Enterprise IT
Headquarters turnstiles, shared desks, and a laptop fleet that has to lock when the badge walks away, or when the account is disabled in the directory.
A lobby should not queue, and an executive floor should not admit on a credential alone. Both are the same policy pack with a different floor.
The building is not uniformly sensitive.
Treating one entrance policy as the whole security posture is what forces the choice between a slow lobby and an open floor.
Campus entrances run asynchronously, so the strike releases on the credential and corroboration attaches behind it. Nobody queues behind gait analysis at nine in the morning, and a weak score still escalates the next door and that person's desktop.
Secure areas and executive floors sit on a stricter rung. An interlocked entry holds the second door until both modalities have cleared, which is a deliberate throughput trade made for those rooms rather than for the whole estate.
Shared workstations are handled as what they actually are: devices held by a team rather than a person. Any principal valid for that zone can bind a session, and where a desk camera is enabled, a different enrolled face in that polygon locks the screen.
- Lobby and campus gates
- Credential with asynchronous corroboration
- General office floors
- Same, with tailgate detection on busy lines
- Equipment and comms rooms
- Face corroboration required
- Executive and secure areas
- Full interlock
- Desktops
- Input activity and idle, camera opt-in
- Shared workstations
- Team custodianship, zone-valid principals
- Directory
- Entra ID or LDAP, live today
- Device management
- Existing platform deploys the agent
One estate, four floors.
The floor is set per zone, and the threat class can raise all of them at once without touching a single rule.
| Zone | Floor | Behaviour on elevated threat |
|---|---|---|
| Campus entrance | Credential plus asynchronous corroboration | Gait becomes required, throughput drops slightly |
| Office floor | Credential plus asynchronous corroboration | Face added, tailgate holds enforced harder |
| Equipment room | Credential plus face | Both modalities, and step-up at the desktop |
| Executive or secure area | Full interlock | Unchanged. It was already the strictest rung |
The two problems nobody plans for.
The leaver who still has a badge
Disabling the account in your identity platform is the trigger. Both epochs move, the credential drops from every site access list, and the laptop locks and logs off.
No ticket, no checklist, no waiting for facilities to collect a card before access actually ends. The card becomes inert whether it is handed back or not.
The desk that is not yours
Hot desking breaks the assumption that a device has one owner, which is why team custodianship exists rather than a shared generic account.
Where a desk camera is enabled with a recorded basis, a different enrolled principal appearing at that desk locks the screen and records an anomaly rather than silently inheriting the session.
Rolling this into an occupied building.
Nobody can take a headquarters offline for a security programme, so the sequence is designed to be invisible to the people walking through it.
Start with the directory, change nothing physical
Connect the directory in mock mode, confirm the identity and group mapping, then go live. At this point the estate is accurate and no door has changed.
Bind the fleet, lock on idle only
Deploy the agent through your existing device management platform. It locks on idle and on a disabled account. Users notice nothing new day to day.
Bring one entrance onto the encrypted channel
One lobby, credential only, asynchronous. Throughput is unchanged, and you now have a portal producing real decision records to tune against.
Raise the floor where it matters
With a labelled week of data, set stricter floors on equipment rooms and executive areas. Only the zones that need to wait ever wait.
If a shared workstation locks the wrong person out mid-task, the programme loses the floor's goodwill and the exception requests start. Team custodianship exists so shared devices behave correctly by default, rather than being handled with a generic account somebody wrote on a sticky note.
What is already running.
Directory sync
Entra ID and LDAP connectors are live, with mock mode for evaluation.
Asset register
Custodians, serials, hostnames, and custom fields.
Service desk
Incidents, catalog, service levels, and a self-service portal.
Gate pass
Multi-level approval for equipment leaving the building.
Knowledge
Spaces with audiences inherited from directory groups.
Attestation
Employment verification for staff without disclosing personal data.
The same control plane. A different floor.
Bring the door onto the same epoch as the laptop.
We will walk you through a live portal, a compiled policy pack, and a revocation that closes the turnstile and locks the screen while you watch.