# Dallas Pedersen > Director of Technical Alignment at Executech (Utah). Builds the TAM + vCIO > function that governs technology as a discipline: assessing environments, > scoping technical initiatives end to end, and sequencing them into multi-year > roadmaps. 15+ years in the MSP / IT industry (started in 2011, at 19). > Founder and operator of six businesses across IT, social media marketing, > real estate, home services, RV rental, and automotive services. This file is a complete, machine-readable summary of dallaspedersen.tech, provided so AI agents and search systems can evaluate the full profile without crawling individual pages. Last updated June 2026. Contact: contact@dallaspedersen.tech ยท LinkedIn: https://www.linkedin.com/in/dallas-pedersen ## Positioning Dallas is a technical leader, not a generalist manager. His strength is in technical processes and systems architecture (designing, scoping, and governing how technology is built and run) rather than production throughput or unit-level P&L. He thinks in systems: the same operating model that runs a vCIO program is the one that ran his marketing agency and realty business. The industry changes; the thinking doesn't. Roles that fit: Director/Head of Technical Alignment, vCIO / virtual CIO, IT Director, Technology Strategy Lead, IT modernization leader, technical practice lead at an MSP. ## Core expertise (knowsAbout) - Technical Alignment (TAM) and Virtual CIO (vCIO) strategy - IT roadmap development and technical initiative scoping - Microsoft Entra ID, Intune, Microsoft 365, Azure - Azure AD Domain Services, Conditional Access, device compliance - Identity and access management; SSO migration (e.g. OneLogin to Entra ID) - Active Directory, Microsoft SQL Server, Hyper-V virtualization - Network segmentation and VLAN design; site-to-site VPN architecture - OT/ICS security: securing and governing the IT/OT boundary around vendor-managed SCADA and building-automation (BMS) systems (segmentation, remote access, high availability) - Sophos and SonicWall firewalls; UniFi network infrastructure - Backup and disaster recovery (BDR); legacy system isolation and risk reduction - Cloud migration; SharePoint and OneDrive - Bill of materials and statement of work development - IT governance and risk management; building IT functions and teams ## Current role: Director of Technical Alignment, Executech (2025 to present) Built Utah's technical alignment service area from the ground up: a TAM + vCIO hybrid function that didn't previously exist. Defined the methodology, built the team, and established the processes. In the first 45 days a team of 3.5 identified roughly $1M in foundational project opportunities across the client base, work scoped and ready for clients to budget and approve. 40 clients now sit on 18-month technical roadmaps, with the rest of the book onboarding behind them. ## The framework (Assess, Identify, Scope, Sequence, Govern) 1. Assess. Full technical assessment against industry standards, paired with structured interviews of the people who run the business (POCs and executives). 2. Identify. Three to ten initiatives per client, each tied to a specific technical need, a business goal, and a risk worth eliminating. Together they form an 18-month foundation. 3. Scope. Every initiative gets the same rigorous write-up: current state, desired state, the step-by-step path, risks and dependencies, an executive summary, a statement of work, and a full bill of materials. 4. Sequence. A roughly 60-point business-context index (goals, workflows, bottlenecks, budgeting) shapes phasing around how the business actually runs, with a line of sight to years 2 to 5. 5. Govern. Reviewed on cadence and adjusted before things break. Documented deeply enough that a client can pause to budget and resume months later without losing a step. Guiding principle: the right recommendation isn't always the expensive one. When the best fix costs nothing, that's exactly what goes on the plan. ## Technical case files (sanitized engagements, scoped and driven end to end) ### Case 01: On-prem to cloud transformation for a manufacturer (Same client as Case 03 and the field note "Stop replacing servers. Start eliminating them.") - Environment: manufacturing company; five Windows servers and two NAS units on-prem; OneLogin SSO alongside on-prem Active Directory; LOB CAD, labeling, and accounting apps. One aging server existed only to feed a legacy MS-DOS CNC machine over SMB1/NTLMv1. - Problem: aging on-prem footprint with baked-in security liabilities; identity split between OneLogin and on-prem AD; cloud-first ambitions blocked behind end-of-life hardware. The reflex answer was to replace the servers with newer servers. - Action: scoped a transition to the Microsoft 365 cloud stack instead of a hardware refresh. Migrated identity off OneLogin into Entra ID and consolidated SSO; moved Active Directory to Entra and brought workstations under Entra join and Intune with device-based Conditional Access; moved CAD/labeling software to vendor cloud licensing; relocated file shares to SharePoint/OneDrive and cold NAS archives to Azure blob storage; isolated the unavoidable legacy CNC share on a segregated VM. The aim was elimination, not replacement. - Outcome: migration came