Local small business

Identity hardening after an account compromise

A focused Entra ID review for a six-person barber shop that needed stronger account protection without adding friction to a simple, location-based way of working.

Client
Six-person local barber shop
Constraint
Focused scope and a limited budget
Work
Entra ID review, hardening, and handover
01

The situation

An employee and contractor account had been compromised. The owners were concerned about what the attacker could still reach and whether business data had been put at risk. Microsoft 365 had been set up previously, but the owners did not have a clear view of which identity protections were actually active.

Because the business was budget constrained, the engagement was deliberately limited to Microsoft Entra ID: the accounts, sign-ins, administrative access, registered devices, and Conditional Access policies behind day-to-day email access.

02

What the review found

Conditional Access policies existed, but some were disabled and others did not enforce the protection the business expected. Multi-factor authentication was not reliably required, and sign-in risk was not configured to generate useful notification or response.

Three accounts held Global Administrator access: the two owners and a stale account that had not signed in for a long time. The compromised user also had unfamiliar devices registered to the account, showing how continued access had been established after the initial compromise.

02 / Control path

From assumed protection to enforced controls.

The work connected each confirmed identity gap to an approved, tested change and a written handover.

Before

Controls were present, not dependable

  • MFA was not reliably enforced
  • Conditional Access was disabled or misconfigured
  • Privileged and stale access needed review
  • Unauthorized devices remained associated with a user
After

Expected access had clear boundaries

  • MFA was required for all user sign-ins
  • Approved Conditional Access policies were active
  • Sign-ins were limited to the client's Canadian use case
  • Risk findings and future administration were documented
The engagement was intentionally narrow: Entra ID controls were reviewed and hardened, while broader Microsoft 365 services remained outside the agreed scope.
03

How we approached it

We sat with an owner to understand who needed access, which company devices were used, and where legitimate sign-ins should originate. That made it possible to strengthen access around the way this business actually operated instead of applying a generic policy set.

Sign-in and risk activity was reviewed to reconstruct where the unauthorized access originated and how it persisted. Findings and proposed changes were explained in plain language. Once the owners approved them, Conditional Access policies were corrected, MFA was enforced, and sign-ins outside the client's Canada-only operating pattern were restricted. Each change was tested against normal work before rollout.

04

What changed

Account protection no longer depended on unfinished policies or assumptions. The business had enforced MFA, working Conditional Access rules, tighter geographic access, and a clear record of the privileged and stale access uncovered during the review.

The updated configuration was monitored for several days before closeout. The owners received the findings, a record of the work completed, and practical notes for anyone administering Entra ID in the future.

Are your Microsoft 365 identity settings still protecting the way your team works today?

Explore Microsoft 365 security reviews