Binod Maharjan โ€” Enterprise Identity & Infrastructure Engineering
INFRASTRUCTURE STATUS โ€” LIVE

Identity and infrastructure, engineered for zero downtime.

I design, harden, and migrate the hybrid Microsoft systems enterprises run on โ€” from Active Directory forests to multi-tenant Microsoft 365 and Azure environments.

SYSTEM STATUS ALL SYSTEMS OPERATIONAL
ACTIVE DIRECTORY Modernized to Windows Server 2025 ยท GPO baseline enforced HARDENED
EXCHANGE CU13 โ†’ CU15 patched ยท OWA secured with MFA PATCHED
MICROSOFT 365 1,000+ seats migrated ยท zero disruption 1,000+ USERS
AZURE 800TB transferred ยท S2S VPN on edge firewalls 0 DOWNTIME
The Vision
Most outages aren’t caused by attackers. They’re caused by infrastructure nobody re-evaluated after it shipped.

Domain controllers fall out of support, certificates expire quietly, conditional access rules drift from what they were meant to enforce. The work here isn’t a one-time migration โ€” it’s keeping identity and infrastructure current enough that they’re never the reason something breaks.

Infrastructure at scale

12
Years Experience
70+
Projects Delivered
500+
Users Supported
99.9
Uptime Achieved (%)

Enterprise technology stack

Active Directory Windows Server Exchange Microsoft 365 Entra ID Azure Intune SharePoint Teams GPO PowerShell Azure AD Connect Conditional Access MFA AD CS Office Online Server MailVault S2S VPN Azure Site Recovery Security Hardening

Certifications & training

๐Ÿ…
MCSE: Productivity Microsoft
๐Ÿ…
MCSA: Windows Server Microsoft
๐Ÿ…
Azure Administrator Microsoft
๐Ÿ…
Microsoft 365 Certified Microsoft

From assessment to hardened, hands-off infrastructure

Every engagement follows the same discipline, regardless of size: understand what’s actually running before changing anything, then migrate and harden in a sequence that keeps people working throughout.

STEP 01 โ€” ASSESS

Map the environment

Domain structure, GPOs, mail flow, tenant configuration, and accumulated technical debt โ€” documented before anything changes.

STEP 02 โ€” DESIGN

Architect the target state

Hybrid identity, network paths, certificate authorities, and migration sequencing โ€” scoped to the environment’s real constraints, not a generic playbook.

STEP 03 โ€” MIGRATE & HARDEN

Cut over in controlled phases

Staged execution with validation at each step, security baselines applied as part of the move โ€” not bolted on afterward.

STEP 04 โ€” OPERATE & SUPPORT

Hand over what’s maintainable

Documentation and runbooks for what changed and why, so the environment doesn’t depend on any one person to keep running.

Active Directory services

Active Directory is the root of trust for almost everything else in the environment โ€” sign-in, file access, mail flow, application permissions. When the directory drifts out of date, every system built on top of it inherits the risk. I keep it current, documented, and hard to compromise.

[AD-DS]

Infrastructure modernization

Modernizing core identity services by upgrading domain controllers to Windows Server 2025, raising forest and domain functional levels where safe, and retiring legacy hardware footprints without service interruption.

[GPO]

Policy hardening

Implementing standardized security baselines via Group Policy, then auditing for conflicting or orphaned GPOs that slow logon times or silently fail to apply across controllers.

[AD-CS]

Advanced AD-CS

Architecting an internal certificate authority hierarchy and issuing certificates for server encryption, authentication, and securing services like Office Online Server โ€” with renewal tracked before anything expires unnoticed.

[SEC]

Vulnerability remediation

Hardening the identity perimeter against the techniques attackers actually use โ€” Kerberoasting, stale privileged accounts, weak trust paths โ€” using lab environments to test fixes before they touch production.

Microsoft 365 & Azure

Cloud platforms change underneath you constantly โ€” new licensing tiers, deprecated connectors, shifting compliance requirements. The goal isn’t just migrating into Microsoft 365 and Azure; it’s building hybrid environments that stay stable as the platform keeps moving.

[M365]

Tenant migrations

Orchestrating large-scale migration projects โ€” 800+ TB across more than 1,000 users โ€” with mailbox, SharePoint, and OneDrive transitions staged so end users barely notice the cutover.

[INTUNE]

Endpoint management

Leveraging Microsoft Intune for MDM/MAM deployment, automated app rollout, and fleet-wide compliance policies โ€” so a lost or non-compliant device is contained, not a fire drill.

[ENTRA]

Hybrid identity

Designing secure architectures using Entra ID, Conditional Access, and MFA to protect the enterprise perimeter while still enabling single sign-on across on-prem and cloud apps.

[NET]

Cloud connectivity

Migrating Site-to-Site VPN connections to new edge firewalls with route-based configurations, validated in parallel with the old path before the cutover โ€” so connectivity never drops.

What clients say

“Binod took over our AD migration mid-stream after the previous contractor left. He documented everything, fixed the broken sync, and completed the cutover without a single helpdesk ticket.”

โ€” IT Director, Financial Services
Enterprise Infrastructure Lead

“Our Exchange environment was in a critical state โ€” certificates expired, queues backing up. Binod patched and stabilized it in days, then laid out a roadmap to modernize the whole stack.”

โ€” Head of IT, Healthcare Org
Infrastructure Manager

“The M365 migration was huge โ€” 1,200 users across multiple countries. Binod planned every phase meticulously. We had zero downtime and users barely noticed the transition.”

โ€” CTO, Global Manufacturing
Enterprise Technology

Before you reach out

A few things that typically come up early in a conversation.

Do you work with on-site teams or fully remote?+

Most Active Directory, Exchange, and Azure work can be done remotely over secure access. On-site time is scoped separately if hardware or physical network changes are involved.

How disruptive is a tenant or directory migration?+

Migrations are staged and tested in phases specifically to avoid disrupting mail flow or sign-in during business hours โ€” the goal on every project is zero perceived downtime for end users.

What happens after a migration or hardening project ends?+

You get documentation of what changed and why, plus a runbook for common operations โ€” so the environment doesn’t depend on me being reachable to keep running.

Can you work alongside our existing IT team or MSP?+

Yes. Most engagements involve handing architecture decisions and hardening work off to an internal team or MSP for day-to-day operation once the project is complete.

Let’s talk infrastructure

Active Directory, Exchange, M365, or Azure โ€” describe what you’re working on and I’ll follow up with next steps.

Your request has been submitted successfully. I’ll get back to you soon.