Skip to main content
Case Studies

Proven outcomes, real environments.

Proven outcomes in Identity, Access Management and Cyber Security across Australia's most complex environments. We protect our clients' identity environments and their privacy.

Client confidentiality is a commitment, not a disclaimer. If you would like to discuss our experience in your sector, we are happy to have that conversation directly. Get in touch.

Industry

Capability

Technology

Federal Government
01

Transforming Identity and Cyber Capability for a Federal Government Department

A large Australian Government department partnered with Modern 42 to overhaul its identity infrastructure and strengthen its cyber security posture.

Sector Government ServicesType Strategic Advisory, Architecture and Design, Engineering
Federal GovernmentIAM StrategyPrivileged Access ManagementZero TrustCloud IAM+4
Read full case study
Higher Education
02

Building a Modern IAM Practice for a Leading Australian University

A leading Australian research university partnered with Modern 42 over multiple years to establish a world-class Identity and Access Management capability from the ground up.

Sector Research UniversityType Strategic Advisory, Architecture and Design, Engineering
Higher EducationIAM StrategyCloud MigrationPAMMFA Rollout+3
Read full case study
Financial Services
03

Defining the Digital Identity Blueprint for a Major Australian Bank

A well-established Australian community bank undergoing a significant digital transformation engaged Modern 42 to architect its future-state identity capability, ensuring its digital ecosystem could securely serve customers, employees and partners.

Sector Banking (Community and Retail)Type Strategic Advisory, Architecture and Design
Financial ServicesBankingCIAMDigital TransformationCyber Strategy+2
Read full case study
Federal Government
04

Modernising Cloud Identity for a Federal Government Agency

An Australian Government agency modernising its operating environment partnered with Modern 42 to consolidate and modernise its identity systems.

Sector Government ServicesType Strategic Advisory, Architecture and Design, Engineering
Federal GovernmentCloud MigrationIAM StrategyAzure ADApplication Migration+1
Read full case study
Automotive
05

Migrating 3,300+ Devices to Cloud-Native Management for a Global Automotive Brand

The Australian subsidiary of a global automotive manufacturer engaged Modern 42 to accelerate its modern management journey, shifting device management entirely to the cloud while keeping employees productive, connected and secure.

Sector Corporate OperationsType Strategic Advisory, Engineering
AutomotiveDevice ManagementCloud MigrationMicrosoft IntuneEndpoint Security+2
Read full case study
Financial Services
06

Comprehensive Entra Security Review and Ongoing Partnership with a Global Financial Services Group

A global financial services group operating across multiple international markets engaged Modern 42 for an independent security review of its Microsoft Entra environment. What began as a focused assessment has since evolved into a strategic, ongoing partnership.

Sector Global Banking, Asset Management, Wealth ManagementType Strategic Advisory, Architecture and Design, Engineering
Financial ServicesSecurity AssessmentEntra IDConditional AccessM365 Security+3
Read full case study
Local Government
07

Deploying Privileged Access Management for a Metropolitan Council

A metropolitan local government authority engaged Modern 42 to design and implement a Privileged Access Management solution, securing critical infrastructure and reducing operational risk across its environment.

Sector Municipal ServicesType Engineering
Local GovernmentPAMBeyondTrustPrivileged AccessVendor Access Management+1
Read full case study
State Government
08

IAM Strategy and Roadmap for a State Government Organisation

A state government organisation engaged Modern 42 to assess its legacy IAM platform and chart a path forward.

Sector Government ServicesType Strategic Advisory, Architecture and Design
State GovernmentIAM StrategyRoadmapCurrent State AnalysisGovernment Services+1
Read full case study
State Government
09

Delivering a CIAM Capability on Entra External ID for a State Government Organisation

A state government organisation partnered with Modern 42 to rapidly deliver a Customer Identity and Access Management (CIAM) capability on Microsoft Entra External ID, enabling a critical departmental transition.

Sector Government ServicesType Strategic Advisory, Analysis and Service Design, Architecture and Design, Engineering and Development
State GovernmentCIAMEntra External IDBespoke DevelopmentDelegated Access+2
Read full case study
Retail Property / Real Estate
10

End-to-End PAM Capability Uplift for a Major Australian Retail Property Group

A major Australian retail property group partnered with Modern 42 over multiple years to embed a mature Privileged Access Management capability.

Sector Property ManagementType Strategic Advisory, Analysis and Service Design, Architecture, Engineering
Retail PropertyPAMBeyondTrustEssential EightIAM Strategy+4
Read full case study
Retail Property / Real Estate
11

Identity Governance and Administration Uplift for a Major Retail Property Group

Continuing its IAM transformation journey, a major Australian retail property group engaged Modern 42 to define its Identity Governance and Administration (IGA) capability, laying the groundwork for automated identity lifecycle management.

Sector Property ManagementType Strategic Advisory, Analysis and Service Design, Architecture
Retail PropertyIGAIdentity GovernanceJML ProcessesService Design+2
Read full case study
Federal Government
12

IAM Strategic Advisory and Data-Driven Access Reviews for a Federal Government Authority

An Australian Government statutory authority engaged Modern 42 to review its workforce identity capability and develop a prioritised uplift plan, supported by data-driven access insights.

