Curated demo content by default.
The /demo route group is a public demonstration surface. Its stories, report packs, and portal views are intentionally curated unless a live tenant is explicitly selected.
Three months of repeated review showing trend, evidence quality, recurring MSP value, and board-level control movement. This page uses the current webapp surface and report structure with a fictional UK financial-services scenario kept explicit about representative data, P1-only licensing, and what is and is not yet mature.
Blast radius framing
Most of the critical paths from the first install have been closed. The residual exposure is concentrated in one shared emergency account and two remaining ADFS dependencies, both under active monthly review.
34
Blast score
4
Affected identities
2
Systems
1
Applications
Three months of measured remediation have reduced the blast radius from 78 to 34. The residual exposure is concentrated in one shared emergency account and two ADFS-dependent workflows, both under monthly governance review.
Score
34
Systems
2
Users
4
Apps
1
Data stores
1
Regulatory impact
Recommended action
Replace the shared weekend emergency account with named accountable access and complete the ADFS trust retirement plan for the two remaining regulated workflows.
sharedadmin-weekend
Shared account / Azure
ext-advisory@pwc.com
Guest / M365
svc-branch-servicing
Service account / AD / ADFS
k.chen (legacy servicing)
Employee / AD / MIM
A shared emergency account holds standing Contributor access to production subscriptions, which grants implicit read access to Key Vault secrets.
A shared emergency administration account still holds standing Contributor access across two production subscriptions used during weekend operations support.
The Contributor role on production subscriptions grants implicit read access to Key Vault secrets, including database connection strings and API keys.
Replace the shared weekend account with named accountable access.
Complete the application-by-application retirement plan.
88% of paths backed by confirmed evidence
Source confidence