Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Microsoft Entra

Microsoft Entra: secure identity & access management for your company

We implement and operate Microsoft Entra in full: Conditional Access, MFA, Privileged Identity Management and Entra ID Governance. As a Microsoft Solutions Partner for Security.

Book a consultation
Man and woman sit outdoors on a terrace looking together at a laptop.
Vorteile

Why companies entrust us with their identity and access infrastructure.

Entra as a zero-trust foundation

We implement Microsoft Entra as the basis of your zero-trust strategy, aligned with Conditional Access, PIM and every other security layer of your environment.

01

Operational depth, not a one-off rollout

As a Solutions Partner for Security, we implement and operate Entra for Swiss SMEs: proven Conditional Access policies, PIM configurations and Entra ID Governance setups included.

02

Compliance as an integral part

We configure Entra so that data access is documented in a verifiable, audit-proof and FADP-compliant way, from the first user login to the administrator audit log.

03

Expertise

Unser Microsoft Entra Portfolio auf einen Blick.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M5.75 17.5C9.9491 21.1667 14.0509 21.1667 18.25 17.5" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M12.75 5.75V12.25C12.75 13.3546 11.8546 14.25 10.75 14.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M4.75 4.75V8.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M19.25 4.75V8.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Conditional Access & MFA

Microsoft Entra ID is the central identity platform for all your applications. Conditional Access defines who can access and under what conditions. MFA, as the most effective single measure against account takeovers, is seamlessly integrated.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M6.75 18.25H3.75V3.75H20.25V18.25H17.25M6.75 18.25V20.25M6.75 18.25H17.25M17.25 18.25V20.25M7.75 11C7.75 13.3472 9.65279 15.25 12 15.25C14.3472 15.25 16.25 13.3472 16.25 11C16.25 8.65279 14.3472 6.75 12 6.75C9.65279 6.75 7.75 8.65279 7.75 11ZM7.75 11H11.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Privileged Identity Management

Entra PIM replaces permanently assigned administrator rights with a Just-in-Time model. Elevated permissions are only activated when truly needed, complete with an approval workflow and a comprehensive audit log.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M11.75 20.2499L12.25 16.4999L17.4952 11.2547C18.4418 10.3081 19.9939 10.3677 20.865 11.3841C21.6465 12.2958 21.5943 13.6555 20.7452 14.5047L15.5 19.7499L11.75 20.2499Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M17 12.5L19.5 15" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M3.25 12C3.25 12.2518 3.26064 12.5012 3.28149 12.7476C3.54145 15.8198 5.38868 18.4397 8 19.7843M19.1816 7C17.6005 4.73314 14.9734 3.25 12 3.25C8.81314 3.25 6.02419 4.95371 4.49429 7.5" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M3.75 3.75V8.25H8.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Entra ID Governance

Entra ID Governance automates Access Reviews, lifecycle workflows, and entitlement management. When roles change or employees leave the company, access rights are automatically revoked.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M15.75 6.5C15.75 8.57107 14.0711 10.25 12 10.25C9.92893 10.25 8.25 8.57107 8.25 6.5C8.25 4.42893 9.92893 2.75 12 2.75C14.0711 2.75 15.75 4.42893 15.75 6.5Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M15 13.838C14.1006 13.4592 13.0928 13.25 12 13.25C7.8098 13.25 4.86894 16.3254 4.5 20.25H12.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M18.25 15.25V18.25M18.25 18.25V21.25M18.25 18.25H15.25M18.25 18.25H21.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Entra External ID

Secure guest user access for external employees, partners, and suppliers. Without additional accounts in your internal directory. You invite them, define their permissions, and retain control at all times.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M5.75 17.5C9.9491 21.1667 14.0509 21.1667 18.25 17.5" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M12.75 5.75V12.25C12.75 13.3546 11.8546 14.25 10.75 14.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M4.75 4.75V8.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M19.25 4.75V8.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Conditional Access & MFA

Microsoft Entra ID is the central identity platform for all your applications. Conditional Access defines who can access and under what conditions. MFA, as the most effective single measure against account takeovers, is seamlessly integrated.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M6.75 18.25H3.75V3.75H20.25V18.25H17.25M6.75 18.25V20.25M6.75 18.25H17.25M17.25 18.25V20.25M7.75 11C7.75 13.3472 9.65279 15.25 12 15.25C14.3472 15.25 16.25 13.3472 16.25 11C16.25 8.65279 14.3472 6.75 12 6.75C9.65279 6.75 7.75 8.65279 7.75 11ZM7.75 11H11.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Privileged Identity Management

Entra PIM replaces permanently assigned administrator rights with a Just-in-Time model. Elevated permissions are only activated when truly needed, complete with an approval workflow and a comprehensive audit log.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M11.75 20.2499L12.25 16.4999L17.4952 11.2547C18.4418 10.3081 19.9939 10.3677 20.865 11.3841C21.6465 12.2958 21.5943 13.6555 20.7452 14.5047L15.5 19.7499L11.75 20.2499Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M17 12.5L19.5 15" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M3.25 12C3.25 12.2518 3.26064 12.5012 3.28149 12.7476C3.54145 15.8198 5.38868 18.4397 8 19.7843M19.1816 7C17.6005 4.73314 14.9734 3.25 12 3.25C8.81314 3.25 6.02419 4.95371 4.49429 7.5" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M3.75 3.75V8.25H8.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Entra ID Governance

Entra ID Governance automates Access Reviews, lifecycle workflows, and entitlement management. When roles change or employees leave the company, access rights are automatically revoked.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M15.75 6.5C15.75 8.57107 14.0711 10.25 12 10.25C9.92893 10.25 8.25 8.57107 8.25 6.5C8.25 4.42893 9.92893 2.75 12 2.75C14.0711 2.75 15.75 4.42893 15.75 6.5Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M15 13.838C14.1006 13.4592 13.0928 13.25 12 13.25C7.8098 13.25 4.86894 16.3254 4.5 20.25H12.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M18.25 15.25V18.25M18.25 18.25V21.25M18.25 18.25H15.25M18.25 18.25H21.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Entra External ID

Secure guest user access for external employees, partners, and suppliers. Without additional accounts in your internal directory. You invite them, define their permissions, and retain control at all times.

