Eurofins · June 2019 — October 2019
Senior System Architect
After a ransomware attack I developed a recovery concept and a controlled migration path to a newly built AD structure.
Identity Infrastructure · Freelance Senior System Engineer
Every AD migration starts with the uncomfortable inventory: trusts, permissions, DNS, replication. Skip it, and you migrate your problems along with everything else.
For IT leaders, recruiters and project agencies · Germany and DACH
By Rizwan KhanTechnically reviewed: 1 Aug 2026
I analyse organically grown Active Directory environments and translate technical and organisational dependencies into controllable integration or migration paths. I keep assessment, target design, pilot, implementation and operational handover clearly separate.
In recovery and integration scenarios the focus is on traceable trust boundaries, GPO structures, permissions, DNS and replication dependencies, and a migration path that takes ongoing operations into account.
Eurofins · June 2019 — October 2019
After a ransomware attack I developed a recovery concept and a controlled migration path to a newly built AD structure.
Volkswagen · July 2022 — March 2023
I analysed heterogeneous Microsoft environments and developed integration paths for Active Directory, GPO, Intune and MECM.
Overland Storage / V3 / Sphere 3D / Tandberg Data · May 2014 — June 2015
I coordinated the technical EMEA integration of several sites into a new global corporate environment.
Hapag-Lloyd · March 2012 — April 2012
I designed Active Directory, replication, GPOs and DNS for container ships with intermittent network connectivity.
Stadt Lübeck · February 2012 — March 2012
I analysed open issues in a newly built Active Directory domain and coached the administrators on the live system.
UKE Hamburg · January 2010 — March 2010
I analysed complex ACL, GPO and folder redirection issues and automated access control via user attributes.
Klett Verlag · October 2013 — May 2014
I combined building an SCCM platform with the subsequent modernisation of Active Directory, file services and Exchange.
Among other things: domain and site structure, DNS, replication, GPOs, permissions, applications, identity flows and operational responsibilities.
No. Only confirmed areas of responsibility and abstracted approaches appear publicly, without sensitive architecture details.
Confidentiality boundary: only confirmed areas of responsibility and abstracted approaches appear publicly. Client-specific architecture details remain unpublished.
Insight · reviewed 2026-08-01
Which domain, DNS, GPO, permission, application and operational dependencies must be transparent before an Active Directory migration.
A short description of the starting point, goal and timeframe is enough for a first technical conversation.