Case Studies

Real engagements, real outcomes. How we take businesses from licensing to a fully operating Microsoft cloud, and stay accountable after go-live.

Hybrid Active DirectoryMicrosoft AzureInfrastructure AssessmentRemote Delivery

Rescuing a hybrid Active Directory from a dead Azure domain controller

An overseas organisation asked us to retire the Azure half of their hybrid identity setup. Read-only discovery told a different story: the cloud domain controller wasn't idle. It was dead, holding a stranded FSMO role, and silently behind months of failed logins.

The challenge

  • A secondary domain controller in Azure had stopped answering LDAP while its VM stayed powered on and reachable, masking the failure
  • Active Directory replication broken for over 60 days, with the Schema Master role stranded on the dead controller
  • Stale DNS records still steered clients to the dead DC, the untraced cause of months of intermittent failed logins
  • Microsoft 365 directory sync had quietly stopped weeks earlier; the “redundant” environment was really running on a single DC

Our approach

  • Strictly read-only discovery before anything else: replication health, FSMO placement, DNS, DHCP, sync status and the full Azure resource inventory
  • Every finding documented with its transcribed evidence, and no change proposed until the assessment was reviewed
  • Both removal paths evaluated (repair-then-demote vs seize-and-force-remove) with a clear recommendation and risk analysis
  • A gated, phased plan (assess, remove, decommission), with each phase requiring sign-off and a verified backup before anything irreversible
What read-only discovery found: a dead cloud DC still advertised by DNS, replication broken for months, and directory sync silently stopped.
What read-only discovery found: a dead cloud DC still advertised by DNS, replication broken for months, and directory sync silently stopped.
The recommended target state: a clean single-DC on-premises domain with the cloud footprint fully retired.
The recommended target state: a clean single-DC on-premises domain with the cloud footprint fully retired.

What we delivered

Root-Cause Diagnosis

Months of intermittent failed logins traced to stale DNS records still advertising the dead controller, identified in the first read-only pass, without touching production.

Full Hybrid AD Assessment

Replication, FSMO roles, DNS, DHCP, directory sync and cloud inventory documented finding-by-finding, with an evidence appendix behind every claim.

Azure Decommissioning Plan

A phased plan to seize the stranded role, metadata-clean the dead DC, scrub DNS, and retire the full Azure footprint: VM, VPN, virtual network, disks and vaults.

Execution Runbook

Step-by-step seize and force-removal procedure with verification gates and rollback conditions at every stage, ready for the execution window.

The results

60+
Days of silently broken replication uncovered
100%
Read-only discovery; nothing changed before sign-off
1
Root cause found for months of failed logins
3
Gated phases, each with a tested way back

Delivered fully remotely. Details anonymised. The pattern of a forgotten cloud DC quietly dying while DNS still points at it is one we see in many hybrid environments. If logins fail intermittently and you have a domain controller “in the cloud somewhere”, it is worth a look before it becomes an outage.

AWSCost OptimizationSmall BusinessCloud Operations

Cutting a small-business AWS bill by more than half, with zero downtime

You don't need a big cloud footprint to be overpaying. A line-by-line audit of a small-business AWS account we manage found idle addresses, leftovers from a retired service, and storage on the wrong tier quietly more than doubling the bill. Cleaning up took the yearly run-rate from over $220 to under $100, a 58% cut with zero downtime.

The challenge

  • A small monthly bill that had quietly doubled, easy to ignore, expensive over a year
  • Idle static IP addresses billing every hour, one locked to an old mail setting that needed an AWS support case to release
  • Leftover DNS and resources from a retired webmail service, still charging months later
  • Backups sitting on standard storage when archive tiers cost a fraction

Our approach

  • Look, don't touch: audit-only access first, so nothing could break while we mapped every charge
  • Traced each line of the bill to what actually uses it; anything idle, unattached or orphaned went on the removal list
  • Did it properly: reset the stale mail record and raised an AWS support case to release the locked address, no shortcuts
  • Moved backups to cheaper storage tiers that match how often they're actually needed
AWS spend as a yearly run-rate, before and after the audit, same workloads, zero downtime.
AWS spend as a yearly run-rate, before and after the audit, same workloads, zero downtime.

What we delivered

Idle-Resource Sweep

Three unused static IP addresses released, including one AWS itself had locked, freed through a proper support case.

Dead-Service Cleanup

DNS records and resources from a retired webmail service removed, with email-critical records double-checked before every deletion.

Smarter Backups

Nightly database backups and long-term archives moved to lower-cost storage tiers, better protection and a smaller bill at the same time.

A Repeatable Checklist

The exact read-only audit playbook we now offer small businesses as a free, no-obligation first step.

The results

58%
Off the AWS bill
<$100
New yearly run-rate, down from $220+
3
Idle IP addresses found silently billing
0
Downtime or changes to running workloads

Real numbers from a small-business AWS account we manage, details anonymised. The waste pattern is the same at any size: idle resources and storage on the wrong tier that nobody remembers. A read-only audit finds it without touching production.

In-depth case study

From Legacy Accounting to Business Central: Intercompany Operations Across Five Entities in Southeast Asia

Five legal entities, four countries, one Business Central. The full story from migration to intercompany configuration, and how we stand behind delivered work.

Read the full case study

Ready to write your own case study?

Whether it's Microsoft licensing, a Business Central rollout, or AI on top of your own data. We scope it, deliver it, and show our work.