Service · Cybersecurity

Access control and endpoint security

Company data no longer lives behind the office door. Microsoft 365, Google Workspace and cloud apps open from anywhere, and that convenience applies to attackers as well: one password typed into a phishing page is enough for a sign-in from the other side of the world. Picture a fifteen-person dental clinic in Ankara. Everyone at reception shares one Windows account, dentists open the booking system on their personal phones, the practice manager's mailbox has no second factor, and if a laptop went missing nobody could wipe it remotely. Access control and endpoint security replace that picture with rules tied to the person, the device and the situation. A user proves their identity with a second factor, from a device the company manages and knows to be patched, in a plausible location, and only then reaches the data. When the conditions are not met, access is limited or an extra check is required. We build this with Entra ID conditional access and Intune or Google endpoint management, without making daily work harder, and entirely remotely.

Second factor
on every account, directors included
Conditional access
based on device, location and risk
Intune
or Google endpoint management for company devices
Personal phones
with a ring-fenced work area

What the work covers in practice

Each layer is worth having on its own, so we add them one at a time, in an order that fits your risks and what your team can absorb.

Agree the scope with the engineer who will do the work

Multi-factor sign-in

An authenticator app for everyone; passkeys or hardware keys for high-value targets such as admins and finance. Text-message codes remain a stopgap only.

Conditional access

Entra ID policies that allow company data only on managed devices, ask for extra proof on risky sign-ins, shut down legacy authentication and block logins from countries you never work in.

Device management

Company laptops and phones enrolled in Intune, with encryption, screen lock, update rules and remote wipe controlled from one console.

Bring-your-own phones

App protection for Outlook and Teams on personal phones: work data stays inside those apps, cannot be pasted into private ones, and is the only thing wiped when someone leaves.

Admin rights

No local admin rights for everyday work, separate accounts for admin tasks, and unique, automatically rotated local admin passwords through LAPS.

Application control

Where the risk justifies it, for example on finance or point-of-sale PCs, only approved software may run. Elsewhere, known high-risk tools are at least blocked.

How we approach the job, from first call to handover

Access rules touch every employee, so the rollout is planned to cost nobody a working day.

01

Baseline

All accounts, those without a second factor, and every device reaching company data, managed or not, in one table.

02

Enrolment and break-glass

Users register with a guide and, where needed, a video call. Two emergency accounts are set aside and secured separately so you can never be locked out of your own tenant.

03

Device onboarding

Company devices move under remote management, with policies tested on a small group first. Staff using personal phones receive a short set-up guide.

04

Enforcement

Conditional access runs in report-only mode first; once it is clear who is affected, policies are switched on step by step.

A password is where identity checks begin, not where they end. Leaked credential lists and phishing kits are so common that it is safer to assume any single-factor account will eventually be taken over. Requiring a second factor and a managed device ends most of those attacks at the sign-in screen.

Frequently asked questions

Full device enrolment is not required. App protection only governs company data inside Outlook and Teams and cannot see photos, private messages or the rest of the phone. A short, honest explanation usually settles the matter; issuing company phones to those who prefer is another route.

Shared PCs can still use personal sign-ins; fast user switching and short lock timers keep the desk moving. It also becomes clear who viewed a patient record, which matters for KVKK safeguards.

Yes. Google offers two-step verification, context-aware access and endpoint management in a similar way, with availability depending on your edition. We show what your current edition supports during the first review.

Tell us immediately: contract clients via helpme@apply.tr, everyone else via support@apply.tr. If the device is in Intune, we revoke sessions and lock or wipe it. With disk encryption the risk of data exposure is low; without it, you may need to assess the loss as a personal data incident.

Let only the right people reach your data

Share your user and device numbers, your platform and how personal phones are used. We will propose a rollout order.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.