The complete sample deliverable: how MG Cloud connects dated evidence, findings, accountable decisions, an approved deviation, a target state, a sequenced roadmap, and the continuity layer that keeps it all current.
This review deliberately keeps four things separate, so the reader always knows what they are looking at:
What the tenant reports — dated evidence items with stable ids (EVD-*).
What repeatable checks evaluated against recognized guidance.
What a senior architect concluded from the evidence — and why.
What a named owner accepted, with a date and a review point (ADR-*, DEV-*, OUTCOME-*).
Cascade Industrial Group (CIG) is a fictional ~2,100-person manufacturing and logistics enterprise on a Microsoft-centric estate. It is not failing — it runs every day. But years of migrations, urgent fixes, and overlapping ownership produced an endpoint environment that is hard to explain and risky to change, and the lead endpoint architect departed three months before the assessment, taking undocumented intent along. A Windows 11 program and a cyber-insurance review are both underway, and both stalled on the same root cause.
The review found one dominant structural issue and a set of consequences that flow from it:
| Dimension | Current state (synthetic) |
|---|---|
| Windows corporate | 1,850 — 1,180 co-managed (64%), 670 cloud-managed only |
| Other endpoints | 140 macOS (45 unmanaged), 85 Cloud PCs, 900 iOS, 260 Android, 420 BYOD Windows |
| Policy surface | 340 configuration profiles (190 settings-catalog), 12 compliance, 28 Conditional Access, 6 app-protection, 260 assignment groups |
| Management model | Hybrid, mid-transition; legacy update path for 64%; ~40 linked group policies; workload ownership undocumented |
| Security coverage | Endpoint detection 82%, disk encryption 91% reported (160 not confirmed), local-admin rotation on co-managed only, attack-surface rules audit-only |
| Lifecycle | 210 stale devices (90+ days), 240 end-of-life Windows builds |
| Team | 4 endpoint engineers, 9 service desk, 3 security, 1 external MSP — no shared architecture picture |
Every finding traces to dated evidence items (20 in the full package), and every finding carries its own stated limitations. Priority reflects exploitability and business impact — severity is never inflated to manufacture urgency.
| ID | Finding | Priority | Evidence |
|---|---|---|---|
| FR-002 | Two-tier control gap: 670 cloud-managed devices under a thinner control set | P1 | EVD-SEC-003/004/005, EVD-INTUNE-002, EVD-SCCM-001 |
| FR-003 | Security-coverage tail: detection 82%, encryption 91% (160 unconfirmed), 45 unmanaged Macs | P1 | EVD-SEC-001/002, EVD-DEVICE-003 |
| FR-005 | Permissive, partly-legacy identity and enrollment posture | P1 | EVD-CA-001/002/003, EVD-DEVICE-004 |
| FR-001 | Policy sprawl, no authoritative winner (340 profiles / 260 groups) | P2 | EVD-INTUNE-001/002, EVD-ASSIGN-001/002, EVD-SCCM-003 |
| FR-006 | Legacy dependency drag (64% co-managed, legacy updates, 40 group policies) | P2 | EVD-SCCM-001/002/003, EVD-DEVICE-002 |
| FR-004 | Lifecycle backlog: 210 stale, 240 end-of-life, 45 unmanaged Macs | P2 | EVD-DEVICE-001/002/003 |
| FR-007 | Key-person and explainability risk: operable but not explainable | P2 | EVD-OPS-001, EVD-INTUNE-001 |
Each finding in the full package carries five fields the summary table cannot show: the observation, the architecture judgment, the business impact, the recommendation, and the finding's own limitations — including where tenant-reported state could differ from on-device reality.
Findings that stop at a report get re-litigated at the next staff change. This engagement converts them into dated, owned records:
Accepted · Owner: Head of Endpoint Engineering · Review 2026-10-16. Same security floor on every corporate Windows device, role-based targeting, versioned naming, the 670-device gap closed first. Addresses FR-001 / FR-002 / FR-003.
Accepted (staged) · Owner: Director of Infrastructure · First ring gate 2026-09-16. End-of-life builds move first; each of the ~40 group policies retires only with an owner decision. Addresses FR-006 / FR-004.
Vendor-certified line software blocks upgrade in the standard window. Risk accepted by the CISO with compensating controls (network isolation, tightened endpoint controls, no general-purpose use) and a 90-day review. A deliberate, owned risk — not an ignored finding.
The outcome record pattern: remediation is verified per device from reporting data. A silent device counts as not-done — never rounded up. Shown pre-remediation in this sample, clearly labeled illustrative.
From a two-tier, dual-managed, undocumented estate to a single authoritative, cloud-primary, continuously-evidenced one. Five pillars:
| Phase | Focus | Highlights |
|---|---|---|
| Days 0–30 | Stabilize the exposure | Local-admin rotation to the 670; close the detection tail; triage the 160 unconfirmed-encryption devices; verify break-glass; start stale reconciliation; stand up the decision register |
| Days 31–60 | Converge the architecture | Publish the authoritative baseline to ring 1; promote attack-surface rules from audit to enforce on a validated set; modern update ring 1 with end-of-life builds first; tighten enrollment; decide the 45 unmanaged Macs |
| Days 61–90 | Modernize and operationalize | Baseline to full fleet by ring; workload cutover stage 2 and group-policy retirement with owner decisions; document the Conditional Access model; verify outcomes per device; operating-model handoff |
A point-in-time review decays the day after it is delivered — and this fictional client already lived that cost once, when the architect left. The engagement design addresses it in three layers:
The assessment is repeatable tooling, not a one-off. Each re-run produces a new dated picture that compares against the last one — drift shows up as a difference between two dated views, not as a surprise two years later.
Remediation is proven from per-device reporting under a positive-evidence rule: success, partial results, failure, and missing data stay separate, and missing data is never counted as success.
Decisions and deviations carry review dates. The register surfaces what is due, what changed out-of-band, and what still lacks an owner — so judgment stays current alongside the facts.
Findings, decisions, and verification results are structured, dated data — built to be consumed by your own reporting and assistant tooling, with citations and honest refusal when the evidence is not there.
| Layer | You receive | MG Cloud retains |
|---|---|---|
| Evidence | Dated assessment reports and evidence packages — your data, in your hands | — |
| Records | The decision / deviation / outcome register for your estate | The methodology and refusal discipline behind it |
| Design | Target architecture, roadmap, runbooks, and handoff documentation | The content-authoring and validation system that produces them |
| Operations | An operating model your team runs after handoff | Ongoing architecture judgment, by engagement |
Plainly: you own your evidence, your records, and your operating model. There is no lock-in by hostage-holding — the ongoing relationship exists because keeping the judgment current is worth it, not because you cannot leave.