IAM and PAM consulting: identity architecture that also supports detection
ANOMAL consulting designs identity architecture covering directories, federation, external and guest identities, and service and workload identities. We also design authorisation models based on least privilege and segregation of duties, alongside joiner-mover-leaver automation. Privileged access consulting covers admin account tiering, just-in-time elevation, session recording and break-glass procedures. It also covers secrets and service account hygiene. Well-designed identity architecture also provides the telemetry foundation for ITDR and the SOC. We scope every engagement individually and provide a dedicated quote per customer.
Identity architecture
We start with directory and tenant design, covering single-tenant and multi-tenant structures, separate test and production environments, and federation with partners and customers. We also address external and guest identities, plus service principals and workload identities for applications and automation. For Microsoft environments, we work through these topics using Microsoft Entra ID. Our consulting for other directory services remains vendor-neutral.
- Directory and tenant structure with a clear split between production and test environments.
- Federation design for partners, customers and suppliers without unnecessary trust expansion.
- External and guest identities with expiry dates and no permanent accounts.
- Service principals and workload identities clearly mapped to applications. Shared service accounts are eliminated.
Privileged access
- Tiering of admin accounts: separation between domain admin, server admin and workstation admin, so a compromised account does not automatically drag down the entire environment.
- Time-limited privileged rights granted only when needed through just-in-time elevation.
- Session recording for privileged sessions as an evidence and investigation basis.
- Break-glass procedures for emergency access with subsequent review. Permanently open backdoors are excluded.
- Secrets and service account hygiene: rotation, vault integration, elimination of hardcoded credentials.
The consulting focuses on capabilities. We address Microsoft Entra ID specifically for Microsoft environments. We discuss other PAM platforms generically, including common PAM solutions for session brokering and vaulting.
From identity to detection: foundation for ITDR and the SOC
Well-designed identity architecture is also a prerequisite for Identity Threat Detection and Response. Detecting login anomalies, token abuse or unusual elevation requires baselines derived from consistent roles and tiering. See ITDR: Identity Threat Detection and Response for details on detection. For specific attack patterns, see Token theft and session hijacking and Business email compromise on M365.
Evidence for ISO 27001 and FINMA
Documented role models, access reviews and tiering evidence directly support audits. See ISO 27001 and SOC and FINMA requirements for details on evidence in the SOC context. For governance topics beyond technical implementation, we provide occasional supporting advice within the consulting engagement. This scope excludes a standalone leadership role.
How this compares to neighbouring topics
| Offering | Focus | Where it stops |
|---|---|---|
| IAM and PAM consulting | Identity architecture, authorisation model, JML automation, privileged access. | Does not run ongoing detection; delivers the foundation for it. |
| Cloud and identity hardening project | Concrete technical implementation of configurations and controls in cloud and directory services. | Often assumes an already defined target role model instead of designing it. |
| Managed ITDR detection | Ongoing 24/7 detection and response on identity telemetry inside the SOC. | Needs clean roles and tiering as input, otherwise many false positives result. |
| Zero-Trust architecture consulting | Overarching architecture principle across network, endpoint and identity. | Identity is one of several pillars within the broader scope. |
Placement in SOC operations
IAM and PAM consulting provides the data foundation that lets ITDR and a SOC reliably distinguish normal from abnormal activity. See SOC as a Service Switzerland for details on ongoing operations. If the overarching operating model remains undefined, SOC consulting provides complementary support. See Security consulting Switzerland for an overview of all consulting services.
Frequently asked questions
Does the consulting only cover Microsoft environments?
The consulting also covers environments beyond Microsoft. We use Microsoft Entra ID as a specific example because many Swiss environments use it. We describe other directory services and PAM platforms through their capabilities, taking a vendor-neutral approach.
What is the difference to a hardening project?
IAM and PAM consulting designs architecture and models. A hardening project technically implements concrete configurations and controls, often based on an already defined role model.
How long does introducing just-in-time elevation take?
This depends on the number of privileged accounts, existing processes and the chosen platform. ANOMAL scopes this individually and provides a dedicated quote per customer.
Does IAM and PAM consulting replace an ITDR solution?
IAM and PAM consulting does not replace an ITDR solution. It provides the foundation of clear roles, tiering and baselines that enables reliable ITDR detection. See [ITDR](/en/soc/itdr-identity-threat-detection) for details.
Does the consulting also help with segregation of duties for finance processes?
Yes, segregation of duties for critical processes such as payment approvals or procurement is part of the authorisation model and is checked specifically.
Related terms
- IAM Identity and Access Management (IAM) controls who can access specific systems and data within an organisation.
- MFA Multi-Factor Authentication requires a second form of verification in addition to a password during login.
- Conditional Access Conditional Access is a form of policy-based access control for user sign-ins and sessions.
- Privilege Escalation Privilege escalation describes the process of gaining higher permissions than an account or process is assigned.
- Lateral Movement Lateral Movement describes how attackers move from system to system and escalate privileges after initial access.