RKRizwan KhanDE

Identity Infrastructure · Freelance Senior System Engineer

Active Directory migration, integration and recovery

Every AD migration starts with the uncomfortable inventory: trusts, permissions, DNS, replication. Skip it, and you migrate your problems along with everything else.

For IT leaders, recruiters and project agencies · Germany and DACH

What it means in practice.

I analyse organically grown Active Directory environments and translate technical and organisational dependencies into controllable integration or migration paths. I keep assessment, target design, pilot, implementation and operational handover clearly separate.

In recovery and integration scenarios the focus is on traceable trust boundaries, GPO structures, permissions, DNS and replication dependencies, and a migration path that takes ongoing operations into account.

  • Active Directory assessment and target architecture
  • Domain, site and subsidiary integration
  • GPO, permission and delegation models
  • Recovery concepts after security incidents
  • Migration planning, pilots and technical handover

When support makes sense.

  • Domains, sites or subsidiaries need to be integrated
  • GPO, DNS, replication or permission dependencies are unclear
  • After a security incident a dependable recovery or migration path is needed

Concrete deliverables.

  • Assessment of trust boundaries, identities and technical dependencies
  • Phase model for pilot, migration, recovery and operational handover
  • Documented decision and fallback points

Matching project evidence

Eurofins · June 2019 — October 2019

Senior System Architect

After a ransomware attack I developed a recovery concept and a controlled migration path to a newly built AD structure.

Volkswagen · July 2022 — March 2023

Microsoft Solution Architect

I analysed heterogeneous Microsoft environments and developed integration paths for Active Directory, GPO, Intune and MECM.

Overland Storage / V3 / Sphere 3D / Tandberg Data · May 2014 — June 2015

Senior System Engineer

I coordinated the technical EMEA integration of several sites into a new global corporate environment.

Hapag-Lloyd · March 2012 — April 2012

System Engineer

I designed Active Directory, replication, GPOs and DNS for container ships with intermittent network connectivity.

Stadt Lübeck · February 2012 — March 2012

System Administrator

I analysed open issues in a newly built Active Directory domain and coached the administrators on the live system.

UKE Hamburg · January 2010 — March 2010

System Administrator

I analysed complex ACL, GPO and folder redirection issues and automated access control via user attributes.

Klett Verlag · October 2013 — May 2014

Senior System Engineer

I combined building an SCCM platform with the subsequent modernisation of Active Directory, file services and Exchange.

Frequently asked questions from projects.

What is checked before an Active Directory migration?

Among other things: domain and site structure, DNS, replication, GPOs, permissions, applications, identity flows and operational responsibilities.

Are confidential recovery details published?

No. Only confirmed areas of responsibility and abstracted approaches appear publicly, without sensitive architecture details.

Confidentiality boundary: only confirmed areas of responsibility and abstracted approaches appear publicly. Client-specific architecture details remain unpublished.

Further reading

Discuss your project context in confidence.

A short description of the starting point, goal and timeframe is enough for a first technical conversation.

Required fields are marked with *.

Your details are only used to answer your enquiry. Please do not send passwords or confidential client data through this form.