Sector Government ServicesType Strategic Advisory, Architecture and Design
Federal GovernmentIAM StrategyAccess ReviewsApporetumData-Driven Insights+1
Read full case study
Healthcare
13

Data-Driven IAM Discovery and Planning for a Major Healthcare Provider

A large Australian healthcare provider with international operations engaged Modern 42 to conduct a data-driven discovery of its identity landscape and develop a practical implementation plan.

Sector Healthcare ServicesType Strategic Advisory, Architecture and Design
HealthcareIAM DiscoveryAccess ReviewsApporetumData-Driven Insights+2
Read full case study
Higher Education
14

PAM Implementation and Essential Eight Uplift for an Australian Research University

A leading Australian research university engaged Modern 42 to expand its Privileged Access Management capability and progress toward ASD Essential Eight Maturity Level 2.5.

Sector Research UniversityType Analysis and Service Design, Architecture and Design, Engineering and Development
Higher EducationPAMBeyondTrustEssential EightCredential Migration+3
Read full case study
Healthcare / Health Services
15

IAM Strategy, Conditional Access Uplift and CIAM Blueprint for a National Health Services Organisation

A national health services organisation, designated as critical infrastructure, engaged Modern 42 to define its IAM strategy and deliver targeted security uplifts across its broad identity ecosystem.

Sector National Health ServicesType Strategic Advisory, Analysis and Service Design, Architecture and Design, Engineering and Development
HealthcareCritical InfrastructureIAM StrategyConditional AccessCIAM Blueprint+4
Read full case study

Case Study 01: Transforming Identity and Cyber Capability for a Federal Government Department

A large Australian Government department partnered with Modern 42 to overhaul its identity infrastructure and strengthen its cyber security posture.

Industry
Federal Government
Sector
Government Services
Engagement Type
Strategic Advisory, Architecture and Design, Engineering
Technologies
Microsoft Entra ID, Apporetum, CyberArk
Frameworks
ASD Essential Eight, ASD ISM, Zero Trust Architecture
Duration
Multi-year (ongoing)

Tags: Federal Government, IAM Strategy, Privileged Access Management, Zero Trust, Cloud IAM, Entra ID, Essential Eight, DevOps, Event-Driven Architecture

The Situation

This department delivers essential services to a broad Australian community. Its identity and access management (IAM) environment had grown organically over many years, creating a complex web of legacy systems, fragmented processes and inconsistent access controls. The department recognised that a comprehensive evaluation of its IAM capability was essential. Without a clear understanding of its current posture, it could not chart a path toward a modern, cloud-native identity platform. At the same time, the department was establishing new shared infrastructure and needed assurance that its privileged access controls met the required security standards. Internal reviews had identified gaps in how privileged access was being governed, adding urgency to the initiative.

What We Did

Strategy and Architecture

We conducted a thorough current state analysis, benchmarking IAM maturity against our proprietary IAM Capability Model. From this assessment, we developed the IAM Strategy, Roadmap, Target Architecture and High-Level Design, giving the department a clear, sequenced plan for transformation.

Privileged Access Management

We designed the PAM Blueprint, defined use cases and delivered a prioritised implementation plan, directly addressing review findings and securing the shared infrastructure environment.

Zero Trust and Network Security

We led a Zero Trust Network Architecture Proof of Concept, validating the approach for integration into the department's broader security posture.

Platform Engineering

We designed and built a new cloud-native Identity and Access Management platform to replace the legacy Microsoft Identity Manager. This included deploying Apporetum Access Manager into production and transitioning it into service. The new platform leverages event-driven architecture with microservices, with all deployments managed through DevOps CI/CD pipelines.

Additional Deliverables

Stabilisation of critical legacy Active Directory infrastructure. Security advisory for privileged access in response to internal review findings. Security classification uplift for the department's network. Uplift of Microsoft Entra capabilities to reduce reliance on on-premises Active Directory.

The Outcome

The department now operates a contemporary cloud-based identity solution built on Microsoft Entra ID, supported by automated provisioning, modern access governance, and a fully defined service design. Identity data remediation and migration activities are actively progressing. What began as a strategic advisory engagement has evolved into a deep, multi-year partnership spanning strategy through to engineering, with Modern 42 continuing to deliver across the department's IAM and Cyber Uplift program.

Key Wins

  • Delivered end-to-end IAM Strategy, Architecture and Roadmap aligned to ASD ISM and Essential Eight
  • Addressed privileged access findings with a comprehensive PAM Blueprint and implementation plan
  • Successfully deployed and transitioned a cloud-native identity platform into production
  • Validated Zero Trust Network Architecture through a successful Proof of Concept
  • Supported security classification uplift for the department's network
  • Automated IAM capabilities across multiple environments and Azure tenants using CI/CD pipelines

Case Study 02: Building a Modern IAM Practice for a Leading Australian University

A leading Australian research university partnered with Modern 42 over multiple years to establish a world-class Identity and Access Management capability from the ground up.

Industry
Higher Education
Sector
Research University
Engagement Type
Strategic Advisory, Architecture and Design, Engineering
Technologies
Microsoft Entra ID (Azure AD), Delinea
Frameworks
ASD Essential Eight, NIST Cybersecurity Framework
Duration
Multi-year

Tags: Higher Education, IAM Strategy, Cloud Migration, PAM, MFA Rollout, Access Governance, AD FS Decommission, Blended Team

The Situation

This university launched an ambitious Cyber Security program to modernise its identity infrastructure. Legacy systems presented significant challenges: security vulnerabilities, outdated authentication protocols, and no centralised access governance. As a major research institution, the university manages a vast digital ecosystem with hundreds of thousands of external users (students, researchers, industry partners) who interact with its systems daily. The university needed a long-term partner who could work side-by-side with its internal IAM Operations team to guide the transformation from legacy, on-premises identity services to a secure, cloud-native capability.

