Aotearoa New Zealand · Core Market

Identity architecture & access governance.
Built for New Zealand.

MAITS provides independent identity architecture, cyber security and access governance advisory for New Zealand government agencies, crown entities, local authorities and commercial enterprises. Headquartered in Wellington, we help organisations modernize access, eliminate standing privilege and achieve robust compliance with New Zealand cyber security standards.

Wellington-based technical leadership.

New Zealand organisations face distinct sovereign identity challenges: navigating the New Zealand Information Security Manual (NZISM), adhering to Protective Security Requirements (PSR), respecting the Privacy Act 2020, and moving away from legacy on-premises Active Directory environments toward modern cloud trust architectures.

MAITS provides hands-on senior architects who understand public sector machinery, crown procurement and local operating realities.

Regulatory & security alignment

Designed to satisfy New Zealand standards and governance expectations.

We translate government standards and statutory privacy obligations into concrete architecture decisions and enforceable system controls.

NZISM ALIGNMENT

New Zealand Information Security Manual

We architect authentication, privileged access and auditability to meet NZISM guidelines, specifically Chapter 16 identity controls, multi-factor authentication requirements and cryptographic protection.

PSR GOVERNANCE

Protective Security Requirements

Governance, personnel security lifecycle alignment, and segregation of duties configured to support Mandatory Requirements under the NZ Protective Security Requirements framework.

PRIVACY ACT 2020

Information Privacy Principles (IPPs)

Architecting identity and credential exchange around IPP 5 (storage and security of personal information), IPP 10 (limits on use) and strict data minimisation principles across all identity flows.

DIGITAL IDENTITY

DISTF Principles & Reusable Identity

Strategic guidance on the Digital Identity Services Trust Framework (DISTF), privacy-preserving digital credentials, and interoperability between public registers and commercial relying parties.

Enterprise Microsoft Entra

Modernising Microsoft identity for New Zealand organisations.

The vast majority of New Zealand enterprises and government agencies run Microsoft Entra ID (formerly Azure AD). However, many tenants still rely on legacy MFA methods (telephony, basic push notifications), unmanaged hybrid sync from aging Active Directory domain controllers, and unreviewed standing administrative access.

MAITS designs and executes end-to-end Entra modernisations:

  • Phishing-Resistant Authentication: Transitioning workforce and privileged users to FIDO2 passkeys and certificate-based authentication (CBA).
  • Conditional Access Architecture: Comprehensive policy sets enforcing device compliance, risk signals and zero-trust evaluation without lockout gaps.
  • Privileged Identity Management (PIM): Eliminating permanent Global Admin and tier-0 roles through just-in-time, approval-gated role activation.
  • Entra ID Governance: Automated joiner-mover-leaver lifecycle workflows, access packages and recurring certification reviews.
  • External Identities: Governed B2B collaboration and cross-agency directory federation that terminates access when projects finish.

Capabilities in NZ

Specialist services delivered across New Zealand.

Engage MAITS for targeted technical assessments, architecture reviews or embedded engineering capability.

01

IAM Health Check

Structured 9-area diagnostic of your identity architecture, authentication strengths, PIM, Conditional Access and governance controls.

Explore IAM Health Check
02

Passkey & Passwordless

Strategy and rollout roadmap for hardware security keys, device-bound passkeys and synced passkeys across enterprise fleets.

Explore Passkey & Passwordless
04

Identity Governance (IGA)

Role-based and attribute-based access control, entitlement lifecycles and auditable access review certification workflows.

Explore Identity Governance (IGA)
05

Customer Identity (CIAM)

Modern customer journeys, migration from Azure AD B2C to native Entra External ID, and high-assurance customer verification.

Explore Customer Identity (CIAM)
06

Technical Leadership

Fractional Chief Identity Architect or lead security advisory for major digital transformations and public sector programmes.

Explore Technical Leadership

Start a conversation

Discuss your New Zealand identity programme.

Whether preparing for an audit, planning an Entra modernization, or rolling out phishing-resistant passkeys, our Wellington team is ready to assist.