Results

Practical Azure, security and FinOps outcomes.

These examples show how CloudQbit helps New Zealand organisations find hidden cost, security and governance issues, then turn them into measurable remediation outcomes.

Proven outcomes from real Azure and security environments

  • 95% storage cost reduction for migrated backup data
  • Six-figure annualised cloud savings from root-cause analysis
  • 100+ inappropriate privileged workstation access paths removed
  • About 80% of one environment鈥檚 cost traced to excessive logging
Cloud cost optimisation results

Azure FinOps and cost optimisation case studies

Cloud cost optimisation 路 Large New Zealand council

95% storage saving through Azure Backup retention redesign

Problem: Historical VM backup data was still sitting in expensive Azure Backup storage after workloads had been decommissioned.

Action: We separated active recovery needs from long-term retention, confirmed which data still needed to be kept, and moved around 200 TB of eligible backup data into secure archive storage.

Outcome: Storage cost for migrated data dropped by around 95%, creating a six-figure annual saving while preserving required retention.

95% storage cost reduction
Read case study
Cloud cost optimisation 路 Large enterprise cloud environment

Hidden Azure consumption pattern resolved through root-cause FinOps analysis

Problem: Azure spend kept growing even after reservations and savings plans had already been addressed.

Action: We traced the cost increase back to unmanaged storage growth linked to a specific operational process, then helped define the remediation path.

Outcome: The root-cause fix created a five-figure monthly reduction and a six-figure annualised saving.

Six-figure annualised savings
Read case study
Cloud cost optimisation 路 Large government agency

Six-figure compute saving through VM reservation and SKU standardisation

Problem: A fragmented VM estate was carrying high pay-as-you-go compute cost, with too many SKU variations to optimise cleanly.

Action: We rationalised VM families, modelled reservation coverage, and kept enough pay-as-you-go capacity for workloads that still needed flexibility.

Outcome: The optimisation plan identified six-figure compute savings, with up to 64% saving available through selected three-year reservations.

Up to 64% savings over 3-year reservations
Read case study
Cloud cost optimisation 路 Large enterprise cloud environment

Significant saving from discovering a cloud-unsuitable legacy workload

Problem: A legacy VM-based workload was repeatedly crawling Azure file shares and generating tens of millions of transactions across Storage, Defender, and networking.

Action: We traced the cost back to workload behaviour, confirmed the affected services, and helped the team move to a more suitable existing technology path.

Outcome: The process was retained, but the workload pattern changed, creating around 90% cost reduction for the affected area.

Another six-figure savings experience
Read case study
Cloud cost optimisation 路 Large government agency

Five-figure annual saving by tuning excessive Azure diagnostic logging

Problem: A complex Azure integration environment had high spend that was being treated as normal platform cost.

Action: We analysed service-level cost behaviour and proved excessive diagnostic ingestion into Log Analytics was the main driver.

Outcome: Logging was tuned without removing required visibility, creating a five-figure annual saving and clearer cost ownership.

About 80% of cost traced to logging in one case
Read case study
Azure governance results

Tagging, ownership and showback case studies

Azure governance 路 Large enterprise cloud environment

Azure tagging and showback foundation delivered across 6,000+ resources

Problem: A large Azure estate had around 2% usable tagging coverage, inconsistent tag names, and no reliable showback model.

Action: We built tag visibility, defined a practical baseline, created controlled update scripts, and coached internal engineers through the rollout.

Outcome: More than 6,000 resources across 740 resource groups and 32 subscriptions were tagged, enabling showback, ownership, cleanup, and around 35% cloud cost reduction.

35% cloud cost reduction enabled by tagging visibility
Read case study
Security and identity results

Identity hardening and privileged access case studies

Security and identity 路 Large enterprise environment

Removing accidental privileged workstation access for business users

Problem: Business users had inherited workstation admin rights through nested privileged group membership.

Action: We validated effective access paths, removed inappropriate nesting, and realigned access to least-privilege requirements.

Outcome: More than 100 non-IT privileged access paths were removed, reducing unnecessary admin exposure and improving group governance.

100+ non-IT privileged access paths removed
Read case study
Security and identity 路 Two large New Zealand enterprises

Modernising enterprise identity by removing AD FS dependency

Problem: Enterprise authentication still depended on AD FS for Microsoft 365 and applications, with decommissioning stalled by complexity and risk.

Action: We migrated Microsoft 365 authentication to modern cloud authentication, moved applications to Microsoft Entra ID SSO, and introduced MFA and Conditional Access controls.

Outcome: AD FS dependency was removed or significantly reduced, improving identity security and lowering legacy federation risk.

AD FS dependency removed
Read case study
Security and identity 路 Large multinational enterprise

HR-driven identity lifecycle automation with Workday and Microsoft Entra ID

Problem: A multinational enterprise needed Workday integrated with Microsoft Entra ID and Active Directory for joiner, mover, and leaver processes.

Action: We worked through HR attributes, transformation logic, provisioning and deprovisioning flows, and Workday SSO.

Outcome: The organisation gained HR-driven identity lifecycle automation, stronger joiner/leaver control, modern SSO, and an integration model still in use years later.

HR-driven provisioning and SSO enabled
Read case study
Security and identity 路 Large New Zealand manufacturing enterprise

Tiered admin model reduced identity-critical credential exposure

Problem: Domain Administrator credentials were being used too broadly for routine server operations.

Action: We separated Tier 0 identity systems from Tier 1 operational workloads and redesigned privileged access paths around least privilege.

Outcome: Domain Admin exposure was reduced while operational access stayed workable, cutting thousands of potential credential exposure paths.

Thousands of credential exposure paths reduced
Read case study

What these results have in common

  • Root-cause analysis before remediation
  • Business context before technical change
  • Practical fixes teams can sustain
  • Measurable outcomes across cost, risk and governance

Want to find similar savings, risk or governance gaps in your environment?

CloudQbit can review your Azure cost, identity, governance and security posture to identify practical opportunities for savings, risk reduction and stronger operational control.