by app.

🎟️
License Tier Right-Sizing

Mapping what your license actually includes, across Microsoft 365 / Entra ID, Google Workspace, and other in-scope SaaS platforms, against the security features you're relying on, so you're not missing conditional access, or paying for a tier nobody's using.

🧩
Scoped to Your SaaS Footprint

Beyond your identity provider, we assess whatever platforms matter to your business, such as Atlassian, Salesforce, and GitHub, for the same gaps: weak MFA, missing SSO enforcement, over-permissioned admins, and inconsistent access policy.

How the Engagement Runs

  1. 1
    Scope the SaaS platforms that matter to your business

    Microsoft 365 or Google Workspace as the identity anchor, plus whatever else you depend on, such as Atlassian, Salesforce, or GitHub, sized to your actual footprint, not a fixed list.

  2. 2
    Inventory current MFA methods and auth strength

    What's enforced today across each in-scope platform, for whom, and which accounts are still relying on phishable methods.

  3. 3
    Map license entitlements against features in use

    Confirm what each platform's tier actually includes, and where there's a mismatch either way.

  4. 4
    Design a conditional access policy set

    Built around real risk and business needs, such as device compliance, location, legacy auth, and risk-based sign-in, not a copy-pasted baseline.

  5. 5
    Rollout support, staff communication, and validation

    Phased enablement, break-glass accounts handled correctly, and confirmation the policies work as intended before you're done.

What You'll Have When We're Done

  • Phishing-resistant MFA recommendation and rollout plan
  • Conditional access policy set matched to your risk and business needs
  • License entitlement review across every in-scope platform: gaps and unused spend identified
  • SSO configuration review across your key applications
  • Written report suitable for leadership and cyber insurance renewal
  • Prioritized hardening plan for anything left for a later phase

Who This Is For

Organizations running Microsoft 365 or Google Workspace, plus whatever other SaaS platforms the business actually runs on, like Atlassian, Salesforce, or GitHub, that haven't revisited their MFA and access configuration since it was first set up. Especially if that setup predates recent phishing-kit capability, or if it's never been reviewed against what the current license tier actually offers.

Also a good fit after a near-miss: a phishing attempt that got further than it should have, an insurance renewal asking pointed questions about MFA, or growth that's outpaced the original access setup.

Risk Doesn't Stop at Your Own Tenant

Hardening your own configuration across the SaaS platforms you use closes one door. If your organization also depends on third-party SaaS vendors that hold your data or connect into your systems, their security posture matters just as much as yours.

Vendor Risk Assessment

Find out whether the vendors you depend on are secure, before their breach becomes your incident.

Learn About Vendor Risk Assessment

Frequently Asked Questions

Isn't MFA already enough?

Not all MFA is equal. SMS codes, one-time passcodes, and push notifications can all be phished by adversary-in-the-middle kits that relay your login in real time and steal the resulting session: the second factor doesn't stop it because you're really authenticating to the attacker's proxy. Phishing-resistant methods like FIDO2 security keys and passkeys close that gap because the credential is bound to the real site's origin and can't be relayed.

What's phishing-resistant MFA, exactly?

It's authentication built on FIDO2/WebAuthn (hardware security keys or platform passkeys such as Windows Hello, Touch ID, and Android/iOS biometrics), where the cryptographic proof is bound to the legitimate site's origin. A fake login page simply can't complete the exchange, which is what makes it resistant to the phishing kits that defeat SMS and TOTP.

Do we need to buy a more expensive license to get this?

Sometimes, and sometimes you already have it and it's just not turned on. Conditional access in Microsoft 365 requires Entra ID P1 (bundled into Business Premium and E3); risk-based conditional access needs P2 (E5 or an add-on). Google Workspace context-aware access requires Enterprise Standard/Plus or a Cloud Identity Premium add-on, and it's not in the Business tiers. Other SaaS platforms have their own version of this trap, with SSO enforcement, audit logging, or access policies locked behind a higher plan. We map what your current license includes against what you're actually using before recommending any change in spend.

Does this cover more than Microsoft 365 and Google Workspace?

Yes. Those two are usually the anchor because they're the identity provider for everything else, but the assessment scopes to whatever SaaS platforms your business actually depends on, such as Atlassian, Salesforce, GitHub, and other common additions. We scope the engagement around your specific stack rather than assuming it stops at your primary email/identity platform.

How long does this take?

It's a focused engagement, not an open-ended project: an inventory of current MFA methods and license entitlements across the platforms in scope, a conditional access policy design session, and rollout support. Most engagements run over a few weeks, scoped to your tenant size, how many platforms are in scope, and how many policy exceptions your business actually needs.

Ready to Get Started?

Let's discuss how SaaS Security & Access Assessment can protect your organization.

Schedule a Free Consultation