What We Did

Strategy and Governance

We defined the IAM Strategy and Roadmap, establishing the vision and sequenced plan for the university's identity transformation. We consulted on policy and controls to ensure the framework was fit for purpose in a complex academic environment.

Architecture and Design

We developed IAM architecture patterns and target state designs, then delivered the Azure AD design and implementation that became the foundation of the university's modern identity platform.

Security Uplift

We identified and mitigated security vulnerabilities in legacy IAM services, executed an Active Directory security uplift, and delivered Privileged Access Management service design and implementation to protect tier-zero accounts.

Cloud Migration

We migrated applications from legacy authentication protocols (such as AD FS) to modern standards including OAuth and OpenID Connect in the cloud. We developed and executed the AD FS decommissioning strategy, eliminating a major source of technical debt and security risk.

Access Governance and MFA

We established a comprehensive Access Management and Governance capability, conducted data normalisation and User Access Reviews, and delivered MFA reporting and rollout across faculty and students.

The Outcome

Over the course of the engagement, the university achieved a fundamental transformation of its identity and access management capability. The results included stronger security posture through vulnerability remediation, modern authentication protocols and organisation-wide MFA. Streamlined user experience with centralised access management replacing fragmented legacy processes. Scalable, cloud-native infrastructure enabling the university to adapt its identity platform as its needs evolve. Embedded internal capability through five years of knowledge sharing in a blended team model. The multi-year partnership spanned IAM, Cyber Uplift and Cloud Transformation programs.

Key Wins

  • Multi-year strategic partnership delivering IAM transformation across strategy, architecture and engineering
  • Successfully migrated authentication to modern cloud protocols (OAuth, OpenID Connect) and decommissioned AD FS
  • Deployed Privileged Access Management to secure tier-zero accounts and critical infrastructure
  • Rolled out MFA across faculty and student populations
  • Reduced operational costs through cloud-native, evergreen IAM infrastructure
  • Built sustainable internal IAM capability through a blended team delivery model

Case Study 03: Defining the Digital Identity Blueprint for a Major Australian Bank

A well-established Australian community bank undergoing a significant digital transformation engaged Modern 42 to architect its future-state identity capability, ensuring its digital ecosystem could securely serve customers, employees and partners.

Industry
Financial Services
Sector
Banking (Community and Retail)
Engagement Type
Strategic Advisory, Architecture and Design
Technologies
Product-agnostic (architecture-led)
Frameworks
APRA CPS 234, ASD Essential Eight

Tags: Financial Services, Banking, CIAM, Digital Transformation, Cyber Strategy, IAM Strategy, Architecture

The Situation

This bank was in the midst of a complex digital transformation. Like any financial institution, its ICT ecosystem is layered with both legacy and modern components. As the bank moved toward a "Digital Front Door" model, identity became the critical enabler. Every customer, employee and partner interacting with the bank's digital channels needed to be known, verified and appropriately governed. The bank needed strategic advisory services to define how digital identities would be managed and transitioned as part of this broader transformation.

What We Did

IAM Enterprise Architecture

Modern 42 provided IAM Enterprise Architecture leadership to guide the bank's identity strategy across its interconnected digital initiatives.

Key Deliverables

Customer IAM (CIAM) Reference Architecture establishing the foundational patterns for external identity management. CIAM Target Architecture defining the future-state design for customer-facing identity services. Digital On-Boarding Strategy ensuring frictionless, secure customer acquisition through digital channels. Cyber Strategy aligned to the bank's regulatory obligations and risk appetite. IAM Strategy covering the full identity lifecycle across workforce and customer populations. Network Security Architecture supporting the bank's shift to modern connectivity patterns. Technology Blueprint for the Digital Front Door tying identity into the broader digital experience.

The Outcome

Modern 42 successfully brought stakeholders from across multiple transformation initiatives into alignment. We achieved consensus on the business requirements for digital identity management and defined a clear path from the bank's current state (a mix of legacy and bespoke systems) to a modern, standards-based capability that will serve the institution well into the future.

Key Wins

  • Unified identity strategy across a complex, multi-initiative digital transformation program
  • Delivered seven interconnected architecture and strategy artefacts in a single engagement
  • Achieved cross-stakeholder alignment on digital identity direction
  • Client testimonial: recognised as providing industry-leading enterprise architecture expertise in the identity space

Case Study 04: Modernising Cloud Identity for a Federal Government Agency

An Australian Government agency modernising its operating environment partnered with Modern 42 to consolidate and modernise its identity systems.

Industry
Federal Government
Sector
Government Services
Engagement Type
Strategic Advisory, Architecture and Design, Engineering
Technologies
Microsoft Entra ID (Azure AD)
Frameworks
ASD Essential Eight, ASD ISM

Tags: Federal Government, Cloud Migration, IAM Strategy, Azure AD, Application Migration, Modern Authentication

The Situation

This agency launched a Cyber Security program that included a project to consolidate and modernise its Identity and Access Management systems. It needed a modern IAM solution capable of supporting cloud-based workloads and the transformation of existing digital services.

