Meet our experts at Gartner Identity & Access Management Summit in Las Vegas, NV | December 7-9, 2026

Turning a Security Incident Into a Resilient Identity Foundation 

Customer IAM
Microsoft, Microsoft Entra ID

A security incident became the turning point for the client’s identity and access management. As a global company whose business depends on external partners reaching its platform every day, it had grown authentication one exception at a time rather than by design. Working with iC Consult on Customer Identity & Access Management (CIAM), it rebuilt the foundation into one system its security team can now manage and improve with confidence.

Content

Customer & Project Overview

Customer Profile

Industry: Manufacturing

About the Customer

The client designs and manufactures its products for customers worldwide, selling and supporting them through a network of independent partners who use a platform built for their needs.

Project Description

Following a security incident, the client needed to consolidate a fragmented approach to authentication and access management, protect its partner facing portal, and build a foundation that could scale with future requirements.

Products & Services

Microsoft Entra ID (Azure AD B2C)

Results

Centralized CIAM platform protecting the applications partners rely on every day

Consistent, streamlined login experience for partners across the platform

Self-service password reset for partners and employees, reducing helpdesk load while strengthening security

Consolidated conditional access policy serving as the baseline for all new projects

Single authentication methods policy for simplified administration and built-in scalability

Situation

The incident response confirmed the problem quickly. The harder question came next: how had identity and access actually been managed for years? The answer was a setup shaped by individual exceptions rather than a coherent design.

Legacy security tools were still in use because none could safely be retired without disrupting the reliable access partners depended on every day to reach the platform. The Microsoft Entra ID policies protecting that portal had been built for requirements that had since evolved. A newly launched external facing application needed a protection plan tailored to it. Conditional access rules were in place, but their original purpose had not been documented, making them hard to review with confidence. Self-service password reset had been set up early on but was rarely used, so employees still relied on the helpdesk for something the tool was designed to handle.

None of this had caused the incident on its own, but together these gaps showed that authentication and access could no longer be treated as a set of separate decisions. What was needed was one coherent, well governed system: one that closed the gaps the incident had uncovered while staying flexible enough to support a modern way for partners to log in and do business.

Solution

Starting with a Clear Picture

The work started with a CIAM assessment conducted with iC Consult, mapping how identity and access were managed across its partner platforms. This gave both teams one clear view of where legacy decisions had accumulated and which gaps mattered most, so the next steps could address the highest risk areas first, not just the easiest ones.

Securing Access for Partners

The team then built CIAM capabilities that give partners secure, user friendly access to the portal, including support for OpenID Connect and a streamlined login and password reset flow. For a business built on an independent partner network, that access is not a convenience. Partners rely on it every day, so keeping it secure and simple protects the relationship instead of getting in its way.

Closing the Self-Service Gap

Adoption of self-service tools had been limited, so the team reactivated and optimized Self-Service Password Reset (SSPR) in Microsoft Entra ID. Employees can now manage their own credentials without contacting the helpdesk. This also removed a bottleneck that had slowed the original incident response: when many credentials need to be reset quickly, a self-service process people actually use is faster and safer than routing every request through a support queue.

One Policy, Full Visibility

With iC Consult’s support, fragmented legacy policies were then consolidated into a single authentication methods policy, replacing a patchwork of individual configurations with one framework the security team can govern and extend. Consolidation like this does more than simplify administration. It gives the security team one place to see and control how people authenticate, providing the visibility it needs to respond quickly to any future incident. The final step reviewed the existing conditional access rules, closed the gaps it found, and produced clear recommendations for a stronger, more transparent security posture going forward. Together, these changes replaced a fragmented setup with one the team can audit and adjust with confidence.

Outlook

A Foundation Built to Last

The new authentication methods policy gives the security team one framework to build on as requirements change, making it easier to demonstrate compliance going forward.

What started as a response to a security incident became a lasting improvement in how identity is managed across the business. The result is a stronger, more resilient setup, ready for what comes next.