Quadra's team began with a rapid validation of the existing findings, confirming severity and status across every in-scope account, then moved directly into hands-on remediation. This included correcting IAM roles and policies down to least-privilege, closing exposed network paths, and enabling AWS Security Hub, Config, CloudTrail, and GuardDuty for continuous detective coverage. In parallel, Quadra designed and implemented Service Control Policies to enforce guardrails across the customer's AWS Organization, preventing entire classes of misconfiguration from recurring.
Quadra also led the identity federation project end-to-end, configuring SAML-based SSO between Microsoft Entra ID and AWS IAM Identity Center, including SCIM-based automated user provisioning. This gave the customer centralized, auditable control over who could access which AWS accounts, replacing a patchwork of locally managed IAM users.