[AD2] TechConfidential

Technology Posture Assessment

Prepared for Acme Industries, Inc. — 87 employees, Denver, CO.

EngagementAEGIS‑A‑2026‑041
Report dateApril 24, 2026
Prepared byAD2 Tech partners
ScopeM365 · AD · Meraki · Endpoints
AEGIS · an AD2 Tech methodology

Executive summary

Acme Industries operates a typical SMB infrastructure — Microsoft 365 for productivity, on‑prem Active Directory inherited from a prior integrator, a Meraki network across three sites, and roughly 140 endpoints managed by a mix of Intune and local accounts. The environment is stable but carries three critical findings that together represent a realistic path to material business disruption.

Critical3
High14
Medium29
Low28

The three critical findings (F‑047 phishing‑resistant MFA on Global Admin; F‑052 unmonitored S3 bucket with production backups; F‑061 lapsed EDR coverage on four production endpoints) can be addressed inside 14 days for an estimated 46 hours of remediation effort. We recommend starting there.

Beyond the immediate risk items, we identified $62,400 / year in Microsoft 365 licensing over‑provision and a duplicate SaaS stack between marketing and sales that would consolidate to a single $9,600 / year tool. These recover roughly half the assessment fee in the first year alone.

Recommended next 90 days
  1. Close the three critical findings (AEGIS Remediation, est. $9k fixed).
  2. Adopt the proposed Microsoft 365 licensing baseline; cancel unused Dropbox tenancy.
  3. Establish quarterly posture review under a right‑sized Partnership retainer.
Start an assessment How this gets produced
Anatomy of a finding

Every issue ships with the fix attached.

Findings aren’t a list of problems we hand off and walk away from. Each one comes with current state, business risk, a recommended remediation, and an effort estimate — diagnosis and prescription, side by side.

F‑047

Domain administrator accounts do not require phishing‑resistant MFA.

Critical
Current stateFour Entra ID accounts with the Global Administrator role accept SMS and authenticator‑push factors. Two have never registered a hardware key.
Business riskA phished admin credential lets an attacker pivot to every cloud‑connected system — M365, Dropbox, HubSpot. Average recovery cost in SMB: 6–9 weeks of disruption.
RecommendationEnforce FIDO2/WebAuthn on the Global Administrator role. Issue YubiKey 5Cs to the four named admins. Remove legacy SMS fallback.
Effort
~6 hrs
Includes hardware procurement & four 30‑min admin sessions.