What We Did

Phase One

Focused on current state review, future state architecture, and an application migration stream to deliver organisational outcomes and reduce cyber risk quickly. Modern 42 consultants worked closely with the agency's technical, architecture, security and cloud project teams.

Phase Two

Expanded to address the broader strategy and roadmap for identity lifecycle management, while delivering tactical "quick wins" through deployment of solutions to meet known business goals.

Key Deliverables

IAM Strategy and Roadmap setting the direction for the identity transformation. Overarching architecture, solution design, deployment and security patterns for the Azure AD implementation. Policy and controls guidance ensuring alignment with government security standards. Application migration to cloud, moving applications to Microsoft Azure AD with modern authentication protocols. Authentication handler uplift across various software stacks to support modern protocols.

The Outcome

The agency successfully transitioned from legacy, fragmented identity services to a modern, cloud-native IAM capability built on Microsoft Azure AD. The phased approach ensured that high-priority applications were migrated first, delivering security improvements and reduced cyber risk early in the program, while the longer-term identity lifecycle management strategy was developed in parallel.

Key Wins

  • Delivered a phased transformation that balanced quick wins with long-term strategic outcomes
  • Migrated applications to modern authentication protocols, reducing the agency's attack surface
  • Provided a team of four specialists embedded with the agency's own teams for seamless delivery
  • Established the IAM foundation for the agency's cloud modernisation program

Case Study 05: Migrating 3,300+ Devices to Cloud-Native Management for a Global Automotive Brand

The Australian subsidiary of a global automotive manufacturer engaged Modern 42 to accelerate its modern management journey, shifting device management entirely to the cloud while keeping employees productive, connected and secure.

Industry
Automotive
Sector
Corporate Operations
Engagement Type
Strategic Advisory, Engineering
Technologies
Microsoft Intune, Microsoft EMS, Azure AD, Conditional Access, MFA, SSPR, Microsoft Information Protection
Frameworks
ASD Essential Eight

Tags: Automotive, Device Management, Cloud Migration, Microsoft Intune, Endpoint Security, Application Packaging, Managed Service Transition

The Situation

This organisation was looking to accelerate its Modern Management journey by moving device management into a full cloud solution. The challenge was significant: the existing environment relied on traditional on-premises management (SCCM), with over 125 applications to consider, approximately 2,000 laptops and desktops, and more than 1,300 mobile devices. The organisation needed a partner who could not only design and deliver the cloud-first solution but also ensure it could be smoothly transitioned to their incumbent Managed Service Provider for ongoing operations.

What We Did

Platform Design and Deployment

We designed and delivered a solution leveraging Microsoft's cloud-native toolset: Microsoft Enterprise Mobility + Security (EMS), Microsoft Intune, Azure Active Directory with Conditional Access, MFA and Self-Service Password Reset, Microsoft Information Protection, and the Microsoft Store for Business / Company Portal.

Application Packaging and Deployment

We completed discovery, analysis and packaging of over 125 applications for cloud-native deployment, then removed SCCM from all devices.

Service Transition

We defined all Standard Operating Procedures (SOPs) and performed comprehensive knowledge transfer to the incumbent Managed Service Provider, ensuring a clean handover into BAU operations.

The Outcome

Modern 42 successfully migrated the management of approximately 2,000 laptops/desktops and over 1,300 mobile devices to the cloud. The solution reduced complexity by using native tools and processes to reach target state. With the legacy technology stack removed, the organisation eliminated double-run costs associated with maintaining both legacy and modern platforms. The clean transition to the incumbent MSP ensured simplified, sustainable support from day one.

Key Wins

  • Migrated 3,300+ devices to cloud-native management, eliminating the on-premises management footprint
  • Packaged and deployed 125+ applications for cloud-native delivery
  • Eliminated double-run costs by decommissioning the legacy management stack
  • Delivered complete SOPs and knowledge transfer for a seamless MSP transition
  • Won the engagement through a competitive tender process

Case Study 06: Comprehensive Entra Security Review and Ongoing Partnership with a Global Financial Services Group

A global financial services group operating across multiple international markets engaged Modern 42 for an independent security review of its Microsoft Entra environment. What began as a focused assessment has since evolved into a strategic, ongoing partnership.

Industry
Financial Services
Sector
Global Banking, Asset Management, Wealth Management
Engagement Type
Strategic Advisory, Architecture and Design, Engineering
Technologies
Microsoft Entra ID, M365, Conditional Access, Azure AD Connect
Frameworks
ASD Essential Eight, APRA CPS 234, NIST Cybersecurity Framework

Tags: Financial Services, Security Assessment, Entra ID, Conditional Access, M365 Security, Authentication Uplift, Blended Team, External Partner Channel

The Situation

This organisation, a major global financial services group, required an independent and detailed security review of its Azure Active Directory (now Microsoft Entra ID) environment. The assessment needed to cover platform-level configurations, application security, access controls and synchronisation settings. Additionally, previous findings in their on-premises Active Directory required validation and remediation.

What We Did

Security Assessment

Modern 42 conducted a comprehensive security assessment of the Entra environment, evaluating platform-level security configuration, application configuration, Role Based Access Control (RBAC), Conditional Access policies, activity logging and monitoring, MFA configuration, AAD Sync configuration, guest account usage, and Graph API usage. We also validated and remediated previous Active Directory findings that had been captured in the organisation's risk register.

Conditional Access Framework

Following the assessment, we remediated Conditional Access policies and documented a CA Policy Framework for the organisation. We continue to provide ongoing support to the BAU team in maturing and implementing this framework.

