Identity Security & Zero Trust in India & UAE.
End-to-end identity security: IAM topology review, privileged-access (PAM) tightening, SSO / OIDC / SAML hardening, conditional-access design and a phased Zero Trust roadmap mapped to NIST SP 800-207 and India's CERT-In + DPDP authentication expectations.
What is Zero Trust identity security?
Zero Trust identity security replaces implicit network trust with continuous verification — strong authentication, least-privilege access, and segmentation so a stolen credential can't roam freely. Macksofy assesses and builds IAM, PAM, and Zero Trust architectures aligned to the RBI IT-Governance mandate for banks and enterprises across India.
Nobody designed this. It accreted.
On-prem AD still authoritative, Entra syncing part of the estate, a federation layer in front of SaaS, and privileged access split across vaults that different teams own. The attack paths live in the seams between them.
- Phishing-resistant MFA on tier-0 and admin populations
- Cut blast radius — kill standing privilege, enforce JIT/JEA
- Pass RBI / SEBI / DPDP authentication evidence asks on first pass
- Reduce identity-related audit findings to near-zero within one cycle
- Cost-rationalise overlapping IAM/PAM tooling
Delegation, ACLs and service accounts accumulated over a decade
The sync boundary is where on-prem admin becomes cloud admin
Stale OAuth grants and app-to-app scopes nobody reviews
Dormant safes and standing admin that no single team can see whole
Privilege inherited across the directory-sync boundary
Kerberoastable SPN with a password older than the policy that governs it
A shared OAuth client trusted by both
Engineering laptops domain-joined to the corporate forest
Hybrid is the norm in India, not an edge case. The assessment enumerates every identity provider, directory, federation and break-glass account before it maps a single path.
A Zero Trust plan that survives the change board.
Zero Trust programmes fail on sequencing, not on architecture. The first ninety days have to close real paths without needing a budget cycle — everything else follows from having proved that.
Phishing-resistant MFA on tier-0 and every admin population
Passwordless as default, continuous risk-based re-authentication
Compliance signal enforced in conditional access for admin sessions
Device posture as a first-class input to every access decision
Tier-0 isolated, break-glass paths documented and alerted
Microsegmentation across east-west, ZTNA replacing flat VPN
Stale OAuth grants revoked, shared clients split by trust level
Per-app authorisation with workload identity, no long-lived secrets
Crown-jewel stores identified and standing access removed
Classification-driven access with JIT elevation and full session record
Sequencing recommendation, not a maturity score. Where your estate actually sits on each pillar is the output of the assessment — and the 90-day column is deliberately the part that survives a change-advisory board.
Inventory, then paths, then architecture.
In that order — a target-state diagram drawn before the inventory is a diagram of somebody else’s network.
- ▸Enumerate every IdP, directory, federation and break-glass account
- ▸Crowdsource shadow-IAM via SaaS SSO logs + finance procurement data
- ▸Tier-0 / Tier-1 / Tier-2 classification of human + service identities
- ▸Privileged-account census — domain, cloud, app and DB admins
- ▸BloodHound + Azure AD attack-path enumeration
- ▸Kerberoasting, AS-REP, ACL-abuse and constrained-delegation review
- ▸Cloud lateral movement — IAM trust policies, role chaining, secrets
- ▸SaaS-to-SaaS OAuth scope abuse and stale grants
- ▸Trust-boundary diagram aligned to NIST 800-207 + CISA ZTMM
- ▸Conditional access policy design (Entra ID / Okta / Ping)
- ▸Phishing-resistant MFA rollout plan — FIDO2 / passkeys / certificate-based
- ▸Microsegmentation design for east-west traffic
- ▸Vault rationalisation across CyberArk / Delinea / HashiCorp Vault
- ▸JIT / JEA workflows; break-glass with dual-control + alerting
- ▸Service-account rotation, password-less wherever possible
- ▸Privileged session recording + UEBA alerting
- ▸90-day quick wins backlog + 12-month maturity plan
- ▸RBI / SEBI / DPDP authentication-evidence pack
- ▸Quarterly red-team identity validation (optional retainer)
- ▸Board-level metrics: standing-privilege count, MFA coverage, JIT %
You do not have to buy the whole programme.
Vault rationalisation, standing-privilege removal, JIT and break-glass with dual control. The fastest way to cut blast radius.
Full identity inventory, attack-path map and a staged target-state architecture. Sized against roughly a 5,000-identity estate.
Architecture advisory through a phased rollout, with optional quarterly red-team validation of the identity boundary.
Every finding lands against a control.
Authentication and privileged-access controls mapped finding by finding, in the language the inspection uses.
Identity controls for market intermediaries, with the governance sign-off trail the framework expects.
Access control mapped to the reasonable-security-practices obligation, including processors and vendor identities.
A.5.15 access control, A.5.16 identity management, A.5.17 authentication information and A.8.5 secure authentication.
Three estates, three kinds of seam.
Scope · Tier-0 path mapping + PAM consolidation
Finding · Kerberoastable tier-0 service account + dormant CyberArk safes with 100+ unused admins
Standing privilege cut 78% in 60 days; clean RBI inspection
Scope · Zero Trust architecture for SOC 2 + EU customers
Finding · Public-app to admin-app lateral path via shared OAuth client
Split-tenant identity model shipped pre-Series-C diligence
Scope · IT-OT identity boundary for IEC 62443
Finding · OT engineering laptops domain-joined to IT AD; flat trust
Dedicated OT realm + jump-host model; USFDA-PAI ready
We assess first and sell nothing.
CyberArk, Delinea, HashiCorp Vault, SailPoint and Saviynt are all in the delivery toolkit and none of them pay us. The architecture comes before the shortlist, which is the only order that produces an honest shortlist.
Transparent tiers. No surprises at quote time.
Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.
Build
- Tooling (Wazuh / ELK / Splunk) implementation
- Baseline detection rules
- Runbook authoring
Operate
- Everything in Build
- 24×7 monitoring across business hours
- Monthly threat-hunt + posture reviews
Resilience
- Everything in Operate
- L3 threat hunters + IR retainer
- Annual table-top + DR drill
Note · Indicative pricing in INR. Setup + 12-month operate is the most-asked combination. Custom blends available.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Questions before the inventory starts.
Where Macksofy delivers Identity & ZT.
On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
