Enforceable least privilege, reduced blast radius and evidence that controls are operating, not just purchased.
Security &
Identity.
Security stacks grow one product at a time until nobody owns the whole control path: inherited firewall rules, admin accounts that double as daily drivers, MFA that exists but binds nothing. ModernOps designs the layers as one system, identity first, then the devices, applications, data and network edge that trust it. Architected, sourced, deployed, and operated by the same team.
One accountable partner across architecture, procurement, implementation and operations instead of four vendors pointing at each other.
A governed edge: documented rulebases, validated HA, ticketed changes and monitoring on the firewalls, VPNs and NAC everyone depends on.
A phased path from AD, GPO and legacy authentication to Entra, Intune and Conditional Access, without breaking what still depends on the old world.
Key design
considerations.
Identity is the control plane.
MFA existing is not the same as least privilege enforced. One recent assessment found MFA unenforced, no Conditional Access, and administrator accounts doubling as daily-use accounts. The fix is systematic: separated privileged roles, Conditional Access, just-in-time elevation and access reviews, not another agent.
The real number.
A firewall doing decryption, IPS and app control delivers a fraction of its datasheet rating. Sizing to the marketing number is how refreshes fail in year two. We size with inspection on.
You already own controls you are not using.
Organizations buy point products while E5 and P2 entitlements sit idle: Conditional Access, PIM, Defender, Purview, paid for and unconfigured. Activating what you license is usually the cheapest security project on the table.
Legacy identity has roots.
LDAP, NTLM, Kerberos, GPO, service accounts and aging applications hang off Active Directory. You do not exit AD by wishing; you map the dependencies, remediate them in phases and retain hybrid only where it is justified.
Consolidated platform or best of breed.
Fewer consoles genuinely reduces missed alerts; the tradeoff is negotiating leverage. There is a defensible answer either way, and security renewals have more pricing flexibility than any other line on the pile.
Reference
architectures.
Legacy ASA-class estates moved to Palo Alto or Fortinet: rule rationalization, NAT and VPN documentation, policy conversion, HA validation and staged cutover. A productized services motion, not a first attempt.
FortiGate-class firewalls for branch and mid-market sites where price-performance decides, sized with inspection enabled and onboarded with the rulebase archived and changes ticketed from day one.
Entra-first target states built on a mapped current state: Conditional Access, MFA enforcement, PIM, access reviews and entitlement management, with a dependency-aware, phased reduction of on-premises AD. Delivered through structured engagements up to full identity and access strategy workshops.
Intune and Autopilot deployment, Defender for Endpoint, encryption, attack surface reduction and BYOD application protection, including migrations from ConfigMgr, Jamf, Workspace ONE and MobileIron, so device health becomes an input to every access decision.
Zscaler policy and tenant operations, Microsoft Global Secure Access evaluation, Duo MFA lifecycle, and network access control with Cisco ISE and Aruba ClearPass, designed jointly with the switching practice so segmentation intent survives into the network.
SaaS discovery and app-consent governance with Defender for Cloud Apps, data classification and DLP with Purview, and integration patterns like Rubrik with Okta, where sensitive-data access risk can force reauthentication or kill a session automatically. Detection that ends in a ticket is a start; detection that ends in an action is the design goal.
Supported
platforms.
NGFW hardware from branch to data center, subscription structuring and renewals, and the migration practice that moves aging estates onto the platform cleanly. Renewals negotiated like they have competition, because with us they do.
The FortiGate line from 70G-class branch boxes to enterprise chassis, FortiGuard services, and the price-performance play, quoted with inspection-on throughput instead of datasheet numbers, and operable under managed firewall service from day one.
Falcon licensing, renewals and endpoint standardization for teams committed to best-of-breed EDR, paired with Managed Security for organizations without a SOC.
The stack most organizations already license and underuse: Entra Conditional Access and PIM, Intune and Autopilot, the Defender family, Sentinel and Purview, delivered by a senior-led practice through assessments, workshops, implementations and migrations. The honest pitch: before buying the next tool, activate the ones inside your E5.