M365 Security Assessment

We were subsequently engaged to deliver an M365 Security Assessment covering Office 365, Exchange Online, SharePoint Online, OneDrive for Business, Teams and M365 Defender. This report provided detailed findings and tailored recommendations for each platform.

Ongoing Partnership

The engagement has evolved into a strategic partnership, with Modern 42 resources now embedded in the organisation's Authentication project and Directory Services BAU team as a blended team. We are also leading the Blueprint, technical design and Proof of Concept for the External Partner Channel project.

The Outcome

Modern 42 delivered a detailed findings report with actionable recommendations, each with a proposed response priority, enabling the organisation to focus remediation efforts where they would have the greatest impact. The initial assessment engagement has grown into a deep, ongoing partnership. Modern 42 continues to provide Entra Engineers and Architects supporting both project and BAU activities across the organisation.

Key Wins

  • Delivered independent security assessments across both Entra ID and the full M365 suite
  • Designed and documented a Conditional Access Policy Framework now in active use
  • Remediated Active Directory findings from the organisation's risk register
  • Evolved from a single assessment into an ongoing blended team partnership
  • Leading the design and Proof of Concept for a new External Partner Channel capability
  • Embedded engineers and architects supporting both project delivery and BAU operations

Case Study 07: Deploying Privileged Access Management for a Metropolitan Council

A metropolitan local government authority engaged Modern 42 to design and implement a Privileged Access Management solution, securing critical infrastructure and reducing operational risk across its environment.

Industry
Local Government
Sector
Municipal Services
Engagement Type
Engineering
Technologies
BeyondTrust Password Safe, BeyondTrust Privileged Remote Access
Frameworks
ASD Essential Eight (Restrict Administrative Privileges)

Tags: Local Government, PAM, BeyondTrust, Privileged Access, Vendor Access Management, Essential Eight

The Situation

This council was looking to reduce operational risk and secure its critical infrastructure by restricting administrative privileges, ensuring privileged sessions were initiated securely, and putting appropriate monitoring in place for privileged activities. At the same time, the council needed a solution that could be fully documented and transferred to its internal technical team for ongoing management.

What We Did

Design and Deployment

Modern 42 worked directly with council staff to understand the environment and business requirements, then designed and deployed a BeyondTrust solution tailored to those needs. We delivered environment and business requirements analysis, detailed design of the BeyondTrust solution (Password Safe and Privileged Remote Access), implementation in accordance with the approved design, as-built documentation, and handover to internal technical staff including Standard Operating Procedures and knowledge transfer.

The Outcome

Modern 42 successfully deployed and transitioned a BeyondTrust PAM capability (Password Safe and Privileged Remote Access) into production service for the council. In a subsequent engagement, we extended the solution to cover vendor access management, migrating external vendors off a legacy Citrix solution. This delivered improved visibility and compliance around security controls for third-party access, while also reducing double-run costs.

Key Wins

  • Deployed BeyondTrust PAM solution aligned to ASD Essential Eight requirements for restricting administrative privileges
  • Complete knowledge transfer and SOPs enabled self-sufficient internal operations
  • Subsequent engagement extended PAM to vendor access, replacing a legacy Citrix solution
  • Improved compliance visibility and security controls for third-party privileged access
  • Reduced double-run costs through legacy platform decommission

Case Study 08: IAM Strategy and Roadmap for a State Government Organisation

A state government organisation engaged Modern 42 to assess its legacy IAM platform and chart a path forward.

Industry
State Government
Sector
Government Services
Engagement Type
Strategic Advisory, Architecture and Design
Technologies
Product-agnostic
Frameworks
ASD Essential Eight, Applicable government protective security frameworks

Tags: State Government, IAM Strategy, Roadmap, Current State Analysis, Government Services, Legacy Transformation

The Situation

This organisation's IAM platform had been in place for over a decade. It approached the market to find a partner who could conduct a gap analysis, understand the current state, define the future state, and formulate an IAM roadmap to guide the future direction of this critical service.

What We Did

Current State Analysis

We assessed the existing IAM environment against the Modern 42 IAM Capability Model, producing a detailed set of findings alongside a placemat of pain points and pressure points impacting the organisation.

IAM Strategy

We reviewed the Corporate Strategy, IT Strategy, Cyber Strategy and future directions to define a target state for IAM that would deliver on organisational objectives while meeting the needs of the departments and agencies it serves.

IAM Roadmap

We developed a three-year roadmap of prioritised activities, specifically designed to deliver incremental value with measurable business objectives being met in each six-month period.

The Outcome

The organisation received a comprehensive view of its IAM capability, clear advice on where it needed to be to deliver on strategic objectives, and a practical, sequenced plan to get there.

Key Wins

  • Delivered a complete IAM current state assessment, strategy and three-year roadmap
  • Product-agnostic approach ensured unbiased, best-fit recommendations
  • Roadmap structured around six-month value increments, enabling progressive business case justification
  • Assessed against a proven IAM Capability Model, providing an objective benchmark

Case Study 09: Delivering a CIAM Capability on Entra External ID for a State Government Organisation

A state government organisation partnered with Modern 42 to rapidly deliver a Customer Identity and Access Management (CIAM) capability on Microsoft Entra External ID, enabling a critical departmental transition.