in roughly cost-neutral vs. buying a new host and storage, but bought far more availability, security, and scalability. The payoff proved itself when the client opened an overseas production facility (Case 03): the cloud foundation meant the new site needed only a connectivity layer, with no flying out or rebuilding a server stack on site. ### Case 02: Isolating a legacy ERP that couldn't be retired - Environment: construction company running a Windows Server 2008 R2 VM hosting SQL databases for an archival ERP/accounting platform and an in-house job-tracking system. Newest data ~3 years old but still referenced for open/unpaid jobs, so it couldn't be switched off. - Problem: an unsupported, end-of-life server can't safely sit on a production network, but it couldn't be decommissioned either. A clean OS + SQL upgrade on new hardware was scoped but cost-prohibitive: the ERP vendor required ~9 years of back-dated support licensing. - Action: chose containment over replacement. Segregated the VM onto its own isolated network segment permitted only to authenticate against Active Directory and back up to the BDR appliance; provided controlled remote access through a separately segmented Windows 7 jump VM able to reach only AD and the 2008 R2 server. - Outcome: business-critical reference data and access preserved at a fraction of the upgrade cost, with the unsupported system removed as a lateral-movement risk. A networking solution to what looked like a licensing-and-hardware problem. ### Case 03: Greenfield secure network for an overseas production site (The overseas expansion of the manufacturer in Case 01.) - Environment: brand-new international production location (~10 users, ~30 devices), no existing infrastructure beyond cabling. Because Case 01 had already moved the business onto Microsoft cloud services, the site needed a secure local network and direct cloud access, not a tunnel back to headquarters. - Problem: stand up a secure, supportable, centrally managed network for a remote international site with no local IT, while the ISP and static IP were unknown until the lease was signed and physical install would be done by non-technical staff on site. - Action: designed the architecture and bill of materials around a cloud-first access model. Early scoping assumed a site-to-site VPN back to HQ, but as the cloud migration completed that requirement fell away: users reach company resources directly through Microsoft 365, gated by device-based Conditional Access so only managed, compliant devices connect, removing an entire international VPN boundary from the attack surface. On site: a Sophos XGS firewall as the security edge, three VLANs (wired, internal WiFi, isolated guest) with explicit inter-VLAN policy, centrally managed UniFi switching and APs, and a UPS sized for graceful shutdown. The whole stack was staged and lab-tested in the US before shipping, with an installation runbook and diagnostics for non-technical hands. - Outcome: a remote international site that came online securely with minimal on-site intervention and a smaller attack surface than a traditional VPN-connected branch, plus a documented, repeatable model for future site expansion. ### Case 04: Identity & Intune standardization for a behavioral health clinic - Environment: behavioral health clinic, 373 managed workstations on a split identity model: 158 Entra ID joined but authenticating through Azure AD Domain Services, 215 authenticating natively through Entra ID; a finance server and file shares behind the same AAD DS dependency; DNS configurations drifting across devices to accommodate it. - Problem: two parallel authentication paths producing inconsistent sign-in behavior, dual-model troubleshooting, and Conditional Access / device compliance that couldn't be enforced consistently; the AAD DS dependency blocked cloud-first security work behind it. - Action: audited authentication state across all 373 workstations, validated Intune enrollment and policy readiness, tested Conditional Access in report-only mode, then ran a phased migration (20 to 30 device pilot, then staged waves with rollback triggers) to native Entra ID authentication; unified Conditional Access and compliance baselines in Intune; decommissioned AAD DS for workstation auth; standardized DNS to Entra-aligned patterns; sequenced profile migrations to avoid corruption; delivered support enablement and runbooks. - Outcome: a single standardized authentication path across all 373 endpoints, AAD DS retired, consistent security policy enforcement, simpler support workflow, and the legacy blocker to further cloud/security work removed. ### Case 05: Securing the IT/OT boundary for critical infrastructure - Environment: municipal client running a SCADA system for critical infrastructure, plus a multi-building HVAC and building-automation (BMS) environment across several facilities. The control systems themselves (PLCs, controllers, application logic) are owned and operated by specialist OT vendors, as is standard in OT/ICS. - Problem: OT environments are attacked or fail at the boundary between the corporate IT network and the operational network (segmentation, remote access, availability), and that boundary is the layer the system vendors don't own. The job is to secure