Clients say

As a leading institution for international arbitration and mediation proceedings, we require an IT infrastructure with the highest security and availability. Baggenstos provided us with a modern, Microsoft-based solution that is very well tailored to our needs.

Korinna von Trotha

Executive Director, Swiss Arbitration Centre

Certified. Verified. Confirmed.

Baggenstos is a Microsoft Solutions Partner for Security with expertise in Identity, Endpoint and Cloud Security. This specialisation is audited and confirmed by Microsoft every year.

Microsoft Solutions Partner for Security certification logo

Microsoft Solutions Partner for Security

Certified for Identity, Endpoint, and Cloud Security, including the «Cloud Security» specialization. Proven on real-world projects across the Microsoft security stack.

Microsoft Solutions Partner certification logo

Microsoft Solutions Partner

Highest Microsoft Partner designation, re-certified annually. Baggenstos holds several Solutions Partner Designations.

Microsoft Solutions Partner for Security certification logo

Microsoft Solutions Partner for Security

Certified for Identity, Endpoint, and Cloud Security, including the «Cloud Security» specialization. Proven on real-world projects across the Microsoft security stack.

Microsoft Solutions Partner certification logo

Microsoft Solutions Partner

Highest Microsoft Partner designation, re-certified annually. Baggenstos holds several Solutions Partner Designations.

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund

Sounds like what you need?

Video

Conditional Access: managing access securely and conveniently

Why Baggenstos

Why Baggenstos Should Be Your Partner

60,000+

Microsoft 365 users in the Managed Service Program

1'000+

Cloud projects successfully implemented

Since 1925

100 years of continuity in family ownership

Zwei Mitarbeiter im Gespräch an einem Tisch mit Laptop vor begrünter Fensterfront im Büro

Holistic consulting

Identity and access management is not a single measure but part of your entire security strategy. We design zero-trust architectures that fit your operations.

Certified Microsoft excellence

As a Solutions Partner for Security, we implement Conditional Access, MFA and Privileged Identity Management at the level that Microsoft audits require.

Focus on security & compliance

Identity is the most important attack surface today. We secure it systematically: with Entra as the foundation, aligned with the FADP and industry requirements.

Guiding the change (change management)

Zero trust changes how employees access systems. We guide the introduction so that convenience is preserved and security increases.

FAQ

Frequently Asked Questions, Honest Answers

What does Microsoft Entra cost as a managed service?

Microsoft Entra ID is part of most Microsoft 365 licences, with a different feature scope depending on the plan. Additional features such as Privileged Identity Management or Entra ID Governance require Entra ID P2. The operating costs depend on the size of your environment and the scope you want. In an initial consultation we clarify licensing and operating model together and set everything out contractually.

What changes for our users with the update to Microsoft Entra?

For end users little changes: login with password plus MFA still works, and Microsoft 365 apps stay the same. Entra becomes visible through the new logo at login. Concrete improvements: single sign-on for more apps, faster password resets and passwordless login via Authenticator. The terminology only changes for IT.

What is Microsoft Entra Conditional Access and how does it protect against unauthorised access?

Conditional Access checks several criteria before every login: Who is accessing, from which device, from which location, with what risk? Only when all conditions are met does Entra grant access. A login from an unknown country is blocked or forces additional verification. A stolen password alone becomes worthless.

What is the difference between Azure Active Directory (Azure AD) and Microsoft Entra ID?

Functionally there is no difference: Microsoft renamed Azure Active Directory to Entra ID in 2023. All features, licences and configurations remain identical. The renaming is part of the Entra product family, which additionally includes Conditional Access, Privileged Identity Management and Entra Permissions. You do not need to change anything.

How does Microsoft Entra improve security through Zero Trust principles?

Zero Trust means: trust no one, verify everything. Entra checks every access individually based on identity, device, location and risk, regardless of the user's location. MFA, Conditional Access and Privileged Identity Management form the foundation of the Zero Trust architecture and replace the old perimeter model.

Does Microsoft Entra also support the management of identities in multi-cloud environments?

Yes. Entra is not only for Microsoft 365 and Azure: you can also connect AWS, Google Cloud and SaaS applications such as Salesforce or ServiceNow centrally via Entra. SSO, MFA and Conditional Access work across platforms. Entra Permissions Management gives you an overview of permissions across Azure, AWS and GCP.

Can we keep using our existing Active Directory?

Yes. Microsoft Entra Connect synchronizes your on-premises Active Directory with Microsoft Entra ID. Existing user accounts, groups and password policies are retained and transferred into the cloud identity solution. The transition works step by step and without interruption to day-to-day business. In the long term, you can decide whether to keep the local AD or migrate fully to Entra ID.

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund
Schedule an appointment now

When do we secure your identities with zero trust?

Let's define your access strategy together.