Identity, collaboration, and security — engineered for zero downtime.
I design, harden, and migrate the hybrid Microsoft ecosystem — from Active Directory forests and Exchange Server to multi‑tenant Microsoft 365, Azure, and Office Online Server. Zero‑trust principles, continuous compliance, and surgical cutovers.
Security isn’t an add‑on — it’s the foundation. Every domain controller, every mailbox, every tenant must be continuously validated.
Modern infrastructure demands Zero‑Trust identity, automated patch management, and incident response readiness. I keep Active Directory, Exchange, Office Online Server, and Azure aligned with NIST and CIS benchmarks — so your environment is resilient, auditable, and always up to date.
Infrastructure at scale
Enterprise technology stack
Certifications & training
Active Directory services
Active Directory is the root of trust. I provide domain modernization, fine‑grained password policies, Kerberos hardening, and AD CS — with automated health checks and disaster recovery drills. All aligned with CIS Level 1 & 2 benchmarks.
Infrastructure modernization
Upgrading domain controllers to Windows Server 2025, raising functional levels, and decommissioning legacy hardware. Implementing read‑only DCs for branch offices and securing replication with IPSec.
Policy hardening
Designing and deploying security baselines via Group Policy — including Windows Defender Firewall rules, AppLocker restrictions, and user rights assignments. Auditing GPOs for performance bottlenecks.
Certificate Services
Architecting a two‑tier PKI with offline root CA, issuing certificates for S/MIME, VPN authentication, and Office Online Server. Automated renewal with PowerShell scripts and monitoring.
Vulnerability remediation
Protecting against Kerberoasting, pass‑the‑hash, and privilege escalation. Implementing Protected Users group, Kerberos armouring, and regular entropy checks on service accounts.
Microsoft 365 & Azure
From hybrid identity to advanced threat protection — I build and operate Microsoft 365 tenants with conditional access, DLP, and Defender for Office 365. On Azure, I deploy infrastructure‑as‑code, Site Recovery, and secure networking.
Tenant migrations
End‑to‑end migrations of mailboxes, OneDrive, and SharePoint sites with minimal user impact. Using native tools and third‑party solutions for cutover, staged, or hybrid migrations — always with rollback plans.
Endpoint management
Deploying Intune for MDM and MAM, with compliance policies, conditional launch, and automated app deployment. Integrating with Defender for Endpoint for real‑time threat detection.
Hybrid identity
Configuring Entra ID Connect with pass‑through authentication, seamless SSO, and federation for legacy apps. Implementing Conditional Access policies with location, device, and risk‑based signals.
Cloud connectivity
Designing hub‑spoke network topologies in Azure, with S2S VPN and ExpressRoute failover. Using Azure Firewall and NSGs for micro‑segmentation and traffic inspection.
Exchange Server & Office Online Server
On‑premises Exchange remains critical for many organisations. I specialise in Exchange 2019 and the new Subscription Edition, with high availability, modern authentication, and integration with Office Online Server for document previews.
Exchange 2019 & SE
Deploying and upgrading Exchange Server 2019, implementing DAGs for high availability, configuring OWA and ECP with MFA, and integrating with Exchange Online for hybrid mail flow.
Office Online Server
Installing and configuring Office Online Server to enable browser‑based document editing and preview for SharePoint, Exchange attachments, and custom applications — with certificate management and load balancing.
Email archiving
Deploying MailVault for journaling and e‑discovery, with retention policies and GDPR compliance. Integrating with Exchange for seamless user access.
Mail flow & hygiene
Configuring transport rules, anti‑spam, and connector security. Monitoring message queues, implementing DMARC/DKIM/SPF, and troubleshooting mail flow issues across hybrid environments.
What clients say
“Binod took over our AD migration mid‑stream after the previous contractor left. He documented everything, fixed the broken sync, and completed the cutover without a single helpdesk ticket.”
“Our Exchange environment was in a critical state — certificates expired, queues backing up. Binod patched and stabilised it in days, then laid out a roadmap to modernise the whole stack.”
“The M365 migration was huge — 1,200 users across multiple countries. Binod planned every phase meticulously. We had zero downtime and users barely noticed the transition.”
Let’s talk infrastructure
Active Directory, Exchange, OOS, M365, Azure — or any combination. Describe your environment and I’ll follow up with a tailored plan.
📬 Email me
I respond within 24 hours. Include a brief overview of your current setup and goals.
📧 helpdesk@maharjan-binod.com.np