Request an Assessment

Powered by happy clients

Secure · Platforms we sell and architect

Security &
Identity.

Security stacks grow one product at a time until nobody owns the whole control path: inherited firewall rules, admin accounts that double as daily drivers, MFA that exists but binds nothing. ModernOps designs the layers as one system, identity first, then the devices, applications, data and network edge that trust it. Architected, sourced, deployed, and operated by the same team.

24/7 NOC 50+ partners PA + AZ regions
CISO / Risk Leader

Enforceable least privilege, reduced blast radius and evidence that controls are operating, not just purchased.

CIO / VP of IT

One accountable partner across architecture, procurement, implementation and operations instead of four vendors pointing at each other.

Infrastructure / Network Leader

A governed edge: documented rulebases, validated HA, ticketed changes and monitoring on the firewalls, VPNs and NAC everyone depends on.

Identity / Endpoint / Microsoft Platform Leader

A phased path from AD, GPO and legacy authentication to Entra, Intune and Conditional Access, without breaking what still depends on the old world.

03The decision

Key design
considerations.

01 /

Identity is the control plane.

MFA existing is not the same as least privilege enforced. One recent assessment found MFA unenforced, no Conditional Access, and administrator accounts doubling as daily-use accounts. The fix is systematic: separated privileged roles, Conditional Access, just-in-time elevation and access reviews, not another agent.

02 /

The real number.

A firewall doing decryption, IPS and app control delivers a fraction of its datasheet rating. Sizing to the marketing number is how refreshes fail in year two. We size with inspection on.

03 /

You already own controls you are not using.

Organizations buy point products while E5 and P2 entitlements sit idle: Conditional Access, PIM, Defender, Purview, paid for and unconfigured. Activating what you license is usually the cheapest security project on the table.

04 /

Legacy identity has roots.

LDAP, NTLM, Kerberos, GPO, service accounts and aging applications hang off Active Directory. You do not exit AD by wishing; you map the dependencies, remediate them in phases and retain hybrid only where it is justified.

05 /

Consolidated platform or best of breed.

Fewer consoles genuinely reduces missed alerts; the tradeoff is negotiating leverage. There is a defensible answer either way, and security renewals have more pricing flexibility than any other line on the pile.

04What we architect

Reference
architectures.

Pattern 01

Legacy ASA-class estates moved to Palo Alto or Fortinet: rule rationalization, NAT and VPN documentation, policy conversion, HA validation and staged cutover. A productized services motion, not a first attempt.

Pattern 02

FortiGate-class firewalls for branch and mid-market sites where price-performance decides, sized with inspection enabled and onboarded with the rulebase archived and changes ticketed from day one.

Pattern 03

Entra-first target states built on a mapped current state: Conditional Access, MFA enforcement, PIM, access reviews and entitlement management, with a dependency-aware, phased reduction of on-premises AD. Delivered through structured engagements up to full identity and access strategy workshops.

Pattern 04

Intune and Autopilot deployment, Defender for Endpoint, encryption, attack surface reduction and BYOD application protection, including migrations from ConfigMgr, Jamf, Workspace ONE and MobileIron, so device health becomes an input to every access decision.

Pattern 05

Zscaler policy and tenant operations, Microsoft Global Secure Access evaluation, Duo MFA lifecycle, and network access control with Cisco ISE and Aruba ClearPass, designed jointly with the switching practice so segmentation intent survives into the network.

Pattern 06

SaaS discovery and app-consent governance with Defender for Cloud Apps, data classification and DLP with Purview, and integration patterns like Rubrik with Okta, where sensitive-data access risk can force reauthentication or kill a session automatically. Detection that ends in a ticket is a start; detection that ends in an action is the design goal.

05The platforms

Supported
platforms.

NGFW hardware from branch to data center, subscription structuring and renewals, and the migration practice that moves aging estates onto the platform cleanly. Renewals negotiated like they have competition, because with us they do.

The FortiGate line from 70G-class branch boxes to enterprise chassis, FortiGuard services, and the price-performance play, quoted with inspection-on throughput instead of datasheet numbers, and operable under managed firewall service from day one.

Falcon licensing, renewals and endpoint standardization for teams committed to best-of-breed EDR, paired with Managed Security for organizations without a SOC.

The stack most organizations already license and underuse: Entra Conditional Access and PIM, Intune and Autopilot, the Defender family, Sentinel and Purview, delivered by a senior-led practice through assessments, workshops, implementations and migrations. The honest pitch: before buying the next tool, activate the ones inside your E5.

PlatformZTNA and network identity

Zscaler tenant and policy management, Microsoft Global Secure Access design, Duo MFA lifecycle operations, and NAC with Cisco ISE and Aruba ClearPass, including posture policy, directory and MDM integration and HA validation.

Also on the line card

Cisco Secure (Firepower, Umbrella, Meraki MX), Okta, Proofpoint, Arctic Wolf, SentinelOne, KnowBe4, Varonis, Delinea, Wiz.

ModernOps engineer reviewing conditional-access identity policies on one monitor and firewall IPv4 policy rules on another, with a firewall appliance and a change implementation plan on the desk and an identity-first zero-trust diagram on the whiteboard
Identity first, enforced at the edge · Conditional-access policy and firewall rules designed as one system
06The old model vs ModernOps

The ModernOps
difference.

