Customer: One of the Dominican Republic’s largest financial institutions Industry: Financial Services — Banking Employees: ~5,000 Engagement: Zero Trust Identity & Endpoint Transformation Timeline: 12-week Proof of Concept, delivered remotely with zero disruption to banking operations Result: ~35 percentage point improvement in Microsoft Secure Score
This bank is one of the Dominican Republic’s largest financial institutions, with approximately 5,000 employees and regulatory obligations that demand the highest security standards. When the bank set out to modernize endpoint governance, identity security, and enterprise compliance, the objective extended beyond deploying new technology — the bank was preparing for the future.
Like many mature financial institutions, this bank had accumulated years of endpoint administration processes built primarily around traditional management methods. These systems were functional but increasingly difficult to scale.
Endpoint security, device management, identity controls, and compliance enforcement were not centrally governed through a cloud-native security framework. Visibility into device health and policy compliance required substantial manual effort. Identity protections that form the basis of modern Zero Trust architectures had not been fully implemented across the environment.
For a banking institution responsible for protecting sensitive customer information, this presented both operational and strategic concerns:
Operationally, administrative overhead continued to increase as the organization managed users and devices across a growing technology footprint. Strategically, the bank lacked many of the foundational controls necessary to support future innovation initiatives. The bank chose to address this challenge proactively.
When the bank needed to modernize endpoint governance, identity security, and Zero Trust readiness, it did not issue an RFP — it called MDS. That decision reflected more than five years of earned trust and was reinforced by a direct recommendation from Microsoft’s Caribbean and Central America field team.
Rather than approaching the engagement as a traditional technology deployment, MDS structured the initiative as a Zero Trust transformation program designed to validate security controls, improve cyber resilience, and establish long-term governance standards.
The engagement began with a detailed assessment of the bank’s existing environment. MDS evaluated Entra Connect health, Hybrid Azure AD Join readiness, BitLocker and firewall policies, TPM 2.0 compatibility, MFA registration status, identity readiness, device governance processes, endpoint management practices, encryption policies, firewall administration, authentication controls, and cloud integration capabilities. Every design decision was based on the bank’s validated environment rather than generic assumptions.
Based on those findings, MDS designed a comprehensive Microsoft-centered Zero Trust architecture:
The Proof of Concept focused on 50 users and 50 Windows 11 endpoints. Although limited in scope, the pilot was intentionally designed to validate enterprise-scale deployment methodologies and governance processes.
Deployment required both technical execution and change management. The bank’s security team had concerns about MFA adoption and potential disruption. MDS addressed this through staged rollout sequencing, guided enrollment, and clear communication on security rationale — resistance converted into adoption, resulting in 100% MFA enrollment.
When a network configuration issue blocked policy application to a subset of devices, MDS diagnosed the problem, coordinated with the bank’s internal team, and resolved the issue without extending the timeline. All 50 pilot devices were enrolled in Intune and all intended policies applied.
MDS delivered structured knowledge transfer to the bank’s security team — led by its Senior Manager of Information Security and Cybersecurity — enabling independent management of Intune, Conditional Access, device compliance, BitLocker, firewall governance, and Entra ID. MDS did not simply deploy technology; it built lasting internal capability.
Within the pilot population, the bank achieved:
| Metric | Result |
| Multifactor Authentication Enrollment | 100% |
| BitLocker Encryption Coverage | 100% |
| Windows Hello for Business Adoption | 100% |
| Microsoft Intune Enrollment | 100% |
| Conditional Access Policies Enforced | 5 of 5 |
| Hybrid Azure AD Join Completion | 100% |
| Firewall Governance | Migrated from legacy GPOs to Microsoft Intune |
| Microsoft Secure Score | +~35 percentage points |
This improvement represented far more than a numerical increase — it demonstrated measurable progress in cyber maturity, identity protection, compliance enforcement, endpoint governance, and security readiness.
Traditional endpoint management approaches often require significant manual effort, fragmented administrative processes, and specialized expertise. The move toward centralized Microsoft Intune governance fundamentally changed this model.
Through policy automation, centralized administration, compliance monitoring, and cloud-based management, the bank is projected to eliminate approximately 80 to 90 hours of endpoint administration effort per week as the framework expands toward its 5,000-device target. Security teams spend less time on repetitive administrative activities and more time focusing on strategic initiatives. Leadership gains better visibility. Compliance becomes easier to demonstrate. Endpoint governance becomes more consistent and scalable — and operational growth no longer requires proportional increases in administrative overhead.
Financial institutions remain among the most frequently targeted industries for cyberattacks. According to IBM’s 2024 Cost of a Data Breach Report, the average breach within the financial services sector costs approximately $6.08 million. The controls implemented through this engagement directly address many of the primary attack vectors associated with modern breaches:
While no organization can eliminate risk entirely, the bank significantly improved its ability to prevent, detect, and respond to modern threats through a more mature and integrated security posture.
The most strategic outcome of the engagement may be what it enables next. Prior to this initiative, the bank lacked many of the controls required to safely deploy enterprise AI technologies at scale. Artificial intelligence depends upon trusted identities, compliant endpoints, governed access, and secure information management — without those controls, organizations expose themselves to unnecessary security and compliance risks.
Through the implementation of Microsoft Intune, Entra ID governance, Conditional Access, multifactor authentication, BitLocker encryption, Windows Hello for Business, and compliance management, MDS established the security foundation necessary for responsible AI adoption. The bank is now positioned to extend these capabilities across approximately 5,000 users and leverage Microsoft Copilot and future AI innovations with confidence. This project did not simply modernize security — it created the conditions necessary for the next generation of work.
The bank selected Microsoft because Microsoft offered an integrated platform capable of unifying endpoint governance, identity security, device compliance, authentication, encryption, and policy enforcement. The bank selected MDS because of a proven history of successful execution, deep Microsoft expertise, and a trusted partnership built over multiple engagements. This initiative was not the beginning of the relationship — it was the next chapter in an ongoing collaboration focused on helping the bank modernize securely while preparing for the future.
This engagement reflects a validated methodology — a Latin American Financial Institution Zero Trust Modernization Framework — encompassing discovery protocols, change management playbooks, Intune enrollment, BitLocker, firewall governance, Conditional Access, compliance baselines, and structured knowledge transfer designed specifically for regulated financial institutions. Similar Zero Trust modernization engagements are active with financial institutions across Latin America, confirming that this model scales across markets and regulatory environments.
This bank’s transformation demonstrates that successful security modernization is about more than technology deployment — it is about creating measurable business outcomes. By improving Microsoft Secure Score by approximately 35 percentage points, establishing centralized endpoint governance through Microsoft Intune, reducing future administrative effort by 80 to 90 hours per week, and creating the Zero Trust foundation required for enterprise AI adoption, MDS helped the bank achieve far more than a successful proof of concept.
The engagement delivered a repeatable model for financial institutions seeking to modernize security, improve operational efficiency, and prepare for the future of intelligent work. The bank is now positioned to scale these capabilities across approximately 5,000 users and continue its journey toward a more secure, compliant, and AI-ready future.
“MDS did not simply deploy technology. We helped build the foundation for what comes next.”
Maureen Data Systems (MDS) is a Microsoft Security Solutions Partner with specializations in Threat Protection, Information Protection and Governance, and Identity and Access Management, and a member of the Microsoft Intelligent Security Association (MISA). MDS has delivered measurable Microsoft-powered security transformations for enterprises across the Dominican Republic, the Caribbean, and Latin America for more than a decade. Learn more at www.mdsny.com.
Annamarie Mueller
I look forward to reading your next articles.