DexOnDuty.Meet Dex ↗
On duty for your Microsoft setup

Meet Dex.
Your virtual IT & security worker.

Find the risks. Cut the waste.
Know what to do next.

Dex checks Microsoft 365 and Azure for security gaps, reliability risks, and wasted spend. You get the affected resource, why it matters, and concrete next steps.

Read only. Always.

Early pilot · For small businesses and the IT people who support them

DEX / WEEKLY REVIEWEXAMPLE
YOUR NEXT MOVES

Here’s what needs attention.

3 findings. Clear next steps. ↓
01
Database ports allowed from any IPCheck reachability. Restrict source addresses.
NETWORK
02
Storage allowed anonymous file accessConfirm intent. Restrict private containers.
STORAGE
03
Running VMs with Azure Backup stoppedConfirm other coverage. Restore protection.
BACKUPS
MICROSOFT 365 • AZURE • SECURITY & ACCESS • RELIABILITY • COST & LICENCES
01 / HOW DEX WORKS

A weekly check.
A clear explanation.
A practical next step.

  1. Connect your Microsoft environment. Read only.

    Dex always uses read only access to Microsoft 365 and Azure. It can inspect your setup, but cannot change settings, edit data, or remove resources.

  2. Dex checks security, reliability, and cost.

    Overly broad network access, public storage, unnecessary app permissions, backup gaps, expiring certificates, and wasted spend.

  3. You get a specific action for each finding.

    What was found, the evidence behind it, and what to check or change. Written so you or your IT provider can act on it. Open findings carry forward into the next review.

More than one angle on the same finding.

The pilot is designed to use different AI models to examine findings from security, access, and cost perspectives, and cross-check the recommendations.

Read only. Always. Dex reviews and recommends. You or your IT provider make any changes.
02 / A REAL CLIENT REVIEW

What a real Azure review
brought to the surface.

One client’s weekly Azure review flagged network rules allowing database and remote access ports from any IP, storage allowing anonymous file access, and running servers whose Azure backups had stopped. Each finding included a priority and the affected resources.

Anonymised client review · 2 October 2026 · 12 items marked “act now”

AZURE / NETWORK ACCESS

Database and admin ports
allowed from any IP.

The review flagged network rules allowing MySQL, PostgreSQL, Remote Desktop, and SSH ports from any internet address.

The next moveConfirm which services are reachable. Restrict the rules to required sources and use private access where appropriate.
AZURE / PUBLIC STORAGE

Stored files could be read
without signing in.

The review flagged storage containers configured for anonymous public read access.

The next moveConfirm which files should be public. Remove anonymous access from containers meant to be private.
AZURE / BACKUPS

The servers were running.
Their Azure backups had stopped.

Azure Backup had stopped for four virtual machines that were still running.

The next moveConfirm whether another backup covers them, then restore the required protection.

Selected findings from the client’s register. Names, domains, and resource identifiers have been omitted.

More findings from earlier reviews.

Forgotten permissions, unused resources, and paid licences left behind.

MICROSOFT 365 / APP ACCESS

The migration finished.
The access didn’t.

Old Office 365 migration apps still had full read and write access to mailboxes, long after their original job was done.

The next moveConfirm the app is no longer used, then revoke the mailbox permissions it no longer needs.
AZURE / UNUSED RESOURCES
$200 / month

Empty plans.
A very real bill.

A recent review found unused Azure resources, including empty App Service plans, costing about $200 a month.

The next moveCheck the plans have no apps or dependencies, then remove the unused resources and verify the billing change.
MICROSOFT 365 / LICENCES

They left the company.
The licences stayed.

Licences were still assigned to former employees. Offboarding had left paid seats behind.

The next moveConfirm offboarding and data retention requirements, then reclaim licences that are no longer needed.

These earlier examples come from separate reviews. The $200/month figure is observed spend, not a claim of savings already achieved.

Firsthand experience
“In my experience, Dex has replaced two IT security specialists.”
03 / WEEK AFTER WEEK

A review that carries forward to next week.

Dex keeps track of what is still open, when it first appeared, and what has been marked resolved. Important findings stay on the list until they are addressed or accepted.

Every item names the affected resource, explains why it matters, and gives you the next step. No scorecards to decode. You or your IT provider carry out the changes.

Get a review of your setup ↗
WEEKLY REVIEWEXAMPLE / SELECTED FINDINGS
01 / NETWORK ACCESSACT NOW
Database and admin ports allowed from any IP.Confirm reachability and restrict network rules to required sources.
02 / PUBLIC STORAGEACT NOW
Storage containers allow anonymous file access.Confirm whether public access is intended. Restrict containers that should be private.
03 / BACKUPSIMPORTANT
Azure Backup stopped on running servers.Confirm other backup coverage and restore the required protection.
STILL OPEN FROM LAST WEEKCertificates approaching expiry.First flagged: 25 September 2026.

Next action: Confirm renewal, update bindings, and verify the certificate being served.

04 / JOIN THE EARLY PILOT

Let Dex take the weekly checks off your list.

I’m building Dex with a small group of businesses and IT people. If forgotten access, gaps in backup protection, or wasted Azure spend sound familiar, tell me about your setup.

✓ Always read only access✓ A short conversation first✓ No commitment to sign up✓ Your real problems shape the pilot
JOIN THE CONVERSATION

Tell me a little about your setup.

Your details will be used only to follow up about this pilot.