Infrastructure overhaul and managed IT support for a Melbourne marketing agency
This 35-person marketing company had worked with us for several years and already had a solid IT and security foundation. The attacks reaching them were becoming more targeted, arriving through compromised vendor accounts and from attackers based in Australia, and were getting past traditional controls. They wanted to align with higher cyber standards before one of those attacks landed. We hardened the environment with Intune device management, risk-based Conditional Access, passkeys for phishing-resistant MFA, and written policies to back the technical controls up.
The challenge
The company had made significant improvements to its IT systems and cybersecurity posture over several years of working with us. The attacks reaching them were changing, though. Phishing and impersonation attempts were increasingly targeted, arriving from the compromised accounts of real vendors the business dealt with, and from threat actors operating within Australia.
These attacks are hard to stop with traditional controls. An email from a genuine supplier account passes authentication checks, and an attacker signing in from an Australian IP address doesn’t trip geo-blocking.
Leadership wanted to align with higher cyber standards, close off the techniques these attacks rely on, and set clear expectations with staff about how technology is used.
What we did
Company-owned devices were brought fully under Microsoft Intune management, with BYOD enrolment for mobiles. We locked down which devices could access the business’s systems and from which locations, and secured the device registration process itself so an attacker can’t enrol their own device into the environment.
On identity, we deployed risk-based Conditional Access using Microsoft Entra ID P2, so risky sign-ins and risky users are challenged or blocked automatically based on signals like impossible travel, unfamiliar patterns and leaked credentials. Supporting applications were moved behind SAML authentication through Entra, so every app benefits from the same protections instead of maintaining its own weaker login.


The biggest single uplift was the migration to passkeys for phishing-resistant MFA. Unlike codes and push approvals, passkeys cannot be phished or relayed through a fake login page, which removes the technique most of these targeted attacks depend on. We also locked down enterprise browsers, controlling which profiles can sign in on company devices.
The uplift also included written policies for Cybersecurity, AI use, Acceptable Use, BYOD and Secure Information Handling. These come from our partnership with GuidedHR, a Melbourne-based team of HR experts, and are Australian-made policy templates aligned with the SMB1001 standard. They’re distributed and version-controlled through usecure, which also collects staff sign-offs, so every staff member has read and acknowledged them.
The results
The company’s security controls are significantly hardened against the targeted techniques that were getting through. A phished password is useless without a trusted device, and a fake login page has nothing to steal from a passkey.
Written policies set clear expectations with staff for security, AI and acceptable use, and the technical controls back those policies up.
Leadership now has considerable trust in the layered defences, and the business can keep growing safely on top of them.
Questions this project raised
Why isn’t standard MFA enough to stop phishing anymore?
Codes and push notifications can be phished. Modern attacks use fake login pages that relay your password and MFA code to the real site in real time, or bombard you with push prompts until you approve one. Passkeys close this off because the credential is bound to the legitimate website and your device, so there is nothing to type into a fake page and nothing to approve by mistake.
What is Microsoft Entra ID P2?
Entra ID P2 is the top tier of Microsoft’s identity platform, and its standout feature is Identity Protection. It scores every sign-in and every user for risk using signals like leaked credentials, unfamiliar locations and impossible travel, and those risk scores can then drive Conditional Access policies automatically, such as forcing a password reset for a risky user or blocking a risky sign-in outright. It’s included in Microsoft 365 E5 or available as an add-on, and for businesses facing targeted attacks it’s usually the most cost-effective step up.
What is Conditional Access?
Conditional Access is a Microsoft Entra capability that evaluates every sign-in against rules you define: who the user is, what device they’re on, where they’re signing in from, and how risky the attempt looks. Legitimate sign-ins pass through, while anything unusual is challenged or blocked. It turns identity into the security perimeter, which matters now that work happens well beyond the office network.
What IT policies should a business have in place?
Technical controls decide what staff can do, while policies set out what they should do, and collecting sign-offs makes the expectations shared rather than assumed. Aus Advantage supplies a full policy set to all managed services clients, aligned with SMB1001 Gold: a Cybersecurity Policy, IT Acceptable Usage Policy, Artificial Intelligence Policy, Bring Your Own Device Policy, Password and Authentication Policy, Secure Data Handling Policy, and Secure Remote Work Policy.
See how we have helped other businesses
Could your business run like this?
Tell us where your IT is at and we will tell you, plainly, whether we can help. A straight conversation with an onshore engineer, no obligation.