Identities and trust boundaries
First it must be clear which accounts, groups, services and administrative boundaries exist. Otherwise unclear responsibilities or implicit trust relationships are carried into the target unnoticed.
- User, service and administrative accounts
- Groups, delegations and privileged roles
- Trusts and organisational responsibilities
DNS, sites and replication
Active Directory depends directly on name resolution, the site model and replication. These foundations must be matched against network paths, firewalls and operating locations.
- DNS zones and forwarders
- Sites, subnets and domain controllers
- Replication paths and time windows
GPOs, permissions and applications
Applications and operating processes often use groups, attributes, paths or policies that do not show up in a pure object inventory. This usage determines the sequence and the scope of the pilot.
- GPO links and filters
- File, application and service permissions
- Attributes, interfaces and technical accounts
From assessment to a controlled path
The assessment is translated into a phase model with pilot, transition rules, checks and fallback points. The public project evidence shows integration and recovery contexts without disclosing confidential target architectures.
- Prioritised dependencies
- Pilot and coexistence rules
- Check, approval and handover points
Matching project evidence
July 2022 — March 2023
Volkswagen
I analysed heterogeneous Microsoft environments and developed integration paths for Active Directory, GPO, Intune and MECM.
June 2019 — October 2019
Eurofins
After a ransomware attack I developed a recovery concept and a controlled migration path to a newly built AD structure.
May 2014 — June 2015
Overland Storage / V3 / Sphere 3D / Tandberg Data
I coordinated the technical EMEA integration of several sites into a new global corporate environment.
Every AD migration starts with the uncomfortable inventory: trusts, permissions, DNS, replication. Skip it, and you migrate your problems along with everything else.
View Active Directory & Recovery →