Common identity gaps
The right person. The right device. The right access. Every time.
Identity is the new perimeter. Most breaches start with a sign-in, not a firewall.
What success looks like
Identity you can trust, governed and monitored
- Least-privilege access enforced and reviewed
- Consistent MFA and conditional access across the organisation
- Risky sign-ins detected and investigated
- Accounts provisioned and removed reliably
- Access evidence available for audits and insurers
- Fewer identity-driven security incidents
Identity is the new perimeter — for cloud-first organisations, it's the perimeter attackers go after first. Microsoft Entra ID is the system that decides who can sign in, from which device, into which app, and with what privileges; configured well it blocks the overwhelming majority of credential-based attacks before they reach a mailbox. Configured to defaults (the way most SMBs run it) it does almost nothing. Mycelium 365 designs, deploys and continuously tunes your Entra tenant — Conditional Access, phishing-resistant MFA, Privileged Identity Management and Huntress ITDR — so identity stops being your weakest link.
Who this is for
SMBs and mid-market organisations on Microsoft 365 that have outgrown default security settings, businesses preparing for cyber-insurance renewal or an Essential Eight uplift, and any organisation in legal, finance, healthcare or defence supply chain where a compromised identity is a regulated incident. It's especially relevant if you've had a phishing scare, a failed insurance questionnaire, or just bought Business Premium or E3/E5 and want to actually use the security you're paying for.
Ready to see our competitive pricing?
Entra ID Configuration & Lifecycle
End-to-end configuration of Microsoft Entra ID — tenant baseline, group strategy, role-based access control and automated joiner/mover/leaver flows so a new starter has the right access from day one and a leaver loses it within minutes of HR notification. We document the design and review it quarterly as your business changes.
SSO & Phishing-Resistant MFA
Single sign-on rolled out across Microsoft 365, Intune and your line-of-business SaaS so users have one credential and one MFA prompt. We standardise on phishing-resistant MFA (Authenticator with number matching, FIDO2 keys for admins) to block the adversary-in-the-middle and push-bombing attacks that defeat older MFA methods.
Conditional Access Policies
A layered policy set that blocks legacy authentication, requires MFA for every user, demands compliant or hybrid-joined devices for sensitive apps, blocks sign-ins from countries you don't operate in, and steps up verification for risky sessions flagged by Entra ID Protection. Admins get stricter rules and just-in-time elevation through Privileged Identity Management.
Huntress ITDR
24/7 Identity Threat Detection and Response watching your Entra tenant for token theft, suspicious sign-ins, privilege escalation, lateral movement and malicious OAuth consent grants. The Huntress SOC investigates each alert and contains active incidents — the post-compromise detection layer most SMBs can't staff internally.
Huntress SIEM
Centralised logging of identity, endpoint and Microsoft 365 events with correlation, threat hunting and audit-ready reporting. We retain the evidence trail you'll need for cyber-insurance renewal, incident response, and any future Essential Eight or ISO 27001 assessment.
Benefits for Your Business
Frequently Asked Questions
What our clients say
Verbatim client reviews, grouped by responsiveness, technical expertise, security and ongoing support, sit on one page alongside the case studies and Microsoft Solutions Partner credentials behind them.
Read our client reviews