Skip to content
AI-accelerated delivery · You pay when it works
Plano, TX · Munich · HyderabadAccepting Q3 2026 briefs
All case studies →
Manufacturing / Identity and security

Customer identity and security operations, handed over

Customer identity and security operations were delivered as separate programs, followed by training for the customer engineering team to operate and extend them.

Organization
Global commercial vehicle manufacturer
Engagement period
2023 to 2025
Delivery stage
Delivered programs with team enablement
At a glance
  • Customer identity delivered in five weeks
  • Security operations delivered in four weeks
  • Customer engineers trained for independent operation
Inside the implementation

Architecture overview

The engagement had two delivery tracks. Customer identity established authentication and application integration. Security operations combined detection logic with automated response workflows.

Track 1: customer identity

  1. 01

    Authentication context

    Customer authentication and federation requirements.

    • Customer sign-in
    • Federated identity

    Next: Identity flow

  2. 02

    Custom identity policies

    The policy layer shapes the authentication experience.

    • Azure AD B2C
    • Identity Experience Framework
    • Claims transformation

    Next: Identity and claims

  3. 03

    Application integration

    The identity program connects the flows to customer applications.

    • Integrated authentication flows
    • Application identity context

Track 2: security operations

  1. 01

    Security analytics

    Security operations capabilities within Sentinel.

    • Microsoft Sentinel
    • KQL analytics

    Next: Detection logic

  2. 02

    Detection rules

    Analytics support the defined detections.

    • Detection rules
    • Response workflow definitions

    Next: Response workflow

  3. 03

    Automated response

    Playbooks support the response operations.

    • Azure Logic Apps
    • Automated response workflows

Separate program scopes

Identity was delivered in five weeks. Security operations was delivered in four weeks. Each track had its own implementation scope.

Customer-team ownership

Training covered independent operation and extension of both platforms after delivery.

Logical view of the documented architecture. Client-specific infrastructure and identifiers are omitted.

The challenge

The customer needed application-integrated identity flows and security operations capabilities, with an engineering team able to own the platforms after delivery.

Design identity around the application flows

The customer identity program used Azure AD B2C custom policies and Identity Experience Framework. The implementation covered authentication flows, claims transformation, and federation, together with application integration.

Custom policies defined the identity behavior needed by the applications. Claims transformation and federation formed part of the implementation rather than being left as separate downstream integration tasks.

Build the security operations workflows

A separate Microsoft Sentinel program established security operations capabilities with KQL analytics and detection rules. Automated response workflows used Logic Apps playbooks.

The engagement covered both the detection logic and the response workflow. Those were delivered as operational capabilities for the customer team, not simply a set of platform recommendations.

Keep delivery milestones specific

The Azure AD B2C program was delivered in five weeks. The Microsoft Sentinel program was delivered in four weeks. Each program had its own delivery scope.

The case describes the technologies used during the engagement. It does not imply that the same identity product or delivery duration is the default choice for every new implementation.

Give the engineering team ownership

After delivery, the customer engineering teams were trained to operate and extend both platforms independently. Enablement was part of the engagement, alongside the platform implementation.

That handover connected the initial delivery to ongoing ownership. The customer team could operate and extend the platforms independently after the initial delivery.

Key design decisions

Make identity behavior explicit in policy

Custom policies and Identity Experience Framework supported authentication flows, claims transformation, and federation. Application integration was part of that program.

Connect detection to a response workflow

The security operations program included KQL analytics and detection rules as well as Logic Apps playbooks. Its scope covered the operational response alongside the analytics.

Include enablement in delivery

Customer engineers were trained to operate and extend both platforms. The handover therefore covered ongoing ownership as well as the initial implementation.

How the workflow fits together

  1. 01

    Identity track: apply the configured flow

    Custom B2C policies handle the authentication and federation behavior required by the applications.

  2. 02

    Identity track: transform and integrate claims

    Claims transformation and application integration connect the identity flow to the business application.

  3. 03

    Security track: evaluate the detection logic

    Sentinel KQL analytics and detection rules provide the security operations logic.

  4. 04

    Security track: run the defined response

    Logic Apps playbooks support automated response workflows, with the customer team trained to operate and extend the program.

Questions for a similar implementation

Use these review points when you assess this architecture for your own environment.

  • Do transformed claims preserve the identity information each application expects?
  • Can the customer team explain how a detection relates to its response playbook?
  • Can the owning engineers safely extend a policy or detection after handover?

The outcome

The customer received identity and security operations capabilities in separate five-week and four-week programs, with training to operate and extend both platforms independently.

Technology used
  • Azure AD B2C
  • Identity Experience Framework
  • Microsoft Sentinel
  • KQL
  • Azure Logic Apps

Client and delivery-partner names are withheld.

Start with your workflow.

We define the scope and acceptance criteria with you. One bounded workflow starts at $10,000, payable after acceptance. Wider programs are scoped separately.

Tell us the workflow →

Explore the work