Azure Adfs/b2c Architect Resume
Atlanta, GA
SUMMARY:
I am an innovative Senior Solution Architect/ Engineer, offering 20 years’ experience, specializing in Windows 2000 - 201 6 enterprise migrations, corporate acquisitions/divestitures, and project management. I have been involved in over 50 migration projects, large and small, with the largest being more than 150,000 users. Experience includes Banking/Finance, FDA Regulated Food and Drug, Government, Oil/Gas, Distribution/Shipping, and Fortune 10 corporate environments.I have broad technical knowledge across multiple platforms, and an exceptional work ethic. I work as many hours as it takes to meet deliverables, without billing the client. I do not miss deadlines, and do not ever sit around if there is a lull in the project. To stay productive, I find other areas to use my skill set. The recommendations I have received on LinkedIn from colleagues and managers speaks of this.
EXPERTISE AREA:
- Certified and experienced in planning and implementing Windows 2000 to 201 6 Active Directory, desktop (BDD), and server migration projects, with over 10000 hours as project management
- Created planning, design, testing, and implementation procedures for Active Directory projects (upgrade and migration), co-existence scenarios, cloud based Azure solutions, corporate acquisitions/transitions/divestitures, security solutions, AD Sites and Services remediation, domain and OU organization, and Group Policy design/remediation
- Designed security and system integrity solutions for physical/virtual resources, pre and post migrations
- Certified and experienced in administering, monitoring, training, and troubleshooting most aspects of physical/virtual enterprise infrastructures
- Extensive testing of HP, IBM, and Dell servers, workstations, and laptops. Comparisons included costs, ease of deployment, performance, setting up hardware RAID (servers), knowledge of troubleshooting, remediation, planning, and deployment
- Certified and experienced creating IDM Solutions, focusing on provisioning/deprovisioning accounts for on-boarding/off-boarding, management of groups and users, who owns resources/applications, what department users belong too, what is added based on the HR system data, administration, etc.
TECHNICAL SKILLS:
- Windows NT4.0 - 2016 OS/Active Directory
- ADFS 2.0/3.0
- ADLDS
- RADIUS/IAS
- SCCM
- Virtualization
- Office 365 (ADFS, MS Azure AD Connect sync) SaaS
- DNS (Dynamic, Unix/BIND, QIP)
- DFS (Stand-alone, Domain Based)
- DHCP, IPAM, WINS, RRAS, TCP/IP, SNMP
- MS Azure implementations
- Proxy Server, Index Server, Site Server, ISA and IIS
- Security
- Windows 2000-201 6 Terminal Services, RDP
- Windows Load Balancing & Clustering, NLB, wlbs.exe, MSCS, Highly Available Web Farms
- Office ( 97 - 201 6), Visio, Veritas, ARCServ, NetBackup, ZenWorks, PowerQuest, Ghost, SMS, RightFax, Shiva, Sophos, McAfee, Lotus Notes
- UNIX/Linux (Samba/Winbind/Centrify), AS400 LDAP authentication to Microsoft Active Directory
- HP, Dell, IBM, & Custom Built Physical/VM Servers
- Exchange 5.5 - 2016
- Citrix, XenApp, XenDesktop
- Identity Management: MIM/FIM, ARS, Custom
- HIPAA, Sarbanes-Oxley
- VSphere up to 5.X and MS Virtual Server
- PowerShell Expert
- Migration Tools Quest/Dell, BindView, NetIQ, ADMT
- BYOD Solutions IPhone, Android, IPad, Windows
- BDD Windows XP to Windows 10
PROFESSIONAL EXPERIENCE:
Confidential, Atlanta, GA
Azure ADFS/B2C Architect
Responsibilities:
- Designed, tested, and configured custom Azure ADFS and B2C environment for FISERV customers to access Service Now with social email accounts
- Created Dev, QA, and Production instances of Service Now to comply with FISERV requirements for a complete overall solution
- Implemented MFA solution to include registered cell phones for clients, and email based password reset options through B2C
- Implemented Fiserv Active Directory Authentication to Service Now through B2C cloud services
- Designed DR solution to comply with failover requirements and 99.999% (5 “9’s”) uptime
- Worked with the network team to load balance firewalls across two Azure data centers for complete redundancy
- Documented and trained completed solution and continuing support for post deployment support
Confidential, Chicago, IL
Active Directory Architect/SME/Engineer
Responsibilities:
- Assessment and implementation of Active Directory Sites and Services remediation plan. This included a full subnet overview, NO CLIENT SITE netlogon.log DC review, working with the network/SCCM teams to determine the appropriate scopes, physical location, security boundaries, and authentication requirements.
