Client details are anonymized to protect their privacy. Results are taken from our project records.
Employees at several sites and on the road needed the same office systems: file shares, remote desktops and the company’s inventory and order system. That inventory system was hosted by a third party with remote desktop open to the internet and unencrypted connections, and an inbound port was forwarded through the office firewall to reach it.
At the same time, the company’s Microsoft 365 tenant had no enforced security baseline. Settings drifted, and nothing put them back.
Instead of a traditional VPN that puts a laptop “on the network,” each user and server gets access only to the specific resources it needs. Remote-desktop users get a tightly scoped profile that reaches the remote desktop gateway and nothing else, so file shares aren’t exposed. Access is tied to Microsoft 365 sign-in with multi-factor authentication.
We moved the inventory and order system onto the company’s own server, put a trusted certificate on it and switched client and shipping-station connections to encrypted TLS 1.3. The inbound port forward was closed and the old hosted server’s access was removed.
We defined the company’s Microsoft 365 security standards and set them to automatically correct drift every 12 hours, alongside written governance policies mapped to the CIS Controls.
Infrastructure monitors had been sending alerts to a retired destination. We re-pointed them so an outage opens a ticket and a recovery adds a note, and added automatic detection and repair for offline virtual desktops.
New and wiped laptops now enroll and configure themselves from the box. In testing, a wiped laptop re-enrolled itself about 13 minutes after the wipe.
33% → 94%
Microsoft 365 security baseline alignment (17 of 18 standards compliant), with drift corrected automatically every 12 hours.
21 / 23
workstations reconnected to the relocated inventory system on the first try; the other two connected after a quick fix.
0
inbound port forwards left for the inventory system; remote desktop is no longer exposed to the internet.
Every open port is a door. The fix isn’t a bigger lock on each door. It’s giving each person a key to only the rooms they need, and checking every day that nobody propped a door open.
Book a free 15-minute discovery meeting. No pressure, no obligation.
We ask before we track you.
Nothing from Google, Microsoft, or Meta loads on this site unless you say yes. We keep basic, cookieless visit counts on our own server either way. Details in our Privacy Policy.
Essential site function and first-party, cookieless visit counts run either way and can't be switched off here.