Skip to main content

Cloud Identity, MFA & Device Management

How DTC approaches user identity, sign-in strength and device management for clients. Credentials themselves (naming, length, rotation, storage) are in the Client Credential Administration Standard; this page is the identity architecture around them.

Identity provider

  • SSO first. Microsoft Entra ID (or the client's existing IdP) is the authentication source for client applications wherever the application can federate. Federation candidates are identified during technology assessments and recorded in IT Glue.
  • Legacy on-prem AD stays in scope until it can be federated or replaced. New domains follow AD-001; workgroup sites moving to a domain follow the Workgroup-to-Domain Conversion SOP.
  • DTC's own approved providers — Entra ID and Cloudflare Zero Trust — are listed in Approved Identity Providers.

MFA

  • Every administrative account has MFA. No exceptions.
  • End-user MFA is pursued, not blanket-enforced — raised at onboarding and renewal and enabled wherever the client's licensing and workflow allow.
  • Strength order: phishing-resistant (FIDO2, passkey, Windows Hello for Business, certificate) → authenticator app (push or TOTP) → email code only where nothing stronger exists → SMS avoided and removed when something stronger becomes available. Same tiers as Approved MFA and Passwordless Methods.

Device management

  • NinjaOne is the management plane for every Windows endpoint and server; the baseline it enforces is in Windows Workstations MSA Standard Configuration.
  • Intune covers mobile devices (MDM/MAM), compliance policy, and environments where NinjaOne cannot be the control point (GCC High). Procedures are in the Microsoft Intune & Mobile Device Management book.
  • BitLocker recovery keys escrow to the directory the device is joined to — AD, Entra ID, or both.

Identifiers

Every organisation, location, device and user DTC manages carries an OUID — see Operational UUID (OUID) Standard.

Open

  • End-user default passwords. The credential standard sets a 16+ character baseline for all systems but still lists clientshortname@user1 as an end-user default. Needs a ruling.
  • Conditional Access baseline for client M365 tenants is not written down as a standard yet.