Industry
State Government
Sector
Government Services
Engagement Type
Strategic Advisory, Analysis and Service Design, Architecture and Design, Engineering and Development
Technologies
Microsoft Entra External ID, Apporetum
Frameworks
Applicable government protective security frameworks

Tags: State Government, CIAM, Entra External ID, Bespoke Development, Delegated Access, Government Transition, Rapid Delivery

The Situation

The state government required an urgent migration from a legacy, bespoke CIAM platform to support a departmental transition. The timeline was non-negotiable: the new capability had to be delivered within a fixed government deadline. The solution needed to support a closed community model (where only invited organisations could participate), self-service access management for external organisations, and seamless integration with existing government identity services.

What We Did

CIAM Platform Delivery

Modern 42 partnered with the ICT services provider to design, build and deploy the new CIAM capability on Microsoft Entra External ID, with Apporetum delivering delegated access management. The solution included out-of-the-box Sign Up and Sign In flows configured to meet the business requirements, bespoke web application development to support the closed community requirement, delegated access management via Apporetum deployed from the Microsoft Marketplace, B2B capability allowing business owners to seamlessly interact with reliant applications, and full service design covering processes, accountabilities and documentation for external customers, business owners and technical operators.

The Outcome

The organisation successfully migrated off the legacy CIAM channel to the new Entra External ID solution within the required deadline. The solution integrated tightly with other identity services and transitioned seamlessly to the BAU team for ongoing operations and maintenance.

Key Wins

  • Delivered a production CIAM capability within a fixed government deadline
  • Built a bespoke closed-community invitation model on top of Entra External ID
  • Deployed delegated access management via Apporetum from the Microsoft Marketplace
  • Full service design ensures long-term maintainability and readiness to adopt new CIAM features as they are released
  • Seamless transition into BAU operations

Case Study 10: End-to-End PAM Capability Uplift for a Major Australian Retail Property Group

A major Australian retail property group partnered with Modern 42 over multiple years to embed a mature Privileged Access Management capability.

Industry
Retail Property / Real Estate
Sector
Property Management
Engagement Type
Strategic Advisory, Analysis and Service Design, Architecture, Engineering
Technologies
BeyondTrust (PasswordSafe, Privileged Remote Access), Apporetum
Frameworks
ASD Essential Eight (Restrict Administrative Privileges)
Duration
Multi-year

Tags: Retail Property, PAM, BeyondTrust, Essential Eight, IAM Strategy, Access Reviews, Service Design, Vendor Access, Blended Team

The Situation

This organisation approached the market looking for an IAM partner to assist with policy uplift and IAM remediation planning. Modern 42 was the successful respondent and has since become the organisation's ongoing IAM Strategic Advisory and services partner. The initial engagement established the foundation: a current state analysis, IAM strategy definition and a comprehensive three-year roadmap. The roadmap identified Privileged Access Management as the highest-priority uplift, leading to a full end-to-end PAM program.

What We Did

Assessment and Strategy

IAM Current State Analysis against the Modern 42 IAM Capability Model. IAM Strategy definition aligned to overarching ICT and Cyber strategies. Three-year roadmap with actionable work packages prioritised by risk and business value. IAM Policy Uplift and Monitoring Uplift. IAM Audit Response and Improvement Plan.

PAM Program Delivery

PAM Blueprint and Platform Options Analysis (impartially assessed against three market-leading vendors). PAM Discovery and remediation of existing privileged access. PAM Service Design and Process Design and Implementation. PAM Architecture and Design. PAM Solution Deployment (BeyondTrust PasswordSafe and Privileged Remote Access). PAM onboarding of core infrastructure and business-critical applications.

Access Governance

IAM Business Rules and Service Design. Access Review of 24 critical applications. Access Review of third-party vendor access.

The Outcome

The organisation has embedded an organisational PAM capability encompassing people, process and technology, aligned to the ASD Essential Eight. Privileged access is now governed through defined rules and processes, supported by tooling that secures core infrastructure and critical applications. The PAM capability was deployed with full documentation, including service design, standard operating procedures and operational guides, ensuring long-term sustainability. Modern 42 continues as the organisation's IAM partner, now supporting the next phase: Identity Governance and Administration platform implementation and capability rollout.

Key Wins

  • Multi-year strategic partnership evolving from initial assessment to full capability delivery
  • PAM capability deployed and aligned to ASD Essential Eight requirements
  • Impartial vendor assessment across three market-leading PAM platforms ensured best-fit selection
  • Privileged access governance embedded across people, process and technology
  • Completed access reviews of 24 critical applications and third-party vendor access
  • Ongoing partnership now extending into Identity Governance and Administration

Case Study 11: Identity Governance and Administration Uplift for a Major Retail Property Group

Continuing its IAM transformation journey, a major Australian retail property group engaged Modern 42 to define its Identity Governance and Administration (IGA) capability, laying the groundwork for automated identity lifecycle management.

Industry
Retail Property / Real Estate
Sector
Property Management
Engagement Type
Strategic Advisory, Analysis and Service Design, Architecture
Technologies
Product-agnostic (market scan phase)
Frameworks
ASD Essential Eight, NIST SP 800-63

Tags: Retail Property, IGA, Identity Governance, JML Processes, Service Design, Market Scan, IAM Uplift

The Situation

Having successfully embedded a PAM capability, the organisation's attention turned to the broader identity lifecycle. Manual processes for managing joiners, movers and leavers (JML) were creating governance gaps, and the organisation needed a structured approach to defining its target-state IGA capability.