DimensionThe old modelModernOps
ArchitectureFirewall, endpoint, identity and data controls bought separatelyOne Zero Trust system across identity, devices, applications, data and the edge
IdentityMFA inconsistent, admin and daily accounts overlapEnforced MFA, Conditional Access, separated privileged roles, PIM, access reviews
Firewall operationsRules, NAT and VPNs live in tribal knowledgeRulebase archived, objects documented, HA validated, changes ticketed
Device trustUnknown devices reach company dataCompliance, encryption and Defender posture gate access, BYOD contained by policy
ApplicationsUsers grant consent, shadow SaaS accumulatesApp discovery, consent governance and session controls shrink the exposure
DataPolicy watches where data sits, not where it movesClassification, labels and DLP follow the data across endpoints and SaaS
OwnershipReseller, implementer, MSP and vendors point at each otherOne team architects, sources, deploys, operates and escalates
07The first 30 days

The first
30 days.

PhaseWhat happensWhat you hold at the end
Assess · Days 1 to 7Inventory firewalls, ZTNA, identity providers, privileged roles, endpoints, app consent, data controls, licensing and legacy dependencies. Review rulebases, MFA and Conditional Access coverage and incident workflows.A fact-based baseline: immediate exposure, unused entitlements you already pay for, and prioritized quick wins.
Implement · Days 8 to 21Archive configurations, separate privileged accounts, enforce MFA, restrict app consent, land approved Conditional Access, firewall, endpoint and data policies, connect monitoring, pilot the high-impact changes first.The highest-risk gaps closed under change control, with testing, documentation and rollback.
Optimize · Days 22 to 30Tune alerts and policies, validate HA and access paths, review exceptions, finalize ownership and change workflows, train administrators.Measurable controls in production, documented baselines, named ownership and a 30-to-90-day roadmap.
Scope control

Thirty days lands the baseline and the quick wins. Full identity migrations and firewall estate cutovers then run in dependency-aware phases on their own timeline, which is the only honest way to exit twenty years of Active Directory.

08Two paths, one team

Engagement
models.

This page is the assess, design, procure, implement and migrate motion. The recurring disciplines are productized: Managed Security carries firewall policy operations, monitoring, endpoint and identity administration and coordinated response, and it works on estates we sold or estates we inherited. Device lifecycle lives with the Microsoft practice.

09Proof

Proven
results.

A funded week on identity alone.

A global software company commissioned a forty-hour identity and access strategy engagement covering Conditional Access, Global Secure Access, device strategy and E5 utilization. Zero Trust as a planned program, not a poster.

What one assessment found.

MFA unenforced, no Conditional Access, admin accounts doubling as daily accounts, unmanaged devices and untracked third-party app consent. The roadmap closed them in phases, starting with the free fixes.

We hold ourselves to it.

ModernOps runs its own operations the way this page prescribes: Entra-authenticated, MFA-enforced, encrypted administrative access and separated privileged roles.

10FAQ

Frequently asked
questions.

01 /Palo Alto or Fortinet?
Throughput math with features enabled, operating fit and budget. We quote both, and the answer is allowed to be different per site.
02 /Our ASAs are end of life. What does migration actually involve?
Rule rationalization first, because you do not want twenty years of cruft converted faithfully. Then NAT and VPN documentation, policy conversion, HA validation and a staged cutover with rollback.
03 /Do you manage the firewall after selling it?
Yes. Onboarding archives the rulebase, documents the objects and validates HA, then changes run through tickets with approvals and maintenance windows. We also take over firewalls we did not sell.
04 /We have MFA. Why is access still too broad?
Because MFA answers who you are, not what you should reach. Least privilege takes Conditional Access, separated admin roles, just-in-time elevation and periodic access reviews.
05 /Can we get rid of on-premises Active Directory?
Usually reduce, sometimes retire, never by flipping a switch. LDAP, NTLM, Kerberos, GPO, service accounts and legacy apps get mapped and remediated in phases; hybrid stays only where a dependency earns it.
06 /We pay for Microsoft E5. What are we probably not using?
Commonly: Conditional Access beyond defaults, PIM, Defender for Cloud Apps, Purview labeling and DLP, and Intune compliance gating access. Activating them is the cheapest project on this page, and it is exactly what our M365 Tools Rationalization assessment measures.
07 /ZTNA or keep the VPN?
ZTNA grants per-application access based on identity and device health instead of network placement. Most environments run both during transition; the design decides what moves first.
08 /How do we handle BYOD and unmanaged devices?
Application protection and session controls for personal devices, full Intune management for corporate ones, and Conditional Access that treats device health as part of the access decision.
09 /CrowdStrike or the Defender we already license?
Both are real answers. It comes down to operating model, existing licensing, SOC tooling and who watches the console. We sell and support both, so the recommendation follows your estate, not our margin.
10 /How do we get leverage on security renewals?
Co-term them into one event, know your utilization before the quote arrives, and make the incumbent aware there is a bid. Security subscriptions have more pricing flexibility than any other renewal line.
11Direct to an engineer

Tell us about
your stack.

Firewalls, identity, endpoints: whatever you have. We will map the exposure and the entitlements you already own.

Start the conversation

Two minutes of fields · Replied to within 1 business hour · No obligation

Or call 484-429-9328 and skip the form entirely