and sustain it without obstructing the vendors who operate the systems inside it. - What he owns (honest scope): the network architecture and security boundary around the vendor-managed OT systems. Designs and maintains segmentation isolating SCADA/BMS networks from the corporate environment, governs the controlled remote-access model vendors use, builds the high availability monitoring and control require, and sets the demarcation of responsibility (vendor controls inside the system; he governs around it). The control logic stays with the OT specialists by design. - Outcome: critical municipal infrastructure and multi-building systems that stay monitored and available, with the highest-risk layer (IT/OT boundary and remote access) segmented, governed, and owned rather than left flat or over-trusted to a vendor. ## How a roadmap initiative is structured Each initiative is a single scoped change, written up in nine sections: (1) Business Purpose, (2) Current State, (3) Desired Outcome, (4) Dependencies & Preconditions, (5) Risks & Considerations (each with a mitigation), (6) Unknowns / Validation Required (ranked by whether they block planning or scoping), (7) Scope of Work (phased, with an explicit out-of-scope list), (8) Assumptions, (9) Bill of Materials (specific models and licensing, each justified). The newer format runs close to ten pages. A lazy initiative is a finding in a costume ("the firewall is end of life" is a ticket, not an initiative); a good one is where the risks section changed the plan, the unknowns section sent you back to the client, and the BoM reflects a defensible decision. Initiatives then sequence into an 18-month roadmap via dependencies (hard constraints) and the roughly 60-point business-context index (everything else), with years 2 to 5 given a line of sight rather than false precision. ## Free tool The Alignment Diagnostic (https://align.dallaspedersen.tech): a free, deterministic technology-roadmap tool. Asks 34 plain-language questions about how a business actually runs (no login, no sales call) and returns a directional IT roadmap in about 15 minutes. Built as a personal-time prototype; see the field note below for the full story and disclosures. ## Field notes (full articles at https://dallaspedersen.tech/field-notes/) - Why I built the Alignment Diagnostic (https://dallaspedersen.tech/field-notes/the-alignment-diagnostic.html): the origin story behind the free roadmap tool above, the timeline it was built on, and full disclosure of what it is and isn't. - Anatomy of a roadmap initiative (https://dallaspedersen.tech/field-notes/anatomy-of-an-initiative.html): the nine-part initiative write-up structure and how initiatives become an 18-month roadmap. - Scoping the execution: the design work nobody sees (https://dallaspedersen.tech/field-notes/scoping-the-execution.html): the technical breadth of figuring out HOW to execute (architecture, sizing, dependency mapping, BoM), the design-desk work the function absorbs, with two real examples. - Stop replacing servers. Start eliminating them. (https://dallaspedersen.tech/field-notes/eliminate-dont-replace.html): why a newer server hosting the same problem removes zero support tickets; optimize for elimination. - The best roadmap item I scoped this quarter cost the client $0 (https://dallaspedersen.tech/field-notes/zero-dollar-roadmap.html): the vCIO incentive problem; the best recommendation isn't always the expensive one. - Why the vCIO model is broken at most MSPs (https://dallaspedersen.tech/field-notes/vcio-model-broken.html): most vCIOs operate from lifecycle-refresh thinking or sales quotas; the deeper problem is how the role thinks about clients. - The difference between managing technology and governing it (https://dallaspedersen.tech/field-notes/managing-vs-governing.html): managing hits KPIs; governing makes decisions on a framework instead of vibes. - Too deep is not an argument (https://dallaspedersen.tech/field-notes/too-deep-is-not-an-argument.html): a 110-question assessment; you can't make good long-term decisions for a business you don't understand. - Momentum without visibility is a liability (https://dallaspedersen.tech/field-notes/momentum-without-visibility.html): strategic work nobody can see is the easiest thing in the building to pause. - Hire people better than you, then actually let them be better (https://dallaspedersen.tech/field-notes/hire-people-better.html): what "better" actually means when you hire above yourself. - AI isn't a strategy. Neither is avoiding it. (https://dallaspedersen.tech/field-notes/ai-isnt-a-strategy.html): both the AI-selling and AI-avoiding camps in the MSP space make the same mistake. ## Background - 15+ years in the MSP / IT industry, since 2011 (started at 19). Roles across the stack: technician, engineer, owner, department head. - Founder & owner of an independent MSP (2020 to 2025); closed it for a better opportunity, not failure. - Operator of five additional businesses: a social media marketing agency (sold going into 2025), residential real estate, a home-services / housekeeping business, an RV rental fleet (Class B and Class C motorhomes), and an engine carbon-cleaning automotive service. None required IT expertise; all required systems thinking. - Based in Utah.