An empty meeting room lit by sunlight through vertical blinds
Industries

Enterprise IT

Headquarters turnstiles, shared desks, and a laptop fleet that has to lock when the badge walks away, or when the account is disabled in the directory.

Directory sync shippingShared desk handlingAttestation for staffOne codebase on premise or hosted

A lobby should not queue, and an executive floor should not admit on a credential alone. Both are the same policy pack with a different floor.

Asynchronous lobbiesThroughput unchanged at the busiest entrance
Interlocked floorsExecutive and secure areas hold until the score clears
Shared desksA foreign face locks the screen where cameras are enabled
Directory drivenA disabled account is what ends access, everywhere
01

The building is not uniformly sensitive.

Treating one entrance policy as the whole security posture is what forces the choice between a slow lobby and an open floor.

Campus entrances run asynchronously, so the strike releases on the credential and corroboration attaches behind it. Nobody queues behind gait analysis at nine in the morning, and a weak score still escalates the next door and that person's desktop.

Secure areas and executive floors sit on a stricter rung. An interlocked entry holds the second door until both modalities have cleared, which is a deliberate throughput trade made for those rooms rather than for the whole estate.

Shared workstations are handled as what they actually are: devices held by a team rather than a person. Any principal valid for that zone can bind a session, and where a desk camera is enabled, a different enrolled face in that polygon locks the screen.

Typical configuration
Lobby and campus gates
Credential with asynchronous corroboration
General office floors
Same, with tailgate detection on busy lines
Equipment and comms rooms
Face corroboration required
Executive and secure areas
Full interlock
Desktops
Input activity and idle, camera opt-in
Shared workstations
Team custodianship, zone-valid principals
Directory
Entra ID or LDAP, live today
Device management
Existing platform deploys the agent
02

One estate, four floors.

The floor is set per zone, and the threat class can raise all of them at once without touching a single rule.

ZoneFloorBehaviour on elevated threat
Campus entrance Credential plus asynchronous corroboration Gait becomes required, throughput drops slightly
Office floor Credential plus asynchronous corroboration Face added, tailgate holds enforced harder
Equipment room Credential plus face Both modalities, and step-up at the desktop
Executive or secure area Full interlock Unchanged. It was already the strictest rung
Raising the threat class is one action and reaches every site inside a second. Lowering any floor below the tenant minimum needs two administrators.
03

The two problems nobody plans for.

The leaver who still has a badge

Disabling the account in your identity platform is the trigger. Both epochs move, the credential drops from every site access list, and the laptop locks and logs off.

No ticket, no checklist, no waiting for facilities to collect a card before access actually ends. The card becomes inert whether it is handed back or not.

The desk that is not yours

Hot desking breaks the assumption that a device has one owner, which is why team custodianship exists rather than a shared generic account.

Where a desk camera is enabled with a recorded basis, a different enrolled principal appearing at that desk locks the screen and records an anomaly rather than silently inheriting the session.

04

Rolling this into an occupied building.

Nobody can take a headquarters offline for a security programme, so the sequence is designed to be invisible to the people walking through it.

01

Start with the directory, change nothing physical

Connect the directory in mock mode, confirm the identity and group mapping, then go live. At this point the estate is accurate and no door has changed.

02

Bind the fleet, lock on idle only

Deploy the agent through your existing device management platform. It locks on idle and on a disabled account. Users notice nothing new day to day.

03

Bring one entrance onto the encrypted channel

One lobby, credential only, asynchronous. Throughput is unchanged, and you now have a portal producing real decision records to tune against.

04

Raise the floor where it matters

With a labelled week of data, set stricter floors on equipment rooms and executive areas. Only the zones that need to wait ever wait.

Hot desking is the detail that decides whether people trust this.

If a shared workstation locks the wrong person out mid-task, the programme loses the floor's goodwill and the exception requests start. Team custodianship exists so shared devices behave correctly by default, rather than being handled with a generic account somebody wrote on a sticky note.

05

What is already running.

Directory sync

Entra ID and LDAP connectors are live, with mock mode for evaluation.

Asset register

Custodians, serials, hostnames, and custom fields.

Service desk

Incidents, catalog, service levels, and a self-service portal.

Gate pass

Multi-level approval for equipment leaving the building.

Knowledge

Spaces with audiences inherited from directory groups.

Attestation

Employment verification for staff without disclosing personal data.

Bring the door onto the same epoch as the laptop.

We will walk you through a live portal, a compiled policy pack, and a revocation that closes the turnstile and locks the screen while you watch.