Skip to content
Lambert Consulting

Our first department

This is what needs to work every morning.

Your servers, your workstations, your phone systems, and your identities. The foundation that no one notices as long as it holds, but that everyone notices the day it fails.

View the department
Multi-siteNational and international projects
3Branches in French-speaking Switzerland
View our client projectsCase Studies and References
Let us know how you're doingGetting a quote is free

How We Work

A piece of advice, not a sales pitch.

Our approach is consultative: we tell you what we think, even when it’s not in our best interest. That’s what makes projects succeed.

About Us
1995First project, using Microsoft SMS
Family-orientedOn a human scale and sustainable
Contact UsFirst 30-minute consultation, with no obligation

Infrastructure / Security and Identity / Conditional Access

Writing the access rule is easy. Knowing who it applies to is much harder.

Who is entering, from where, on what device—and what they are asked to prove.

Conditional access examines every connection to your Microsoft 365 services and determines what to require: multi-factor authentication, a company-managed device, or nothing at all because the person is in the office using their usual computer. The challenge is never the syntax; it’s knowing who is involved in each scenario and making sure no one gets locked out while figuring it out.

Nothing is enforced until it has been observed The reporting-only mode shows who would be affected and what would be required, without preventing anyone from working.
Emergency access accounts first There are two backup accounts, which are tested before the first rule is applied. This prevents users from being locked out of their own directory.
Direct access to Microsoft support As a partner, we can open a support case with Microsoft on your behalf when a connection is not working properly.

Connections That Raise Questions

A correct password doesn't mean much on its own. It just means that someone knows the password—not that it's the right person, nor that the device being used is trustworthy enough to handle your documents.

01

A connection is coming in from a country where no one works

The account is valid, the password is correct, and the login is coming from a location where your company has no office, no clients, and no employees on business travel.

A requirement related to the connection location may require additional verification or prevent access, and the system will notify you of this.

02

An employee checks his email on his personal phone

The device is not managed by the company; it may not have a passcode; and it may end up being resold with the documents still on it.

Access can remain open in the browser without allowing the download, or require a managed device to proceed.

03

An external service provider accesses your documents

He needs two folders for three months. His guest account often remains active long after the work is finished, and no one closes it.

Guest accounts have their own, stricter requirements, without complicating things for your internal teams.

04

An outdated protocol bypasses all verification

Some older email clients do not support multi-factor authentication. An account accessed this way can be accessed using only the password.

It's the first thing we shut down, and often the one that has the biggest impact on the actual level of risk.

05

An admin account can also be used to read emails

The same account is used to access email, browse the web, and manage the directory. A single malicious page is then enough to grant the highest privileges.

Administrator accounts have separate requirements and are used solely for administrative purposes.

06

Two logins from the same account, two hours apart by plane

The first one is from Lausanne at 9:00 a.m., and the second is from the other side of the world at 9:20 a.m. One of them isn't the right person.

Microsoft Entra ID Protection flags this type of connection as risky, and conditional access may then require additional identity verification.

What Conditional Access Is About, and What It Requires

A conditional access policy reads like a sentence: if a certain person, from a certain location, on a certain device, opens a certain app—then require this. The whole process involves filling in the blanks for your company.

What He's Watching

Connection signals

  • Who—the person, their group, their administrative role, and whether it is a guest account.
  • From where—the network address, the country, and the locations you have designated as your offices.
  • On which device—whether it's managed by the company or not, and whether it meets your requirements or not.
  • Which application—email, documents, ordirectory management?
  • What level of risk are we talking about—an unusual login, or an account whose password has been leaked?

What he may demand

The decision, once the signals have been interpreted

  • Multifactor authentication—right away, or only when you're away from your office.
  • A managed and compliant device—otherwise, access is denied.
  • A limited-time session—read in your browser, no download or printing required.
  • Periodic reconnection—instead of a session that remains open indefinitely.
  • Nothing at all—and that's usually the case for anyone who works a normal job.

The device-type-based condition is based on what the browser reports about itself: Microsoft notes that it can be spoofed. It is intended to guide usage, never to serve as a standalone security requirement.

What we're implementing first

Six points, in this order, before making any specific requests. They cover most of the actual risk and can be explained to management in five minutes.

Two emergency access accounts

Exempt from all requirements, with a long password stored outside the system, and tested before they are needed.

Legacy Closed Protocols

Authentication methods that do not support a second factor are rejected for everyone.

A second factor affecting administrative accounts

Without exception and regardless of location: these are the accounts whose losses are the most costly.

A second factor for everyone

This is addressed next, once the specific cases are known. Microsoft itself now requires this for administration.

Requirements Specific to Guest Accounts

An outside contractor is not entitled to the same terms as an employee of your company.

A predetermined session duration

Rather than a session that remains open indefinitely on a shared device or in a public place.

The only truly costly mishap: locking yourself out

A misdirected requirement may apply to all accounts, including yours. At that point, no one can log in to remove it, and recovery requires filing a request with Microsoft, with the resulting delay.

That is why emergency access accounts are set up first, separate from everything else, and why we verify that they work before implementing anything else.

How We Do It

Five steps, in this order. The third step is the one that helps you avoid unpleasant surprises: you consider what might happen before anything actually happens.

01

Track who is logging in and how

Active accounts, forgotten service accounts, devices in use, usual login locations, and old protocols that are still open. This report determines everything else.

02

Set up emergency access accounts and test them

Before the first requirement. An emergency account that has never been tested is not an emergency account.

03

View in report-only mode

Each request is initially made to no avail: she reads it, counts it, and reports who might be affected. That’s how we discover the service account that has apparently stopped working, or the team on the road that was turned away on a Monday morning.

04

Roll out in phases, starting with the IT department

Start with your technical teams, then a pilot department, and then the rest. Each phase allows for adjustments before the next one, so no one is caught off guard by the change one morning without warning.

05

Document and plan for the review

Each requirement is documented along with the reason it was established. Without that reason, no one dares to change it two years later, and the whole thing becomes set in stone.

What You Need to Know Before Making a Decision

Four questions that come up in every project.

What licenses are required?

Conditional access requires Microsoft Entra ID P1. Risk-based decisions regarding a sign-in or an account require P2. Both plans are available separately and as part of certain Microsoft 365 suites.

What about the default security settings—are they already enabled?

The two cannot coexist: enabling conditional access requires disabling the default security. This provides greater flexibility, but it also removes an automatic safety net—hence the importance of the initial foundation.

Is our directory already affected without us knowing it?

Probably. Microsoft itself deploys certain requirements in eligible directories—initially as drafts—and then activates them after about 30 days if no one takes action. They appear in the admin center, marked as created by Microsoft.

What Conditional Access Doesn't Do

It controls who comes in, not what goes out. Preventing a document from leaving once someone has entered falls under data loss prevention, and that's a different issue.

Tell us about your access options, and we'll let you know where to start.

The initial conversation is meant to identify who is joining and where they’re connecting from, and then to determine what needs to be addressed first. You’ll meet the people who will actually do the work—not a salesperson who will just describe it.

Renens +41 21 806 37 15 · Sion +41 27 552 00 22 · Châtel-Saint-Denis +41 26 322 59 05