Passkeys, FIDO2 and MFA
Select phishing-resistant and other authentication methods for user, device and assurance needs.
Identity security
MAITS connects authentication strength, device assurance, risk, session controls, recovery and privileged access into a usable security architecture.
A strong primary method is undermined when registration, recovery, emergency access or support processes establish identity with less assurance.
Capability
Controls are organised around people, resources, assurance and risk instead of accumulated platform settings.
Select phishing-resistant and other authentication methods for user, device and assurance needs.
Map authentication strength, device state, application sensitivity, location and risk to clear grant and session controls.
Define when managed, compliant or strongly bound devices are required and how exceptions are governed.
Use supported identity and sign-in risk signals with clear investigation, remediation and false-positive handling.
Protect bootstrap, lost-device, help-desk and self-service recovery so trust is re-established deliberately.
Apply separate identities, phishing-resistant methods, protected workstations and emergency access to high-value administration.
Engagement outcomes
Populations and use cases have suitable authentication methods.
Conditional Access expresses control intent with fewer unmanaged exceptions.
Registration and recovery retain proportionate assurance.
Monitoring, support and emergency procedures are owned and tested.
Expected outputs
Outputs are agreed for the engagement scope and written for the leaders, architects, engineers, operators and assurance teams who will use them.
From advice through implementation
MAITS can provide one bounded stage or remain involved across design, delivery, validation and capability transfer.
Clarify the people, systems, obligations, constraints, ownership and outcome involved.
Review evidence, architecture, controls, risk, capability and delivery readiness.
Set principles, architecture, policy, operating ownership and a practical change sequence.
Configure, integrate, automate, migrate and roll out alongside accountable teams.
Review behaviour, evidence, exceptions, recovery, readiness and residual risk.
Embed knowledge, governance, runbooks, measures and an owned improvement path.
Related capability
Start a conversation
Tell us what needs senior attention and what outcome the organisation needs. We’ll agree an engagement shape around the work.