Customer Overview
A reputed educational institution with approximately 18,000 students, more than 1,200 staff members, 15+ departments, one main campus and eight campus extensions across India.
The institution used a large number of laptops and desktops for administration, teaching, academic content preparation, LMS activities, research, journals and laboratory experiments.
The Challenge
The institution did not have centralised endpoint management or security monitoring across its campuses.
- No central visibility of devices and user logins
- No common security policies across locations
- Some users had local administrator rights
- Limited control over software installation and configuration changes
- No central monitoring of suspicious endpoint activities
- Administrative devices and laboratory devices required different security controls
CyberAxis Approach
CyberAxis assessed the complete device environment and divided it into two separate categories:
- Mail Machine Network: Official laptops and desktops used by staff, faculty and administrators
- Lab Network : Computers used for university Computer labs, Ethical hackers, experiments, development, innovation and academic laboratory activities
Strong centralized security controls were applied to institutional devices. Laboratory devices were isolated through a separate internet connection so that academic activities could continue without affecting the official university network.
Solution Implemented
- Microsoft 365 Education licensing enabled for all mail machine users
- Official endpoints enrolled and managed through Microsoft Intune
- Microsoft Defender security controls implemented
- Strong endpoint and device-compliance policies applied
- Unnecessary local administrator rights restricted
- Wazuh SIEM implemented for centralised security monitoring
- Login activity and important endpoint events brought under monitoring
- Main campus and remote campus devices brought under central control
- Laboratory network separated through a different internet service provider
- Laboratory traffic monitored through perimeter firewall controls
- Laboratory computers updated with the latest operating-system and security patches
- Day-to-day laboratory administration retained with authorised lab administrators
Business Value
- Centralised management of institutional devices across all locations
- Improved visibility of users, logins and endpoint-security events
- Consistent security policies across departments and campuses
- Reduced risk from uncontrolled administrator privileges
- Clear separation between official and laboratory network traffic
- Better protection for institutional email, documents and academic information
- Remote campuses brought under a common security framework
- Academic laboratories retained the flexibility required for experimentation
- Reduced confusion through clearly defined device and security zones
