Skip to main content

← All posts

Managed identity for a 50-person company: when accounts become the perimeter

Managed identity for a small business means Entra ID as the control plane, MFA and conditional access as baseline, SSO to cut password sprawl, a joiner-mover-leaver lifecycle and ITDR monitoring for the Microsoft 365 tenant.

· Jake Schaaf, Founder of Atticus Rowan

A company crosses 50 users and the way it managed accounts at 15 people quietly stops working. Someone leaves and their mailbox stays live for three weeks because nobody owned the offboarding. A shared password floats around in a spreadsheet named “logins”. Half the staff are local administrators on their own laptops because that was easier during setup and nobody circled back. The firewall still gets renewed every year, but the actual break-ins are not coming through the firewall. They are coming through a reused password and a sign-in prompt an employee approved without thinking.

At this size the security perimeter is no longer the network edge. It is the set of identities that can log in. Managed identity is the discipline of treating those identities as the thing you protect, govern and monitor. This post covers what managed identity actually means for a small business on Microsoft 365, why the starting state most 50-person companies live in is the real exposure and how to move to a governed identity fabric in 30 to 60 days.

Why identity became the perimeter

The industry data is blunt. The Verizon 2024 Data Breach Investigations Report found that the human element, which includes stolen credentials and phishing, was involved in 68% of breaches. Stolen credentials remain one of the most common ways attackers get initial access, and they do not trip a firewall rule because they walk in the front door with a valid login.

For a 50-person company the math is simple. You have dozens of identities, each of which can reach email, files and business applications from anywhere. Every one of those identities is a way in. A firewall protects a location. Nobody works only from that location anymore. The control that decides whether a login succeeds, from what device and under what conditions, is now doing the job the firewall used to do.

That control is identity. Managing it deliberately is managed identity.

What managed identity actually means at this scale

Managed identity is not a product you buy. It is a set of connected practices with the Microsoft 365 tenant as the foundation. For a small business the pieces are:

  • Entra ID as the control plane. Every account, every application login and every access decision runs through one directory. Entra ID (formerly Azure AD) is where identity lives for any organization on Microsoft 365. Managed identity treats it as the single source of truth for who exists and what they can reach.
  • MFA and conditional access as baseline. Multi-factor authentication is the floor, not a premium feature. Conditional access is the layer above it that decides, per sign-in, whether to allow, block or challenge based on user, device, location and risk. This is where phishing-resistant MFA and blocking legacy authentication live.
  • SSO to reduce password sprawl. Single sign-on connects business applications to Entra ID so staff authenticate once through the central identity instead of holding a separate password for every tool. Fewer standalone passwords means a smaller attack surface and fewer credentials to reuse or leak.
  • A joiner, mover, leaver lifecycle. Access is granted on hire, adjusted on role change and fully removed on departure, every time, on a documented process. This is the part ad-hoc management fails at most visibly.
  • Identity threat detection and response. ITDR is monitoring aimed specifically at identity: risky sign-ins, impossible travel, token theft, unusual privilege use. It closes the window between a credential being stolen and someone noticing.

None of these is exotic. Most are already available in the Microsoft 365 licensing a 50-person company is probably already paying for. The gap is almost never the tooling. It is that the tooling was never turned on, configured or operated.

The starting state most companies are in

The honest baseline for a company that grew organically to 50 people usually looks like this:

  • Users are local administrators on their own machines, so any malware they run inherits admin rights.
  • Passwords are reused across the business application stack, and at least one is written down somewhere shared.
  • MFA is on for some people, off for others and not enforced for the accounts that matter most, the administrators.
  • Offboarding is a manual checklist that sometimes gets done late, so departed staff retain live access.
  • Nobody can produce a current list of who has privileged access without spending an afternoon on it.

This is not negligence. It is what happens when account management scales by habit instead of by design. The reused-password, everyone-is-admin starting state is exactly the shape attackers are optimized to exploit, because one phished credential on an over-privileged account gives them the run of the tenant.

The contrast is a governed identity fabric. Admin rights are removed from daily accounts and granted deliberately, the same principle behind endpoint privilege management and application allowlisting. Every identity carries the least access it needs. Conditional access decides each login on its merits. Offboarding is same-day and complete. And a monitoring layer watches the identities for signs of compromise. The difference between the two states is not a bigger budget. It is a deliberate rollout.

Moving from ad-hoc to governed in 30 to 60 days

A 50-person tenant does not need a year-long identity program. The rollout in the how-to above is a 60-day sequence: inventory the accounts and licenses, enforce the MFA and conditional access baseline, consolidate to SSO where applications support it, put a real joiner-mover-leaver lifecycle in place, turn on identity threat detection and then review and document the standing state.

The order matters. Inventory first, because you cannot govern accounts you have not counted. The baseline enforcement next, because MFA and conditional access are the highest-value controls and every day without them is exposure. Lifecycle and monitoring after that, because they are what keep the governed state from decaying back into the ad-hoc one.

The offboarding change alone is worth calling out. The gap between “we should probably disable that account” and “the account is disabled, sessions revoked and license reclaimed” is where a departed employee or a phished credential does damage. Getting that from an inconsistent multi-day process to a same-day one is one of the fastest security improvements a growing company can make.

Managed identity also compounds with the other work a company at this size takes on. It sits naturally alongside the broader shift covered in scaling IT from 25 to 75 users, where the operational model has to mature across the board, not just in one control.

The evidence a governed identity produces

A managed identity program leaves a trail, and that trail is what proves the controls are real:

  • A current inventory of accounts, licenses and privileged roles.
  • The conditional access baseline as documented policy, not tribal knowledge.
  • Access review records showing who has privileged access and when it was last confirmed.
  • Offboarding records showing accounts disabled on the departure date.
  • Identity alerts and the response to them.

This evidence is also what a cyber insurance application, a customer security questionnaire or a SOC 2 readiness review will ask for. Building managed identity the right way produces the artifacts those reviews need as a byproduct, rather than as a scramble later.

Where Atticus Rowan fits

Atticus Rowan builds and operates managed identity for small and mid-size companies on Microsoft 365. We run the inventory, enforce the MFA and conditional access baseline, consolidate applications to single sign-on where they support it, put the joiner-mover-leaver lifecycle in place and operate the ITDR monitoring on an ongoing basis. The goal is a tenant where identity is governed and watched, not a stack of licenses nobody configured. Our solutions page outlines the broader engagement model.

If your company has grown past the point where ad-hoc account management still works, and you are not confident MFA is enforced everywhere or that departed staff lose access the same day, schedule a discovery call. We can inventory the tenant, show you the gaps and scope the path to a governed identity fabric inside a 60-day window.