- Created automated/unattended process for DC rollouts using PowerShell to pre-install windows features/rolls, server promotion and post validation for compliance/security. This included the appropriate ITIL, SQ, and STD, documentation for the EUC.
- Designed, tested, implemented a global upgrade of Windows 2003 to Windows 2012 R2 Active Directory on new VMs, meeting security requirements, FDA regulations, and validated systems. This included full redesign and migration of “split-scoped” DHCP/IAS off the 2003 DCs, and utilizing 2012 R2 DHCP/RADIUS true failover to regional hubs in EMEA, APAC, LATAM, and the US on different non-DC 2012 R2 servers.
- Created a custom process for removing retired 2003 DC’s at sites with new 2012 R2 DCs deployed. This mitigated outages of hard-coded AD Integrated applications/DNS, and bypassed the “shut it down, and see who screams” method.
- Integrated multiple external vendor applications to ADFS 2.0 in order to enable seamless SSO capabilities
- Designed the ADFS 2.0 migration to ADFS 3.0 on Win 2012 R2 for new datacenter. This allowed multiple authentication methods (forms-based/integrated/pass-through), and new features, based on application security requirements and internal/VPN/external connections.
- Created multi-factor authentication process for SSO applications to use registered cell phones, email, and computers. Each user created a designated PIN for the first factor, and used integrated AD for the second.
- Designed and implemented a custom user and group share migration process of over 70TB of data from multiple aging 2003 clusters to Windows 2012 R2 clusters, successfully navigating paths longer than 260 characters, admin/owner issues, and validating zero data loss.
- Implemented ADLDS, which allowed safer SSL application based LDAP queries against synchronized, Active Directory, User, and Group objects
- Migrated a Stand-alone DFS infrastructure to a Domain based 2012 R2 DFS infrastructure
- Implemented Forest Trust with Confidential and DNS design on the Hospira side to prepare for the corporate acquisition of Hospira by Confidential
- Supported/designed SCCM security boundaries. This includes client, software, and file deployments, Working with SCCM Teams to plan, deploy, and manage distribution points, Planning and creating security boundaries, Creating and managing the GPOs for both Clients and Servers, Writing trigger/response PowerShell scripts for SCCM
- Created migration process documentation, presented designs to the ARB, and created ITIL SQs, and SOPs
- Lead/SME on the “acquired” side of the Directory Services integration, in the acquisition of Hospira by Confidential . Acknowledged by Confidential as the best/smoothest day 0/1 integration in Confidential ’s history, with the least amount of issues, and zero user impact.
- Lead/SME for all LDAP, DNS, LDS, and Federated services during the Data Center migrations from three Hospira Datacenters, to two Confidential Datacenters.
- SME for planning, testing, and implementation of LDAP (Active Directory, Unix/Linux, AS400, ADLDS, Federated Services, etc.), DNS, DHCP, and RADIUS at legacy Hospira sites, to mitigate issues, and transition to a new “ Confidential -ized” infrastructure. This included IP conflict resolution, cross-forest authentication, and resource access, required during the transition to new Confidential standards, hardware (laptops, servers, printers, etc.), and user migrations.
Confidential, Atlanta, GA
Active Directory Migration Architect/SME
Responsibilities:
- Designed, Tested, and implemented a custom Migration process, for the consolidation of two Forests into one, which provided a centralized management system, after the corporate acquisition.
- Crated the provisioning process for all Site GPOs, for a seamless transition to the new forest.
- Created and represented a custom change control process for the migration
- Developed a quality control process, which checked, and validated the migration for Sites, Servers, Users, and other domain services (File/Print, DHCP, DNS, etc.) were ready to proceed.
- Created custom PowerShell/WMI scripts, to provide higher rates of success during AD object migrations.
- Designed and built a custom ADMT server/process for use with the migration.
- Created user provisioning/deprovisioning process during, and post, for the migration.
- Created all migration processes, and standards documentation, for the migration/acquisition
- Provided/presented migration statistics, issues/resolution, and deliverables to leadership, detailing user, group, and physical device success percentages, tracking milestones for what had been migrated or was still in need of migration.
- Provided end-to-end support for the migration of all the directory objects, from the source, to the target domain/forest.
- Provided coaching, training, and mentoring from a technical perspective, to the migration team of 10 staff positions.
