Protecting a Perth firm's identities in the AI era with Conditional Access
A Perth CBD firm worried that AI-powered phishing made identity theft inevitable and their antivirus couldn't stop it. We rebuilt their security around identity — Microsoft Conditional Access, session-theft protection and passwordless sign-in — reaching 100% MFA coverage and cutting phishing success ~95% in four weeks.
100%
MFA coverage
~95%
Lower phishing success rate
Passwordless
Credential theft closed off
4 weeks
Assessment to rollout
The challenge
A 35-person professional-services firm in the Perth CBD came to us anxious about identity theft in the AI era. Their leadership had read how AI is making phishing and social engineering dramatically more convincing, and they had realised their traditional antivirus — fine against known malware — did nothing to stop an attacker who simply steals a staff member's credentials and signs in as a legitimate user. With phishing now behind a large share of Australian cyber incidents, they wanted protection built around identity, not just the endpoint.
What we did
We implemented a layered identity-protection strategy centred on Microsoft Entra Conditional Access. Sign-in and session-risk policies now evaluate every authentication in real time — blocking risky sign-ins, requiring compliant and recognised devices, restricting access to expected locations, and enforcing MFA on all users. To stop session-token theft we added continuous session validation, anomaly detection and automatic re-authentication or sign-out when behaviour looks suspicious. We layered on Azure Identity Protection, privileged access management with time-limited admin elevation, and passwordless sign-in (FIDO2 security keys and Windows Hello) to take stealable passwords out of the equation entirely.
The outcome
The firm moved from a single antivirus layer to enterprise-grade identity security in four weeks — assessment, design, rollout and tuning. Every account is now covered by MFA, sessions are monitored with automatic threat response, and passwordless sign-in has effectively closed the credential-theft door, cutting phishing's success rate by around 95%. The controls also brought the firm in line with the ASD Essential Eight and satisfied modern cyber-insurance requirements, giving leadership the confidence to operate — and to show their own clients — that data stays protected as AI-era threats evolve.
The difference is remarkable. We no longer feel vulnerable to AI-powered identity attacks. Our team can work confidently, and we know our customers' data is protected even when threats evolve.
Could we do the same for you?
Book a free 30-minute IT assessment. We'll review your setup and tell you honestly where you stand.