PlatformZTNA and network identity
Zscaler tenant and policy management, Microsoft Global Secure Access design, Duo MFA lifecycle operations, and NAC with Cisco ISE and Aruba ClearPass, including posture policy, directory and MDM integration and HA validation.
Cisco Secure (Firepower, Umbrella, Meraki MX), Okta, Proofpoint, Arctic Wolf, SentinelOne, KnowBe4, Varonis, Delinea, Wiz.
The ModernOps
difference.
| Dimension | The old model | ModernOps |
|---|---|---|
| Architecture | Firewall, endpoint, identity and data controls bought separately | One Zero Trust system across identity, devices, applications, data and the edge |
| Identity | MFA inconsistent, admin and daily accounts overlap | Enforced MFA, Conditional Access, separated privileged roles, PIM, access reviews |
| Firewall operations | Rules, NAT and VPNs live in tribal knowledge | Rulebase archived, objects documented, HA validated, changes ticketed |
| Device trust | Unknown devices reach company data | Compliance, encryption and Defender posture gate access, BYOD contained by policy |
| Applications | Users grant consent, shadow SaaS accumulates | App discovery, consent governance and session controls shrink the exposure |
| Data | Policy watches where data sits, not where it moves | Classification, labels and DLP follow the data across endpoints and SaaS |
| Ownership | Reseller, implementer, MSP and vendors point at each other | One team architects, sources, deploys, operates and escalates |
The first
30 days.
| Phase | What happens | What you hold at the end |
|---|---|---|
| Assess · Days 1 to 7 | Inventory firewalls, ZTNA, identity providers, privileged roles, endpoints, app consent, data controls, licensing and legacy dependencies. Review rulebases, MFA and Conditional Access coverage and incident workflows. | A fact-based baseline: immediate exposure, unused entitlements you already pay for, and prioritized quick wins. |
| Implement · Days 8 to 21 | Archive configurations, separate privileged accounts, enforce MFA, restrict app consent, land approved Conditional Access, firewall, endpoint and data policies, connect monitoring, pilot the high-impact changes first. | The highest-risk gaps closed under change control, with testing, documentation and rollback. |
| Optimize · Days 22 to 30 | Tune alerts and policies, validate HA and access paths, review exceptions, finalize ownership and change workflows, train administrators. | Measurable controls in production, documented baselines, named ownership and a 30-to-90-day roadmap. |
Thirty days lands the baseline and the quick wins. Full identity migrations and firewall estate cutovers then run in dependency-aware phases on their own timeline, which is the only honest way to exit twenty years of Active Directory.
Engagement
models.
This page is the assess, design, procure, implement and migrate motion. The recurring disciplines are productized: Managed Security carries firewall policy operations, monitoring, endpoint and identity administration and coordinated response, and it works on estates we sold or estates we inherited. Device lifecycle lives with the Microsoft practice.
Proven
results.
A funded week on identity alone.
A global software company commissioned a forty-hour identity and access strategy engagement covering Conditional Access, Global Secure Access, device strategy and E5 utilization. Zero Trust as a planned program, not a poster.
What one assessment found.
MFA unenforced, no Conditional Access, admin accounts doubling as daily accounts, unmanaged devices and untracked third-party app consent. The roadmap closed them in phases, starting with the free fixes.
We hold ourselves to it.
ModernOps runs its own operations the way this page prescribes: Entra-authenticated, MFA-enforced, encrypted administrative access and separated privileged roles.
Frequently asked
questions.
01 /Palo Alto or Fortinet?
02 /Our ASAs are end of life. What does migration actually involve?
03 /Do you manage the firewall after selling it?
04 /We have MFA. Why is access still too broad?
05 /Can we get rid of on-premises Active Directory?
06 /We pay for Microsoft E5. What are we probably not using?
07 /ZTNA or keep the VPN?
08 /How do we handle BYOD and unmanaged devices?
09 /CrowdStrike or the Defender we already license?
10 /How do we get leverage on security renewals?
Tell us about
your stack.
Firewalls, identity, endpoints: whatever you have. We will map the exposure and the entitlements you already own.