Confidential, Atlanta, GA
Active Directory Migration SME
Responsibilities:
- Active Directory Consultant for global side-by-side upgrade of Windows 2003 R2 to Windows 2008 R2 project
- Created implementation and test strategy for the upgrade of 3 forests to Windows 2008 R2
- Created implementation and test strategy for the upgrade of all Quest products (ARS, InTrust, Change Auditor, Spotlight on AD, Reporter, and RMAD FE)
- Planned and tested the Office 365 integration with MS Azure AD for the CCR and KO merger and decommissioned the Office 365 infrastructure at CCR ( Confidential ). This included deprovisioning/decommissioning the Azure Domain Controllers located at Microsoft, and integrating authentication and email to KO Office 365 infrastructure at KO.
- Designed and Implemented Active Directory “Role Based” security model
- Implemented and tested new GPO’s
- Confirmed compatibility and/or tested “gold” and “silver” tier applications with Windows 2008 R2 functional level
- Decommissioned Confidential .com internal domain
- Created strategy for KO and CCR merger
- Cleanup of Stale and “un-used” objects
- Coordination with application owners with specific DC pointers to new Load Balancer
- UNIX platform testing and implementation from VAS to QAS
- Created test environment to emulate policies and procedures for the upgrade
Confidential, Houston, TX
Active Directory Migration SME
Responsibilities:
- Lead Active Directory Consultant for global upgrade to Windows 2008 R2 project
- Designed and Implemented Active Directory “Role Based” security model and monitoring
- Backup consultant for Exchange 2010 upgrade from Exchange 2003
- Created custom upgrade and migration solutions for each global location based on individual goals and requirements
- Design, Testing and Implementation Consultant for Confidential Product Suite. These include Active Roles Server (ARS), Group Policy Management Console (GPMC), ARS with Quick Connect, and Spotlight
Confidential
Principle Consultant
Responsibilities:
- Design, Testing and Implementation Consultant for Confidential Product Suite. These include Active Roles Server (ARS), Group Policy Management Console (GPMC), ARS with Quick Connect, Spotlight, etc.
- Engaged with multiple clients on IDM/IAM solutions using ARS
- Designed and Implemented IDM Active Directory “Role Based” security model and monitoring
- Designed and Implemented Active Directory synchronization for IDM - MIIS and SQL with HR systems for SSO solutions
- Created custom solutions for each client based on individual goals and requirements
- Developed client relationships and acted as liaison between project sponsors and Quest Sales and Engagement Managers
- Designed and implemented several migrations from NDS, GroupWise, Active Directory 2000/03, and Exchange to Active Directory 2008 and Exchange 2010.
Confidential, Houston, TX
Project Manager/Migration SME/Technical Lead
Responsibilities:
- Global Windows XP SP2 Business Desktop Deployment (BDD) project manager for migration of over 9000 desktops to a single universal platform
- Managed the scheduling of the rollout to global locations with considerations for business shipping and personnel shifts
- Managed the application discovery, packaging and distribution process to standardize all desktops with “base” applications and distribute “approved” applications to necessary PC’s
- Managed the SMS design, test, build, and distribution process for the base image and approved applications
- Implemented a custom application to scan individual stations PC’s to determine users, PC’s, and applications needed from the approved application list
- Managed six (6) “Coordinators” for contacting stations, scheduling any “pre-deployment” and deployment tasks as well as handling post migration issues and lessons learned
- Created custom training materials that included hand-outs and FAQs to prepare users for the upcoming migration as well as training for helpdesk and administration staff for handoff preparation
Confidential, Plano, TX
Active Directory Migration SME/Technical Lead
Responsibilities:
- Migrated 380 application servers from the primary NT 4.0 Domain to Windows 2003 Active Directory. This included 180 Citrix applications from 1.8 and XP in 2 farms
- Coordinated migration with Change Management Board and application owners with a no interruption to service policy
- Migrated 8 NT 4.0 domains into a single global Windows 2003 Active Directory environment for North and South America
- Migrated 3 Novell trees into a single global Windows 2003 Active Directory environment for North and South America
- Created a new Active Directory Integrated DNS environment, which had to be fully functional with the previous UNIX based environment before, during, and after migration with no interruption to service
- Designed and implemented all security (Sarbanes-Oxley, user and computer), logon scripts, and monthly Microsoft Updates policies to comply with Cadbury Standards
- Combined 11 separate corporate NT and Novell environments including Mott's, Canada Dry, Halls, Trident, Dentyne, Bubblicious, Trebor, Bassett, Dr Pepper/7 Up, Snapple and Orangina into a single Active Directory Structure
- Created and coordinated testing requirements for application integration into Active Directory including planning, personnel, scheduling, documentation and qualifications for completion/sign-off
Confidential, Houston, TX
Project Manager
Responsibilities:
- Created project plan, milestones and deliverables to migrate from Novell NDS to Windows 2003 Active Directory
- Created Sarbanes-Oxley compliance plan for migrating financial servers into the Active Directory environment from stand-alone and NT 4.0 based systems
- Managed project plan, team leads and lead the PMO team for Networking, Desktop, Infrastructure, and Messaging for the Windows migration initiative
- Created Gap analysis to determine best course of action for the migration and meeting Sarbanes-Oxley compliance
- Designed Windows 2003 Active Directory environment and schedule to comply with corporate goals and standards and to meet deadlines determined by Sarbanes Oxley project deadline
Confidential, Houston, TX
Active Directory Architect and Technical Lead
Responsibilities:
- Designed new global architecture of BP for over 120,000 users and 6,000+ servers around 5 primary and 14 sub control points. The control points were: Authentication - NTP, DNS, Active Directory; Configuration Management - OS Construction, Update/Upgrade Process; Monitoring - Global Monitoring Center Design, Trending, Inventory; Security - Compliance, Internet Access Control, Passwords, Access Control Groups, Hot OS Backup; High Availability - Clustering
- Technical Lead for Authentication and Configuration Management primary Control Points being a backup resource and reference for the other 3 primary control points
- Phase I included Current State, Gap Analysis, and Requirements. The processes for phase I was a thorough interview process with every business unit to determine its requirements and current state. The team then created a Gap Analysis on the 14 control points around these requirements and presented its findings to the Technical Advisory Board for moving to the design phase.