What We Did

IAM Service Design

We defined the high-level components across people, process and technology required to support and operate the organisation's Identity and Access Management target state.

IAM Processes and Business Rules

We documented detailed JML processes, business rules (covering account lifecycle events such as inactivity and orphaned accounts) and governance rules to ensure consistent, auditable identity management.

IGA Market Scan and Recommendation

We conducted a detailed market scan of Identity Governance and Administration solutions, evaluated against a defined set of requirements, and delivered a recommendation to guide platform selection.

The Outcome

The organisation has commenced its IGA uplift journey and continues to enhance capability across all pillars of people, process and technology. Modern 42 remains the identity partner for this ongoing program of work.

Key Wins

  • Defined the complete IAM Service Design covering people, process and technology
  • Documented JML processes and governance rules to enforce consistent identity lifecycle management
  • Delivered an independent IGA market scan with structured requirements and vendor recommendations
  • Ongoing partnership continues as the organisation moves into IGA platform implementation

Case Study 12: IAM Strategic Advisory and Data-Driven Access Reviews for a Federal Government Authority

An Australian Government statutory authority engaged Modern 42 to review its workforce identity capability and develop a prioritised uplift plan, supported by data-driven access insights.

Industry
Federal Government
Sector
Government Services
Engagement Type
Strategic Advisory, Architecture and Design
Technologies
Apporetum
Frameworks
ASD Essential Eight, ASD ISM

Tags: Federal Government, IAM Strategy, Access Reviews, Apporetum, Data-Driven Insights, Roadmap

The Situation

This authority went to market for a comprehensive review of its workforce Identity and Access Management capability. The objectives were clear: assess the current state, define target-state requirements, prepare an options paper with a prioritised implementation plan, and undertake access reviews of critical applications to understand whether access was being appropriately managed.

What We Did

Current State Analysis

We assessed the authority's IAM posture against the Modern 42 IAM Capability Model, identifying findings, pain points and pressure points requiring attention.

IAM Requirements

We reviewed the Corporate Strategy, IT Strategy, Cyber Strategy and future directions to define target-state requirements aligned to organisational objectives.

IAM Options Paper

We developed a three-year implementation plan designed to deliver incremental value, with business objectives met in each six-month period, along with resource and dependency mapping.

Access Reviews

Using Apporetum, we conducted access reviews across critical applications, providing data-driven insight into how effectively access was being managed against policy.

The Outcome

Modern 42 provided the authority with a comprehensive view of its IAM current state and a clear plan for uplift. The data-driven access insights proved particularly valuable, enabling the authority to prioritise areas where cyber risk could be addressed early through targeted process improvements.

Key Wins

  • Delivered a complete IAM current state assessment, requirements definition and implementation plan
  • Conducted access reviews across critical applications using Apporetum
  • Data-driven insights directly informed roadmap prioritisation, identifying quick-win opportunities for risk reduction
  • Roadmap structured in six-month increments for progressive value delivery

Case Study 13: Data-Driven IAM Discovery and Planning for a Major Healthcare Provider

A large Australian healthcare provider with international operations engaged Modern 42 to conduct a data-driven discovery of its identity landscape and develop a practical implementation plan.

Industry
Healthcare
Sector
Healthcare Services
Engagement Type
Strategic Advisory, Architecture and Design
Technologies
Apporetum
Frameworks
ASD Essential Eight, Australian Privacy Principles

Tags: Healthcare, IAM Discovery, Access Reviews, Apporetum, Data-Driven Insights, Identity Correlation, Multi-Division

The Situation

This healthcare organisation had already developed strong IAM and Cyber Strategies. What it lacked was a data-driven understanding of its current state and a practical plan to move from where it was to where it needed to be. With operations spanning multiple divisions and international locations, the identity ecosystem was complex and distributed. The organisation wanted to let the data tell the story, requiring a significant assessment of identity data quality and access patterns across its systems.

What We Did

Current State Assessment

We assessed the organisation against the Modern 42 IAM Capability Model, producing findings and a placemat of pain points and pressure points requiring attention.

Identity Correlation Discovery

Using Apporetum, we performed identity correlation between the HR Source of Truth and identity data in target directories. This revealed data quality issues and process gaps, giving the organisation objective evidence of where its identity management was falling short.

Access Discovery Reports (30 Critical Applications)

We conducted access reviews across 30 critical applications spanning multiple operating divisions, providing insight into how well access was being managed against policy.

IAM Implementation Plan

We developed a prioritised implementation plan structured around six-month value increments, informed directly by the data insights to ensure the most impactful issues were addressed first.

The Outcome

The data-driven approach gave the organisation valuable intelligence about what was actually happening in its identity systems, rather than what was assumed to be happening. Processes that were clearly broken or missing were identified and prioritised for remediation. This is an ongoing engagement, with Modern 42 now delivering against the implementation plan.

Key Wins

  • Data-driven discovery approach revealed the true state of identity management across multiple operating divisions
  • Identity correlation analysis identified data quality gaps between HR and directory systems
  • Completed access reviews across 30 critical applications
  • Implementation plan directly informed by data insights, ensuring highest-risk items are addressed first
  • Ongoing partnership progressing from discovery into active implementation

Case Study 14: PAM Implementation and Essential Eight Uplift for an Australian Research University

A leading Australian research university engaged Modern 42 to expand its Privileged Access Management capability and progress toward ASD Essential Eight Maturity Level 2.5.

