Required for all clients
Identity Security Posture Management (ISPM) is ongoing hygiene for logins, privileges, and apps that can reach your data. It finds MFA gaps, over-privileged accounts, stale guests, and risky consents before an attacker uses them.
ITDR watches for active identity attacks. ISPM shrinks what there is to attack. Both matter. Posture without detection is incomplete. Detection without posture means you keep fighting the same open doors.
Stride IT requires ISPM for every client on Continual Security Uplift. It sits on Microsoft 365 Business Premium as the licence floor, and it is reviewed on a cadence so last quarter’s tidy-up does not quietly undo itself.
What ISPM is
ISPM assesses how identities are set up and whether that setup stays healthy. Coverage of multi-factor authentication. Gaps in Conditional Access. Legacy sign-in methods that bypass modern controls.
It surfaces privilege problems: too many global admins, standing high rights that nobody uses daily, shared admin accounts, and break-glass accounts that are undocumented or overused.
Guest and partner access gets checked. Old project guests who still read SharePoint are a quiet risk. So are broad guest permissions granted “to make collaboration easy”.
Risky apps and consents matter. Staff can approve apps that read mail or files. Some are fine. Some are over-scoped. ISPM flags odd or excessive grants so you can revoke them.
Findings become remediations against the Stride IT Security Standard. Then you re-check. Posture drifts when people join, leave, change roles, or install tools under deadline pressure.
ISPM is not a one-page Secure Score screenshot. Score helps. Posture work names the accounts, apps, and policies that still create blast radius, then tracks them to closed.
It also watches for identity debt that feels harmless until it is not: old mail forwarding rules, forgotten shared mailboxes with owners who left, and privileged roles granted for a weekend cutover that never got rolled back.
Why it matters for Perth SMEs
Identity is the front door for cloud work. If your team lives in Microsoft 365, a stolen password or token can reach email, files, and finance systems without touching the office firewall.
Lean Perth teams often share admin duties. The bookkeeper becomes a global admin “temporarily”. Temporary sticks. ISPM makes that visible.
Hybrid work across WA means sign-ins from home, site, and travel. Weak MFA and loose Conditional Access turn that flexibility into an open invitation.
Boards and insurers ask who has privileged access and whether MFA is real. ISPM gives you answers with evidence, not vibes.
One over-privileged mailbox can undo months of good endpoint work. Identity hygiene is not optional overhead. It is blast-radius control.
Professional services and project firms bring partners in and out of tenants all year. Guest sprawl is normal unless someone ages it out. ISPM puts that ageing on a calendar.
When staff use personal phones for MFA and mail, weak identity setup becomes a business risk, not only an IT preference. Clear posture rules keep that mix workable without leaving doors open.
Day-to-day reality
You should see regular posture checks: MFA coverage by role, admin counts, guest ageing, and Conditional Access gaps called out in plain language.
Joiners and leavers should trigger identity changes the same day. Disabled accounts with lingering app access are a classic miss.
When staff request a new SaaS tool, consent and permission scope get a quick review. “Approve all” is not a process.
Privileged work should use separate admin accounts and stronger MFA methods where Business Premium and your policies support them. Daily email should not run as a global admin.
Quarterly uplift reviews track whether privilege sprawl is shrinking and whether last quarter’s fixes stayed fixed.
Exceptions need expiry dates. A temporary Conditional Access bypass for a vendor visit should not still be live at Christmas.
Common failure modes
MFA enabled for “most people” while a few shared or service accounts stay exempt forever.
Legacy authentication left on because one old device or mail client still needs it.
Ten people with global admin because it was easier than designing roles.
Guest accounts from finished projects still active two years later.
App consents approved by end users with no central review.
A one-time identity tidy-up with no re-check, so drift returns within a quarter.
Treating Conditional Access as finished after the first policy pack, then never testing exclusions.
Break-glass accounts that everyone uses for convenience, so they stop being break-glass and start being a shared back door.
Questions for your IT provider
Do you continuously assess identity posture, or only during onboarding?
Can you show MFA coverage, admin privilege counts, and guest ageing in our quarterly review?
How do you handle exceptions for service accounts and break-glass access?
What is the process when staff approve a new app that wants mail or file access?
How do ISPM findings feed Conditional Access and privilege changes, not just a spreadsheet?
How does ISPM connect to ITDR so the same hole is not left open after an incident?
Who owns joiner-mover-leaver identity steps when HR changes roles mid-project?
Fit with Continual Security Uplift and Business Premium
Business Premium is the floor that makes Conditional Access, stronger MFA options, Intune compliance, and Defender controls workable as one stack. ISPM checks whether you are actually using that floor well.
In Continual Security Uplift, Baseline maps identity risk early. Stabilise closes urgent gaps. Uplift hardens roles and access patterns. Continual reviews catch drift.
ISPM and ITDR are a pair. Posture reduces chance and blast radius. Detection catches what still slips through. Neither replaces the other.
SAT helps people avoid handing over credentials. ISPM makes stolen credentials less powerful when phishing still wins.
Stride IT requires ISPM for every client. If you want identity left as a set-and-forget checkbox, we will decline. Hardening before the incident is part of the Standard.
Uplift reviews should show identity posture moving: fewer standing admins, fewer aged guests, fewer open MFA gaps. If the only story is “we enabled MFA once”, the work is not done.
ISPM keeps identity tidy on purpose: MFA gaps closed, privileges trimmed, risky apps reviewed, guests aged out. For Perth SMEs on Business Premium and Continual Security Uplift, it is how you shrink the blast radius before the next stolen password tries its luck.
Further reading
What Is Identity Security Posture Management (ISPM) for Perth Businesses?
A longer owner’s guide on the same topic, written for Perth businesses comparing providers.
Read the blogWHAT YOU GET
Identity hygiene that keeps improving, not a one-time tidy-up.
Fewer standing privileges waiting for a stolen token.
Clear link between posture findings and ITDR response when something slips through.
FREQUENTLY ASKED QUESTIONS
Is ISPM required for Stride IT clients?
Yes. Identity Security Posture Management (ISPM) is required for every client under the Stride IT Security Standard. It is not an optional add-on. If you will not run it, we decline.
How does ISPM fit Our One Plan?
ISPM is part of the required detection and posture stack inside Our One Plan. It sits on top of Microsoft 365 Business Premium. We baseline it in the Baseline Review, implement it during Stabilise and Uplift, and review it in quarterly Continual reviews.
Do you sell this as a standalone product?
No. This stack runs as part of Our One Plan with Continual Security Uplift. We do not cherry-pick detection controls while leaving the rest of the Standard unfinished.
THE REST OF THE STACK
APPLY FOR BASELINE
We confirm Business Premium readiness and the full required stack, including ISPM, before we start.
Apply for Our One Plan