Projekterfahrung aus Cloud, Microsoft 365 & Azure
Project experience in Cloud, Microsoft 365 & Azure
Kompakt dargestellt nach Technologiebereichen: Der Fokus liegt auf Herausforderung,
Umsetzung und messbarem Mehrwert – ohne den Besucher mit langen Projektberichten
zu überladen.
Presented compactly by technology area: The focus is on challenge,
implementation and measurable value — without overwhelming visitors
with lengthy project reports.
Microsoft 365AzureExchangeBackupSecurityAutomation
Microsoft 365AzureExchangeBackupSecurityAutomation
Hinweis zur VertraulichkeitConfidentiality note
Die dargestellten Referenzen sind anonymisiert. Kundennamen,
interne Systemdetails und vertrauliche Informationen werden bewusst nicht genannt.
Auf Wunsch können weitere Projektdetails im persönlichen Gespräch eingeordnet werden.
The references shown are anonymized. Customer names, internal system details
and confidential information are intentionally not disclosed. Further project
details can be discussed in a personal conversation if required.
Migration einer bestehenden On-Premises-Exchange-Umgebung zu Exchange Online –
strukturiert geplant, kontrolliert umgesetzt und ohne produktive Ausfälle abgeschlossen.
Migration of an existing on-premises Exchange environment to Exchange Online —
planned in a structured way, implemented under control and completed without
production downtime.
Modernisierung einer unternehmensweiten Azure-Plattform mit standardisierten
Subscription-Strukturen, zentraler Governance und verbindlichen
Sicherheitsvorgaben.
Modernisation of an enterprise-wide Azure platform with standardised
subscription structures, central governance and consistent security
requirements.
Aufbau und Governance von 40 Azure Subscriptions
Standardisierte Subscription- und Plattformstrukturen
Ausgangslage:
Gewachsene Azure-Umgebung mit hohen Anforderungen an Skalierbarkeit,
einheitliche Governance sowie nachvollziehbare Sicherheits- und
Verantwortungsstrukturen.
Initial situation:
An organically grown Azure environment with demanding requirements for
scalability, consistent governance, and transparent security and
ownership structures.
Umsetzung:
Modernisierung der Azure Landing Zone mit standardisierten Subscriptions,
zentralen Governance-Richtlinien und verbindlichen
Sicherheitsgrundsätzen nach dem Zero-Trust-Prinzip.
Implementation:
Modernisation of the Azure landing zone using standardised subscriptions,
central governance policies, and consistent security requirements based
on Zero Trust principles.
Ergebnis:
Skalierbare und zentral steuerbare Azure-Plattform mit klarer
Mandantentrennung, konsistenten Vorgaben und standardisierten
Voraussetzungen für den sicheren Betrieb neuer Cloud-Workloads.
Result:
A scalable, centrally managed Azure platform with clear tenant
separation, consistent requirements, and standardised foundations for
securely operating new cloud workloads.
Aufbau einer segmentierten Azure-Netzwerkarchitektur und zentralen
Application-Identity-Struktur für sichere Verbindungen, kontrollierte
Zugriffe und einheitliches Single Sign-on.
Implementation of a segmented Azure network architecture and central
application identity structure for secure connectivity, controlled access
and consistent single sign-on.
Zentrale Verwaltung von rund 400 App Registrations
Security-first Hub-and-Spoke-Architektur
Segmentierte VNets und Subnets
Zentrale Routing-Steuerung über Route Tables
Einheitlicher Identity Provider und Single Sign-on
Central management of approximately 400 app registrations
Ausgangslage:
Komplexe Netzwerk- und Identitätsstrukturen mit steigenden Anforderungen
an Segmentierung, zentrale Steuerung und sichere Anwendungszugriffe.
Initial situation:
Complex network and identity structures with increasing requirements for
segmentation, centralised control, and secure application access.
Umsetzung:
Aufbau einer Security-first Hub-and-Spoke-Architektur mit segmentierten
VNets und Subnets, zentraler Routing-Steuerung sowie strukturierter
Verwaltung von rund 400 App Registrations. Ergänzend wurden ein
einheitlicher Identity Provider und Single Sign-on eingebunden.
Implementation:
Implementation of a security-first hub-and-spoke architecture with
segmented VNets and subnets, centralised routing control, and structured
management of approximately 400 app registrations. A unified identity
provider and single sign-on were also integrated.
Ergebnis:
Klar segmentierte und zentral steuerbare Azure-Architektur mit
nachvollziehbaren Anwendungsidentitäten, kontrollierten
Kommunikationswegen und standardisierten Zugriffsprozessen.
Result:
A clearly segmented and centrally managed Azure architecture with
transparent application identities, controlled communication paths, and
standardised access processes.