Red Queen Security
Services  /  Identity & Access Review
Service — No. 02 Google Workspace · Microsoft 365 · Cloud

Identity & Access Review

The keys to your kingdom are no longer a lock on a door — they're who can sign in, from where, and with what permission.

We audit your Google Workspace, Microsoft 365, or cloud environment and verify that your identity systems are properly secured — who has access to what, where multi-factor authentication is missing, and which forgotten admin accounts are quietly waiting to be exploited.

What's included

Every key, accounted for

A complete audit of who can get into your systems and what they can do once they're in — delivered as a prioritized, plain-language report your team can act on.

01

Workspace & tenant audit

A full inventory of your Google Workspace or Microsoft 365 environment — users, groups, shared mailboxes, external sharing, and the dormant accounts everyone forgot to deactivate.

02

Permissions & least privilege

We map who can access what and flag over-broad permissions — so every person and app holds exactly the access they need, and not a key more.

03

Multi-factor authentication

We find every account without MFA, prioritize the riskiest gaps, and give you a clear rollout plan — the single highest-impact control you can turn on.

04

Admin privilege review

Super-admin and global-admin accounts are the crown jewels. We review every one, remove what's unnecessary, and recommend break-glass and monitoring practices.

05

Dark web exposure monitoring

We search dark-web breach dumps, paste sites, and combolists for credentials tied to your domain — and flag every leaked account so you can force a reset before it's used against you.

How it works

A review in three moves

Week 1

Connect & collect

Read-only access to your environment. We gather configuration and access data — no disruption to your team, no agents to install.

Week 2

Analyze & prioritize

We translate findings into a ranked list — what's urgent, what's important, and what can wait — in plain language, not a 200-page scanner dump.

Week 3

Report & remediate

A working session to walk through the report together. We'll help you fix the critical items on the call, and leave you a roadmap for the rest.

Why it matters

80%

of breaches involve compromised or misused credentials

99%

of account-takeover attacks are blocked by enabling MFA

1 in 3

admin accounts sit unused — over-privileged and unmonitored

Sources — Verizon DBIR · Microsoft Security · CISA identity guidance

Dark web exposure

Already out there

Your team's passwords may have leaked in breaches you've never heard of. We search dark-web dumps, paste sites, and combolists for credentials tied to your domain — so you can force resets before an attacker logs in with them.

darkweb-monitor tweedale.co
0%
Searching · 0/5 sources
Breach corpus · 14.2B
Paste sites
Hacker forums
Combolists
Telegram dumps
Exposed credentials · 0
LinkedIn breach · 2021 plaintext · still valid
Collection #1 combolist SHA-1 hash · password reused
Dropbox breach · 2012 bcrypt · rotated since
Telegram dump · 2024 plaintext · still valid
The report

A report you can act on

You walk away with a prioritized findings report, a remediation roadmap, and a one-page summary for leadership — proof of exactly who holds the keys, and a plan to take back the spares.

Common questions

Straight answers about access, disruption, and what we touch.

Will this disrupt my team's access while you work?

No. The review is read-only — we collect configuration and access data without changing anything. You stay in full control of every change; we only recommend and, if you'd like, help you implement.

Do you support both Google Workspace and Microsoft 365?

Yes — both, plus common cloud platforms like AWS and Azure identity. If your environment is a mix, we audit them together and reconcile access across all of them.

What access do you need from us to start?

A scoped, read-only admin role for the duration of the review. We document exactly what we request and why, and you revoke it the moment we're done — no standing access, ever.

Get started

Find out who holds the keys

Book a free 30-minute consultation. We'll talk through your environment and where an access review would help most — no obligation.

Read-only — zero disruption to your team
Prioritized report within 2–3 weeks
Plain language, ranked by real risk