Microsoft 365 Identity & Access Security

4security
Identity Protect

Your identity is your perimeter.

Strengthen your Microsoft 365 tenant against credential theft, MFA bypass, token hijacking and Teams impersonation.

Protect Identities
Block Attacks
Secure Collaboration
Prove Resilience
Three active threats. One service.

The Threat Landscape

These are not hypothetical risks. They are live attack patterns targeting Microsoft 365 tenants across South Africa and globally.

01

Identity-driven cloud breaches

“Storm-2949” style attacks abuse self-service password reset and social-engineer MFA approvals to take over Entra ID accounts, then move laterally to SharePoint, mailboxes and connected services.

Closed by: least-privilege access reviews, just-in-time admin access (PIM), and phishing-resistant MFA.

02

Token-theft phishing kits

“Kali365” kits (first seen April 2026) steal sign-in tokens via OAuth and device-code flows, bypassing MFA entirely and putting every tenant in scope.

Closed by: blocking device-code and legacy authentication in Conditional Access, plus session controls limiting token persistence.

03

Teams external chat exposure

Chat with external, unmanaged Microsoft accounts is on by default, opening the door to impersonation and phishing through Teams channels users trust.

Closed by: disabling chat with unmanaged accounts, restricting access to trusted domains, and reviewing Teams messaging policies.

Three tiers. One clear path.

Choose Your Protection Level

Each tier includes everything in the tier before it. Start where your risk is today and upgrade as your requirements grow.

Bronze
Basic

Quick wins, minimal disruption
R 13,200 ex VAT
3–5 business days
  • Basic MFA posture and secure admin accounts
  • Block obvious insecure sign-in patterns
  • Baseline guest access review
  • Disable Teams chat with unmanaged external accounts
  • Before/after summary and admin access report

Silver
Standard

Balanced protection for most organisations
R 29,040 ex VAT
5–10 business days
  • Everything in Basic, plus
  • Conditional Access baseline – MFA for all users and admins always
  • Block legacy authentication and device-code flow tenant-wide
  • Stronger external and guest access restrictions
  • Monitoring, alerting and persona-based access policies

Gold
Premium

Maximum security, regulated & high-risk
R 47,520 ex VAT
10–20 business days
  • Everything in Standard, plus
  • Phishing-resistant MFA (FIDO2 / certificate-based) for privileged users
  • Just-in-time admin access via PIM, tiered admin model
  • Geo-fencing, impossible-travel detection and token controls
  • Advanced monitoring, incident-response runbook and user adoption pack
All tiers include policy documentation, implementation and user communication support.
Active Managed Service Add-On

Managed Security Monitoring (6-Month)

R 7,920 / Month ex VAT

6-month term (renewable)

Light-touch ongoing protection after hardening is complete.

Continuous security monitoring
Monthly security report and review session
Risky sign-in, identity alert and threat triage
Proactive incident-response hour pool

6-month total: R 47,520 ex VAT. Indicative pricing at approximately 6 consultant hours per month.

A structured rollout, not a big-bang change

How It Works

Every engagement follows a phased approach designed to keep users productive while meaningful security improvements are implemented.

1. Discovery and risk workshop

Review authentication posture, admin roles, sign-in logs, legacy apps and external access configuration. 0.5–1 day.

2. Design and policy mapping

Map findings to Conditional Access policies, MFA strategy and an admin model aligned to licensing and risk tolerance. 1–2 days.

3. Pilot deployment

Apply changes to a small pilot group first to validate policy behaviour and user experience. 3–7 days, tier-dependent.

4. Tenant-wide rollout

Deploy department by department with user communication templates and MFA setup guides so your helpdesk is ready for common questions.

5. Handover and documentation

Receive a full admin guide, policy documentation, support pack and optional managed monitoring.

Outcomes, not just activities

What You Get

Identity Protect is designed to deliver measurable security and operational improvements, not a report that sits on a shelf.

Reduced account takeover risk

Credential theft, phishing logins and token replay attacks become significantly harder to execute.

Measurable Secure Score improvement

Optional monthly KPI dashboard tracks Secure Score deltas, risky sign-in trends and MFA adoption.

Admin protection

Separated admin accounts, reduced Global Admin counts and just-in-time access for privileged operations.

Controlled external access

Guests and external collaborators operate within defined, auditable boundaries.

Audit-ready documentation

Policy documentation, Conditional Access configurations and implemented-controls summaries for governance and compliance.

ϟ

Faster incident response

Compromised-account containment, token revocation and sign-out playbooks are ready before you need them.

Protect your Microsoft 365 identities

Start with a Security Workshop

Tell us a little about your environment and the 4Sight security team will follow up with you about 4security Identity Protect.

  • Discuss your current identity and access security posture
  • Identify the most suitable protection level for your organisation
  • Plan the next steps for strengthening your Microsoft 365 tenant

By submitting this form, your details will be sent to 4Sight so the team can respond to your enquiry.

Confidence starts with protection

Secure your Microsoft 365 environment today.

Know your identity is protected by experts.

✉ sales@4sight.cloud ◎ 4sight.cloud ☎ +27 (0) 12 640 2600