Client Login
Menu

Closing Exposed Remote Access and Hardening Microsoft 365 for a Multi-Site Industrial Company

Industry
Industrial testing and inspection
Location
Houston area, multiple sites
Size
About 100 Microsoft 365 mailboxes; 200+ managed Windows devices
Services
Network security, Microsoft 365 security, managed IT

Client details are anonymized to protect their privacy. Results are taken from our project records.

The challenge

Employees at several sites and on the road needed the same office systems: file shares, remote desktops and the company’s inventory and order system. That inventory system was hosted by a third party with remote desktop open to the internet and unencrypted connections, and an inbound port was forwarded through the office firewall to reach it.

At the same time, the company’s Microsoft 365 tenant had no enforced security baseline. Settings drifted, and nothing put them back.

What we did

Zero-trust remote access

Instead of a traditional VPN that puts a laptop “on the network,” each user and server gets access only to the specific resources it needs. Remote-desktop users get a tightly scoped profile that reaches the remote desktop gateway and nothing else, so file shares aren’t exposed. Access is tied to Microsoft 365 sign-in with multi-factor authentication.

Inventory system brought in-house

We moved the inventory and order system onto the company’s own server, put a trusted certificate on it and switched client and shipping-station connections to encrypted TLS 1.3. The inbound port forward was closed and the old hosted server’s access was removed.

Self-correcting Microsoft 365 baseline

We defined the company’s Microsoft 365 security standards and set them to automatically correct drift every 12 hours, alongside written governance policies mapped to the CIS Controls.

Monitoring into tickets

Infrastructure monitors had been sending alerts to a retired destination. We re-pointed them so an outage opens a ticket and a recovery adds a note, and added automatic detection and repair for offline virtual desktops.

Hands-off device setup

New and wiped laptops now enroll and configure themselves from the box. In testing, a wiped laptop re-enrolled itself about 13 minutes after the wipe.

The results

33% → 94%

Microsoft 365 security baseline alignment (17 of 18 standards compliant), with drift corrected automatically every 12 hours.

21 / 23

workstations reconnected to the relocated inventory system on the first try; the other two connected after a quick fix.

0

inbound port forwards left for the inventory system; remote desktop is no longer exposed to the internet.

Every open port is a door. The fix isn’t a bigger lock on each door. It’s giving each person a key to only the rooms they need, and checking every day that nobody propped a door open.

← All case studies

Ready to Talk?

Book a free 15-minute discovery meeting. No pressure, no obligation.