Your perimeter is a login
If your files, mail, and finance tools live in Microsoft 365, the office firewall is not your main perimeter. Sign-ins are. Identity Security Posture Management (ISPM) is how you keep that perimeter tidy before someone else tests it.
ISPM looks for weak setup: people without proper MFA, admins with more power than their job needs, guests who never left, apps that can read more than they should. It is hygiene on a schedule.
For Stride IT’s required definition and uplift fit, see /security-standard/security-stack/ispm/ and /one-plan/.
Posture versus response
Identity Threat Detection and Response watches for active abuse: odd sign-ins, token theft patterns, privilege misuse in motion. ISPM reduces how much abuse is possible in the first place.
Think of ISPM as locking spare keys and cutting unused master keys. Think of detection as the alarm when someone still tries a key. Skipping either leaves you with a story you will not like telling a board.
After an incident, posture work should close the hole that made the incident easy. If you only reset a password and leave standing global admin sprawl, you bought time, not safety.
A useful rule: every serious identity incident earns at least one lasting posture change. No change means you will meet the same problem again.
The SME patterns we see in Perth
Shared mailboxes turned into shared admin habits. Everyone knows the password. Nobody owns the risk.
“Just make me admin for this migration” that never gets reversed. Migrations end. Privileges remain.
Guests from a completed joint venture still reading project libraries. Convenient. Careless.
Legacy sign-in methods left enabled for one stubborn device, quietly undermining Conditional Access for everyone.
Staff approving a handy app that wants full mailbox access because the consent screen was skimmed on a phone.
Service accounts exempt from MFA “because scripts break”, with no owner and no review date. Those exemptions age into silent holes.
What a healthy cadence looks like
Regular reports that a non-technical owner can read: MFA coverage, number of highly privileged accounts, aged guests, Conditional Access exceptions, risky consents.
Joiners get right-sized access on day one. Leavers lose access the same day, including app grants and devices.
Privileged work uses separate admin accounts and stronger MFA methods where your licences and policies support them. Daily browsing and email should not run as a global admin.
Quarterly uplift reviews prove drift is being caught. If privilege counts only go up, posture is not being managed.
Exceptions carry expiry dates. Temporary bypasses for vendors and projects close when the work closes, not when someone remembers.
Questions to put to your MSP
How often do you re-assess identity posture after onboarding?
Can you show MFA gaps and admin sprawl without exporting a mystery spreadsheet?
What is your process for break-glass accounts and service account exceptions?
Who reviews new app consents, and how fast can a bad grant be revoked?
How do ISPM findings become Conditional Access and role changes with owners?
When ITDR catches an identity incident, what posture fixes are mandatory afterwards?
How do role changes from HR show up in access rights within a day, not a month?
Business Premium and uplift
Microsoft 365 Business Premium is Stride IT’s minimum because identity, device compliance, and mail protections need a workable floor. ISPM checks whether that floor is configured and kept clean.
Continual Security Uplift uses Baseline to map identity risk, then Stabilise and Uplift to close gaps, then Continual reviews to stop drift. ISPM is required for every client, not a premium add-on for nervous boards.
Pair it with SAT so fewer credentials get handed over, and with ITDR so active attacks still get caught. Read /security-standard/security-stack/ispm/ and /one-plan/ for the program shape.
If a provider says Business Premium alone “covers identity”, ask for the privilege count and guest age list. Licences enable controls. Posture work finishes them.
Start this month
Count global admins. If the number surprises you, that is the point.
List MFA exemptions and give each one an expiry date or a removal plan.
Age out guests older than your project window.
Review app consents that can read mail or files.
Put identity posture on the quarterly agenda with Secure Score, not as a side note.
If your provider cannot do that rhythm, you do not have identity management. You have hope dressed as a tenant.
Privileges without the spreadsheet fog
Start with a simple question: who can change everything in the tenant today? If the answer is more than a handful of people, you have standing risk.
Next: who can read every mailbox or every SharePoint site? Broad roles feel efficient in a small firm. They also mean one stolen account becomes a full data event.
Then age the guests. If a partner left six months ago and still has access, that is not collaboration. That is leftover permission.
Finally, list apps with mail or file rights. Revoke what you do not recognise. Keep what you need with the least permission that still works.
Those four lists are ISPM in working clothes. Put them in the quarterly review until the numbers stop surprising you.
If you cannot produce the lists in under an hour, your identity estate is not being managed. It is being hoped for. Fix the reporting first, then the privileges.
What good identity posture feels like
Staff sign in with strong MFA and stop treating codes as optional theatre. Admins use separate accounts for privileged work. Guests leave when projects end.
New tools get a consent check before they can read the company mailbox. Exceptions expire. Drift shows up in reviews before it shows up in an incident.
Finance stops sharing a global admin login “because payroll runs tonight”. Privileged work gets a planned window and a named account instead.
That is ISPM in practice. Not a buzzword. A rhythm. For the required stack page and uplift path, use /security-standard/security-stack/ispm/ and /one-plan/.
Want the required-stack definition we run with clients? Read /security-standard/security-stack/ispm/ and the Our One Plan.
