Case Studies
Real engagements, real outcomes. How we take businesses from licensing to a fully operating Microsoft cloud, and stay accountable after go-live.
Rescuing a hybrid Active Directory from a dead Azure domain controller
An overseas organisation asked us to retire the Azure half of their hybrid identity setup. Read-only discovery told a different story: the cloud domain controller wasn't idle. It was dead, holding a stranded FSMO role, and silently behind months of failed logins.
The challenge
- A secondary domain controller in Azure had stopped answering LDAP while its VM stayed powered on and reachable, masking the failure
- Active Directory replication broken for over 60 days, with the Schema Master role stranded on the dead controller
- Stale DNS records still steered clients to the dead DC, the untraced cause of months of intermittent failed logins
- Microsoft 365 directory sync had quietly stopped weeks earlier; the “redundant” environment was really running on a single DC
Our approach
- Strictly read-only discovery before anything else: replication health, FSMO placement, DNS, DHCP, sync status and the full Azure resource inventory
- Every finding documented with its transcribed evidence, and no change proposed until the assessment was reviewed
- Both removal paths evaluated (repair-then-demote vs seize-and-force-remove) with a clear recommendation and risk analysis
- A gated, phased plan (assess, remove, decommission), with each phase requiring sign-off and a verified backup before anything irreversible
What we delivered
Root-Cause Diagnosis
Months of intermittent failed logins traced to stale DNS records still advertising the dead controller, identified in the first read-only pass, without touching production.
Full Hybrid AD Assessment
Replication, FSMO roles, DNS, DHCP, directory sync and cloud inventory documented finding-by-finding, with an evidence appendix behind every claim.
Azure Decommissioning Plan
A phased plan to seize the stranded role, metadata-clean the dead DC, scrub DNS, and retire the full Azure footprint: VM, VPN, virtual network, disks and vaults.
Execution Runbook
Step-by-step seize and force-removal procedure with verification gates and rollback conditions at every stage, ready for the execution window.
The results
Delivered fully remotely. Details anonymised. The pattern of a forgotten cloud DC quietly dying while DNS still points at it is one we see in many hybrid environments. If logins fail intermittently and you have a domain controller “in the cloud somewhere”, it is worth a look before it becomes an outage.
Cutting a small-business AWS bill by more than half, with zero downtime
You don't need a big cloud footprint to be overpaying. A line-by-line audit of a small-business AWS account we manage found idle addresses, leftovers from a retired service, and storage on the wrong tier quietly more than doubling the bill. Cleaning up took the yearly run-rate from over $220 to under $100, a 58% cut with zero downtime.
The challenge
- A small monthly bill that had quietly doubled, easy to ignore, expensive over a year
- Idle static IP addresses billing every hour, one locked to an old mail setting that needed an AWS support case to release
- Leftover DNS and resources from a retired webmail service, still charging months later
- Backups sitting on standard storage when archive tiers cost a fraction
Our approach
- Look, don't touch: audit-only access first, so nothing could break while we mapped every charge
- Traced each line of the bill to what actually uses it; anything idle, unattached or orphaned went on the removal list
- Did it properly: reset the stale mail record and raised an AWS support case to release the locked address, no shortcuts
- Moved backups to cheaper storage tiers that match how often they're actually needed
What we delivered
Idle-Resource Sweep
Three unused static IP addresses released, including one AWS itself had locked, freed through a proper support case.
Dead-Service Cleanup
DNS records and resources from a retired webmail service removed, with email-critical records double-checked before every deletion.
Smarter Backups
Nightly database backups and long-term archives moved to lower-cost storage tiers, better protection and a smaller bill at the same time.
A Repeatable Checklist
The exact read-only audit playbook we now offer small businesses as a free, no-obligation first step.
The results
Real numbers from a small-business AWS account we manage, details anonymised. The waste pattern is the same at any size: idle resources and storage on the wrong tier that nobody remembers. A read-only audit finds it without touching production.
In-depth case study
From Legacy Accounting to Business Central: Intercompany Operations Across Five Entities in Southeast Asia
Five legal entities, four countries, one Business Central. The full story from migration to intercompany configuration, and how we stand behind delivered work.
Read the full case studyReady to write your own case study?
Whether it's Microsoft licensing, a Business Central rollout, or AI on top of your own data. We scope it, deliver it, and show our work.