Microsoft Entra ID consulting
identity review, MFA & Conditional Access
I provide Microsoft Entra ID consulting for organisations that need a clearer, safer identity setup: tenant and identity review, MFA and Conditional Access, device-compliance alignment, hybrid-to-cloud planning, documentation and staged rollout. I work across Copenhagen and Malmö, on-site or remotely.
- 15+ years of professional IT experience
- Hands-on Microsoft 365, Entra ID, Intune and hybrid identity work
- 17 professional certifications, including Microsoft, Cisco, ITIL and Skillsoft
- On-site in Copenhagen and Malmö, remote across Denmark and Sweden
Entra ID consulting services
Conditional Access design
A documented policy set built from a baseline, tested in report-only mode and rolled out in controlled rings.
MFA & passwordless
Authenticator, FIDO2 and Windows Hello for Business, plus a break-glass plan and legacy authentication blocked.
Single sign-on (SSO)
SAML/OIDC integration for your SaaS applications and SCIM provisioning where supported — fewer passwords, faster offboarding.
Hybrid-to-cloud identity planning
Entra Connect or Cloud Sync review, dependency mapping and a documented plan for what moves to cloud-only identity and what must remain on-premises.
RBAC & privileged access
Least-privilege admin roles, PIM for just-in-time elevation and a hard separation between daily and admin accounts.
Access governance
Access reviews, group strategy, guest lifecycle and joiner/mover/leaver processes that actually get followed.
How an identity project runs
Tenant and identity review
Current tenant, admin roles, MFA coverage, legacy authentication, guests, device signals and sync health — with a prioritised action list.
Policy design
A target Conditional Access and role model documented in plain language, agreed before anything is enforced.
Report-only rollout
Policies run in report-only mode, impact is measured, exclusions are fixed, then enforcement moves out in rings.
Govern & operate
Access reviews, break-glass testing, documentation and monitoring so the model survives staff changes.
Frequently asked questions
What is the difference between Azure AD and Entra ID?›
They are the same service — Azure Active Directory was renamed Microsoft Entra ID. Existing tenants, licences and configuration carried over; only the name and portal branding changed.
Where should we start with Conditional Access?›
With a baseline: MFA for all users, block legacy authentication, require compliant devices for admin roles, and use report-only mode first so you see the impact before enforcing anything.
Can you connect our on-premises Active Directory?›
Yes. Hybrid identity with Entra Connect or Cloud Sync, password hash sync or pass-through authentication, plus a plan for what stays on-premises and what moves to the cloud.
Can you set up SSO for our other applications?›
Most SaaS applications support SAML or OIDC single sign-on against Entra ID, with automated user provisioning where the vendor supports SCIM — fewer passwords, faster offboarding.
Do you work with companies in København?›
Yes. I am based in Copenhagen (København) and work on-site in the capital region and Malmö, and remotely across Denmark, Sweden and the EU.
Read more
Need an Entra ID tenant and identity review?
Start with a focused conversation about your tenant, MFA, Conditional Access, device signals and hybrid identity dependencies. I will help define a safe, documented next step without overpromising a one-size-fits-all result.