Services

Fixed-scope assessments. Identity is the depth.

Every engagement works the same way: scope is agreed in writing, the environment is examined under temporary read-only access, a written report is delivered, and the engagement ends. No managed services, no remediation contracts, no retainers. The depth of the practice is Microsoft identity — workload and non-human identity in Entra above all.

01

Specialty

Primary assessment

Entra workload & non-human identity assessment

Most tenants are governed as if only people hold access. Some of the broadest and least-visible access in a tenant belongs to identities no one logs into: service principals, app registrations, managed identities, and the automations and AI agents built on them. This assessment examines that layer directly — what these identities can reach, what credentials they hold, who is accountable for them, and whether any of that is still true by intention rather than by accident.

The report documents each material finding with the Graph query or portal evidence behind it, the practical impact in this tenant, and specific remediation guidance — including credential replacement, permission reduction, and ownership assignment.

Enterprise applications and app registrations

What has been integrated into the tenant, whether each integration is still used, and whether its configuration matches its stated purpose.

Service principals and managed identities

Which non-human identities exist, what they can access, and whether each has a named, accountable owner.

Graph application and delegated permissions

What each identity is permitted to do, whether application-scope permissions are justified, and where broad rights like Mail.Read or Directory access sit unreviewed.

OAuth consent grants

Which applications hold delegated access on behalf of users, at what scopes, and whether each grant remains necessary and proportionate.

Application secrets and certificates

Credential age, expiry, and validity windows — which credentials are long-lived, approaching expiry unnoticed, or past rotation with no replacement plan.

Privileged role assignments held by workload identities

Whether any service principal holds directory roles, and whether that standing privilege is deliberate, documented, and monitored.

Stale and orphaned integrations

Which connected applications have gone quiet — no sign-in activity, no owner, no remembered purpose — and what they could still reach.

Ownership and human accountability

Whether every non-human identity maps to a person responsible for its rotation, review, and eventual removal.

AI agents are assessed as what they are in the tenant: non-human identities with credentials, permissions, and trust boundaries. The same objects, the same questions.

02

HIPAA

HIPAA Security Rule risk analysis

A Security Rule risk analysis is the requirement most covered entities and business associates cite and few have actually performed to the standard OCR expects: an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI, documented and updated. This engagement produces that analysis for the agreed environment — administrative, physical, and technical safeguards examined against the Security Rule, with risks documented, rated, and tied to specific remediation.

The assessor administers a HIPAA-regulated healthcare environment day to day. The analysis is written by someone who operates under the same rule — who knows which safeguards exist on paper, which exist in configuration, and how often those differ. Findings are written for both the compliance record and the people who have to implement them.

03

Further assessments

Further assessment work

04

Also available

Also available

Vulnerability assessment

Authenticated review of the agreed environment for known vulnerabilities and misconfigurations, validated and prioritized by practical exploitability rather than scanner severity.

Security posture assessment

Assessment of the control environment against NIST CSF 2.0 or CIS Controls, documenting current-state maturity and the gaps that matter most for the organization's size and obligations.

Subcontract engagements: Kino works with security firms as a named or white-label assessor under the firm's client agreement — NDA first, and the report is delivered in your format or Kino's. The same scope, evidence, and data-handling terms apply.

05

Questions

Common questions

What does a non-human identity assessment cover?

A non-human identity assessment examines the workload identities in a Microsoft Entra tenant: enterprise applications and app registrations, service principals and managed identities, Graph application and delegated permissions, OAuth consent grants, secrets and certificates with their rotation state, privileged roles held by workload identities, workload identity federation, and stale or orphaned integrations. Each identity is evaluated for what it can reach, who owns it, and whether its access is still justified.

What access is required?

Assessment access is temporary, read-only, and limited to what the agreed scope requires — typically read access to Microsoft Graph and the relevant admin portals. No changes are made to the environment. Access is removed at delivery, and the removal is confirmed in writing.

What is the deliverable?

The deliverable is a written assessment report: what was examined, what was found, the evidence behind each finding, a severity rating under a fixed rubric, and specific remediation guidance. The report states its own coverage limits. Working evidence is destroyed at closeout; the client retains the report.

How are scope and fee set?

Scope and fee are set in a short scoping conversation and agreed in writing before any access is granted. The fee is fixed for the agreed scope — it does not change with the number of findings. If the work does not fit the practice, the answer is no, early.