01 · Starting point
Situation
Reliable client operations first required a robust SCCM infrastructure. Core Microsoft services then had to be migrated to newer server generations without decoupling deployment, user access and messaging from one another.
Constraints
- Build and migration within a live Microsoft environment
- Dependencies between client deployment, AD, file services and Exchange
- Traceable documentation for operations and handover
02 · Responsibility
My scope of responsibility
I was responsible for the design, documentation and build of the SCCM environment and the subsequent AD, file server and Exchange migration, including GPO, MDT, certificate and rollout topics.
03 · Technical work
Documented scope of work
Key decisions
First create a controllable deployment foundation, then build the platform migration on top of it. A working SCCM and MDT structure reduced the risks for images, applications and tasks after the server migrations.
- I designed SCCM sites, collections, distribution points, reporting, Endpoint Protection, images and task sequences.
- I integrated MDT and automated validation, offline updates and language packs with PowerShell.
- I planned and supported AD, file server and Exchange migrations including FSMO roles, GPOs, certificates and mailbox moves.
04 · Technical context
Technology in use
SCCM
SCCM was part of the documented toolset in this Endpoint Management engagement.
MDT
MDT was part of the documented toolset in this Endpoint Management engagement.
Active Directory
Active Directory was part of the documented toolset in this Endpoint Management engagement.
Exchange
Exchange was part of the documented toolset in this Endpoint Management engagement.
PowerShell
PowerShell was part of the documented toolset in this Endpoint Management engagement.
Windows Server
Windows Server was part of the documented toolset in this Endpoint Management engagement.
05 · Factual basis
Evidence and limits
Endpoint deployment and core Microsoft services were modernised on a documented, jointly designed target architecture.
- Role
- Senior System Engineer
- Period
- October 2013 — May 2014
Lesson from the engagement
Deployment and core infrastructure should not be planned as separate programmes, because identity, applications and user transitions share the same dependencies.
Confidentiality note: Internal architecture and operating data of this engagement are not published.