Hybrid Office Network
Dexfense ReviewedOn-premises and cloud-connected corporate network with Active Directory, VPN, EDR/XDR, firewalls and managed Windows workstations.
Overview
Represents a typical corporate environment combining on-premises Windows infrastructure with cloud-connected services. Includes Active Directory domain controllers, Windows workstations and servers, a VPN gateway for remote access, network firewalls, DNS services, endpoint detection and response (EDR/XDR), mobile device management, network file servers and email. Mobile and BYOD devices connect through conditional access policies.
Intended for
IT administrators, network security engineers and MSPs managing corporate Windows environments.
Architecture Assumptions
This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.
- Workstations are domain-joined Windows devices managed via Group Policy
- Remote access is via a corporate-managed VPN with MFA
- Firewall rules restrict both inbound and outbound traffic
- EDR/XDR is deployed and actively monitored on all corporate devices
- Backups are stored off-site and restored periodically to verify integrity
Out of Scope
- OT/ICS environments and factory floor networks are not included
- Assumes no datacenter co-location; not suitable for large enterprise with co-lo racks
- Guest and visitor Wi-Fi is not separately modelled
Architecture Components14 components selected
Endpoints
Windows Clients
Windows-based end-user devices
EDR/XDR
Endpoint Detection and Response systems
Mobile Devices
Smartphones and tablets (iOS, Android)
Servers
Windows Servers
Windows-based servers
Domain Controllers
Active Directory domain controllers
Mail Servers
Email servers and services
Auth & IAM
Active Directory
Directory service for user and resource management
Multi-Factor Auth
Additional authentication verification layer
Network
VPN Services
Virtual Private Network services
Firewalls
Network and application firewalls
DNS Services
Domain name resolution services
Monitoring
Logging Systems
Centralized log collection and management
Storage
Backup Systems
Data backup and recovery systems
File Servers
Network attached storage for file sharing
Security Preview
Based on this architecture's component selection
Indicative Risk Score
43/100
25 techniques identified
3 Critical · 2 High
Top Attack Techniques
- CriticalT1068Exploitation for Privilege Escalation
- CriticalT1003OS Credential Dumping
- CriticalT1486Data Encrypted for Impact
- HighT1133External Remote Services
- HighT1574Hijack Execution Flow
Top Recommended Controls
- 1Implement privileged access management and monitor for suspicious directory queries
- 2Focus on Attack Surface Reduction as your highest priority security initiative
The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.
Remix copies the components so you can add or remove items before generating your assessment.
Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.