Skip to content

A login has a lifecycle too.

Multi-factor authentication, conditional access, and password hygiene usually get a single bullet inside a bigger service description. They deserve the same treatment a device already gets: a named owner, a recurring cadence, and a plain description of what good looks like.

Read this page in French

Why this needs its own rhythm

An account is secured continuously, not once.

A new employee's account gets configured correctly on day one, multi-factor authentication included. Eighteen months later, nobody has looked at it since - no review of what it can reach, no confirmation the recovery details are still correct, no check that a contractor's temporary access ever actually expired. Identity is not a setup task finished at onboarding. It is a standing responsibility with its own cadence, whether or not a provider names it that way.

Four pieces, one rhythm

The pieces that make up everyday identity work.

Multi-factor authentication

A second proof of identity beyond a password, applied across email, files, and any business application that supports it - not only the one system that happened to prompt for it first.

Access rules

Conditions that call for extra scrutiny on an unfamiliar location, a new device, or a sign-in pattern that does not match how someone normally works, instead of treating every login identically.

Single sign-on

One verified identity carried across the applications that support it, so people are not juggling a different password for every system they touch.

Credential hygiene

Passphrases instead of short complex strings, a password manager instead of reused logins, and a clear break from writing credentials on paper or in a shared spreadsheet.

See where this fits inside everyday managed IT

Across the identity lifecycle

Each moment has a typical action and a decision owner.

MomentTypical actionDecision owner
New accountCreate the account, assign licensing, enrol multi-factor authentication before first useManaged service, per the agreed standard
Routine access reviewConfirm who can reach what, and whether it still matches the roleManaged service proposes; your team confirms sensitive changes
Suspicious sign-inInvestigate the alert, challenge or lock the session, contact the employee directlyManaged service, escalated immediately when warranted
Departure or role changeRemove or adjust access on the agreed timelineYour team confirms the trigger date; managed service executes

This is not a claim of a specific compliance framework, a maturity score, or a breach-prevention guarantee. It describes what a workable identity rhythm actually contains - exact tools and coverage are confirmed in writing for your environment. See how a departure connects to the wider onboarding and offboarding sequence

Who this fits

Built for named accounts, not shared logins.

A good fitTeams where every employee has a named account across email, business applications, and any remote-access tool, and where multi-factor authentication is realistic to enforce.

Probably not the fitEnvironments still relying entirely on shared logins with no individual accounts, or a single specialized system whose own vendor already manages its own identity model end to end.

See the Microsoft 365 side of everyday identity

Before you compare providers

Ask how a suspicious sign-in actually gets handled.

Every provider will say they use multi-factor authentication. The more useful question is what happens after enrollment: who reviews access every few months, who gets contacted when a sign-in looks wrong, and how access actually gets shut off on the day a departure happens - not the day someone remembers to do it. See how identity review fits the recurring maintenance rhythm

See the security layers beyond the login itself

Prepare the responsibilities before contacting a provider.

The service map turns your context into a short, copyable list: people, devices, Microsoft 365, vendors, and decisions to clarify.

Build the service map