ANOMAL consulting

IAM and PAM consulting: identity architecture that also supports detection

ANOMAL consulting designs identity architecture covering directories, federation, external and guest identities, and service and workload identities. We also design authorisation models based on least privilege and segregation of duties, alongside joiner-mover-leaver automation. Privileged access consulting covers admin account tiering, just-in-time elevation, session recording and break-glass procedures. It also covers secrets and service account hygiene. Well-designed identity architecture also provides the telemetry foundation for ITDR and the SOC. We scope every engagement individually and provide a dedicated quote per customer.

All

Identity architecture

We start with directory and tenant design, covering single-tenant and multi-tenant structures, separate test and production environments, and federation with partners and customers. We also address external and guest identities, plus service principals and workload identities for applications and automation. For Microsoft environments, we work through these topics using Microsoft Entra ID. Our consulting for other directory services remains vendor-neutral.

  • Directory and tenant structure with a clear split between production and test environments.
  • Federation design for partners, customers and suppliers without unnecessary trust expansion.
  • External and guest identities with expiry dates and no permanent accounts.
  • Service principals and workload identities clearly mapped to applications. Shared service accounts are eliminated.

Authorisation model and lifecycle

Role and entitlement design based on least privilege requires ongoing maintenance. Segregation of duties prevents critical combinations, such as one person initiating and approving payments. Access reviews and recertification regularly remove unused entitlements. The automated joiner-mover-leaver process updates entitlements consistently when people change roles or leave. This prevents outdated permissions from accumulating.

  • Role and entitlement design along actual tasks instead of generic templates.
  • Segregation of duties for critical processes such as finance, procurement and system administration.
  • Access reviews and recertification with clear owners and deadlines.
  • Automated joiner-mover-leaver processes, triggered directly by HR events, without manual tickets.

Privileged access

  • Tiering of admin accounts: separation between domain admin, server admin and workstation admin, so a compromised account does not automatically drag down the entire environment.
  • Time-limited privileged rights granted only when needed through just-in-time elevation.
  • Session recording for privileged sessions as an evidence and investigation basis.
  • Break-glass procedures for emergency access with subsequent review. Permanently open backdoors are excluded.
  • Secrets and service account hygiene: rotation, vault integration, elimination of hardcoded credentials.
Vendor-neutral

The consulting focuses on capabilities. We address Microsoft Entra ID specifically for Microsoft environments. We discuss other PAM platforms generically, including common PAM solutions for session brokering and vaulting.

From identity to detection: foundation for ITDR and the SOC

Well-designed identity architecture is also a prerequisite for Identity Threat Detection and Response. Detecting login anomalies, token abuse or unusual elevation requires baselines derived from consistent roles and tiering. See ITDR: Identity Threat Detection and Response for details on detection. For specific attack patterns, see Token theft and session hijacking and Business email compromise on M365.

Evidence for ISO 27001 and FINMA

Documented role models, access reviews and tiering evidence directly support audits. See ISO 27001 and SOC and FINMA requirements for details on evidence in the SOC context. For governance topics beyond technical implementation, we provide occasional supporting advice within the consulting engagement. This scope excludes a standalone leadership role.

How this compares to neighbouring topics

OfferingFocusWhere it stops
IAM and PAM consultingIdentity architecture, authorisation model, JML automation, privileged access.Does not run ongoing detection; delivers the foundation for it.
Cloud and identity hardening projectConcrete technical implementation of configurations and controls in cloud and directory services.Often assumes an already defined target role model instead of designing it.
Managed ITDR detectionOngoing 24/7 detection and response on identity telemetry inside the SOC.Needs clean roles and tiering as input, otherwise many false positives result.
Zero-Trust architecture consultingOverarching architecture principle across network, endpoint and identity.Identity is one of several pillars within the broader scope.

Placement in SOC operations

IAM and PAM consulting provides the data foundation that lets ITDR and a SOC reliably distinguish normal from abnormal activity. See SOC as a Service Switzerland for details on ongoing operations. If the overarching operating model remains undefined, SOC consulting provides complementary support. See Security consulting Switzerland for an overview of all consulting services.

Frequently asked questions

Does the consulting only cover Microsoft environments?

The consulting also covers environments beyond Microsoft. We use Microsoft Entra ID as a specific example because many Swiss environments use it. We describe other directory services and PAM platforms through their capabilities, taking a vendor-neutral approach.

What is the difference to a hardening project?

IAM and PAM consulting designs architecture and models. A hardening project technically implements concrete configurations and controls, often based on an already defined role model.

How long does introducing just-in-time elevation take?

This depends on the number of privileged accounts, existing processes and the chosen platform. ANOMAL scopes this individually and provides a dedicated quote per customer.

Does IAM and PAM consulting replace an ITDR solution?

IAM and PAM consulting does not replace an ITDR solution. It provides the foundation of clear roles, tiering and baselines that enables reliable ITDR detection. See [ITDR](/en/soc/itdr-identity-threat-detection) for details.

Does the consulting also help with segregation of duties for finance processes?

Yes, segregation of duties for critical processes such as payment approvals or procurement is part of the authorisation model and is checked specifically.

Continue reading in this cluster
ITDR: Identity Threat Detection and Response for Switzerland
ITDR (Identity Threat Detection and Response) detects attacks on the identity itself, not just endpoints or networks. Targets are accounts, tokens, sessions, permissions and identity providers such as Entra ID or Okta. ITDR extends EDR and SIEM with signals only visible in the identity layer. These include impossible travel, consent phishing, refresh-token abuse, role abuse and attacks on federation and directory objects. For Swiss organisations running M365, Entra ID and regulated processes, ITDR today is as important as EDR was five years ago.
Detecting and stopping token theft and session hijacking
Token theft means attackers steal the session or refresh token of an already authenticated user and use it to bypass MFA. The classic path is reverse-proxy phishing (adversary-in-the-middle), increasingly also endpoint info-stealers. A SOC detects this from token usage outside the user context, not from the login itself. Defence means phishing-resistant MFA, Continuous Access Evaluation, token binding and detection on refresh-token replay.
Detecting and stopping Business Email Compromise in Microsoft 365
Business Email Compromise (BEC) in Microsoft 365 rarely involves malware. The attack chain involves phishing, session or token theft, inbox rules and OAuth consent abuse. A SOC detects BEC by correlating signals from Entra ID, Exchange Online and Defender for Cloud Apps. The email body alone is insufficient for detection. Responders revoke sessions, remove inbox rules, withdraw OAuth consents and enforce MFA again. They document these actions in line with ISG and insurance requirements.
SOC consulting: target picture, operating model and decision before build
ANOMAL consulting assesses an organisation's SOC maturity and derives a target operating model. The assessment covers visibility, detection coverage per MITRE tactic, process and escalation readiness, and evidence readiness. The core decision concerns in-house operations, managed SOC or co-managed SOC. The design centres on a tierless, highly automated SOC that replaces classic tier-1 queues. The resulting operating design defines shift and coverage planning, an escalation matrix and mandate, metrics and a clear transition plan into operations. ANOMAL scopes every engagement individually and provides a dedicated quote per customer.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
ISO 27001 and SOC: where the ISMS ends and operations begin
ISO 27001 requires a management system for information security with documented processes, risks and controls. A SOC complements the ISMS as its operational foundation. It puts controls A.5.24 to A.5.30 (incident management, continuity, readiness) and A.8.15 to A.8.16 (logging, monitoring) into practice. Without 24/7 detection, several Annex A controls remain operationally ineffective despite formal compliance.
SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor
FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.