- Phase II included the design from the findings in the Gap Analysis. The major function of the design phase was to implement the requirements into 2 new Mega Datacenters and 3 Micro Datacenters from over 100 regional locations. The motto of the project was “World Class Organization”.
- Phase III was the proof of Concept. This focused on a long term goal structure with a 5 year plan. Each technical lead of the respective control points determined what must be done to prepare for the Mega Data Centers and what processes must be in place for the implementation of the design
- Tested each proposed design control point with emphasis on functionality, response, cost, resources and impact to the current environment. Each phase of the project was designed around following the current Sarbanes-Oxley requirements
Confidential, Fredericksburg, VA
Active Directory Architect and Project Manager
Responsibilities:
- Developed Active Directory Windows 2003 planning and testing requirements for corporate move to another complex
- Created functional testing to mirror the current production environment and encompass the needs for the new deployment requirements
- Designed AD environment to use FastLane from Quest to migrate NT 4.0 domains to Windows 2003 and Active Directory
- Designed Exchange architecture to use FastLane to move Exchange 5.5 to a multi front-end and network Load Balanced (NLB) Exchange 2003 environment
- Designed the new AD architecture to assimilate a separate Windows 2000 forest necessitated from a corporate purchase of another company
- Developed test plans, migration strategy, project plan, risk assessment and priority for the move and migration
Confidential, Houston, TX
Active Directory Project Manager and Citrix Consultant
Responsibilities:
- Implemented Windows 2003 Active Directory into MD Andersons 13000 user and 80 Domain and Workgroup environment
- Created HIPAA Compliance and Sarbanes-Oxley plan for moving patient information access requirements
- Created the plan to set up direct communication with the Windows 2003 Active Directory Domain and E-Directory Environment
- Consolidated primary domains into a single OU based Domain and set up long term plans for moving secondary and “Critical” domains into the environment
- Created a new Citrix XP farm and consolidated 21 servers into six servers and organized the Citrix role in the MD Anderson environment.
- Moved a two year pilot program on Citrix into production in a 3 week window across departmental control
- Created new build procedures and SOP’s for new installations of Windows 2003
- Worked with another department to get standard image packages put together for rollout of servers to both organize and facilitate the installations
- Developed/implemented Domain and OU policies to comply with MD Anderson’s policies after security audit
- Created Active Directory structure to mirror as closely as possible the E-directory OU structure
- Coordinated on high/mid-level migration and backup procedures with all domain and federated groups within the MD Anderson environment on the Active Directory Structure and migration
Confidential
Active Directory and Windows 2000 Consultant
Responsibilities:
- Created comprehensive migration plan that encompassed design, security, planning and information gathering procedures for Windows 2000 and Active Directory Migration from Windows NT 4.0
- Developed security strategy for pre and post migration procedures
- Architect of Active Directory structure and migration procedures using NetIQ
- Organized Directory structure using Hyena
- Developed a test environment which exactly mirrored the production environment to fully test any procedures and applications before affecting production
- Worked with security, desktop services, and the information department to develop an AD structure so that each department could manage their own Organizational Units
- Provided extensive documentation on all procedures, from creating a simple user account, to how to create application distributions to multiple sites.
- Created ownership for each server group and a complete network diagram using Visio to better organize and document current network environment