Industry
Higher Education
Sector
Research University
Engagement Type
Analysis and Service Design, Architecture and Design, Engineering and Development
Technologies
BeyondTrust Password Safe, BeyondTrust Secret Safe (migrated from Delinea Secret Server)
Frameworks
ASD Essential Eight (targeting Maturity Level 2.5)

Tags: Higher Education, PAM, BeyondTrust, Essential Eight, Credential Migration, Service Design, Change Management, Blended Team

The Situation

This university sought to expand its PAM capability by implementing BeyondTrust Privileged Account and Session Management (PASM). The objectives were to strengthen governance, enforce privileged access controls and streamline credential management, all supporting progress toward Essential Eight Maturity Level 2.5. While the technical scope was well defined, the broader challenge lay in navigating a complex environment of distinct teams, inconsistent practices and varied organisational readiness. Success required close collaboration, flexibility and hands-on support throughout the implementation.

What We Did

Credential Migration

We migrated secrets from the existing Delinea Secret Server to BeyondTrust Secret Safe, then transitioned into BeyondTrust Password Safe to support greater maturity and control over privileged credentials.

Platform Configuration and Onboarding

We configured Password Safe, onboarded privileged assets, and uplifted associated business processes and governance to ensure successful adoption across the university.

Service Design

We completed a PAM service design defining key people, process and technology components, along with standard operating procedures aligned to the university's Essential Eight Maturity Level 2.5 target state.

Training, Support and Change Management

We provided training and augmented BAU support through a blended delivery model, ensuring internal teams could sustain the capability independently. We partnered with the university's Change Management team to support communication, engagement and user readiness throughout the program.

The Outcome

The engagement delivered several key outcomes: successful migration from the legacy password vault, matured credential management within BeyondTrust Password Safe, and a tailored service design aligned to Essential Eight controls supporting progress toward Maturity Level 2.5. The program also built strong working relationships across business and technical teams, establishing the foundation for continued PAM maturity through an ongoing augmented support model.

Key Wins

  • Successfully migrated from Delinea Secret Server to BeyondTrust Password Safe
  • PAM service design aligned to ASD Essential Eight Maturity Level 2.5 target
  • Partnered with the university's Change Management team to drive adoption
  • Blended delivery model ensures sustainable internal capability
  • Laid the foundation for ongoing PAM maturity and future collaboration

Case Study 15: IAM Strategy, Conditional Access Uplift and CIAM Blueprint for a National Health Services Organisation

A national health services organisation, designated as critical infrastructure, engaged Modern 42 to define its IAM strategy and deliver targeted security uplifts across its broad identity ecosystem.

Industry
Healthcare / Health Services
Sector
National Health Services
Engagement Type
Strategic Advisory, Analysis and Service Design, Architecture and Design, Engineering and Development
Technologies
Microsoft Entra ID, Apporetum
Frameworks
ASD Essential Eight, SOCI Act (Critical Infrastructure)

Tags: Healthcare, Critical Infrastructure, IAM Strategy, Conditional Access, CIAM Blueprint, Apporetum, Entra ID, Data-Driven Insights, Roadmap

The Situation

This organisation had undergone significant change: the introduction of remote hybrid working, adoption of SaaS-based applications, and a shift in strategic business focus. These changes highlighted the need for an effective, mature Identity and Access Management strategy covering all areas of identity. The organisation commissioned a strategy to support future business objectives, reduce technology and business risk, and establish appropriate governance. With a broad range of identity types across an extensive ecosystem, the challenge was both strategic and technical.

What We Did

Current State Analysis

We assessed the organisation's IAM posture against the Modern 42 IAM Capability Model, identifying findings and a placemat of pain points and pressure points.

IAM Data-Driven Insight

Using Apporetum, we deployed data insights and reporting capability to validate the effectiveness of current IAM tooling in managing accounts and entitlements against the Information Security Policy. This provided a baseline for improvement and targeted recommendations for process and tooling uplifts.

IAM Strategy and Roadmap

We reviewed the Corporate Strategy, IT Strategy, Cyber Strategy and future directions to define a target state for IAM aligned to organisational objectives. We developed a three-year roadmap structured in six-month increments, designed to deliver progressive value with clear business objectives at each stage.

Conditional Access and CIAM

We delivered a Conditional Access Policy Assessment and Uplift, and developed a CIAM Blueprint to guide the organisation's approach to external identity management.

The Outcome

The organisation now has a clear IAM strategy aligned to its business objectives, a practical roadmap for execution, and data-driven insights that inform prioritisation. The Conditional Access uplift has strengthened its security posture, and the CIAM Blueprint provides a foundation for managing external identities at scale. Modern 42 continues to partner with the organisation as it progresses through its IAM transformation roadmap.

Key Wins

  • Delivered comprehensive IAM strategy and three-year roadmap for a national critical infrastructure organisation
  • Data-driven insights via Apporetum validated and informed the transformation approach
  • Conditional Access uplift strengthened the organisation's security posture
  • CIAM Blueprint established the foundation for external identity management
  • Ongoing partnership progressing through the transformation roadmap

Facing a similar challenge?

Whether you are preparing for an audit, planning an IAM programme, or replacing a legacy PAM platform, we have done it before. Let us talk about your situation.

We use cookies

We use cookies and similar technologies to help personalise content, measure the performance of our site, and provide a better experience. By clicking Accept, you consent to the use of all cookies.
Learn more.